This document sets out to explain how data (with a focus on personal data) is transferred, processed and stored by third parties outside of AWS, where our main cloud platform resides.
Customer support and success, email & web chat tool
| Audience | All users of CybSafe platform via the browser. |
|---|---|
| Address | 55 2nd Street, 4th Fl., San Francisco, CA 94105 |
| Data: | IP Address / Browser details, will track return visits. If provided: Email, name, customer conversations, company of employment. |
| Mechanism | Browser based js tool, using cookies, and HTTPS API |
| Retention | Anonymous interactions are held for 90 days only. Conversations / Identified leads or customers are kept indefinitely. CybSafe keep the 400-500 most recent. |
| Jurisdiction | US |
| Terms | https://www.intercom.com/terms-and-policies#terms |
| Privacy | https://www.intercom.com/legal/privacy |
| https://www.intercom.com/security |
Product analytics
| Audience | All users of Cybsafe platform via the browser |
|---|---|
| Address | |
| Data: | IP Address / Browser details / Internet usage monitoring. Not personally identifiable but Google can provide profiling in aggregate form if they have enough data. |
| Mechanism | Browser based js tool, using cookies |
| Retention | 26 months. After contract cease, client/user PII is removed/pseudo anonymised, but with test scores and usage stats retained. |
| Jurisdiction | EEA & US (we cannot guarantee which data centre this information might go to). |
| https://support.google.com/analytics/answer/7105316?hl=en | |
| Terms | https://privacy.google.com/businesses/processorterms/ |
| Privacy | https://www.google.com/analytics/terms/dpa/dataprocessingamendment_20160909.html |
| EU-US Privacy Framework | |
Email sending and measuring deliverability performance
| Audience | Any user intended to receive an email notifications. This excludes simulated email phishing |
|---|---|
| Address | Twilio, 101 Spear Street, First Floor, San Francisco, CA 94105 |
| Data: | Sendgrid are CybSafe's SMTP relay, Email address, names and account information can be placed in emails. To customer administrators, they can be sent information relating to and identifying their employee users. Sendgrid record mailbox delivery records, clicked links, metadata etc. |
| Mechanism | Email Relay (SMTP) |
| Retention | (Sendgrid quote) We retain email message activity/metadata (such as opens and clicks) for 365 days. We store bounce messages and spam reports (which may contain content) indefinitely, and we store minimal random content samples for 61 days. |
| Jurisdiction | US & Ireland |
| Terms | https://www.twilio.com/legal/tos |
| EU based | |
| Privacy | https://www.twilio.com/en-us/legal/privacy |
****Error Reporting platform