GDPR Compliance
Updated Jan. 6, 2022
YARDSAIL.COM is committed to protecting the privacy and security of personal information that we collect, use, and disclose in connection with our B2B service (the "Service"). We comply with the European Union's General Data Protection Regulation ("GDPR"), which regulates the collection, use, and disclosure of personal data of individuals located in the European Economic Area ("EEA").Data Controller and Processor
For the purposes of the GDPR, we act as both a data controller and a data processor. When we act as a data controller, we collect and use personal information of our customers and their employees for the purpose of providing the Service. When we act as a data processor, we process personal information on behalf of our customers in accordance with their instructions.
Lawful Basis for Processing
We rely on one or more lawful bases for processing personal information, including but not limited to:
- Performance of a contract with our customers or their employees
- Compliance with legal obligations
- Legitimate interests pursued by us or our customers
- Rights of Data Subjects
Under the GDPR, individuals located in the EEA have certain rights with respect to their personal information, including but not limited to:
- The right to access their personal information
- The right to rectify inaccurate or incomplete personal information
- The right to erasure (also known as the right to be forgotten)
- The right to object to the processing of personal information
- The right to data portability
We will respond to requests to exercise these rights in accordance with the GDPR.
Data Security
We implement appropriate technical and organizational measures to protect personal information from unauthorized access, disclosure, alteration, and destruction. We regularly review and update our security measures to ensure their effectiveness.
Data Transfers
We may transfer personal information to third-party service providers and partners who process personal information on our behalf or who assist us with the provision of the Service. We ensure that such transfers comply with the GDPR and other applicable data protection laws and regulations.
Data Breach Notification
In the event of a data breach that affects personal information, we will notify affected individuals and the relevant supervisory authority without undue delay, in accordance with the GDPR.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, or as required by law. We have established retention policies and procedures to ensure that personal information is not retained for longer than necessary.
Contact Us
If you have any questions or concerns about our GDPR compliance or our processing of personal information, please contact us at support@yardsail.com.
Effective Date: 1/6/2023