This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
faq:gdpr_hosted_vpop3 [2018/05/29 15:54] – paul | faq:gdpr_hosted_vpop3 [2018/11/14 10:45] (current) – external edit 127.0.0.1 | ||
---|---|---|---|
Line 16: | Line 16: | ||
- **The exception to the above statement** is if we have to access data to mitigate a serious problem. The usual circumstance for this is if one of your user's accounts is being used for sending spam, we will proactively check the outgoing message queue on your server to check if messages being sent are spam. We will notify you if this has happened. We do not look at individual message contents except at your request, but may look at the list of subject lines, and sender & recipient email addresses. These are not recorded or stored at all, except at your request. Again, these accesses are logged. | - **The exception to the above statement** is if we have to access data to mitigate a serious problem. The usual circumstance for this is if one of your user's accounts is being used for sending spam, we will proactively check the outgoing message queue on your server to check if messages being sent are spam. We will notify you if this has happened. We do not look at individual message contents except at your request, but may look at the list of subject lines, and sender & recipient email addresses. These are not recorded or stored at all, except at your request. Again, these accesses are logged. | ||
- In our company, only the senior technical support person (Paul Smith) has access to any of the data held on your hosted server. | - In our company, only the senior technical support person (Paul Smith) has access to any of the data held on your hosted server. | ||
- | - In the case of a data breach due to our fault we will contact the account contact we have for you with the details of the breach. | + | - In the case of a data breach due to our fault we will contact the account contact we have for you within 24 hours of discovery of the breach |
- Note that usernames & passwords are set by you, or at your explicit request. If we set passwords we will choose secure passwords, but they may be reset to less secure passwords by you or your users. In this case, there may be a data breach because of a discovered password. We will inform you if we discover this happening, but this is not our fault. | - Note that usernames & passwords are set by you, or at your explicit request. If we set passwords we will choose secure passwords, but they may be reset to less secure passwords by you or your users. In this case, there may be a data breach because of a discovered password. We will inform you if we discover this happening, but this is not our fault. | ||
- We strongly recommend that you use SSL/TLS in email clients/ | - We strongly recommend that you use SSL/TLS in email clients/ | ||
Line 24: | Line 24: | ||
- We do not have a Data Protection Officer because we are not required to do so under the GDPR regulations. If you want to contact us about data protection issues, contact support@pscs.co.uk | - We do not have a Data Protection Officer because we are not required to do so under the GDPR regulations. If you want to contact us about data protection issues, contact support@pscs.co.uk | ||
- Your data is not transmitted to other organisations/ | - Your data is not transmitted to other organisations/ | ||
+ | - Upon termination of the contract we will delete all your data within one week of termination where the termination was explicitly requested by you, or one month if not (eg on non-payment of an invoice). If you require it to be deleted sooner, please ask. We only store the data for this time after termination as a courtesy in case you need to recover the data or change your mind and decide to continue with our service. | ||
+ | - We will provide reasonable assistance to you to help you to meet your GDPR obligations. Note that you have almost as much access to your data as we do (except for backups) so we will not, for instance, search through emails to delete personal data on request, but we will advise/ | ||
+ | - We will allow for audits/ | ||