User Tools

Site Tools


faq:gdpr_hosted_vpop3

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
faq:gdpr_hosted_vpop3 [2018/05/29 16:20] paulfaq:gdpr_hosted_vpop3 [2025/10/14 15:43] (current) paul
Line 1: Line 1:
 ======GDPR for hosted VPOP3 service====== ======GDPR for hosted VPOP3 service======
 +
 +(Since Brexit, the UK has "UK GDPR" instead of "EU GDPR", so this document refers to UK GDPR)
  
 Also see [[GDPR for VPOP3]] as most of that applies to the VPOP3 hosting service as well. Also see [[GDPR for VPOP3]] as most of that applies to the VPOP3 hosting service as well.
Line 8: Line 10:
  
 For our hosting services: For our hosting services:
-  - Data is held in the UK. Data is not transmitted outside of the EU except at your request or command (for instance VPOP3 supports backing itself up to the Amazon S3 data service. We don't set this up ourselves, but, if you set it up or request us to do so for you, then data will be transferred to Amazon S3 which may be outside of the EU).+  - Data is held in the EU or UK. Data is not transmitted outside of the EU/UK except at your request or command (for instance VPOP3 supports backing itself up to the Amazon S3 data service. We don't set this up ourselves, but, if you set it up or request us to do so for you, then data will be transferred to Amazon S3 which may be outside of the EU/UK).
   - **The exception to the above statement** is for sent or received emails as they are being delivered to the recipient(s). Obviously if you send an email message to a user in the USA, for instance, that email will eventually be transmitted to the USA, otherwise it would not be able to reach the recipient. Similarly, if one of your users is based outside of the EU and downloads email to their email client, that data is being transmitted outside of the EU.   - **The exception to the above statement** is for sent or received emails as they are being delivered to the recipient(s). Obviously if you send an email message to a user in the USA, for instance, that email will eventually be transmitted to the USA, otherwise it would not be able to reach the recipient. Similarly, if one of your users is based outside of the EU and downloads email to their email client, that data is being transmitted outside of the EU.
   - For the hosted VPOP3 service, the data we may hold is usernames & email addresses of your users, contact details of your users and contacts, email addresses & names of your contacts, email message data. All this data is provided by you, we do not add it ourselves except at your explicit request.   - For the hosted VPOP3 service, the data we may hold is usernames & email addresses of your users, contact details of your users and contacts, email addresses & names of your contacts, email message data. All this data is provided by you, we do not add it ourselves except at your explicit request.
Line 21: Line 23:
   - In the case of passwords being used illicitly and we discover this or are informed of it by you, we will reset the password to a new secure password, and inform you of this (if you don't already know).   - In the case of passwords being used illicitly and we discover this or are informed of it by you, we will reset the password to a new secure password, and inform you of this (if you don't already know).
   - The hosted VPOP3 servers run on shared servers. They are protected from being accessed by other users of the same server by Windows access restrictions (each hosted server runs as a different restricted user) and the message store databases and message archives are protected by individual login details, This means that there is no way for one customer to access another customer's data.   - The hosted VPOP3 servers run on shared servers. They are protected from being accessed by other users of the same server by Windows access restrictions (each hosted server runs as a different restricted user) and the message store databases and message archives are protected by individual login details, This means that there is no way for one customer to access another customer's data.
-  - We backup the hosted servers daily for disaster recovery purposes. The backups are stored in the UK and are kept for 2 weeks. Weekly backups are stored at an alternate site in the UK and are also kept for 2 weeks. On your request we can delete the backups of your hosted server, as long as you accept the risk of doing so.+  - We backup the hosted servers daily for disaster recovery purposes. The backups are stored in the EU & UK and are kept for 2 weeks. Weekly backups are stored at an alternate site in the EU and are also kept for 2 weeks. On your request we can delete the backups of your hosted server, as long as you accept the risk of doing so.
   - We do not have a Data Protection Officer because we are not required to do so under the GDPR regulations. If you want to contact us about data protection issues, contact support@pscs.co.uk   - We do not have a Data Protection Officer because we are not required to do so under the GDPR regulations. If you want to contact us about data protection issues, contact support@pscs.co.uk
   - Your data is not transmitted to other organisations/people except at your direct instruction. If you address an email to an external user this is classed as an "direct instruction". In this case your message data will be transmitted to other mail servers/companies as necessary for the message to reach the addressee. If you log in to your email account to view or send email from another organisation, then that is also classed as an "explicit request". In these cases, we believe that we have not "engaged" these other organisations as further Data Processors under GDPR Article 28 (2), so there is no need for prior written authorisation or contracts, and no continuation of liability once the data has left our control.   - Your data is not transmitted to other organisations/people except at your direct instruction. If you address an email to an external user this is classed as an "direct instruction". In this case your message data will be transmitted to other mail servers/companies as necessary for the message to reach the addressee. If you log in to your email account to view or send email from another organisation, then that is also classed as an "explicit request". In these cases, we believe that we have not "engaged" these other organisations as further Data Processors under GDPR Article 28 (2), so there is no need for prior written authorisation or contracts, and no continuation of liability once the data has left our control.
faq/gdpr_hosted_vpop3.1527610806.txt.gz · Last modified: 2018/11/14 10:44 (external edit)