Skip to main content

GDPR

We have implemented all the technical and organisational measures (TOM)
Yes. we have implemented the Data Subject Access Rights Procedure
Yes. The Data Processing Agreements is in place.
Yes. The Data Processing Agreements is in place.
Yes. we conduct the Data Privacy Impact Assessments on annual basis and there are no high risk involved in handling the PII
formal data breach notification process is in place.
Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. We have implemented many technical controls to safeguard the customer data. For example - Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection services, Amazon CloudWatch, IDS/IPS etc.
We are GDPR compliant. Implemented the Data security and Personally Identifiable Information Policy
We have implemented the Data Subject Access Rights Procedure.
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller’s written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits.
Yes. It’s a part of the agreement.
We have implemented the GDPR Xoxoday is the data processor.
Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and make all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties.
We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls etc..
We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws. Attached the Xoxoday Data Subject Access Rights Procedure.
We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document.
We are GDPR compliant. And atatched the Data security and Personally Identifiable Information Policy
Attached the Data Subject Access Rights Procedure. Please visit here for Privacy policy - https://www.xoxoday.com/privacy-policy
We are GDPR Complaint and respect the data subjet access rights. We erase or delete the data upon request of the data subject or on the request of the customer upon termination of the contract. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places. Attached the Data Retention and Disposal Policy.
Xoxoday is Compliant with EU GDPR.
We are compliant with GDPR. We inform the customer within 48 hours, if there are any data breach as per the compliance requirements.
At Xoxoday we have appointed the DPO. Please click here to know more about Xoxoday GDPR - https://www.xoxoday.com/gdpr
Over 2 millions of customers across the globe trust us with their data security. We back ourselves up with robust data security and privacy practices that form an integral part of our product engineering and service delivery principles. Our comprehensive GDPR program is supported by key privacy principles — Accountability, Privacy by Design and Default, Data Minimization, Subject Access Rights, among others. Technology and operations related to the business are subject to regular sensitization programs. Please click here to know more about Xoxoday GDPR - https://www.xoxoday.com/gdpr
We have implemented the Data Subject Access Rights procedure (DSAR) 1. Personal data can be deleted based on a formal written request, with justification. 2. Xoxoday would delete the data within 30 days of receiving the request Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places. Attahed the Data Subject Access Rights procedure (DSAR)
Xoxoday is GDPR Compliant and shared the Data Protection Impact Assessment (DPIA) We are not required to submit the report to the Data Protection authority.
Xoxoday is compliant with GDPR
We offer EU Standard Contractual Clauses.
We support end users to Exercise their Rights as per the GDPR compliance requirements.
We are compliant with GDPR. We inform the customer within 48 hours, if there are any data breaches as per the compliance requirements.
In accordance with Data Protection Laws, we make necessary documents, Audit reports and certifications available to Controllers on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller’s written request and subject to the confidentiality obligations set forth in the Agreement, Xoxoday will make available to Controller a copy of Nreach then most recent third-party audits or certifications, as applicable.
We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We offer standard contractual clauses (SCC) or binding corporate rules to regulate transfers of data to non-adequate third countries.
We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
Attached the GDPR Data Protection Policy and Data Security Policy
AWS - We have deployed our application on AWS Virtual platform cloud. And AWS is GDPR, ISO 27001, SOC 2 certified organization.
We collect names, email IDs and Phone numbers. These are the mandatory information required to use the application platform.
Yes. We are GDPR Compliant
The application is deployed on AWS virtual platform cloud. We are a data processor as per GDPR and all the information is collected only throgh our application. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Notify data controllers within 48 hours of the breach or within stipulated time as agreed with the data controller
Yes
Yes
Yes
Yes. We have appointed DPO
No. The EU-U.S. Privacy Shield Framework is no longer a valid mechanism to comply with EU data protection requirements when transferring personal data from the European Union to the United States. Please visit here for more details - https://www.privacyshield.gov/Program-Overview
See Security Incident Reporting & Response Procedure attached We are GDPR Compliant. Our information security team and Customer support team will inform the POC of the customer via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have formally defined criteria for notifying a client during an incident that might impact the security of their data or systems. We notify within 72 hours as per EU-GDPR
Data Protection Training and Awareness – Indicate what awareness-raising controls are carried out with regards to colleagues We conduct Information security and Data protection awareness training as soon as new employees joined the organization and annually once for the old employees. The training material includes the below concepts – Information Security Objective How to handle and protect PII What is ISO 27001:2013 Confidentiality, Integrity, Availability and Privacy. Business and cyber security PDCA – Continual improvement General guidelines for security Visitor management Security guidelines Guidelines while using Xoxoday provided devices Password guidelines Email related guidelines Social media related guidelines Phishing attack and its types Information storage related guidelines Incident Management Business continuity management
We have implemented Security Incident Reporting & Response Procedure and tested annually. We also have Data Breach Notification Procedure as per the GDPR compliance requirements. We will share the supporting documents with regards to data breach notification and Incident management procedures.
Yes. We provide these rights to the data subject as per GDPR
We inform our customer in 48 hours if in case any security breaches as per the GDPR regulation.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
Yes. Attached the data retension and disposal policy.
Yes. we are GDPR compliant. We have procedure in place to provide services to data subject.
We do not share the PII with any third parties.
We are GDPR Complaint and respect the data subjet access rights. We erase or delete the data upon request of the data subject or on the request of the customer upon termination of the contract. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places. Attached the Data Retention and Disposal Policy.
We restrict the processing of data as per the contract signed.
We are GDPR compliant. we have implemented the Data Breach Notification Procedure. Our information security team and Customer support team will inform the customer via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
We have provided the features to withdraw consent or exercise the right for the end users. Attached the Data subject access rights procedures
Yes. We collect the data through our application application. As per the GDPR we are the data processor.
No. Since it’s a SAAS product we are having EU customers who are using our application application.
Employees.
No. We collect the data through this application and store it. We do not use or transfer or share the PII
Yes. Its posted on our website and they can exercise their rights as per the law.
We Dispose the data Upon the expiry of the data retention as per the agreements, or when the data subject exercises their right to have their personal data erased, the personal data shall be deleted.
NA. We do not use personal information for Marketing or Advertisement.
No. But we have deployed our application on AWS cloud virtual platform for maximum security.
we are the data processor.
We are GDPR compliant.
Yes. We are GDPR Compliant and we have a data retention and disposal policy. We assure secure data disposal when storage is decommissioned or when the contract comes to an end. We also provide rights to the users to request for data deletion. GDPR Policy - https://www.xoxoday.com/gdpr
We will be deleting the customer data upon termination of the contracts.
Our data cleansing process goes through an organized purge. Once the data is purged, it’s purged from all places or completely wiped out.
We are GDPR Compliant. And we would be notifying Nova Professional Services of an incident or data breach within 72 hours. We will make sure that we will be fully informed of incident response and investigation.
Yes. We provide service to the data subject as per the GDP Compliance requirements. They can rectify, erase or restrict processing of their personal data.
Xooxday is GDPR Compliant. We collect the data which are only required. We collect the PII - Name, Email ID and Phone/

CCPA/CPRA

We are compliant with EU GDPR and CPRA (California Privacy Rights Act)
We are EU GDPR Compliant and CPRA Certified.
Yes. We comply with all the applicable new laws and regulations. We also have a service provider who helps us with regards to Information security, compliance and certifications etc.. We have identified the upcoming CPRA and implemented the controls and achieved the CPRA Attestation with the help of the external auditor..