The General Data Protection Regulation (GDPR) is a European Union regulation which protects the rights of data subjects in the European Economic Area (EEA), with respect to the processing of their “personal data,” as such term is defined in the GDPR.
Compliance
The OAYAW website and platform are designed to meet the principles of the GDPR. Here are some of the actions we’ve taken to ensure our compliance with GDPR:
- We limit the personal data we collect;
- We have established a legal basis for the processing of that data;
- We only retain personal data for a limited time period, after which, the data is deleted
What Personal Data is Collected and How it is Collected
Please see the OAYAW Privacy Policy, which describes the categories of information we process, the purposes for which we process personal data, and how we collect that personal data.
How Long is Personal Data Retained
If you provide information to us to request a demo, we will keep that information for up to twelve months after your last communication with us.
We will keep personal information provided by customers for up to three months after the end of our business relationship and subject to our SaaS agreement. All payment information will be deleted three months after processing, unless
we are required by law to keep it longer.
If you contact us directly using the contact information provided on the OAYAW website, we will retain your contact information for a period of up to three months after we respond to your inquiry. After that, the communications will be deleted from our system, unless we are required by law to retain it longer.
Children's Privacy
The OAYAW website and platform were not developed or intended for individuals that are deemed to be children under applicable data protection or privacy laws, and we do not knowingly collect information from children.
Legal Basis for Processing
If you are a user of the OAYAW website or platform located in the EEA, we rely on legitimate interest as the legal basis for processing the personal data we collect via the website and platform.
Controller and Processor
Depending on which features you choose to use, OAYAW, Inc., a Delaware C Corporation is both Controller and Processor of personal data covered by the Privacy Policy for purposes of European data protection legislation.
If you choose to use the Vendor Risk Monitoring, Policy Change Detection, Vendor Lawsuit Alerts, Privacy Law Alerts, and Ask the Privacy Expert feature, OAYAW is a Controller when the GDPR applies.
If you choose to use the Consent Management or Subject Rights Management features, OAYAW is Processor when the GDPR applies. OAYAW's Data Processing Addendum can be found here. OAYAW's Data Processing Addendum applies only when required under the GDPR and does not apply to Customers who are currently in a trial evaluation period or who are using a free tier of service.
Subprocessors
In connection with the operation of our website, OAYAW may engage third parties (each a “Subprocessor”) to process your personal data. As a condition of permitting a Subprocessor to process your personal data, OAYAW will enter into a written agreement with each Subprocessor containing data protection obligations at least as protective as the technical and organizational measures OAYAW has put into place to protect your personal data from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access.
We use the following Subprocessors to operate our website and provide our services:
Name | Subprocessing Activity | Country of Origin |
---|---|---|
Microsoft Corporation | Collaboration, Productivity, and Cloud Services | United States and Ireland |
Amazon Web Services, Inc. | Cloud Service Provider | United States and Ireland |
HubSpot, Inc. | Content Management System | United States |
Chargebee, Inc. | Subscription & Billing | United States |
Stripe, Inc. | Payment Processing Gateway | United States |