Third-party providers and subprocessors
Last revised on March 20th, 2022.
In order to support our operations we rely on several Service Providers. They help us with various services such as payment processing, web audience analysis, cloud hosting, marketing and communication, etc.
Google Cloud EMEA Ltd
We contract the Cloud Cloud Platform (GCP) to host www.activityinfo.org and all customer databases and backups. All customer data is stored in datacenters in the Netherlands, Belgium, and Germany.
- Data center certifications: ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC3, PCI-DSS, HIPAA, CISPE, CSA STAR
- Privacy & Security
We contract Wildbit LLC for the use of their Postmark service which delivers critical application emails to our users, such as password reset emails, invitations to databases, and security notifications.
In order to deliver our service, we transmit the email address, name, and content of messages to Wildbit LLC. This data is temporarily stored in Wildbit's servers in the United States, and retained for 45 days in order to support troubleshooting. When Wildbit receives a spam complaint or hard bounce, the email address is stored indefinitely to ensure that we do not send additional emails to this address.
The transfer of data from the EU to Wildbit in the US is kept to a minimum, and is covered with our Data Processing Agreement with Wildbit incorporates the Standard Contractual Clauses (SCC). This DPA ensures that this transfer of any data subject to the European data protection law (including the GDPR) from our data centers in the EU to Wildbit in the US respects our obligations under the GDPR.
By design, these messages do not include any customer-owned data. Invitations to users will include the name of your ActivityInfo database.
We manage our help desk, billing, and customer relations management using software provided by Odoo SA. We store and process this data in our role as Data Controller on the basis of fulfilling our contractual and/or pre-contractual obligations and commitments. All data is stored in France and Belgium.
We use Inuit's Mailchimp software to share supportive materials, including documentation and guides to the ActivityInfo software, with our customers, potential customers, and their end users. For this purpose, we share the email address, name and preferred language with Mailchimp, who store this data in the United States. We process this information, and have contracted Mailchimp to process this data on our behalf, in order to fulfill our contractual and/or pre-contractual obligations.
We have signed a Data Processing Addendum (DPA) with Mailchimp that incorporates the Standard Contractual Clauses (SCC). This DPA ensures that this transfer of any data subject to the European data protection law (including the GDPR) from our data centers in the EU to Mailchimp in the US respects the rights of data subjects under the GDPR.
In addition to sharing supportive materials with customers, users and non-user can opt in to receiving our newsletter which includes updates about our product and services.
Stripe Payments Europe, Ltd.
If you purchase your subscription with a credit card, your payment is processed through Stripe.
We share with Stripe the order details, including the amount, description, and a reference, the customer name, and email. We store and process this data in our role as Data Controller on the basis of fulfilling our contractual and/or pre-contractual obligations and commitments.
For recurring payments, we delegate the storage of payment instruments such as credit cards entirely to Stripe Payments Europe, Ltd. BeDataDriven B.V. does not store nor do we have access to credit card details of our customers.
- Certifications: PCI Service Provider Level 1
We use https://www.teachable.com to host our self-paced training courses. We refer to this service as the ActivityInfo Academy, which you can access at https://academy.activityinfo.org. The ActivityInfo Academy is referred to as a school in Teachable's terminology and you must register as a student to access the school and to enroll in a curriculum in the school.
When you register as a student in the ActivityInfo Academy, we receive the following personal information from Teachable:
- your name to identify you in the school, for example when you post a comment or to put on a certificate of completion.
- your email address to send you instructional or promotional email messages, if you have consented to receiving these. We also use this information to track your progress in the course; this includes which lectures you have completed and how much of the video's you have watched.