EventsX and the GDPR
Privacy and Security Contact
privacy@eventsx.com
EventsX
Limited,
Profile West Suite 2,
Floor 1,
950 Great West Road,
Brentford,
England,
TW8 9ES
To ensure the security and privacy of our users, we are
committed to meeting or exceeding the GDPR (General Data Protection Regulation).
There is information on this site about the steps we are taking, their progress,
and how to get in touch with us if you have questions about security. You can
find more information in our FAQ.
Data Processing Partners
We rely on a number of trusted 3rd parties to assist
with our operations. Depending on the exact nature of your account and what
you’ve requested we do, your data may be shared with one of these partners.
We carefully evaluate each to make sure they’re handling your personal data
with the utmost of respect, security, and privacy.
Partner
Locale
Data Shared
Purpose
Amazon CloudFront delivers your static and streaming content using a global
network of edge locations.
Amazon S3 is storage for the Internet. It is designed to make web-scale computing
easier for developers.
Conversion tracking functionality from Facebook, allows a user to track
advertisement clicks.
Custom Audiences from your website makes it possible to reach people who visit
your website and deliver the right message to them on Facebook.
This website contains tracking information that allows admins to see Facebook
Insights out of Facebook to this domain.
Allows a user to make a website more sociable and connected with integrations
from the hugely popular Facebook website.
Facebook Pixel is Facebooks conversion tracking system for ads on Facebook to
websites.
JavaScript SDK enables you to access all of the features of the Graph API via
JavaScript, and it provides a rich set of client-side functionality for
authentication and sharing. It differs from Facebook Connect.
Journalists use Signal to surface relevant trends, photos, videos and posts from
Facebook and Instagram for use in their storytelling and reporting.
Google's primary tag for Google Measurement/Conversion Tracking, Adwords and
DoubleClick.
Google Analytics offers a host of compelling features and benefits for everyone
from senior executives and advertising and marketing professionals to site
owners and content developers.
Web-based email, calendar, and documents for teams. Renamed to Google Apps for
Work, but now known as G Suite From Google Cloud.
Test different variations of a website and then tailor it to deliver a
personalized experience that works best for each customer and for your
business.
Tag management that lets you add and update website tags without changes to
underlying website code.
The analytics.js JavaScript snippet is a new way to measure how users interact
with your website. It is similar to the previous Google tracking code, ga.js,
but offers more flexibility for developers to customize their
implementations.
GSAP is a suite of tools for scripted, high-performance HTML5 animations that
work in all major browsers from GreenSock.
Google has off-loaded static content (Javascript/Images/CSS) to a different
domain name in an effort to reduce bandwidth usage and increase network
performance for the end user.
The LinkedIn Insight Tag is a piece of lightweight JavaScript code that you can
add to your website to enable in-depth campaign reporting and unlock valuable
insights about your website visitors and for conversion optimization of ads.
Segment gives you the ability to instrument your web app for analytics once, and
then send your data to any number of analytics services. Previously known as
Segment.io
Ubuntu is a free, Debian derived Linux-based operating system, available with
both community and professional support.
Compliance Tasks
GDPR Compliance requires maintenance and ongoing
work. We are tracking our efforts here.
APPLICATION SITE SECURITY
Status
Name
Ensure Intrusion Detection Systems are in Place
Establish Stale Data and User Policies
Restrict Personal Data at Signup to the Minimum Necessary
SSL (TLS) Deployed on App Site
Inform Users about the GDPR Page
Ensure internal employees and contractors behaviors around personal data are
documented.
Ensure Web Application Firewall enabled and blocking common attacks
Ensure Access to Backups is Restricted
Ensure Backups are Stored in on Encrypted File Storage
Affirmative Consent mechanism added to User Signup
MARKETING SITE SECURITY
Status
Name
Reviewed list of users with access to site
SSL (TLS) Deployed on Marketing Site
PRIVACY PROCEDURES
Status
Name
Informed all Employees and Contractors about GDPR Compliance
Privacy Policy Updates
Procedure established to allow for people to request that inaccuracies in their
data are fixed.
Process established for subject data requests
Get Management Approval for GDPR Efforts
Data Protection Policy Created
Developed a Data Processing Agreement
Briefed all Staff on GDPR Impact to the organization
Nominate a Data Protection Lead or Data Protection
SECURITY PROCEDURES
Status
Name
Publish statement on public website on how to report security and data
issues.
Frequently Asked Questions
If you have any concerns not answered here, please
reach out to our contact (listed above) and we'll be happy to
assist.
What's the GDPR?
The General Data Protection Regulation (GDPR) is a
new piece of privacy legislation enacted by the European Union. It
represents a significant change in how personal (IP Addresses, Emails,
Names) and sensitive (religion, ethnic origin, health, orientation) data is
handled by companies.
How Do I Report a Security Issue?
We take all security reports seriously. Please
email our security contact (information listed above) with any information
you have regarding any potential data breaches, vulnerabilities or
concerns.
Do Non EU Companies need to comply with the GDPR?
While it remains to be seen if the EU has the
legislative power to levy fines and enforcement against organizations around
the globe, GDPR compliance is being sought by non EU companies for a variety
of reasons.
-
Customers and Prospects are making it a requirement
-
It's a solid framework for improving the handling of personal information and complying with the GDPR requirements improves our own security.