SECTION 1 - YOUR DATA
A. GDPR Article 30 – Records of processing activities
1. SegMate collects the following personal information.
PSID (Page Scoped Identification)
First name
Last Name
Gender
Locale (the language setting applied by the Facebook Users account)
Profile/Avatar Image
2. How the data is collected.
3. Who does SegMate share this information with?
The data collected is not shared with any 3rd Party. If in the future, SegMate adds any 3rd Party connections, you will be notified by email as well as in application notification and will be required to accept new terms.
4. Where personal information collected is stored and who has access to it.
The personal information collected is stored in a secured mySQL database. The data is passed to us from the Facebook API and only site administrators have access to the database.
5. Why does SegMate collect this data?
SegMate collects this information in order to allow its customers to send messages through a specific Fan pages Facebook Messenger. The information collected is used to identify a Facebook Messenger user in order to send a message to the correct user, personalize said messages, identify if the message receiver is Male or Female as well as their locale.
6. How long does SegMate stores this data.
We store this data indefinitely as it is needed in order for SegMate to function properly. All data is disposed upon request.
SECTION 2 - NEW RIGHTS
A. Article 15 – Right of access by the data subject
SegMate provides the tools to you, as the Data Controller, to export all of your subscribers Personal Information. You must provide a method for your Subscribers to contact you should they want to request the Personal Data you have collected. Pursuant to GDPR Article 20 – Right to data portability, a Subscriber may also request you send their data to a 3rd Party.
B. GDPR Article 16 – Right to rectification
All data collected and processed through SegMate are received via Facebook™ API and is based upon the Subscribers Facebook account settings. When your Subscriber contacts you to update the Personal Information stored, you must inform them to update the requested information in their Facebook™ account. SegMate offers a "Re-Import" tool on the "Subscribers" view within SegMate that allows you to update all Subscriber information to its current state.
C. GDPR Article 17 – Right to erasure (‘right to be forgotten’)
SegMate provides a tool for you, as the Data Controller, to delete all Personal Information in regards to a Subscriber request. You must provide a method for your Subscribers to contact you should they want to request deletion of the Personal Data you have collected.
D. GDPR Article 18 – Right to restriction of processing
SegMate provides the tool to prevent further contact with the Subscriber should they request it. There are 3 methods a Subscriber may halt further contact from you, the Data Controller:
1. by sending the message, "Unsubscribe" to your Facebook™ Fan page.
2. clicking a Button or Quick Reply in a current or past message sent by you, the Data Controller, that has applied the "Unsubscribe" action.
3. by contacting you, the Data Controller and requesting to be Unsubscribed from further contact through SegMate.
SECTION 3 - ACCOUNTABILITY & MANAGEMENT
A. Article 37 – Designation of the data protection officer
A data protection will be assigned & can be contacted at [email protected] if assistance is needed.
B. Article 33 – Notification of a personal data breach to the supervisory authority
In the case of a personal data breach, the controller (you) shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
The processor (SegMate) shall notify the controller without undue delay after becoming aware of a personal data breach.
SegMate will notify the Data Controller (you) with the following information:
1. describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
2. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
3. describe the likely consequences of the personal data breach;
4. describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where, and in so far as, it is not possible for SegMate to provide the information at the same time, the information may be provided in phases without undue further delay.
The controller (you) shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with Article 33.
C. Article 34 – Communication of a personal data breach to the data subject
In the case of a personal data breach, SegMate will contact the Data Controller - in this case, you - with the following information. You as the Data Controller must relay this information to the data subject;
1. without undue delay and describe in clear and plain language the nature of the personal data breach and contain the following information and measures;
2. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
3. describe the likely consequences of the personal data breach;
4. describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
If you are collecting personal information from anyone who falls under the General Data Protection Regulation (GDPR), please consult legal council to be sure you are in compliance with all regulations.
SECTION 4 - DATA PROCESSING AGREEMENT (DPA)
In the course of providing our service, SegMate, LLC. may process personal data on your behalf. In order to outline specifics of how we will perform this processing and what our obligations are as well as the obligations of our users/customers we’ve developed a Data Processing Agreement (DPA) that we enter into with anyone that uses our service.
This document forms part of a contract of service with SegMate (as the Data Processor) and our users/customers (as the Controllers). The DPA reflects the parties’ agreement with regard to the processing of personal data performed using our service.