GDPR
How Relnivo supports your obligations under the GDPR.
Last updated
Relnivo is built for organisations that must comply with the General Data Protection Regulation. This page summarises how we support your obligations.
Our role
For data you store in your workspace, you are the controller and Relnivo is the processor. For your own account and billing data, Relnivo is the controller.
Data Processing Addendum
Our DPA incorporates the current standard contractual clauses and is available to every customer. It is pre-signed and can be countersigned from workspace settings.
Supporting data subject requests
- Export any contact's complete record in a machine-readable format
- Permanently erase a contact and all associated conversations
- Rectify records with a full audit trail of the change
- Restrict processing on individual records
Breach notification
We notify affected customers without undue delay and within 72 hours of becoming aware of a personal data breach, with the information you need for your own regulatory notifications.
Transfers
EU workspaces are hosted in Frankfurt. Where a transfer outside the EEA is necessary, we rely on standard contractual clauses with a documented transfer impact assessment.
Records and audits
We maintain records of processing under Article 30 and make our SOC 2 and ISO 27001 reports available under NDA to support your vendor assessments.