The EU’s General Data Protection Regulations (GDPR), effective May 25, 2018, promotes protection of data privacy laws across Europe. Haystack is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. Our preparation and objectives for GDPR compliance have been summarized in this statement.
Privacy Policy
We routinely make updates to our privacy policy to ensure it accurately reflects changes in how your data is processed and to outline your rights and access to your personal data. For more information about our Privacy Policy and the practices it governs, see haystackteam.com/legal/privacy. If you have any questions regarding Haystack’s Privacy Policy, you can reach out to us at privacy@haystackteam.com.
Information Auditing Mapping
We conducted a comprehensive information audit aimed at identifying and evaluating all personal data collected. As a result of this audit, we have meticulously reviewed and removed any data collection practices deemed non-essential to the provision and marketing of our services. This ensures that only necessary data is retained, enhancing both the efficiency and integrity of our service delivery and marketing strategies.
Data Erasure
An enterprise user has the right to request that we delete all of their personal data, with cooperation of their account administrator. We have dedicated removal policies in place to meet this obligation. Users can reach out to us at any time at privacy@haystackteam.com.
Data Subject Rights
An enterprise user has the right to request removal of personal data (where applicable) or to restrict processing in accordance with data protection laws, to object to any direct marketing from us, and to be informed about any automated decision-making that we use. Users can request access to a copy of personal data that we have collected by contacting us at privacy@haystackteam.com.
Subject Access Request
We have revised our Subject Access Requests (“SAR”) procedures to accommodate the revised 30-day timeframe for providing the requested information and for making this provision free of charge. Our new procedures detail how to verify the data subject, what steps to take for processing an access request, what exemptions apply and a suite of response templates to ensure that communications with data subjects are compliant, consistent and adequate.
Sub-processors
Where we engage a third party to process personal data on behalf of a customer, that party is a sub-processor and is engaged under our Data Processing Agreement. We maintain a current list of our sub-processors, which is made available to customers and prospective customers on request, subject to a confidentiality agreement. Where a customer’s agreement provides for advance notice of a new sub-processor and a right to object, those terms govern. An AI assistant or platform that a customer connects to its own workspace using its own provider account is, by virtue of that connection, a recipient acting at that customer’s direction rather than a Haystack sub-processor. If the same provider also appears on our sub-processor list, it is there because we engaged it ourselves to deliver a feature of the platform, and only that engagement is governed by our Data Processing Agreement.
Artificial Intelligence
Haystack does not use customer content to train, fine-tune or improve AI models, and does not use AI to make automated decisions that produce legal effects for individual users. Where a feature involves automated processing that engages rights under the GDPR, we disclose the logic involved and honour the right to contest it. Our AI practices are described at haystackteam.com/legal/ai.
Data Processing Agreement (DPA)
We have created a Data Processing Agreement (“DPA”) that can be executed by our customers. If you have questions regarding Haystack’s GDPR readiness, please contact security@haystackteam.com.