GDPR

Updated:

March 15, 2022

Background

The EU’s General Data Protection Regulations (GDPR), effective May 25, 2018, promotes the protection of data privacy laws across Europe. Haystack is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. Our preparation and objectives for GDPR compliance have been summarized in this statement.

Privacy Policy

We have updated our privacy policy to reflect the changes to how your data is processed and state the rights and access you have to your personal data.

Information Auditing Mapping

We carried out an information audit to identify and assess what personal data is collected and have removed any data collection that is not essential to providing and marketing the service.

Data Erasure

An enterprise user has the right to request that we delete all of their personal data, with the cooperation of their account administrator. We have dedicated removal policies in place to meet this obligation. Users can reach out to us at any time at hello@haystackteam.com.

Data Subject Rights

An enterprise user has the right to request the removal of personal data (where applicable) or to restrict processing in accordance with data protection laws, as well as to object to any direct marketing from us to be informed about any automated decision-making that we use. Users can request access to a copy of personal data that we have collected by contacting us at hello@haystackteam.com.

Subject Access Request

We have revised our Subject Access Request (“SAR”) procedures to accommodate the revised 30-day timeframe for providing the requested information and for making this provision free of charge. Our new procedures detail how to verify the data subject, what steps to take for processing an access request, what exemptions apply, and a suite of response templates to ensure that communications with data subjects are compliant, consistent, and adequate.

Data Protection Agreement

We have created a Data Protection Agreement (“DPA”) that can be executed by our customers that is available upon request.

Contact Information

If you have questions regarding Haystack’s GDPR readiness, please contact:

By Email: gdpr@haystackteam.com

By Mail: 4091 Redwood Avenue, Suite #518 Los Angeles, California 90066