At Bouncify, we are committed to maintaining the security and
confidentiality of user data. This Data Policy outlines our practices and measures to
protect the integrity and privacy of user information in compliance with applicable laws and
regulations.
Purpose
The purpose of this policy is to provide transparency and clarity on how
long
we retain user data and the criteria we use to determine the retention periods. By
establishing clear guidelines, we aim to protect the privacy of our users and ensure the
responsible handling of their data.
Data Retention
We retain user data for as long as necessary to fulfill the purposes
outlined in our Data Policy or as required by law. The retention period may vary depending
on the type of data and the purpose for which it was collected. Below are general guidelines
for data retention:
- User Account Information: We retain user account information as long as the user
maintains an active account with us. If a user chooses to close their account, we will
delete their account information within a reasonable timeframe, unless retention is
required for legal or regulatory compliance.
- Email Lists and Verification Results: We retain email lists and verification
results for
a period of 30 days. After this period, the data will be securely deleted from our
systems. If a user chooses to delete their list, the user maintains complete control
over the process, allowing them to delete the list whenever they wish.
Data Usage
- Purpose Limitation: User data will be collected and processed only for specified
and
legitimate purposes as outlined in our Data Policy. We will not use the data for any
other purposes without obtaining explicit consent from the user.
- Marketing Communications: With user consent, we may use contact information to
send
promotional emails or newsletters related to our services. Users have the option to
unsubscribe from these communications at any time.
Data Storage
User data is stored in secure environments with appropriate technical and
organizational measures in place to prevent unauthorized access, loss, or alteration.
- Multi Vendor Cloud Servers: We store user data on secure and reliable multi
vendor cloud
servers. These cloud providers are selected based on their industry-leading security
measures and compliance with relevant data protection regulations.
- Data Encryption: User data is encrypted both in transit and at rest using
industry-standard encryption protocols. This ensures that data remains protected and
confidential throughout storage and transmission.
- Access Control: We implement strict access control measures to limit data access
to
authorized personnel only. Role-based access controls (RBAC) and two-factor
authentication (2FA) are used to ensure that only authorized individuals can access
sensitive data.
- GDPR Compliance: We strictly adhere to the General Data Protection Regulation
(GDPR) and
other applicable privacy regulations. Our data storage practices align with the
requirements outlined in the GDPR, including the principles of data minimization,
purpose limitation, and data security.
Data Deletion
Upon the expiration of the applicable retention periods, we will take
appropriate measures to delete or anonymize user data to ensure it is no longer accessible
or identifiable. Also users have the right to access, rectify, or delete their personal data
held by us. We provide mechanisms to facilitate these requests and ensure transparency in
our data processing activities.
Updates to the Data Retention Policy
We may update this Data Retention Policy from time to time to reflect
changes in our data retention practices or legal requirements. We will notify users of any
material changes through our website or other communication channels.