{"id":2331,"date":"2018-01-18T15:26:18","date_gmt":"2018-01-18T13:26:18","guid":{"rendered":"https:\/\/woodpecker.co\/?page_id=2331"},"modified":"2021-09-09T07:54:48","modified_gmt":"2021-09-09T05:54:48","slug":"gdpr-compliance","status":"publish","type":"page","link":"https:\/\/woodpecker.co\/gdpr-compliance\/","title":{"rendered":"GDPR Compliance"},"content":{"rendered":"<p style=\"text-align: left;\">This document should be treated as an attachment to Woodpecker.co\u00a0<a href=\"https:\/\/woodpecker.co\/terms-of-service\/\" target=\"_blank\" rel=\"noopener\">Terms of Service<\/a>.<\/p>\n<p>GDPR (General Data Protection Regulation) applies from May 25, 2018. Woodpecker.co is committed to having had introduced all appropriate and necessary changes in the app, on the website, and on the blog by that time. Here&#8217;s what Woodpecker.co will do to comply with the regulation, and what Woodpecker users need to know about GDPR.<\/p>\n<p>&nbsp;<\/p>\n<h2>What is Woodpecker.co doing to comply with GDPR?<\/h2>\n<p>Woodpecker.co sets out to meet all the GDPR requirements that relate to protecting the privacy concerns of our app users, website and blog visitors, as well as email lists subscribers.<\/p>\n<p>Here&#8217;s what we&#8217;re going to do before the regulation becomes binding:<\/p>\n<ul>\n<li>familiarize ourselves with the full text of the regulation (<strong>COMPLETED<\/strong>)<\/li>\n<li>attend legal training sessions (<strong>COMPLETED<\/strong>)<\/li>\n<li>nominate Data Protection Specialist; we&#8217;ve nominated for the role one of our Customer Success Officers: Margaret Sikora LL.M in International and European Law\u00a0(<strong>COMPLETED<\/strong>)<\/li>\n<li>make necessary changes to our Privacy Policy, Terms of Service, Safety &amp; Security documents (<strong>COMPLETED<\/strong>)<\/li>\n<li>make a list of all the in-app areas that need to be taken care of to comply with the regulation (<strong>COMPLETED<\/strong>)<\/li>\n<li>make a list of all the areas on the website and blog that need to be taken care of to comply with the regulation (<strong>COMPLETED<\/strong>)<\/li>\n<li>implement necessary changes on the website and blog to make sure they abide by all the GDPR rules (<strong>COMPLETED<\/strong>)<\/li>\n<li>apply pseudonymization to protect the users&#8217; data which are not necessary to be kept in its original form (<strong>COMPLETED<\/strong>)<\/li>\n<li>make sure the personal data of Woodpecker.co users and email lists subscribers is well-protected (<strong>COMPLETED<\/strong>)<\/li>\n<li>implement necessary changes in the app to make sure all users can comply with GDPR when sending emails from Woodpecker.co (<strong>COMPLETED<\/strong>)<\/li>\n<li>educate the users about GDPR in relation to email outreach (<strong>IN PROGRESS<\/strong>)<\/li>\n<\/ul>\n<h2>What kind of a role Woodpecker.co has in data protection?<\/h2>\n<p>Woodpecker.co is defined as:<\/p>\n<p>1)<strong> data administrator<\/strong> in relation to Woodpecker.co users and email lists subscribers;<\/p>\n<p>2)<strong> data processor<\/strong> in relation to the data owners whose personal data is uploaded to Woodpecker and used in emails sent from Woodpecker by its users.<\/p>\n<p>It means that as a company, we oversee a couple of matters:<\/p>\n<ul>\n<li>Woodpecker.co needs to inform its users and email lists subscribers whenever a third party takes part in processing their personal data.<\/li>\n<li>Woodpecker.co is obliged to immediately inform the data administrator (the user) in case a person from the user&#8217;s prospect list contacts Woodpecker.co to stop the outreach<\/li>\n<li>Woodpecker.co openly informs about the \u2018right to be forgotten\u2019 and the \u2018right to assist in data deletion\u2019 on a special request. As Woodpecker.co user or email list subscriber, you may request your personal data change or deletion. The detailed instruction on how to exercise those rights can be found below in the section <em>Adequacy, relevance, limitedness\u00a0<\/em>of the GDPR Compliance.<\/li>\n<li>Woodpecker.co will address any violation of GDPR submitted at support[at]woodpecker.co.<\/li>\n<\/ul>\n<h2>What is GDPR?<\/h2>\n<p>The General Data Protection Act (GDPR) is being introduced by the European Union to regulate how personal data can be processed. It\u2019s intended to reinforce data protection of the people who live in the EU.<\/p>\n<h3>Why is there a need for GDPR?<\/h3>\n<p>EU data protection rules haven&#8217;t been updated for over two decades. There are at least two reasons why the EU legislative branch decided to improve the existing data protection regulations.<\/p>\n<ul>\n<li>Technological progress has a global reach &#8211; personal data processing is so ubiquitous in today\u2019s online sphere that existing regulations were becoming obsolete;<\/li>\n<li>Answering the need of EU citizens &#8211; according to Eurobarometer, 75% of people that have been asked in the 2011 survey want to exercise their so-called right to be forgotten. 90%, however, believes that it\u2019s necessary to standardize the rights concerning personal data protection (<a href=\"http:\/\/europa.eu\/rapid\/press-release_IP-11-742_en.htm?locale=en\" target=\"_blank\" rel=\"noopener\">source<\/a>).<\/li>\n<\/ul>\n<h3>What kind of information is under protection?<\/h3>\n<p>GDPR is supposed to protect natural persons and their rights. It doesn\u2019t protect businesses, entities or organizations, and processing of their data.<\/p>\n<p>It protects processing personal data, such as name, age, address, phone number, but also indirect identifications that influence their identity including physiological, mental, physical, genetic, economic, cultural and social identity. Basically, any information based on which one can identify the individual.<\/p>\n<h3>What does &#8216;processing&#8217; mean?<\/h3>\n<p>&#8216;Processing&#8217; relates to personal data \u201ccollection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction,\u201d as in Article 4 (2) of the regulation.<\/p>\n<h2>What is the lawful basis for data processing?<\/h2>\n<p>To safely and legally process personal data in the light of GDPR, you should abide by several principles. Those are lawfulness, fairness, transparency, adequacy, relevance, limitedness, accuracy, storage limitation, integrity, and confidentiality.<\/p>\n<p>Below you will read about how Woodpecker.co abides by those principles and what actions you should, or shouldn\u2019t, take to use Woodpecker in accordance with GDPR.<\/p>\n<h3>Lawfulness, fairness, and transparency<\/h3>\n<p>As a data processor, Woodpecker.co remains transparent and legitimate when processing data of its users and subscribers. All Woodpecker.co users and subscribers get notified upon the signup process that the personal data they provide will be processed in ways specified by Terms of Service and Privacy Policy.<\/p>\n<p>As data administrator, you should make sure your actions are transparent and the purpose of processing data is legitimate. It means you should be always able to prove that you had legitimate reasons to process personal data of EU citizens. You also need to be able to describe the whole process of obtaining the personal data you use.<\/p>\n<h3>Adequacy, relevance, limitedness<\/h3>\n<p>As a data processor, Woodpecker.co processes only the data necessary in relation to the purposes for which it is processed. We do not collect or process any sensitive data such as gender, race, ethnic background, political views, etc.<\/p>\n<p>Woodpecker.co processes its users\u2019 data as long as they have a Woodpecker account (either trial account or a premium account), or until they express their wish for their personal data to be removed from our user base.<\/p>\n<p>Woodpecker.co processes its email lists subscribers\u2019 data from the moment they subscribe for one of our mailing lists until they express their wish for their personal data to be removed from the lists.<\/p>\n<p>Woodpecker.co emailing lists include:<\/p>\n<ul>\n<li>Product Newsletter list,<\/li>\n<li>Blog Newsletter list,<\/li>\n<li>a few lists of people who subscribed for specific pieces of content or specific courses.<\/li>\n<\/ul>\n<p>Upon resigning from Woodpecker.co subscription or an email list subscription, the user has a right to request immediate removal of their data from the application and mailing lists (in accordance with the \u2018<em>right to be forgotten<\/em>\u2019.) The users or email list subscribers also have the right to view, update and make any corrections to their data in their Woodpecker account and on the email subscribers lists.<\/p>\n<h4>How can Woodpecker users change or remove their personal data from Woodpecker.co?<\/h4>\n<p>As Woodpecker user, you may change your first name, last name, company name, email address, password, and time zone at any time after logging in to their Woodpecker account. To do that, you should log into your account, choose \u2018Settings\u2019 from a drop-down menu in the top right corner and click on &#8216;My profile&#8217; tab. To change the username, Woodpecker.co users should contact the support team at support[at]woodpecker.co.<\/p>\n<p>Woodpecker.co users can also request deletion of their data by contacting the support team at support[at]woodpecker.co.<\/p>\n<h4>How Woodpecker.co email list subscribers can change or remove their personal data from Woodpecker.co?<\/h4>\n<p>As Woodpecker.co email list subscriber, you can change your personal data on the subscriber\u00a0list\u00a0by clicking the \u201cupdate subscription preferences\u201d link in any message we have sent you using MailChimp.<\/p>\n<p>You can also unsubscribe from any list by clicking a link at the bottom of any message. Such a request to unsubscribe from a list will be applied to this specific list only. If as a subscriber you wish to be removed from all lists at once, please reply to any message and write that you wish to be removed from all Woodpecker.co\u2019s mailing lists.<\/p>\n<h4>How we apply GDPR to cold email campaigns<\/h4>\n<p>If, at Woodpecker.co, we decide to contact an EU citizen, who has not been a Woodpecker user or email list subscriber, we will do so only if we have a clear reason to claim that this is a contact relevant to our business purposes, and that at the same time, this contact could be beneficial to the contacted person.<\/p>\n<p>If a person asks us to stop contacting them, at Woodpecker.co we will always respect that request and stop further contact immediately.<\/p>\n<p>As data administrator, you can process personal data of EU citizens who have granted you permission to process their data by subscribing to one of your mailing lists. GDPR does not forbid cold emailing though, as long as you follow the data processing rules described in the regulation.<\/p>\n<p>If you decide to contact a person who has not subscribed for email correspondence, and has not been in any business relationship with you before (cold email), you should have a clear reason to claim that this will be a contact relevant to your business purposes, and that at the same time this contact could be beneficial to the contacted person. If you place an offer in your cold email, the offer should be logically connected to the specifics of your prospect&#8217;s business.<\/p>\n<p>You are required to inform your cold email recipient that you&#8217;re processing their data and how you process it. The email should also contain a clear and easily available information about how your prospect can request change or removal of their personal data.<\/p>\n<p>You are obliged to immediately stop contacting prospects who expressed their wish not to be contacted again. If a prospect of yours demands that their data gets removed from your contact lists, you are obliged to remove it (in accordance with the \u2018<em>right to be forgotten<\/em>\u2019.)<\/p>\n<p>You should process only the personal data that are necessary in relation to the purposes for which you process it. That means you should remove from your contact base all the personal data that are irrelevant to your email campaign, or be able to justify why a specific type of data is necessary for the goal you are trying to accomplish.<\/p>\n<h3>Accuracy<\/h3>\n<p>As Woodpecker user or email list subscriber, you have the right to make changes in your personal data processed by Woodpecker.co. <a href=\"https:\/\/woodpecker.co\/privacy-policy\/\" target=\"_blank\" rel=\"noopener\">Privacy Policy<\/a> specifies how you can request the changes or where you can edit your data yourself.<\/p>\n<p>As data administrator, you need to make sure all the data you process is up to date. Personal data that is inaccurate or outdated should be deleted or altered immediately.<\/p>\n<h3>Storage limitation<\/h3>\n<p>Woodpecker.co will keep every user\u2019s personal data no longer than it\u2019s necessary for the purposes for which the personal data are processed. At the same time, each data owner can request an exact time limit of their data processing.<\/p>\n<p>As data administrator, you need to make sure you don\u2019t keep personal data of your prospects longer than it\u2019s necessary for the purposes for which the personal data are processed.<\/p>\n<p>In case of cold email campaigns, you shouldn\u2019t process a non-responsive prospect\u2019s data longer than it may be assumed to be necessary, namely one month after you tried to contact the person for the first time. That means you should always keep your prospect base updated.<\/p>\n<h3>Integrity and confidentiality<\/h3>\n<p>As a\u00a0data processor, Woodpecker.co processes its users&#8217; personal data in a way that ensures appropriate security of the personal data. You can find more details on the data processing in our <a href=\"https:\/\/woodpecker.co\/safety-security\/\" target=\"_blank\" rel=\"noopener\">Safety &amp; Security<\/a> document.<\/p>\n<p>As data administrator, you are obliged to take a proper care of the security of the personal data you process. You should never share with third parties the personal data you process, unless you have a clear consent of the data subjects to do that.<\/p>\n<p><a href=\"https:\/\/woodpecker.co\/gdpr-statement\/\" target=\"_blank\" rel=\"noopener\">Read Woodpecker&#8217;s GDPR Compliance Statement &gt;&gt;<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This document should be treated as an attachment to Woodpecker.co\u00a0Terms of Service. GDPR (General Data Protection Regulation) applies from May 25, 2018. Woodpecker.co is committed to having had introduced all appropriate and necessary changes in the app, on the website, and on the blog by that time. Here&#8217;s what Woodpecker.co will do to comply with [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-templates\/legal-page.php","meta":{"inline_featured_image":false},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.13 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GDPR Compliance - Woodpecker.co - Learn how we comply with GDPR<\/title>\n<meta name=\"description\" content=\"GDPR applies from May 25, 2018. Here&#039;s what Woodpecker does to comply with the regulation, and what Woodpecker users need to know about GDPR.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/woodpecker.co\/gdpr-compliance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR Compliance - Woodpecker.co - Learn how we comply with GDPR\" \/>\n<meta property=\"og:description\" content=\"GDPR applies from May 25, 2018. Here&#039;s what Woodpecker does to comply with the regulation, and what Woodpecker users need to know about GDPR.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/woodpecker.co\/gdpr-compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"Woodpecker\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/woodpeckerapp\/\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-09T05:54:48+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@Woodpeckerapp\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/woodpecker.co\/gdpr-compliance\/\",\"url\":\"https:\/\/woodpecker.co\/gdpr-compliance\/\",\"name\":\"GDPR Compliance - Woodpecker.co - Learn how we comply with GDPR\",\"isPartOf\":{\"@id\":\"https:\/\/woodpecker.co\/#website\"},\"datePublished\":\"2018-01-18T13:26:18+00:00\",\"dateModified\":\"2021-09-09T05:54:48+00:00\",\"description\":\"GDPR applies from May 25, 2018. Here's what Woodpecker does to comply with the regulation, and what Woodpecker users need to know about GDPR.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/woodpecker.co\/gdpr-compliance\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/woodpecker.co\/#website\",\"url\":\"https:\/\/woodpecker.co\/\",\"name\":\"Woodpecker\",\"description\":\"Cold email &amp; follow-up automation\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/woodpecker.co\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR Compliance - Woodpecker.co - Learn how we comply with GDPR","description":"GDPR applies from May 25, 2018. Here's what Woodpecker does to comply with the regulation, and what Woodpecker users need to know about GDPR.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/woodpecker.co\/gdpr-compliance\/","og_locale":"en_US","og_type":"article","og_title":"GDPR Compliance - Woodpecker.co - Learn how we comply with GDPR","og_description":"GDPR applies from May 25, 2018. Here's what Woodpecker does to comply with the regulation, and what Woodpecker users need to know about GDPR.","og_url":"https:\/\/woodpecker.co\/gdpr-compliance\/","og_site_name":"Woodpecker","article_publisher":"https:\/\/www.facebook.com\/woodpeckerapp\/","article_modified_time":"2021-09-09T05:54:48+00:00","twitter_card":"summary_large_image","twitter_site":"@Woodpeckerapp","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/woodpecker.co\/gdpr-compliance\/","url":"https:\/\/woodpecker.co\/gdpr-compliance\/","name":"GDPR Compliance - Woodpecker.co - Learn how we comply with GDPR","isPartOf":{"@id":"https:\/\/woodpecker.co\/#website"},"datePublished":"2018-01-18T13:26:18+00:00","dateModified":"2021-09-09T05:54:48+00:00","description":"GDPR applies from May 25, 2018. Here's what Woodpecker does to comply with the regulation, and what Woodpecker users need to know about GDPR.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/woodpecker.co\/gdpr-compliance\/"]}]},{"@type":"WebSite","@id":"https:\/\/woodpecker.co\/#website","url":"https:\/\/woodpecker.co\/","name":"Woodpecker","description":"Cold email &amp; follow-up automation","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/woodpecker.co\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/pages\/2331"}],"collection":[{"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/comments?post=2331"}],"version-history":[{"count":0,"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/pages\/2331\/revisions"}],"wp:attachment":[{"href":"https:\/\/woodpecker.co\/wp-json\/wp\/v2\/media?parent=2331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}