Data privacy and protection policy
Maintaining customer trust is an ongoing commitment, we strive to inform customers of the privacy and data security policies, practices and technologies we’ve put in place. These commitments include:
- Access: We do not access or use customer content for any purpose other than as legally required and for maintaining our services and providing them to our customers and their end users.
- Storage: Customers can choose the region(s) in which their customer content will be stored. We will not move or replicate customer content outside of the customer’s chosen region(s), except as legally required and as necessary to maintain the services and provide them to our customers and their end users.
- Security: We offer our customers strong encryption for customer content in transit or at rest, and we provide customers with the option to manage their own encryption keys.
- Disclosure of customer content: We do not disclose customer content unless we’re required to do so to comply with the law or a valid and binding order of a governmental or regulatory body. Unless prohibited from doing so or there is clear indication of illegal conduct in connection with the use of our services, CKSource notifies customers before disclosing customer content so they can seek protection from disclosure.
Customer data is classified into two categories: customer content and account information.
We define customer content as data, text, audio, video or images that a customer or any end user transfers to us for processing, storage or hosting by our services in connection with that customer's account and any computational results that a customer or any end user derives from the foregoing through their use of our services. For example, customer content includes images that a customer or any end user uploaded to our services. Customer Content does not include account information, which we describe below. The terms of any agreement with us governing the use of our services apply to your customer content.
Customer content ownership
Customers maintain ownership of their customer content. We do not access or use customer content for any purpose other than as legally required and for maintaining our services and providing them to our customers and their end users. We never use customer content or derive information from it for marketing or advertising.
Third-party cloud services provider
Our services are structured on top of the secure and well-established Amazon Web Services (AWS) cloud solutions. We do not run a custom data center, avoiding hundreds of performance, availability and security threads which have been settled down by AWS with their years of presence in the market.
Customer content storage location
Customers can choose the region(s) in which their customer content will be stored, in accordance with their specific geographic requirements. CKSource services are built on top of clusters available in various regions around the globe.
Customer's role in securing their customer content
When evaluating the security of a cloud solution, it is important for customers to understand and distinguish between:
- Security measures that we implement and operate - "security of the cloud"
- Security measures that customers implement and operate, related to the security of their customer content and applications that make use of our services - "security in the cloud"
CKSource is responsible for securing the cloud infrastructure, including computation, storage, databases and networks.
The customer is responsible for securing their customer data, their platforms, applications, identity and access management, their operating systems, networks and firewalls, the data-on-wire encryption and data integrity.
Compliance with EU law
We base our services on AWS solutions, which has already obtained approval from EU data protection authorities, known as the Article 29 Working Party, of the AWS Data Processing Addendum and Model Clauses to enable transfer of data outside Europe, including to the U.S. With their EU-approved Data Processing Addendum and Model Clauses, CKSource customers can run their global operations using CKSource services in full compliance with EU law. The AWS Data Processing Addendum is available to all CKSource customers that are processing personal data whether they are established in Europe or a global company operating in the European Economic Area. For additional information, please visit the AWS EU Data Protection FAQ.
EU-US Privacy Shield
Recently, the European Commission and the US Government agreed on a new framework called the EU-US Privacy Shield, and on July 12, 2016, the European Commission formally adopted it. The EU-US Privacy Shield replaces Safe Harbor. AWS as well welcomes this new framework for transatlantic data flow.
To learn more about this topic in the context of our services, visit the AWS EU-US Privacy Shield page.
On 25 May 2018 the Regulation of the European Parliament and the Council (EU) no. 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, comes into force.
What personal data is collected and processed by CKSource?
CKSource collects and processes personal data collected upon consent of users of websites managed by CKSource sp. z o. o. sp. k. (hereinafter: CKSource), including customers of its online store, users of beta and demo software versions, newsletter subscribers, and users of other functionalities of www.cksource.com website, including data stored in cookies.
Personal data is collected from persons concerned – website users or CKSource customers, who registered themselves with our online store website. Controller of the above details will be CKSource and all of its affiliated entities and subsidiaries, both in personal and capital terms, directly or via other entities, and our trusted partners.
Purpose of personal data processing.
CKSource collects and processes personal data for purposes required by the law, and other purposes specified by CKSource, among others to:
- optimize steps undertaken by its customers, in particular to improve and facilitate the process of purchase, complaint or return of purchased goods;
- develop a customized offer;
- inform our customers of new CKSource products;
- make analyses to improve our services.
Whom can we transfer the data to?
According to the binding law, a personal data controller (CKSource) can transfer personal data to entities processing the details as contracted by us, e.g. our service sub-contractors, marketing agencies, and entities authorized to obtain the details according to the binding law, e.g. courts or prosecution authorities – of course only if they approach us with such a request based on valid legal grounds.
CKSource appointed their personal data protection inspector, who supervises compliance in terms of protection of the details collected and processed by CKSource. Contact details of the inspector: Zuzanna Łaganowska, Attorney at Law, PhD, contact: firstname.lastname@example.org
What are your rights involving your personal details?
You have a right to request access to your details, request that the details be corrected, erased or their processing limited. You can also withdraw your consent for the processing of your personal data, object thereto, and execute other rights, including to:
- get comprehensive information, whether such a database exists, and to learn the controller of the data, their registered address, and full name;
- get information on the purpose, scope and way of processing of personal data stored in such a database;
- get information, since when details concerning yourself have been processes, and be provided the content of the details in clear and plain language;
- get information on the source, the details have been derived from, unless the controller of the details is, in that respect, obliged to keep confidential any classified information, or any professional secrets;
- get information on the process of disclosure of the details, in particular information on recipients and/or their categories, such data is disclosed to;
- get information on the grounds for a resolution, defined under article 26a(2);
- request that your personal details be corrected, updated, rectified, their processing be temporarily or permanently restricted, or that the details be erased, if they are incomplete, no longer up-to-date, untrue, or have been collected in violation of the law, and/or are no longer needed for the purpose they have been collected for;
- request that your personal details no longer be processed.
What are the legal grounds for CKSource to process your personal data?
Each personal data processing exercise must be based on respective legal grounds, compliant with the binding regulations. Legal basis for the processing of personal details for the purpose of selling goods and providing services is their being essential for performance of an agreement concerned (in case of provision of services, such agreements are the Terms and Conditions, or similar documents available within the service you use).
On the other hand, legal basis for customizing the content of services to users of websites and services managed by CKSource, to ensure their safety and security, and for measurements/analyses, and to improve such services, as well for internal CKSource marketing, is so called legitimate interest of personal data controller. Personal data will be processed for marketing purposes, including profiling, and for analytical purposes, based on a voluntary consent, which may be given by ticking the “I agree” button next to the declaration.
The consent is of a voluntary nature and may be withdrawn at any time, however, withdrawing your consent will not affect legality of a consent-based processing before its withdrawal.