Snapshot 58757
Normalized text
Scripts and page chrome removed; this is what change detection compares.
REDA One and GDPR Consistent with REDA One’s commitment to the data privacy of its customers, we offer this overview of the EU General Data Protection Regulation (GDPR), which became effective July 01, 2024. This overview is to help our customers and data subjects navigate the requirements of GDPR and understand how it impacts our relationships and the services we provide. GDPR FAQs What is the GDPR? The GDPR is a new regulation passed by the European Union (EU) that (1) dramatically expands the data privacy rights of EU citi and (2) imposes new obligations on many new businesses that collect, use or store personal data regarding these EU citizens. It is intended to serve as a single set of privacy and security standards for the EU and replace the “patchwork” set of European privacy rules that had previously applied. Who and what does the GDPR protect? The GDPR protects “personal data” regarding “data subjects.” This includes any information related to a natural person (as opposed to businesses) that can be used to directly or indirectly identify the person. It provides a set of rights to data subjects regarding how certain covered businesses must treat their personal data. Personal data is broadly defined. The following are examples of information that would qualify as personal data regarding identifiable data subjects: Financial information Personal and family details Education and employment information Medical information What businesses must comply with GDPR? The GDPR applies to businesses that (1) engage in certain activities concerning personal data AND (2) have established certain contacts with the EU. GDPR Activities. GDPR applies to all “controllers” and “processors” of personal data. In short, processing refers broadly to any treatment of personal data, including collection, use, recording, storage, disclosure etc. A controller determines the purposes and means of processing personal data, while the processor is responsible for processing personal data on behalf of a controller. In other words, the processing is ultimately for the business purposes of the controller. The controller either performs the processing on its own behalf or engages a processor to perform specified processing activities for it. EU Contacts. A business is covered by the GDPR as a controller or processor only if it establishes at least one of the following links to the EU: The business is “established” in the EU and processes personal data in the context of the activities of that establishment, regardless of where the processing takes place. The business is not established in the EU, but offers goods or services to EU data subjects or monitors their behavior (or other operation of law). As a result, the GDPR can apply to processing of personal data that a business performs outside the EU. What data protection does the GDPR require? GDPR sets forth a set of core principles with which covered controllers and processors must comply when processing personal data. They are: Lawfulness, fairness and transparency. Personal data must be processed lawfully, fairly and in a transparent manner. Purpose limitation. Personal data may only be collected for, and processed consistent with, specified, explicit and legitimate purposes. Data minimization. Controllers and processors must limit processing of personal data to that which is adequate, relevant and necessary to achieve a proper purpose. Accuracy. Controllers and processors must take reasonable steps to make sure that personal data is accurate and, where necessary, kept up to date. Storage limitation. Except under certain circumstances, personal data may only be stored as long as necessary for the appropriate processing to occur. Integrity and confidentiality. Personal data must be processed in a manner that ensures its appropriate security (Article 5(1)(f)). This includes protection against unauthorized or unlawful processing and against accidental loss, destruction or damage. In this regard, controllers and processors must use appropriate technical or organizational security measures. Accountability. The controller is responsible for, and must be able to demonstrate, compliance with the other data protection principles (Article 5(2)). The law imposes detailed standards regarding each principle. Further, controllers and processors must implement data security measures to operationalize these principles. What are some of the specific requirements that GDPR-covered businesses must comply with? Examples include: Obtaining consent of for subjects for data processing “Anonymizing” collected data under certain circumstances to protect privacy Providing data subject with breach notifications Safely storing and transferring protected data Under certain circumstances, appointing a data protection officer to oversee GDPR compliance Simply put, the GDPR mandates a baseline set of standards for companies that handle EU citizens’ data to better safeguard the processing and movement of citizens’ personal data. What is a data processing agreement/addendum? Pursuant to EU law, including the GDPR, covered controllers and processors of personal data must use third-party processors that provide sufficient guarantees that processing will be consistent with applicable EU standards. The data processing agreement or addendum (“DPA”) is an instrument to establish these duties. The GDPR further sets forth specific elements that must be included in DPAs between covered controllers and processors, or processors and sub-processors. The GDPR imposes more detailed requirements for DPAs. REDA One has analyzed these requirements and offers DPAs to its customers as necessary to comply with applicable law. How does REDA One process data? REDA One provides customizable applications and related services to help businesses analyze and report financial data to meet their specific needs. Salesforce relationship. REDA One has selected Salesforce as the exclusive host for our applications. We not only believe strongly that Salesforce maximizes the capacity of our unique offerings, but also in Salesforce commitment to data protection. Our customers interface directly with Salesforce to populate and access its data. Customers utilize the REDA One application autonomously within Salesforce’s environment. At all times, all customer data resides on Salesforce’s infrastructure and is subject to its terms and conditions. In order to craft appropriate disclosure language for purposes of obtaining consents of data subjects, we encourage our customers to review the Salesforce GDPR Webpage and its terms and conditions with Salesforce. REDA One Processing. REDA One will only access customer data on the Salesforce platform for troubleshooting and related purposes upon a customer’s request. In these cases, we provide our customers with the ability to grant data access credentials for REDA One’s workforce. REDA One and its workforce do not export customer data from the Salesforce platform. Advertising Data — Google & Meta Integrations The REDA One Ads Connector is an optional Salesforce application that lets a REDA One customer (the advertiser) connect their own Google Ads and Meta (Facebook and Instagram) advertising accounts in order to deliver advertising leads into their own Salesforce CRM and report conversions back to those advertising platforms. This section describes how the application accesses, uses, shares, protects, retains and deletes Google and Meta user data. These integrations apply only to customers who explicitly connect their own advertising accounts. Google User Data What Google user data we access. When you connect your Google Ads account through Google’s OAuth consent screen, the application requests the https://www.googleapis.com/auth/adwords scope (read-only access to your Google Ads account configuration, used to list your conversion actions during setup) and the https://www.googleapis.com/auth/datamanager scope (permission to upload offline, closed-loop conversion events to your own Google Ads account). Through this authorization we obtain and store an OAuth refresh token for your Google Ads account. We do not access your Gmail, Google Drive, Contacts, calendar, profile, or any other Google product or personal data — only the advertising data of the Google Ads account you connect. How we use Google user data. We use it solely to (1) list your Google Ads conversion actions during one-time setup so you can choose a conversion target, and (2) upload your own leads’ conversion events (conversion action, Google Click ID, value and timestamp) back to your own Google Ads account so you can measure campaign performance. Google user data is not used for any other purpose, is not sold, is not used for advertising or profiling, and is not used to train generalized artificial-intelligence or machine-learning models. Who we share Google user data with. Google user data flows only between your own Salesforce organization and Google’s Ads and Data Manager APIs, brokered by REDA’s pass-through connection service. We do not share, sell, transfer or disclose your Google user data to any other third party, except to Google as the API destination, within your own Salesforce organization, or where required by law. How we protect Google user data. Your Google refresh token is stored encrypted at rest (AES-256, with a key derived per Salesforce organization) inside your own Salesforce organization — not on REDA’s servers — and is not decryptable outside the application. All data in transit is protected with TLS/HTTPS, and traffic between your organization and REDA’s connection service is cryptographically signed. The application requests least-privilege scopes, and REDA’s connection service retains no Google user data. Data retention and deletion. The Google refresh token is retained only in your own Salesforce organization and only while the connection is active. It is deleted when you use the in-application Disconnect action, delete the Ad Account record, or uninstall the application. REDA’s connection service does not retain Google user data. To request deletion, use the Disconnect action or contact info@reda.one. Limited Use. REDA One’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Meta (Facebook and Instagram) User Data What Meta user data we access. When you connect your Facebook Page through Meta’s Facebook Login for Business consent flow, the application obtains a Page access token for the Page you connect and subscribes to that Page’s lead notifications. It accesses the lead-form submissions for that Page’s Lead Ads — the information a person voluntarily provides on your ad’s lead form (such as name, email address, phone number and any custom form fields) together with the related Page, form, campaign and platform identifiers. We do not access personal profiles, friend lists, messages, or any Meta data beyond the lead-ad submissions and the Page token needed to retrieve them. How we use Meta user data. We use it solely to deliver each lead-form submission into the advertiser’s own Salesforce CRM so the advertiser can follow up with the person who responded to their ad. It is not used for any other purpose, is not sold, and is not used for advertising, profiling or model training. Who we share Meta user data with. Each lead is delivered only to the advertiser whose ad the person responded to, and is stored in that advertiser’s own Salesforce organization. REDA’s connection service is a pass-through and does not retain lead content. We do not share, sell or disclose Meta user data to any other third party, except to Meta as the source API, to the destination advertiser’s own Salesforce organization, or where required by law. How we protect Meta user data. The Page access token is stored encrypted at rest (AES-256, organization-derived key) in the advertiser’s own Salesforce organization. Inbound webhooks are verified with a cryptographic signature, and lead content is always fetched over TLS through Meta’s authenticated Graph API. All data in transit uses TLS/HTTPS. Data retention and deletion. Lead content is stored in the advertiser’s own Salesforce organization, not on REDA’s servers. The Page access token is deleted when the advertiser uses the Disconnect action (which also unsubscribes the Page) or uninstalls the application. A person may request deletion of their information from the advertiser who ran the ad, or by contacting info@reda.one; REDA operates a pass-through service and does not retain the lead content. For any additional questions please contact info@reda.one Join us on the journey to hyper-growth with the world’s #1 Real Estate Technology Solution Navigate the Real Estate Tech Landscape Explore a spectrum of solutions that redefine property management and investment opportunities. Your gateway to a smarter, more efficient future awaits EXPLORE ALL APPS Experience the Future of Property Management Schedule a demo and unlock the full potential of our comprehensive ERP solution. SCHEDULE A DEMO Stay Ahead in Real Estate Tech Subscribe to our newsletter and receive cutting-edge insights, updates and innovations from the world of property management. SUBSCRIBE TO NEWSLETTER