GDPR compliance & Deloitte as DPO
Given the nature of geo location data, we have to deal with GDPR in a very strict manner. Having started in 2019 we have build our company from a privacy by design point of view. We provide maximum privacy & security for panel members via different efforts.
- A GDPR-focused consent flow limits data tracking to dual optin users referencing our SDK privacy policy. There are two integrations possible (as outlined technically in the SDK documentation - see attachment):
- A default consent flow is triggered when required in the app and optimized for different operating systems
- An app owner can decide to connect our SDK via a custom implementation to integrate it in its own consent framework (such as IABโs TCF 2.2 framework).
- An extensive DPIA documents all efforts in terms of privacy.
- We conduct yearly pen tests to validate & improve security.
- Technical measures are outlined in detail on our Privacy center.
- We have processor agreements (DPAs) with both partners and subcontractors that stipulate how to deal with user rights, privacy and security (see attachment).
- We work with an objective, external partner Deloitte that acts as our DPO office.