From day one, zkipster has been built around a strong commitment to privacy, security, and protecting sensitive event and guest data.
We fully support our users complying with regulation (EU) 2016/679, also known as the General Data Protection Regulation (GDPR), that entered into effect on May 25, 2018 and repealed Directive 95/46/EC. We’ve been busy taking steps to make the transition as smooth as possible for zkipster users who are impacted by this transformative new law.
Please note that this page is provided as a resource to understand the scope of the GDPR in relation to using zkipster. It does not constitute legal advice, representations, or warranties of zkipster. We encourage you to seek professional legal advice if you have questions about how the GDPR may affect your organization and procedures.
ZKIPSTER IS GDPR COMPLIANT
Under the GDPR, there are in particular two types of entities that might process personal data:
- Data controllers are individuals or entities that determine the purpose and means of the processing of personal data of EU citizens, and must therefore be compliant with the GDPR and ensure any third-parties to which they transmit or otherwise make available personal data are also compliant.
- Data processors are third-parties who process personal data on behalf of data controllers, and must in particular implement appropriate technical and organizational security measures that meet the requirements of the GDPR.
In this system under the applicability of the GDPR, zkipster is a data processor, and zkipster users (e.g. event professionals) are data controllers.
As a data processor, we’ve taken various initiatives to ensure zkipster’s compliance with the GDPR’s requirements (to the extent applicable) with respect to the scope of services stated in our terms and conditions (e.g. event management, online invitation, guest list, seating, event check-in, or related service of zkipster) which include among others:
- Ensure that all persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
- Take and implement all appropriate technical and organizational security measures to permanently protect the confidentiality, integrity, availability and capacity of personal data and respective processing systems and services
- Respond in a timely manner to requests to access, correct, return, or delete personal data
- Report security breaches impacting personal data in accordance with GDPR timeframes
- Demonstrate compliance with the GDPR
As a result of diligent internal reviews, zkipster has taken additional measures to support its users in complying with the GDPR. We act only on instructions by users (data controllers) and demonstrate full compliance with obligations across internal entities, subsidiaries, and hosting or cloud providers. Users of zkipster can at any time permanently delete guest data they have uploaded to zkipster.
WHAT YOU NEED TO DO AS A USER
In order for us as data processors to provide (to the extent applicable) GDPR compliance referred to above, we operate under the assumption that you as a data controller do the following:
- Obtain personal data of EU citizens with valid permission, as set forth by the GDPR only, including explicit and informed consent
- Act in compliance with the GDPR’s rules and any other applicable data protection or information privacy laws and regulations
- Agree to have zkipster act as data processor on your (the data controller’s) behalf
Following these steps allows us to operate together under compliance with the GDPR (to the extent applicable), and provide you the same high standard of service you have come to expect.