Data Processing Policy

Data Processing
Effective Date: 03/27/2019

By use of JossyMall services, you instruct JossyMall to process any personal data you provide to JossyMall in alignment with JossyMall’s Service Agreement and Privacy Policy and agree to the processing of any personal data that JossyMall provides to you in connection with the services. Customer also specifically authorizes the engagement of JossyMall’s Affiliates as Sub-processors. In addition, Customer generally authorizes the engagement of any other third parties as Sub-processors.

Customer Obligations
By use of JossyMall services you agree to comply with data protection, security and other obligations with respect to any and all personal data by adhering to the JossyMall Service Agreement and Anti-Spam policies, and Privacy Policy along with all local data protection laws to which you are subject. JossyMall will inform you if, in JossyMall’s opinion, you have violated any data processing obligation.

Details of Data Processing
Subject Matter: All JossyMall services, Customer provided data, and related technical support to Customer, including all publicly available information that is transmitted or retrieved from sub-processors of JossyMall.

Duration of the Processing: As identified in the JossyMall Service Agreement.

Nature and Purpose of the Processing: JossyMall provides an email service, automation and marketing platform and other related services as identified in our Privacy Policy.

Categories of Data: As outlined in our Privacy Policy ("I Am An JossyMall Affiliate.", "I Am A Subscriber To An Email List Managed Through JossyMall.", "I Am An JossyMall Customer.")

Data Subjects: Personal data submitted, stored, sent or received via JossyMall services that may concern the Customer or Subscribers of the Customer.

Data Security
JossyMall takes all reasonable technical and organizational measures to commit to confidentiality of your data including:

Use of encryption
Continual monitoring of the confidentiality, integrity, availability, and resilience of our systems
Preparedness to restore availability of our services in the event of a physical or technical incident
Regular risk assessments of all systems
Commercially reasonable steps to ensure employees and those acting on JossyMall’s behalf maintain confidentiality of personal data
Privacy confirmations of all sub-processors engaged in providing JossyMall services to provide at least the same level of protection for the personal data and the rights of data subject as JossyMall.
Providing written responses to all reasonable requests for information made by customers
In the event of a personal data breach, reasonably assisting customers with data security audits, including inspections, conducted by the customer, auditors, law enforcement, or other supervisory authorities
Providing notice to customers regarding personal data breaches without undue delay
Reasonably assisting customers with their obligations to Supervisory Authority Data Protection Impact Assessments and Prior Consultation taking into account the nature of processing and data involved
Maintaining Privacy-Shield certification
Maintaining Payment Card Industry (PCI) Security certification
Data Rights
Right to be informed: You or your subscribers can ask about personal data, how it is used, and why it is being used at any time.

Right of access: As outlined in our Privacy Policy (Access to Personal Information).

Right of rectification: You or your subscribers can update (or request updates to) personal information at any time.

Right of erasure: You may cancel your JossyMall account at any time and may additionally request that JossyMall erase your personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data. Your subscribers may also request that you or JossyMall do the same for their personal data. JossyMall reserves the right to keep the minimum amount of information that helps us prevent fraud to keep your deliverability the highest it can be.

Right to restrict processing: You may put your account on hold at any time which restricts the sending of email. Your data will still be processed for other actions such as billing and by our sub-processors. You may backup and deactivate a list to verify subscriber data and reactivate within 30 days. You may cancel your account to restrict all data processing of your data and your subscribers and reactivate your account as long as we have not yet deleted your information according to our retention policies.

Right to data portability: You may export any of your lists, or selected information within any list, at any time while your account is active by accessing your JossyMall account.

Right to object: You may unsubscribe from any of JossyMall’s emails at any time. Your subscribers may unsubscribe from your emails at any time.

JossyMall does not discriminate against a customer, price services differently, or reduce quality of service based on exercising of the above data rights.