Privacy

EU General Data Protection Regulation (GDPR)

JustRelate CRM supports you in the process of realizing the EU-DSGVO. Among other things, you will find possibilities for logging purposes of use, functions for obtaining consent to process the personal data of your contacts, and logging the withdrawal of consent, and also the possibility to react to the extended rights of data subjects to information or deletion of personal data.

What GDPR-compliant work with JustRelate CRM also means

Order processing

GDPR-compliant order processing (AV) for our customers.

Secure cloud computing

For customers who process cloud-based data with JustRelate CRM, the data is hosted in a German high-security data center that is certified as a “Trusted Cloud Service”.

Internal security

Technical and organizational measures according to  GDPR, internal safety concept.

See also: Further general information about the GDPR and data protection can be found in JustRelate CRM DSGVO info (German version).

The EU General Data Protection Regulation results in requirements for recording and processing contacts, as well as in email marketing, which the CRM takes into account. Learn what the GDPR changed, and what you need to pay attention to when capturing and processing con­tacts in accordance with the GDPR, and when implementing the rights of data subjects.

Data acquisition not as an end in itself – increased customizing effort

The main principle and prerequisite for complying with the increased data protection requirements is that the amount of data is minimized, i.e., limited to what is necessary for the purposes of processing. Even if it is convenient and tempting to capture personal properties as free text, you must always ensure that you can track this data and remain in control of it.

Tip: When customizing, make sure that only the personal data fields and objects that you can also moni­tor are adjusted. The result of the extensions you request may be that this data has to then also be addi­tionally protected, and additional information concerning it needs to be provided (extended rights of the data subjects).

It cannot be avoided that the customization effort increases if information reports and data protection convenience features are adjusted to the changed or additional objects that represent personal data.

No mandatory information obligation for existing customers

If data was already collected before 25 May 2018 (existing customers, marketing database, etc.), then it is not necessary from the “cut-off date” (or thereafter) to inform the customers about the processing operations by providing “standard information on data protection according to the GDPR”. The German Associ­ation for Data Protection and Data Security (GDD) points out that the “GDPR does not provide for any blanket stock information from 25 May 2018, i.e. no 'transparency reset’”.

Only if new data is collected from 25 May 2018, the data subject must be comprehensively informed in accordance with section 13 (for direct data collection) or Section 14 (for indirect data collection) (source: dataprotect.at).