Data collection, storage & processing | Collect data, only for the purpose its needed for. That is, data collected for specific purposes/reasons cannot be further processed in a manner incompatible with those purposes/reasons. | Mastroke products provide the convenience of enforcing your company’s defined limitations/policies through the product itself. |
Right to rectification | Data controllers must ensure information remains accurate, valid and fit for purpose. To comply with this, organizations must institute a process and policies in place to address this right. | If our customer reaches out requesting correction of their data by contacting our Data Protection officer, we acknowledge and revert with total honesty. |
Right to portability | Data subjects have the right to receive their personal data in a structured, commonly used and machine-readable format. They have the right to transmit this data to another vendor/company of their choice without hindrance from the existing vendor/company. | Our products directly assist our customer’s need to meet ‘right to portability’ requests from their customers. |
Limitation to storage | To ensure compliance, organizations must have control over storage and movement of data. This includes implementing and enforcing data retention policies and not allowing data to be stored in multiple places. | Since all our data are stored on cloud in such a way that data cannot be duplicated over multiple places and also have retention policy. |
Right to be forgotten | Data subjects can request erasure of all personal data concerning them. And, the company/business has the obligation to erase all personal data of that individual without undue delay. | If our customer reaches out requesting correction of their data by contacting our Data Protection officer, we acknowledge and revert with total honesty. |
Confidential and secure | Businesses must protect the integrity and privacy of data by making sure it’s secure. An organization collecting and processing data is solely responsible for implementing appropriate security measures to protect the individuals data. | Mastroke regularly evaluates enforcement of – security policies, utilization of dynamic access controls, identity verification of those accessing data, and implementation of protection mechanisms against data breach. Relevant certifications include ISO 27001, SOC II compliant. |
Accountability and liability | Organizations must be able to demonstrate to governing bodies that they have taken necessary steps to protect an individual’s personal data. Be sure every step within the GDPR strategy can be pulled up as evidence. | Mastroke maintains an audit trail to enable you to provide evidence of appropriate actions taken on an individual’s request. |