Privacy Policy

Data Controller and Data Processor

Protected Harbor’s business customers are the data controllers for most information entered into the Protected Harbor web application, website, and supporting systems or shared periodically with Protected Harbor employees to deliver services. This positions Protected Harbor as the data processor for most information stored and processed by Protected Harbor. Some pieces of information are collected directly by Protected Harbor to facilitate security, logging, and application performance. These items include IP addresses and behavior within the Protected Harbor platform. For these pieces of information, Protected Harbor acts as the data controller and processor. Additionally, Protected Harbor employs a variety of technologies and partners that periodically act as sub-processors. If users have any questions or concerns about the processing and handling of their personal information, they may communicate directly with the Privacy Officer.

Privacy Notice and Transparency

It is important ethically and legally to provide reasonable transparency to data subjects concerning the processing and handling of their personal data. Protected Harbor maintains an upto-date privacy notice that is made available to all customers and users of the Protected Harbor platform and services. Employees and contractors must read this privacy notice. If errors or concerns are discovered, findings must be shared with the Privacy Officer.

Privacy by Design

The concept of privacy by design must be applied to every new product, project, or service and if a change of substance to a current product, project, or service occurs. Privacy by design involves considering privacy at every project stage: planning, design, development, testing, launch,
maintenance, and end of life.
In applying privacy by design, the following elements must be considered:

  • Types of Data Collected
  • The Purposes of Processing
  • Legal Basis of Processing
  • Data Residency and Cross-Border Transfer
  • Retention Time
  • Data Subject Rights

A privacy impact assessment and a threat risk assessment must be conducted as part of the planning and design phases of the project. They must be updated before launch to factor in changes in scope that occur throughout the product development. Additionally, these assessments must be reviewed at least annually or in the event of a significant change in scope, business use case, architecture, or legal landscape.

Legal Basis of Processing

Below are the legal bases for Protected Harbor to collect personal information:

  • Users have given their consent for one or more specific purposes.
  • Provision of data is necessary for the performance of an agreement with the user.
  • Processing is necessary for compliance with a legal obligation.
  • Processing is necessary for the legitimate interests pursued by the controller or a third
    party.

Retention Time

Personal data is to be processed and stored for as long as required to fulfill the purpose for which it is collected.
Therefore:

  • Personal data collected to perform a contract between Protected Harbor and a business
    customer is retained until such contract has been entirely performed or the customer asks
    for the data to be deleted.
  • Personal data collected for Protected Harbor’s legitimate interests shall be retained as
    long as needed to fulfill such purposes.

Protected Harbor may be allowed to retain personal information for a more extended period whenever the user has consented to such processing, as long as such consent is not withdrawn. Furthermore, Protected Harbor may be obliged to retain personal data for a more extended period whenever required to perform a legal obligation or upon order of an authority.
Once the retention period expires, the user’s personal data will be securely deleted.

Processing Requests and Inquiries from Data Owners

  • Withdraw their consent at any time. Users have the right to withdraw consent after they have previously given their consent to processing their personal data.
  • Object to processing of their data. Users have the right to object to the processing of their data if the processing is carried out on a legal basis other than consent.
  • Access their data. Users have the right to learn if Protected Harbor is processing their data, obtain disclosure regarding certain aspects of the processing, and obtain a copy of the data undergoing processing.
  • Verify and seek rectification. Users have the right to verify their data accuracy and ask for it to be updated or corrected.
  • Restrict the processing of their data. Users have the right, under certain circumstances, to restrict the processing of their data. In this case, Protected Harbor will not process their data for any purpose other than storing it.
  • Have their personal data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their data from Protected Harbor.
  • Receive their data and have it transferred to another controller. Users have the right to receive their data in a structured, commonly used, machine-readable format, and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the data is processed by automated means and that the processing is based on the user’s consent, on a contract that the user is part of, or on pre-contractual obligations.
  • Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.

Process for Data Subject to Exercise These Rights

Any requests to exercise data subject rights can be directed to Protected Harbor through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by Protected Harbor as early as possible and always within one month.

Cookie Policy

The Protected Harbor website and Protected Harbor web application use cookies. Users must be able to learn more about the use of cookies via a cookie notice that must be available to the user.

Hey there 👋 Want to learn about Protected Harbor?