GDPR Policy

The General Data Protection Regulation (GDPR) came into effect the 25th May 2018, replacing the Data Protection Act 1998 (UK).

jigsaw kloud, as a Data Protection Officer and Data Controller, is responsible for collecting and protecting sensitive client data.

Information is only ever stored electronically, which is protected by passwords, encryption and 2FA. No paper records are kept.

Data Processor suppliers:
#1 Microsoft
#2 Google
#3 Zoho
#4 Filen
#5 Authy
#6 WordPress and Hostinger

#1 Microsoft
Windows 11 and Office documents containing sensitive data are password-protected and backed up to encrypted cloud storage.
Microsoft’s GDPR statement

#2 Google
Data is saved in various apps.
Google’s GDPR statement

#3 Zoho
Data is saved in various apps.
Zoho’s GDPR statement

#4 Filen
Files encrypted in cloud storage.
Filen GDPR Statement

#5 Authy
Additional security is provided using Two-factor Authorisation (2FA).
Twilio’s GDPR statement

#6 WordPress and Hostinger
All websites are managed via WordPress and Hostinger.
WordPress’ GDPR statement
Hostinger’s GDPR statement

What personal data we collect
jigsaw kloud considers there to be either a contractual or legitimate business interest to maintain contact with current clients, partners and suppliers. We only collect and process personal data we require to provide a specific service, which may include personally identifiable contact information. In addition, if you contact us directly, we may receive additional information, the contents of any message and/or attachments you send us, and any other information you choose to provide. The personal information you are asked to provide, and the reasons you are asked to provide it, will be made clear to you when we request such information.

How we handle your data
We use your data to provide a specific service and may share this data with trusted third parties, only when necessary.

How we protect your data
We take reasonable precautions, utilising encryption (#4) and t2FA (#5) to protect data in our possession from loss, misuse, and unauthorised access.

How long we process your data
Personal data we process will not be held longer than we have an ongoing legitimate business need to do so. When we have no ongoing legitimate business need to process your personal information, we will delete or, if not possible, continue to securely store your information and isolate it from any further processing until deletion is possible.

How we process requests for data
Any clients, suppliers or partners who wish to receive copies of the data jigsaw kloud holds about them are welcome to request copies, free of charge within 30 days (unless the request is complicated; in which case a charge of £25 will be applied and 2 months shall be allowed).


YOUR RIGHTS

Right of access: You have the right to obtain from us information concerning you and to request copies of your data.

Right to rectification: You have the right to request inaccurate data be amended by providing correct data.

Right to be forgotten: You have the right to request the erasure of your data. We must delete without delay.

Right to restriction of processing: In certain situations, you have the right to obtain from us the restriction of processing.

Right to data portability: You have the right to receive your data in a structured, commonly used and machine-readable format to transmit to another controller.

Right to object: In certain situations, you have the right to object to the processing of your data e.g. for marketing purposes.

Right to file complaints: You have the right to complaint to the ICO abow how we process your data.

Right to compensation of damages: In case we breach applicable legislation on processing your data, you have the right to claim damages from us for any damages such a breach may cause you.

If you wish to request your data related to the rights mentioned, contact us.

jigsaw kloud
19th May 2018