Slav Ivanov
slav@encharge.io
59 Uoshbarn St, fl. 7,
Sofia,
Bulgaria
1510
As part of our ongoing efforts to protect the security and privacy of our users, we are working to meet or exceed the GDPR (General Data Protection Regulation). This site contains information on what steps we are taking, their progress, and who to contact for any security concerns. Please see our FAQ for more information.
If you need a signed DPA, please use the button below to cross sign and download your copy of our DPA.
We respect the rights of individuals to know how their data is being used, export it or request that it be deleted.
We rely on a number of trusted 3rd parties to assist with our operations. Depending on the exact nature of your account and what you've requested we do, your data may be shared with one of these partners. We carefully evaluate each to make sure they're handling your personal data with the utmost of respect, security, and privacy.
Services | ||||
---|---|---|---|---|
Partner | Locale | Data Shared | Purpose | |
Amazon Web Services | ![]() |
Any | Amazon CloudFront is a global content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to your viewers with low latency and high transfer speeds. CloudFront is integrated with AWS – including physical locations that are directly connected to the AWS global infrastructure, as well as software that works seamlessly with services including AWS Shield for DDoS mitigation, Amazon S3, Elastic Load Balancing or Amazon EC2 as origins for your applications, and Lambda@Edge to run custom code close to your viewers. |
|
CDN JS | ![]() |
IP Address | CloudFlare's CDN with popular javascript frameworks available. |
|
![]() |
Hotjar | ![]() |
IP Address | A heatmap, survey, feedback and funnel application. |
![]() |
MailChimp | ![]() |
Any data authorized by customer Company | DescriptionMailchimp is a marketing automation platform and an email marketing service. |
![]() |
Segment | ![]() |
IP Address | Segment gives you the ability to instrument your web app for analytics once, and then send your data to any number of analytics services. Previously known as Segment.io |
![]() |
Twilio Inc | ![]() |
email phone number first name last name any other data needed to send email on behalf of customer's Company | Twilio Inc. enables phones, VoIP, and messaging to be embedded into web, desktop, and mobile software. |
![]() |
Zapier Inc. | ![]() |
email first name last name any other data authorized on behalf of customer's Company | Zapier Inc. is a web-based service that allows users to integrate the web applications they use. |
GDPR Compliance requires maintenance and ongoing work. We are tracking our efforts here.
Application Site Security | |
---|---|
Status | Name |
Completed | SSL (TLS) Deployed on App Site |
Completed | Ensure Access to Backups is Restricted |
Completed | Ensure Backups are Stored in on Encrypted File Storage |
Data Mapping | |
---|---|
Status | Name |
Completed | Add CDN Provider to Data Partners |
Completed | Add Exception/Error Reporting Services to Data Partners |
Completed | Add Internal Email Service to Data Partners |
Completed | Add Hosting Provider to Data Partners |
Completed | Add Transactional Email Service to Partners |
Completed | Add Email Newsletter Service to Partners |
Completed | Add Database Provider to Data Partner |
Marketing Site Security | |
---|---|
Status | Name |
Completed | Reviewed list of users with access to site |
Completed | SSL (TLS) Deployed on Marketing Site |
Privacy Procedures | |
---|---|
Status | Name |
Completed | Procedure established to allow for people to request that inaccuracies in their data are fixed. |
Completed | Process established for subject data requests |
Completed | Get Management Approval for GDPR Efforts |
Completed | Nominate a Data Protection Lead or Data Protection |
Security Procedures | |
---|---|
Status | Name |
Completed | Publish statement on public website on how to report security and data issues. |
If you have any concerns not answered here, please reach out to our contact (listed above) and we'll be happy to assist.
The General Data Protection Regulation (GDPR) is a new piece of privacy legislation enacted by the European Union. It represents a significant change in how personal (IP Addresses, Emails, Names) and sensitive (religion, ethnic origin, health, orientation) data is handled by companies.
We take all security reports seriously. Please email our security contact (information listed above) with any information you have regarding any potential data breaches, vulnerabilities or concerns.
While it remains to be seen if the EU has the legislative power to levy fines and enforcement against organizations around the globe, GDPR compliance is being sought by non EU companies for a variety of reasons.