How does Heatmap.com ensure GDPR compliance?
We follow key principles of GDPR, including:
Data Minimization: Only collecting necessary data for our services.
User Consent: Providing an SDK for integrated sites to mark sessions as “Do Not Track” if consent is not given.
Data Subject Rights: Facilitating access, rectification, erasure, and portability of personal data.
Data Processing Agreements (DPAs): In place with clients to outline roles and responsibilities.
Data Protection Officer (DPO): Appointed to oversee compliance.
Security Measures: Implemented to protect personal data from unauthorized access or processing.
What other data protection laws does Heatmap.com comply with? We also comply with:
California Consumer Privacy Act (CCPA): Allowing California residents to exercise their privacy rights.
Personal Information Protection and Electronic Documents Act (PIPEDA): Adhering to rules for collecting and handling personal information in Canada.
Australian Privacy Principles (APPs): Ensuring privacy protections for Australian users.
What are Heatmap.com's data retention policies? We have clear retention policies for various types of data:
User Account Data: Retained for the duration of the active account plus 30 days after closure.
Heatmap Data: Retained for 12 months, with options for shorter or longer periods based on client needs.
Analytics Data: Aggregated data retained for 24 months.
Log Data: Retained for 90 days for security and troubleshooting.
Backup Data: Retained for 30 days.
How does Heatmap.com delete data after retention periods?
At the end of the retention periods, data is securely and permanently deleted from our systems.
How can I inquire about Heatmap.com's data privacy practices or exercise my data rights?
You can contact our Data Protection Officer at support@heatmap.com for any privacy-related inquiries.
When was this policy last updated?
The policy was last updated on 10/21/2024.
Does Heatmap.com review and update its data privacy practices regularly?
Yes, we continuously review and update our practices to stay aligned with global data protection standards.