Lobbytrack Security Guide

EU-U.S. Data Privacy Framework and UK Extension Commitment

Jolly complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. Jolly has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF as described in the site Privacy Policy. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

GDPR Compliance

In May 2018, the EU General Data Protection Regulation (GDPR) went into effect. This law requires that Lobbytrack and users managing visits using the service provide other users with details of how their personal data will be processed.

How will Lobbytrack use your personal data

Your personal data will be collected and processed by Lobbytrack when:

  • We have your consent
  • It is necessary for use of the Lobbytrack site and services
  • We are required by law to provide it for legal or regulatory obligations

Transfer of personal data

Lobbytrack is a global service provider and your data may be stored outside of the country where it was provided. If your personal data is ever transferred from one of our systems to another, we take steps to ensure that appropriate safeguards are in-place to protect your data. Your data is further protected by our participation in the EU-U.S. Data Privacy Framework program, as described above.

Personal data retention

Your personal data is retained as long as necessary to provide you with the ability to use Lobbytrack products and services as well as for other important purposes such as resolving transaction disputes and other legal obligations.

Typically your personal data can be deleted immediately, either by managing your account or upon request, barring any pending or recent transactions.

Lobbytrack as a data controller

Lobbytrack acts as a data controller, per the EU data protection laws, when someone creates an account on Lobbytrack.com. For example, if you are managing visitors with Lobbytrack, Lobbytrack will be a data controller in regards to your personal data.

Lobbytrack as a data processor

Lobbytrack acts as a data processor, per the EU data protection laws, in regards to the use and collection of personal data to assist users in regards to managing their hosts and visitors (e.g. sending notification emails, etc). Lobbytrack does not control what personal data is collected during the registration process, nor does it manage the validity of the collected data.

If you have any questions regarding your personal data related to a visit, please contact the visit organizer as they are the data controller in this case.

Your rights

It is your right to request information on what personal data Lobbytrack maintains about you as well as to correct or delete your personal data. For assistance, please contact us.

Hosting Environment

Lobbytrack is hosted on the Microsoft Azure platform. Microsoft Azure is PCI DSS 3.1 certified. For more information, visit the Microsoft Trust Center.

Data Protection

Lobbytrack encrypts sensitive information such as passwords and credit card numbers using the strong, industry-standard cryptographic protocol, AES-256. Data is maintained in Microsoft Azure and all data communications are encrypted using 256-bit SSL certificates.

Employee Data Access

Lobbytrack is developed and maintained by Jolly Technologies Inc, a California-based corporation. All employees must pass rigorous background checks. Employee access to customer data is strictly limited to a need-to-know basis.

Privacy

We have a strict policy to respect the privacy of customer information. We will not disclose your information to 3rd parties without your express permission. For more information, please refer to our Privacy Policy.

If you have any questions or would like more information, please contact us.