The GDPR is a legal framework of EU legislation intended to standardize data regulation across Europe while providing greater protection and control over data to the consumer. It’s an updated version of the Data Protection Directive.
GDPR aims to protect the privacy of EU citizens, specifically their “right to be forgotten” — their right to demand that organizations identify and eradicate any or all data about them.
The purpose of this guide is to give you details on how RepairSuite is preparing for GDPR and to provide you with an overview of the new requirements to help you prepare.
Being accountable for customers’ data, RepairSuite has updated its platform with procedures to protect your personal data from illegal loss, theft, leakage, or unauthorized sharing. We will be responsible for requesting your consent before collecting any personal information or data.
What can you do to prepare?
If your business is based in the European Union (EU), or you process the personal data of EU citizens, the General Data Protection Regulation (GDPR) affects you.
The GDPR says you must obtain freely given, specific, informed, and unambiguous consent from your contacts. You also must clearly explain how you plan to use their personal data.
If you have customers in the EU, you must ask for consent to store personal details and get permission before sending follow-up marketing or promotional emails/SMS via RepairSuite. Based on customer preferences, you can choose for which individuals you store none-to-all details. Consult legal or other professional counsel about your GDPR preparations.
Features included in the update
- Customer registration process for EU customers where they will be asked for consent related to data processing.
- Recording of customer data for RepairSuite desk end users.
- Edit or “forget” rights for customers of RepairSuite desk end users.
- Updates across the web application: POS, Leads, Customer Module, Invoice, Ticket section, Appointment calendar, Public API, Self-Check-in Widget, Trade-In widget.
- On consent to forget details, RepairSuite will delete customer records and update existing reports with “Walk in Customer” to keep business statistics aligned.
Note: We will be updating this section continuously with our latest roadmap and progress.
Customer Rights
Under GDPR, RepairSuite customers are considered “Data Controllers.” If you have customers in the EU and record their data in RepairSuite, you have the responsibility to allow individuals to exercise:
- Right to be Informed
- Right to Rectification
- Right to be Forgotten
- Right to Object
- Right to Restrict Processing
- Right to Data Portability
Definitions
- Right to Object: Individuals may object to the use of their data for profiling or direct marketing activities.
- Right to be Forgotten: Individuals have the right to request that personal information be removed from RepairSuite.
- Right to be Informed: Individuals may ask for clear and concise information about what you do with their personal data.
- Right to Restrict Processing: Individuals may request the suppression of their personal data (store it but not use it).
- Right to data portability: Individuals may request to get their personal data, in a readable format.