360AI - GDPR & CCPA

GDPR & CCPA

360AI is compliant with GDPR EU & UK, CCPA and USA privacy laws

Putting Privacy First

360AI's Commitment to Privacy Compliance

360AI is dedicated to adhering to the principles of GDPR EU, GDPR UK, CCPA, and USA privacy laws. We strive to provide features and functionality that assist our customers and partners in meeting their privacy obligations.

Our main priorities are to ensure that:

  • The protection of personal data entrusted to us is never compromised or misused.
  • We are fully compliant with our legal and regulatory responsibilities.
  • We continue to provide our customers and partners with the highest standard of services.

Legal Basis for Data Processing

We process data that has been made 'manifestly public' (GDPR Article 9.2(e)) by the data subject. We only aggregate publicly available data from sources such as websites and social media. 360AI has a 'legitimate interest' (GDPR Article 6.1(f)) in helping professionals connect with relevant individuals.

Preparing for GDPR

During the preparation and implementation period, 360AI evaluated the requirements and restrictions imposed by the GDPR and took necessary actions to ensure compliance with EU legislation. These efforts included:

  • Data Processing: Ensuring our data protection commitments as a data processor to our customers are fundamental to our GDPR compliance.
  • Agreements and Policies: Our agreements and policies include provisions to address the processing and storage of personal data by 360AI, outline our privacy commitments to customers, and define the rights and obligations of data controllers (our customers) and data processors (360AI).
  • Expanded Disclosure: We provide clear descriptions of the data we collect, why we collect it, and how we store and process it. This includes information on data sharing, storage duration, and data protection measures.
  • Purpose Limitation: We offer clients business contact data to enhance their recruitment efforts and identify top talent. We collect and provide the minimum data necessary for these activities.
  • Data Subject Requests: We notify customers of data subject deletion requests per Article 19 and grant data subjects control over their data via our self-serve Privacy Centre, allowing them to exercise their rights easily. Individuals can opt out at any time via our opt out page.
  • Privacy by Design: Our product development cycle includes controls, specifications, processes, and policies that safeguard personal data protection throughout the software development lifecycle.
  • Dedicated Privacy Management: We have a designated Data Protection Officer (DPO) and Compliance Manager responsible for developing and implementing our compliance roadmap, promoting GDPR awareness, assessing readiness, identifying gaps, and implementing new policies and controls.
  • Global Privacy Training: Continuous employee awareness and understanding are crucial for ongoing GDPR compliance. We have implemented a Global Privacy Training program as part of our induction and annual refresher training.

Your Privacy Rights

Access

You may request access to a copy of your personal information, including details on the purposes of processing, categories of data processed, data recipients, storage duration, and data transfers.

Erasure

We deal only with public data; information removed from a website will also be removed from our database. You can request the removal of your personal information from our database at any time.

Portability

GDPR grants users the right to download data they have provided to a service.

Rectification

You can request changes, updates, or completion of your personal information.

Security

Data Protection in the Cloud

Our services run on Amazon Web Services (AWS), which provides the highest levels of security. AWS guarantees physical safety with 24/7 surveillance and uses state-of-the-art software security techniques to protect your data from unwanted access. AWS infrastructure is resilient, constantly available, and thoroughly monitored, meeting global security standards like ISO27001, SOC, PCI, and FedRAMP.

Data Encryption

360AI uses HTTPS on all our domains, with HTTP connections redirected to HTTPS. We also use the Key Management Service (KMS) for secure data encryption, ensuring your information's safety.

Credit Card Information

360AI does not store any credit card information. We use Stripe, a PCI Service Provider Level 1 Certified entity, to handle all card details.

Firewall

We have implemented a Web Application Firewall to prevent unwanted intrusions and a server firewall to restrict access to approved IPs only.

Password Hashing

We store only cryptographic hashes of passwords, ensuring that we never see or store actual passwords.

For more information, visit our 360AI Privacy Policy and My Privacy Choices.

Get started with 360AI

Place great candidates. Find new clients. Unlock your data value.

Book a demo
Book a demo
Arrow