Annex 1. Record of data processing activities (ROPA)

Last updated: 2023-03-26

for SaaS First, provided by GBD Software as a Service Private Limited Company

 

Table of contents

If you are a data subject (Customer) affected by our chatbot or email-marketing services on one of our Users’ website.

If you are our registered SaaS First User.

If you are a data subject (Customer) affected by our chatbot or email-marketing services on one of our Users’ website.

processed personal data

the purposes of the processing

legal basis for the processing

the recipients or categories of recipients of the personal data

the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;

entities/persons affected, either based on Article 13 (Customers) or 14 GDPR (Users)

Data Subject data

  • email address
  • main customer ID
  • first and last name
  • operating system type and version number
  • browser type and version number
  • time zone
  • browser language
  • time of profile creation
  • IP address
  • continent code
  • city

  • personal profile based on the feedback given by our data processor, OpenAI (ChatGPT)

The purpose of the processing is to provide services to our Users.


Our Users might use this data to run email campaigns and to use our AI-powered chatbot on their respective websites.

Article 6(1)f) GDPR:

processing is necessary for the purposes of the legitimate interests pursued by the controller 


Provision of our services:

To provide personalized marketing tools and services to our clients, enhancing their marketing strategies and overall customer engagement


Monitoring our services:

Monitor and analyze the performance of our tools and services, ensuring their effectiveness and improving upon them as needed.


Maintaining the security of our services:

Maintain the security of our systems and protect against fraud, cyber threats, and other malicious activities.

Provider, Customers

Provider will keep the Account Data and Personal Data you provided for up to 12 months following we stopped providing our Users with our services, and will delete all these records or Personal Data permanently after this period.


Any Account which shows no activity for more than 12 months may be considered inactive. If an Account is considered inactive, the Account will be deleted, and all data associated with that account may be permanently erased.


1 month before the deletion of the account, we are sending a reminder in email, asking you whether you wish to continue using our services.

Article 14 (Users)



If you are our registered SaaS First User.

processed personal data

the purposes of the processing

legal basis for the processing

the recipients or categories of recipients of the personal data

the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;

entities/persons affected, either based on Article 13 (Customers) or 14 GDPR (Users)

Account Data

  • your name
  • your email address your encrypted password

The Account Data may be processed for the purposes of providing you our services offered on our Website, sending you information about our Service or about our affiliate’s services, ensuring the security of our Website and communicating with you.

This Account Data is voluntarily provided by you upon your registration 

or 

upon your subscription on our free trial.


Article 6(1)a) GDPR:

the data subject has given consent to the processing of his or her personal data for one or more specific purposes

Provider

Provider will keep the Account Data and Personal Data you provided for up to 12 months following we stopped providing you with our services, and will delete all these records or Personal Data permanently after this period.


Any Account which shows no activity for more than 12 months may be considered inactive. If an Account is considered inactive, the Account will be deleted, and all data associated with that account may be permanently erased.


1 month before the deletion of the account, we are sending a reminder in email, asking you whether you wish to continue using our services.

Article 13 (Users)

Payment Data

  • bank card number
  • bank name
  • card details
  • cardholder’s name
  • billing address
  • VAT number

We process information that you voluntarily provide to us after your registration when you decide to continue to use our paid services offered on our Website. 

The Payment Data is processed for the purposes of providing our paid services offered on our Website.

Article 6(1)b) GDPR:

processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract

Provider, payment service providers

Provider will keep the Account Data and Personal Data you provided for up to 12 months following we stopped providing you with our services, and will delete all these records or Personal Data permanently after this period.


Payment service providers will keep the data according to their policies.

Article 13 (Users)

Transaction Data:

  • the time and activity of the purchases of our services 
  • the code of the transactions


The Transaction Data is processed for the purposes of supplying the purchased services, keeping proper records of these transactions, refunding such payments and dealing with complaints.


Financial transactions relating to our services offered on our Website are also handled by our payment service providers.

Article 6(1)b) GDPR:

processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract

Provider, payment service providers

Provider will keep the Account Data and Personal Data you provided for up to 2 months following we stopped providing you with our services, and will delete all these records or Personal Data permanently after this period.


Payment service providers will keep the data according to their policies.

Article 13 (Users)

Usage Data

  • your IP address
  • geographical location
  • browser type and version
  • operating system
  •  referral source
  • length of visit
  • page views and website navigation paths
  • information about the timing, frequency and pattern of your Service use. 

This usage data is processed for the purposes of analyzing the use of the website and services, and to avoid users misusing our Service.


The source of the usage data is our analytics tracking system.

Article 6(1)f) GDPR:

processing is necessary for the purposes of the legitimate interests pursued by the controller 


For analytical purposes:

We have a legitimate interest in analyzing Service operations.


To prevent fraud and abuse: We have a legitimate interest in conducting necessary verification to detect and prevent potential fraud and abuse. We understand processing this Data is beneficial for all parties involved, especially for you, because it allows us to set up precautions.


To contact you:

We have a legitimate interest in contacting you with marketing messages, information about our current services, business opportunities, and special offers on other products, and services we think you might like.


Our legitimate interest to exercise legal claims:

We have a legitimate interest in processing your Data if it’s necessary to exercise claims concerning the use of the Service that’s unlawful or incompatible with the Terms of Service or to defend ourselves against such claims.

Provider

Provider will keep the Account Data and Personal Data you provided for up to 12 months following we stopped providing you with our services, and will delete all these records or Personal Data permanently after this period.


Any Account which shows no activity for more than 12 months may be considered inactive. If an Account is considered inactive, the Account will be deleted, and all data associated with that account may be permanently erased.


1 month before the deletion of the account, we are sending a reminder in email, asking you whether you wish to continue using our services.

Article 13 (Users), 

Visitors of our Website