GDPR Compliance

star_icon

On May 25, 2018, the European Union (the “EU”) implemented a new data privacy and protection regulation, called the General Data Protection Regulation (the “GDPR”). This new regulation aims to standardize data protection laws across the EU and also lay down standards to be observed worldwide while processing of personal data originating in the EU; The GDPR also has a strong emphasis on affording individuals stronger, more consistent rights to access and control their personal information.

At Harbinger, we take compliances of data privacy and security regulations very seriously. For GDPR, we are working diligently to ensure that we are compliant with the rules laid out by the law and provide product functionality that enables us to remain compliant. In the following sections, we have outlined our approach to comply with the GDPR.

 

On May 25, 2018, the European Union (the “EU”) implemented a new data privacy and protection regulation, called the General Data Protection Regulation (the “GDPR”). This new regulation aims to standardize data protection laws across the EU and also lay down standards to be observed worldwide while processing of personal data originating in the EU; The GDPR also has a strong emphasis on affording individuals stronger, more consistent rights to access and control their personal information.

At Harbinger, we take compliances of data privacy and security regulations very seriously. For GDPR, we are working diligently to ensure that we are compliant with the rules laid out by the law and provide product functionality that enables us to remain compliant. In the following sections, we have outlined our approach to comply with the GDPR.

GDPR Compliance

Harbinger Systems is a global company providing software technology services for independent software vendors and enterprises, with a specialization in product engineering. Since 1990, Harbinger has developed a strong customer base worldwide. Harbinger’s customers are software product companies, including high-tech startups in Silicon Valley, leading product companies in the US and large in-house IT organizations. Harbinger Systems builds software solutions leveraging digital technologies for domains such as HR Tech, Health Tech, and Learning Tech and has created personalized interactive video platform.

Because our software products and website are used and explored by our clients (existing and prospective), we at Harbinger process certain amount of personal data of our clients (existing and prospective) in the capacity of a Data Controller (for any personal information submitted on the website) as well as a Data Processor (for our clients, who submit certain personal information as a part of use of our other offerings).

Risk Assessment

We have performed a company-wide information discovery exercise to identify and assess what personal information we hold, where it comes from, how and why it is processed, and to whom it is disclosed.

Data Subject Consent

As a Data Controller, Harbinger has updated its Privacy Policies, Cookies Policy and Disclaimer for the usage of the Cookies in as per the requirements of GDPR on its website https://www.harbingergroup.com/ and it requires all the visitors, users of its website to provide an unequivocal consent. Harbinger also provides various rights to such users in relation modification, rectification, deletion of their data provided to Harbinger.

As a Data Processor, we execute contracts required under the GDPR with our clients (who are the Data Controllers) and process the personal information as per their directions. Additionally, we implement technical and organizational security measures to ensure compliances.

Data Subject Rights & Transfer of Data Outside EU

Harbinger has in place an article 28 GDPR-compliant data processing addendum including the EU Model Clauses to ensure an appropriate legal basis for data transfers outside the EU.

Data Retention & Erasure

We have formulated a data retention policy and schedule to ensure that we comply with the ‘data minimization’ and ‘storage limitation’ principles and that personal information is stored, archived, and destroyed in accordance with the GDPR.

Record Keeping as per the GDPR

According to Article 30 of the GDPR, each processor and controller’s representative needs to maintain a record of all activities pertaining to the processing of personal information in such an organization. Harbinger maintains a controller processing record as required under Article 30(1) of the GDPR as well as processor processing record as required under Article 30(2) of the GDPR.

Data Breach and Mitigation Process

The GDPR has stipulated measures and notifications that must be made upon discovery of a data security breach. Harbinger has put in place internal measures to minimize the risk of any data security breach happening. However, in the unlikely event of any such breach happening, Harbinger intends to honour its responsibilities as laid down under the GDPR, which includes notifying in a timely manner, its customers, and the supervisory authorities (if Harbinger is the Data Controller).

Harbinger Promise on GDPR

At Harbinger, maintaining the security, integrity, safety and confidentiality of personal data in our possession is of the highest priority. Harbinger has already taken adequate measures to ensure that we fulfil our promise of being fully compliant with GDPR! In case you have any queries, please feel free to reach us at complianceofficer@harbingergroup.com