When we process data about buyers, contacts or conversation participants on behalf of a business using Telp, the business is the controller and Artifision is the processor. Processing covers the contracted functions and continues while we provide them or complete authorized data return and deletion. The data types, categories of people and purposes are described in the Privacy Policy and depend on the functions and channels the business enables.
We process that data only on the documented instructions of the business, including its settings, approved actions and requests, unless the law requires otherwise. We inform the business of such a legal obligation in advance unless notification is prohibited by law. If we believe an instruction violates data protection rules, we will alert the business.
We undertake to restrict access to that data to authorized people who need it for their work and are bound by contractual or statutory confidentiality obligations. We apply appropriate safeguards in accordance with the nature of processing and the description in the Privacy Policy.
If we become aware of a personal data breach affecting that data, we will notify the business without undue delay through its account contact. We will provide available information about the nature of the event, affected data, potential consequences and measures, with updates as the investigation progresses. We will cooperate in containing the consequences and meeting applicable notification obligations.
Taking into account the nature of processing and the information available to us, we assist the business with data-subject requests, risk assessments and data protection obligations. On request, we provide information needed to demonstrate compliance with our obligations and cooperate with an appropriate review while protecting other customers' data. Send requests and instructions to [email protected].