Zoho CPaaS is GDPR compliant
The General Data Protection Regulation (GDPR) is a European Data Protection regulation enforced by the EU Commission to regulate the security of personal data. The GDPR became effective on May 25, 2018. All organizations working with the personal data of EU residents are required to comply with GDPR to protect their data.
Why do you need a GDPR-compliant transactional communications platform?
Transactional communications often contain important, sensitive, and sometimes confidential information triggered by customer actions. This information enables the successful delivery of messages across channels. Whether sent through email, SMS, WhatsApp, or voice, these communications may involve personal data such as names, phone numbers, domains, email addresses, recipient details, transaction details, and more. A GDPR-compliant transactional communications platform like Zoho CPaaS can help businesses protect private data and manage customer communications responsibly across channels.
Personal data protection at the forefront
GDPR is a legally binding regulation that mandates the protection of private data. Even before GDPR went into effect, right from our inception, privacy and data protection has been at the forefront of Zoho's applications. As an extension, Zoho CPaaS was built with a privacy-first approach. Zoho has always been and will always be ad free. We have never relied on advertising or data mining for advertising as a revenue source. All customer data belongs to the customer, and it’s only used for the functioning of our application, nothing more.
Zoho CPaaS GDPR readiness
Zoho CPaaS has measures, rules, processes, and strategies in place to address and comply with each aspect of GDPR.
Data Security
Zoho CPaaS comes with many security features. As a testament to this, we’ve acquired multiple security compliance certificates like GDPR, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, ISO 9001, ISO22301, SOC 2 Type II, SOC 1 Type II, and SOC 2 + HIPAA compliance. Also, Zoho Corporation participates in and has certified its compliance with the European Union and the United States.
Data Hosting (Locality)
Zoho servers are located in secure data centers in the US, EU, CN, IN, AU, and JP. The region in which we host your service data depends on the Zoho domain from which the admin registered the Zoho CPaaS account.
The following table lists the Zoho domains and their respective hosting locations.
| Zoho domain account creation | Data center location |
|---|---|
| cpaas.zoho.com | US (United States) |
| cpaas.zoho.eu | EU (European Union) |
| cpaas.zoho.com.cn | CN (China) |
| cpaas.zoho.in | IN (India) |
| cpaas.zoho.com.au | AU (Australia) |
| cpaas.zoho.jp | JP (Japan) |
Data Encryption
Emails, SMS and WhatsApp messages, and Voice calls are stored on CPaaS's servers in an encrypted format. Data is split into fragments, and each fragment is then further encrypted before being stored on our disks. The keys that are used for encryption are managed with the utmost safety and reliability. The data transmissions when using Zoho CPaaS via SMTP are encrypted using the Transport Layer Security (TLS) protocol. We also use the latest and secure ciphers such as AES_CBC/AES_GCM 256 bit/128-bit keys for encryption across all channels.
All data transfers on the web happen in secure mode (HTTPS). These ensure that your Zoho CPaaS data is protected from unauthorized access, disclosure, or modification both within and outside your organization's domain.
The service data stored in Zoho CPaaS is encrypted at rest (EAR). All data across channels is encrypted in transit as well. The highly secure physical controls at our data centers and transit-level encryption ensure that your data stays well protected. You can find more information on our security page.
Data Access
As a user, you have the right to request access to the personal data we hold about you in Zoho CPaaS. You can contact us at any time to inquire about the categories of data collected, how it is used, and to receive a copy of that data.
Data Rectification
Users can edit their personal information in their profile, except the email address, SMS sender, phone number, and WABA configuration, provided by the administrator. The organization administrator has permissions to edit email sending domains, bounce addresses, phone numbers, WABA configuration and Agents.
Data Deletion
The administrator of the account is allowed to delete multiple aspects of a Zoho CPaaS account. They can delete the added entities such as domains, email addresses, sender addresses, phone numbers, WABA configuration or Agents whenever necessary. They can also choose to delete the account entirely. When you delete your Zoho CPaaS account, the complete user data—including audits, logs, added domains, WABA configuration, phone numbers, templates, and reports—will be deleted permanently. It will take 48 hours to delete the account completely.
Data Portability
Zoho CPaaS provides features to export email data from user accounts. Users can export the entire logs, logs of specific Agents,or logs based on certain given conditions. The exported file will be provided as a .zip file. Based on the role given to any particular user, their access to export can be restricted.
Data Retention
Users can choose to retain the content of the emails, SMS and WhatsApp messages, and voice calls they send out. If they choose to save the content, it will be stored for 60 days from the date of sending. Logs of sent emails, SMS, WhatsApp messages, and voice calls are available in the user’s Zoho CPaaS account.
Once the account deletion is initiated, the user is given 48 hours to reverse the action. If no action is taken within that time, the account closure will be processed and all data will be deleted within 24 hours.
Activity Logs
Every account has an activity log section that allows users to track all of the actions performed by every user added to their account. Actions can be a newly created entity, modification of an entity, or deletion of an entity.
The activity log mentions the user’s details, actions performed by the user, the date and time of the action, and the entity the action was performed on. The activity log will be stored for a period of one year from the date of the action. The logs can be exported by user request. They can write to support@zohocpaas.com to have the logs exported.
Disclaimer: The information presented herein should not be taken as legal advice. We recommend that you seek legal advise on what you need to do to comply with the requirements of GDPR.