Fresh Proposals and the GDPR

Privacy and Security Contact

Jay
gdpr@freshproposals.com

#9, Uttam Towers, KP, Pune, India 411006

As part of our ongoing efforts to protect the security and privacy of our users, we are working to meet or exceed the GDPR (General Data Protection Regulation). This site contains information on what steps we are taking, their progress, and who to contact for any security concerns. Please see our FAQ for more information.

Data Processing Addendum

If you need a signed DPA, please use the button below to cross sign and download your copy of our DPA.

Make A Data Request

We respect the rights of individuals to know how their data is being used, export it or request that it be deleted.

Data Processing Partners

We rely on a number of trusted 3rd parties to assist with our operations. Depending on the exact nature of your account and what you've requested we do, your data may be shared with one of these partners. We carefully evaluate each to make sure they're handling your personal data with the utmost of respect, security, and privacy.

Services
Partner Locale Data Shared Purpose
Amazon IP Address

This site is hosted on Amazon AWS EC2 Infrastructure.

Angular JS IP Address

Angular is what HTML would have been if it had been designed for building web applications.

Crisp IP Address

Multi-channel customer support platform for startups and SMBs.

Global Site Tag IP Address

Google's primary tag for Google Measurement/Conversion Tracking, Adwords and DoubleClick.

Google Analytics IP Address

Google Analytics offers a host of compelling features and benefits for everyone from senior executives and advertising and marketing professionals to site owners and content developers.

Google Font API IP Address

The Google Font API helps you add web fonts to any web page.

Google Universal Analytics IP Address

The analytics.js JavaScript snippet is a new way to measure how users interact with your website. It is similar to the previous Google tracking code, ga.js, but offers more flexibility for developers to customize their implementations.

GStatic Google Static Content IP Address

Google has off-loaded static content (Javascript/Images/CSS) to a different domain name in an effort to reduce bandwidth usage and increase network performance for the end user.

Mautic IP Address

Open source Marketing Automation software.

Paddle IP Address

Checkout and sales drop-in ecommerce infrastructure.

Twitter Tweet Button IP Address

Official Tweet Button for sharing articles on websites and counting how many times a URL has been shared.

YouTube IP Address

Embedded videos from YouTube.

Compliance Tasks

GDPR Compliance requires maintenance and ongoing work. We are tracking our efforts here.

Application Site Security
Status Name
Completed Ensure internal employees and contractors behaviors around personal data are documented.
Completed Affirmative Consent mechanism added to User Signup
Completed SSL (TLS) Deployed on App Site
Completed Inform Users about the GDPR Page
Completed Ensure Access to Backups is Restricted
Completed Added External Javascript Files to Data Partners
Completed Restrict Personal Data at Signup to the Minimum Necessary
Marketing Site Security
Status Name
Completed Reviewed list of users with access to site
Completed SSL (TLS) Deployed on Marketing Site
Privacy Procedures
Status Name
Completed Privacy Policy Updates
Completed Informed all Employees and Contractors about GDPR Compliance
Completed Procedure established to allow for people to request that inaccuracies in their data are fixed.
Completed Process established for subject data requests
Completed Get Management Approval for GDPR Efforts
Completed Data Protection Policy Created
Completed Developed a Data Processing Agreement
Completed Briefed all Staff on GDPR Impact to the organization
Completed Nominate a Data Protection Lead or Data Protection
Security Procedures
Status Name
Completed Publish statement on public website on how to report security and data issues.

Frequently Asked Questions

If you have any concerns not answered here, please reach out to our contact (listed above) and we'll be happy to assist.

What's the GDPR?

The General Data Protection Regulation (GDPR) is a new piece of privacy legislation enacted by the European Union. It represents a significant change in how personal (IP Addresses, Emails, Names) and sensitive (religion, ethnic origin, health, orientation) data is handled by companies.

How Do I Report a Security Issue?

We take all security reports seriously. Please email our security contact (information listed above) with any information you have regarding any potential data breaches, vulnerabilities or concerns.

Do Non EU Companies need to comply with the GDPR?

While it remains to be seen if the EU has the legislative power to levy fines and enforcement against organizations around the globe, GDPR compliance is being sought by non EU companies for a variety of reasons.

  • Customers and Prospects are making it a requirement
  • It's a solid framework for improving the handling of personal information and complying with the GDPR requirements improves our own security.