This Policy describes the principles of processing of Personal Data that is submitted to SendSMSGate or that otherwise becomes available to SendSMSGate in connection with use by the Clients and other users of the Website, Software and Services.
This Policy is an agreement between the Clients and SendSMSGate, which states how Personal Data submitted by the Clients is processed by SendSMSGate on behalf of the Clients.
Please read this Policy carefully to understand the practices that SendSMSGate applies regarding processing of Personal Data.
This Policy constitutes an integral part of the agreement entered into between the Clients and SendSMSGate. By viewing the Website and/or using the Software and Services, the Clients confirm that they have familiarized themselves with this Policy, understood it and agree to its terms. Upon initial registration with SendSMSGate, the Clients (via their authorized representatives) also confirm the above-said by clicking on the “Create My Account” button, which declares the Client´s acceptance of and consent to the processing of Personal Data as described in this Policy.
This Policy also constitutes an agreement between the Clients (as controllers of Personal Data) and SendSMSGate (as processor of Personal Data) in the meaning of article 28 of GDPR (General Data Protection Regulation (EU) No 2016/679 of the European Parliament and Council).
SendSMSGate shall be entitled to unilaterally review and amend this Policy from time to time. Therefore, SendSMSGate advises to periodically review the Policy in the case of any changes to it. Continued use of the Website, Software and Services means the consent to any such changes.
If the Client or other users do not agree with any or all terms of this Policy or any possible changes to it, then they should immediately close the Website and cease using the Software and Services.
SendSMSGate has drafted this Policy in cooperation with its legal advisers in accordance with the requirements of GDPR. SendSMSGate does its best to ensure that processing of Personal Data is in full compliance with applicable legal requirements.
1.1 Client(s) means legal entities (or individuals as authorized representatives of legal entities) who register themselves on the Website and use it and the Software according to these Terms for the purpose of using the Services.
1.2 Data Subjects means all natural persons, whose personal data is submitted to SendSMSGate in connection with using the Website, Software and the Services, including recipients of the Services (clients of the Clients).
1.3 GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.
1.5 Personal data means any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
1.6 Processing means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.7 Service(s) means a business text-messaging service for sending notifications, alerts, reminders, confirmations and SMS marketing campaigns. Service is rendered via a Website-based SMS platform or by using the Software.
1.8 Software means web-based interface, mobile app and other downloadable and integrable software developed and maintained by SendSMSGate for the purpose of provision of the Services.
1.9 SendSMSGate means trade name of company TLC Mobile, a limited company registered in London, United Kingdom under company number 12134150 with the registered office at WC1X 0ND, 2 Frederick Street, London, UK and all its affiliates.
1.10 Terms means the terms of service of SendSMSGate that establish the terms and conditions of using the Website, Software and Services by the Clients and other users.
1.11 Website means the Website of SendSMSGate www.sendsmsgate.com and access to cloud with Software www.cloud.sendsmsgate.com.
2. Personal Data that SendSMSGate Processes. Objectives of Processing of Personal Data
2.1 For the purpose of provision of the Website, Software and the Services, SendSMSGate processes the Personal Data that the Clients provide about their own clients, who are the recipients of the Services. The types of such data are not restricted and depend on the decision of the Clients how they want to use the Services and generally include the name, contact telephone number, but may also include e-mails, avatars, country, addresses etc.
2.2 SendSMSGate keeps the register of the Personal Data that it processes in accordance with this Policy.
2.3 SendSMSGate processes the Personal Data upon:
2.3.1 usage of the Software and Services by the Clients, including when they submit to SendSMSGate information about their clients;
2.3.2 communication between Clients and/or Data Subjects with customer support of SendSMSGate in connection with the Website, Software and Services;
2.4 SendSMSGate works closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive Personal Data from them;
2.5 SendSMSGate sends messages to the Clients by electronic means (e-mail or SMS) with information about improvements of the Website, Software and Services, new proposals and developments (direct marketing). SendSMSGate sends such messages to the contact details provided by representatives of the Clients at the moment of registration or updated later. The Clients confirm hereby and guarantee that contact details provided by representatives of the Clients are at all times company details of the Clients, but not personal contact details of representatives and therefore SendSMSGate can use such contact details freely to send its marketing messages without any additional obstacles. The Clients may at any time unsubscribe from the newsletters by clicking on the corresponding specific link contained in each newsletter.
3. Legal Basis for Processing Personal Data
3.1 SendSMSGate processes Personal Data in accordance with the laws of the location of SendSMSGate and its affiliates, where the processing of Personal Data is conducted.
3.2 SendSMSGate processes Personal Data submitted to it by the Clients based on the contracts with the Clients for the purpose of using the Website, Software and Services and to the extent that this data is provided by the Clients.
3.3 In accordance with Article 4 (7) of GDPR the Clients are the controllers of Personal Data that they submit to SendSMSGate for the purpose of using the Website, Software and Services, including the data regarding clients of the Clients that the Clients submit to send and receive SMSs to and from their clients as recipients.
3.4 According to Article 4 (8) of GDPR SendSMSGate acts as the processor on the Client’s behalf when processing the Personal Data submitted by the Clients. Therefore, the Clients:
3.4.1 are fully responsible for the processing of Personal Data that they submit to SendSMSGate;
3.4.2 guarantee to SendSMSGate explicitly that the Clients in order to use the Website, Software and Services have all the necessary consents and/or other legal grounds from Data Subjects for lawful processing of Personal Data in accordance with this Policy;
3.4.3 confirm that they have obtained from the Data Subjects all the necessary consents for submitting of Personal Data to SendSMSGate and processing of such data in accordance with the terms of this Policy;
3.4.4 have a full overview of Personal Data that they submit to SendSMSGate and guarantee that all such data that they submit is necessary for use by them of the Website, Software and Services and is kept up-to-date;
3.4.5 oblige to inform SendSMSGate immediately of the expiry of legal grounds for processing, modification, inaccuracy or change to the Personal Data that the Clients submit to SendSMSGate.
3.5 When using Services for direct marketing, the Clients are responsible for complying with all the legal requirements in connection with direct marketing and data subjects’ rights. SendSMSGate is only providing the platform for sending messages, but the Clients are solely responsible for the content of messages sent using the Services. The Clients understand that there are different legal rules for direct marketing in different countries. When the Services are used for direct marketing, the Clients must comply with all requirements for direct marketing of the country, where the receiver of the direct marketing message is residing. For instance, in EU countries the Clients are obliged to send with direct marketing a message with the information on how the Data Subject can waive from direct marketing and there are also certain requirements for the content of commercial messages.
3.6 SendSMSGate processes the personal data only on documented instructions from the Clients. The Clients insert these instructions by using Services (e.g. inserting command to send messages to its clients) and by agreeing with the Policy and Terms. The instructions of the Clients for processing of Personal Data must always comply with the applicable laws and SendSMSGate reserves to itself the right to refuse to fulfill the instructions that are in the opinion of SendSMSGate unlawful.
3.7 Taking into account the nature of the processing, SendSMSGate shall assist the Clients by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Clients´ obligation to respond to requests for exercising of Data Subject’s rights laid down in GDPR, including the right of access to Personal Data by Data Subjects, right to rectification, right to be forgotten, right to restriction of processing etc. SendSMSGate shall accept instructions for fulfillment of the rights of Data Subjects only from the Clients. Should the Data Subjects approach SendSMSGate with the requests for fulfillment of their rights, SendSMSGate shall inform the Clients and act according to instructions from the Clients. Obligation to delete the data of Data Subjects shall always remain with the Clients and SendSMSGate shall not undertake deletion for and on behalf of the Clients, unless otherwise explicitly stipulated in the Policy or Terms.
3.8 SendSMSGate shall assist the Clients in ensuring compliance with the obligations of guarantying security of processing of Personal Data as established by GDPR while taking into account the nature of processing and the information available to SendSMSGate. Inter alia SendSMSGate undertakes to:
3.8.1 apply appropriate technical and organizational measures aimed to insure security, confidentiality and integrity of data. More precisely the applicable security measures by SendSMSGate are described in section 6 below;
3.8.2 periodically monitor its internal processes and the technical and organizational measures to ensure that processing of Personal Data is in accordance with the applicable law. SendSMSGate shall also monitor the processing of Personal Data conducted by Third Parties as much as possible (see clause 4.3 below);
3.8.3 notify the Clients in the most expedient time possible under the circumstances and without unreasonable delay and, where feasible, not later than 72 hours after having become aware of any accidental, unauthorized, or unlawful destruction, loss, alteration, or disclosure of, or access to, Personal Data (Security Breach). In consultation with the Clients, SendSMSGate shall take appropriate measures to secure the data and limit any possible detrimental effect on the Data Subjects;
3.8.4 cooperate with the Clients and provide them with information and assistance, where reasonably possible, in connection with Security Breaches, including in communication with supervisory authorities and Data Subjects;
3.8.5 cooperate and assist the Clients in conducting processing impact assessments, if applicable.
3.9 SendSMSGate shall make available to the Clients all information necessary to demonstrate compliance with the obligations laid down in Article 28 of GDPR and allow for and contribute to audits, including inspections, conducted by the Clients or another auditor mandated by the Clients (all at the expense of the Clients). On-site audits and inspections must be agreed with SendSMSGate in advance, be conducted during normal working hours and not unreasonably disturb the everyday activity and business of SendSMSGate. Right to audits and inspections does not extend to the facilities and premises of Third Parties.
4. Transfer of Personal Data to Third Parties
4.1 In the course of providing the Services and access to the Website and Software, SendSMSGate uses different third party service providers, to whom it may also transfer Personal Data (herein: Third Parties). By virtue of this clause the Clients are duly informed and expressly authorize, totally or partially, to use the corresponding Third Party service providers and provide Personal Data to them, as it may be required. These service providers include the following:
4.1.1 Server service providers;
4.1.3 Providers of safety measures, including fraud protection, protection and encryption of SendSMSGate traffic, email domain authority detection tool;
4.1.4 E-mail service providers;
4.1.5 SMS sending/receiving service providers;
4.1.6 Communication service providers;
4.1.7 Bookkeeping and payment service providers;
4.1.8 Customer support service providers;
4.1.9 Data processing service providers.
4.2 SendSMSGate shall inform the Clients of any intended changes concerning the addition or replacement of Third Party processors and give the Clients the opportunity to object to such changes. SendSMSGate has the right to stop providing Services to the Clients, who object to the change concerning the addition or replacement of processors.
4.3 SendSMSGate has entered into individual service provision contracts with some of the service providers. With others the relationships are based on the general terms of service of these service providers. Prior to entering into relationships with third party service providers SendSMSGate makes its best efforts to guarantee that the terms of processing of Personal Data of its partners are in accordance with the principles of this Policy and applicable laws. For this purpose SendSMSGate shall carefully review the terms of processing of Personal Data by its partners. Furthermore, SendSMSGate carefully screens the on-going relationships with Third Party service providers and in case of their non-compliance shall immediately terminate relationships with them.
4.4 SendSMSGate discloses Personal Data to its affiliate in the European Union, which is TLC Mobile LTD (registry code 12134150, registered seat in London, UK) that processes Personal Data on behalf of SendSMSGate in accordance with this Policy and applicable law.
4.5 Additionally, SendSMSGate may disclose/transfer Personal Data:under applicable law, including laws outside the locations of SendSMSGate, its affiliates or Data Subjects;
4.5.1 to comply with legal processes;
4.5.2 to respond to requests from the public and government authorities including public and government authorities outside the locations of SendSMSGate and its affiliates;
4.5.3 to enforce this Policy or Terms, to protect operations, the rights, privacy, safety or property of SendSMSGate and/or to pursue available remedies or limit the damages.
4.5.4 SendSMSGate makes its best efforts to limit the amount of Personal Data that it transfers for processing to Third Parties as it is necessary for the provision of specific services or to pursue specific goals.
4.6 The Website and Software may contain links that redirect to other websites. For example, when using payment services by a third party such as Paysera when making a payment. This Policy does not apply to such third party websites, which SendSMSGate does not operate, and SendSMSGate does not accept any responsibility or liability for these policies. SendSMSGate advises to review the privacy policies of those third parties.
5. Transfer of Personal Data to Third Countries
5.1 In connection with some specific development works, troubleshooting of service issues, data storage or other necessary services, SendSMSGate may transfer Personal Data to SendSMSGate’s contractors, some of which may not be working or operating in the European Economic Area (i.e. 28 European Union countries + Iceland, Liechtenstein and Norway), herein: Third Countries).
5.2 Data protection levels in Third Countries might differ from the corresponding level of the European Economic Area, and some Third Countries might have a lower level of data protection. Therefore, in case of the transfer of Personal Data to the Third Countries, the risk of loss, misuse or becoming public of Personal Data may be higher in comparison to the European Economic Area. However, SendSMSGate has taken all reasonable measures to protect Personal Data in Third Countries. Our contractors, who process personal data in Third Countries, are contractually obliged to obey the same data protection level as in the European Union.
5.3 Given the above said, the Clients hereby explicitly confirm their awareness of the named possibility to transfer Personal Data to Third Countries and the possible risks of such transfers. The Clients hereby explicitly confirm that they have also obtained the explicit consent from all Data Subjects, inter alia their clients, who are recipients of the Services, and their own representatives, as required by legislation to transfer their Personal Data to Third Countries.
5.4 Some of the Third Party providers of SendSMSGate are also located in the United States of America. Some of them, but not all are certified by the EU-US Privacy Shield Program agreed to by the U.S. Department of Commerce and the European Union with respect to Personal Data. For additional information regarding the EU-US Privacy Shield Program, see the U.S. Dept. of Commerce website at www.privacyshield.gov. Transfer of Personal Data by SendSMSGate to those service providers, who are not certified by theEU-US Privacy Shield, is subject to the explicit consent for transfer of Personal Data to the Third Countries, as stated above.
5.5 SendSMSGate shall apply appropriate safeguards when transferring Personal Data to the Third Countries.
6. Safety Measures for Protection of Personal Data
6.1 SendSMSGate takes the appropriate legal, organizational and technical measures to protect Personal Data consistent with applicable privacy and data security laws. Security measures shall be applied to protect Personal Data from involuntary or unauthorized processing, disclosure or destruction.
6.2 SendSMSGate stores all Personal Data on secured servers. The security measures include:
6.2.1 Access to the servers is protected with individual accounts, usernames and passwords for each authorized person (employees/subcontractors);
6.2.2 SendSMSGate is keeping track and a log of all activities on the servers;
6.2.3 SendSMSGate can immediately close access to the servers to any authorized persons;
6.2.4 Access to the servers is restricted in terms of (a) persons, who have access to it, (b) information, to which authorized persons have access according to the essence of their working duties, (c) actions that authorized persons can perform with Personal Data stored on the servers;
6.2.5 SendSMSGate keeps reviewing, who of the authorized persons are actually required to have access to Personal Data and, if access is not required, will withdraw the right of access.
6.3 Access for the Clients to the personal cabinets on the Website is protected with individual usernames and passwords. The Clients are responsible for keeping passwords confidential. The Clients are obliged not to share passwords with anyone. In case of suspicion of unauthorized access to personal cabinets of the Clients and/or Personal Data, the Clients are obliged to immediately inform SendSMSGate thereof.
6.4 SendSMSGate shall ensure that all its employees, contractors, agents, suppliers and consultants, who have access to the Personal Data, are fully aware of and abide by their legal duties and responsibilities.
6.5 Employees and other contractors of SendSMSGate are obliged by binding agreements not to disclose or make available for use to anyone other than SendSMSGate during their agreement with SendSMSGate and eternally after its termination any Personal Data that they may have access to during their agreements with SendSMSGate.
7. Retention Periods
7.1 SendSMSGate shall preserve the Personal Data as long as it is required for the use of the Website, Software and Services by the Clients, but no longer then applicable law permits preservation.
7.2 SendSMSGate shall delete the Personal Data submitted by the Clients according to the following principles:
7.2.1 Personal contact data provided by the Clients and messages of the Clients shall be preserved for 60+60 days after the Client has filed a claim to delete such data;
7.2.2 Initial data files submitted by the Clients shall be deleted after 60 days since data is imported to the system of SendSMSGate;
7.2.3 Attachments that the Clients submit to be sent together with SMSs shall be preserved for a maximum of 60 days and then shall be deleted. As attachments the Clients may not upload any Personal Data;
7.2.4 Log files with the activities of the Clients on the Website shall be preserved for a maximum of 1 month and audit log files shall be preserved for 2 years;
7.2.5 In case of closing an account, the Clients must accept the deletion of contacts and messages.
7.2.6 Contacts will be deleted after 60 days and messages after 60+60 days since the Client has given acceptance for closing an account or SendSMSGate has decided to close the Client’s account.
7.2.7 The Clients shall have an opportunity to renew their accounts at any time (except deleted contacts and messages).
7.3 The Clients confirm that they agree with the provided above retention periods and guarantee to inform and obtain necessary approvals from their clients and representatives for application of such retention periods.
8. Data Protection Officer
8.1 SendSMSGate has designated as the Data Protection Officer Irina Vasilyeva, e-mail: firstname.lastname@example.org It`s person who responsible for the proper storage, security and safety of personal data, their accounting and processing.
9. Contact Information
9.1 Should the Clients have any questions regarding this Policy or the processing of Personal Data, they are welcome to contact SendSMSGate with all such requests, inquiries or any complaints via e-mail: email@example.com.