- Original Poster
- #1
Hi
I'm trying to get ourselves GDPR compliant but there's so much scaremongering and random guesswork around the GDPR topic right now its hard to know whats what.
I'm trying to rewrite our website privacy policy but I'm a bit unsure about what to include.
We're a small service company with a "brochure" website, so we have a contact form but no actual shop, database, etc. However as a business we do use many cloud services such as office365, quickbooks, salesforce, etc. I see some sites set out all the services they use and what sorts of data go into them but these are all companies that sell services online. We use some similar tools to these guys but since they are business tools and not linked to the website operations I am correct in thinking these don't go into the privacy policy?
Do we need to have a list of each tool, its use, and data it holds out in public somewhere or we just keep that as an internal record should there ever be a data breach?
Thanks
I'm trying to get ourselves GDPR compliant but there's so much scaremongering and random guesswork around the GDPR topic right now its hard to know whats what.
I'm trying to rewrite our website privacy policy but I'm a bit unsure about what to include.
We're a small service company with a "brochure" website, so we have a contact form but no actual shop, database, etc. However as a business we do use many cloud services such as office365, quickbooks, salesforce, etc. I see some sites set out all the services they use and what sorts of data go into them but these are all companies that sell services online. We use some similar tools to these guys but since they are business tools and not linked to the website operations I am correct in thinking these don't go into the privacy policy?
Do we need to have a list of each tool, its use, and data it holds out in public somewhere or we just keep that as an internal record should there ever be a data breach?
Thanks