GDPR Compliance
MangoApps is GDPR ready with enterprise-grade data protection, security, and compliance. Review our Self-Serve DPA or request enterprise contracting documents for your organization.
We are Committed to the Highest Standards of Data Protection, Security and Compliance
GDPR's Global Impact
The GDPR harmonizes data privacy laws and regulations across the EU, enhances data protection for EU citizens and reshapes the way organizations approach data privacy. The GDPR covers the personal data of every EU person and provides comprehensive rights to data subjects.
Every company that works with European employees, customers and partners will need to comply with the regulation. Failure to meet the GDPR requirements can result in fines up to EUR 20 million or up to 4% of the company's worldwide annual turnover for the preceding fiscal year, whichever is higher.
Our GDPR Commitment
Since our inception, MangoApps approach has been anchored with a strong commitment to privacy, security, compliance and transparency. Like existing privacy laws, compliance with the GDPR requires a partnership between MangoApps and our customers in their use of our services. We have analyzed the requirements of the GDPR, and have made enhancements to our products and processes to support compliance with this regulation. Self-serve customers are covered by our Self-Serve Data Processing Agreement, and enterprise customers can request a countersigned DPA through contracting. Our program is designed to help customers:
- Use available features and support to help respond to data subject requests to access, correct, or delete personal data, to the extent the Service supports it.
- Be made aware of and report personal data breaches to relevant supervisory authorities and data subjects in accordance with GDPR timeframes.
- Demonstrate their compliance with the GDPR as pertaining to MangoApps Services.
GDPR Readiness with MangoApps
MangoApps has a proven history of over 18 years in ensuring data privacy and trust of our customers. This trust and commitment has continued in our journey to be GDPR ready. Here are some of the key steps done at MangoApps to be ready for GDPR and other privacy & data protection regulations:
- MangoApps is hosted on AWS cloud and uses hundreds of security & compliance features of AWS to maintain the highest-level data privacy and protection standards.
- MangoApps ongoing product innovation over the last couple of years has added data portability and data management features to the platform to help serve its customers with their data privacy obligations.
- MangoApps has upgraded its organizational control and processes and added to it regular reviews of the technical and compliance programs, to ensure that they are strong and up to date.
Security, Encryption and Certifications
MangoApps encrypts Customer Data in transit (TLS) and at rest, and maintains role-based access controls, intrusion detection, network segregation, logical tenant isolation, vulnerability management, and a documented incident response plan. The technical and organizational measures for self-serve customers are summarized in Annex 2 of our Self-Serve Data Processing Agreement; enterprise customers may receive additional documentation through contracting. In the event of a personal data breach, MangoApps notifies affected customers without undue delay and in any event within seventy-two (72) hours of becoming aware, as committed in the applicable DPA. Enterprise procurement and security teams may request our current third-party audit reports and certifications (such as SOC 2), sub-processor history, and BCP/DR summary at legal@mangoapps.com.
Use of Subprocessors
To support the delivery of our services, we engage with several trusted subprocessors. These subprocessors are carefully selected to ensure that they meet the high standards set by GDPR for data protection and security. We review and monitor our subprocessors regularly to ensure ongoing compliance and to safeguard your personal information.
For a detailed list of our current subprocessors, including their roles and the services they provide, please visit our dedicated page: GDPR Subprocessors.
Data Processing Agreement
Self-serve customers using MangoApps under the Terms of Service are covered by the Self-Serve Data Processing Agreement without a separate signature. Customers that need a countersigned DPA, custom security terms, HIPAA terms, custom data residency, or procurement documentation should request an enterprise contract package at legal@mangoapps.com.