What is the GDPR?
The General Data Protection Regulation (GDPR) is a EU regulation which will come into effect on the 25th May 2018. The GDPR aims to protect the personal information of all EU citizens. The regulation gives the individuals control over how their personal data is collected, stored and used. Personal data is any piece of data that could identify a person, when used alone or along with other details. This regulation does not apply to business related data, only to personal data.
Total Synergy is committed to being transparent with users about where personal data is stored in Synergy. In this help topic we explain how Total Synergy processes personal data, and what tools are available for people to view / control what personal data is stored by Total Synergy.
Total Synergy is committed to protecting our customers' data and follow the GDPR requirements and industry standards to protect customers' data. The data collected by Total Synergy is stored in the Microsoft Azure cloud. For information about Azure compliance with GDPR see Microsoft Azure GDPR guide.
Tips:
- This document has been written by Synergy staff (who are not lawyers). The details below are only a guide on how to manage the GDPR regulations for personal data saved within Synergy.
-
Total Synergy offers tools and information as a resource, but we don’t offer legal advice. We recommend you contact your legal counsel to find out how the GDPR affects you.
- View the full details of the GDPR regulations here.
Sections in this guide
- What personal data does Synergy store?
- Controller or processor in the Synergy application?
- GDPR new individual rights for personal data and how they effect Synergy
- Synergy add-on partners and the GDPR
Tip: Click on a section above to jump straight to those details.
What personal data does Synergy store?
Synergy stores three types of data that could contain personal details. Synergy personal data types are:
- Profile data
- Synergy stores basic personal data as part of the Synergy profile as provided by users upon sign-up.
- Anyone that has a login to Synergy has a user profile with optional personal data and a profile picture for use in Synergy available to be configured.
- Learn more about the Synergy profile.
- Staff data
- Each organization in Synergy, stores business data about its staff members.
- Some personal data could also be stored as part of setting up this business data.
- This data is stored as part of the staff record.
- The organization might store a combination of personal and business data in these records.
- Learn more about Synergy staff records.
- Contact data - all contact types (Company, Personnel, Individual)
- Each organization in Synergy, stores business data about its external contacts.
- Some personal data might be stored as part of this business data.
- This data is stored as part of the contact record.
- The organization might store a combination of personal and business data in these records.
- Learn more about Synergy contact records.
Depending on what type of user you are in Synergy will depend on which of the following applies to you for personal data e.g. If you are a staff member at the organization you are unlikely to also have details about you also in a contact record.
Details about the exact data we collect and the purposes for which we use personal information are available in the Total Synergy privacy policy. Synergy users agree to this privacy policy when they create a login profile.
Controller or processor in the Synergy application?
The GDPR refers to the terms Controller and Processor. Here we will look at what these terms mean, and if Synergy is a Controller or a Processor for each of the personal data stored.
- Controller - This is an organization or business that is collecting data from EU residents.
- Processor - This is an organization that processes the personal data on behalf of a data controller.
Synergy plays a different role for handling your personal data based on the data type:
- Profile data
- For your Synergy user profile data, Synergy is the controller and processor of the data.
- Synergy requests some fields in your user profile as mandatory when you sign-up for a Synergy account, such as name and email address. Additional profile details that are optional (such as additional email addresses or phone numbers) can be entered later as required.
- Staff data
- For the staff record data in your Synergy organization, Synergy is the processor and your organization which contains the staff record is considered the controller.
- The organization (owner/users) that entered your staff record in Synergy will complete the mandatory fields of name and work email address. Other details about a staff member can be entered as optional fields. Only people that work for that organization can view the staff record or update the data, making the organization the controller of the data.
- Contact data - all contact types (Company, Personnel, Individual)
- For a contact record, Synergy is the processor and the organization in Synergy which contains the contact record is considered the controller.
- The organization (owner or users) can enter a contact record in Synergy, and the only mandatory field for a contact is the name. Other details about the contact can be entered as optional fields. Only people that work for that organization can update the staff record details, making that organization the controller of the data.
GDPR new individual rights for personal data and how they affect Synergy
A. Right of access
Right of access in the GDPR means that individuals have the right to know what data about them is being processed and how.
In Synergy we can provide the individual their personal data using the extract or using 'on-screen' methods below. Synergy personal data options and how to obtain these details:
- Profile data
- To see a Synergy profile you need to be logged into the application at app.totalsynergy.com
- Select the 'edit profile' option from the top right 'profile toolbar menu'.
- The profile data stored is viewable in the edit profile page only by the logged in user.
- Export an extract of the profile data, by:
- Opening the edit profile page.
- Select the '...' button > and choose the 'Export profile to Excel' option.
- An Excel file with all the Synergy profile details will be downloaded.
- The profile picture is not exported to the Excel file. If required save a copy of the profile image to your local folder.
- To see a Synergy profile you need to be logged into the application at app.totalsynergy.com
- Staff data
- Staff details can be seen after logging into Synergy and using the organization drop down menu > selecting the 'Staff' option > selecting to open the specific staff member from the list of all staff.
- Based on your staff access level in Synergy different detail will available on a staff record. If you are a Director or System Administrator then you can view all the details on the staff record. If you are set at any other access level then you can only view the general details for the staff record.
- The personal data for a staff record is available in these staff sub menu options:
- Staff > Details
- Staff > Documents
- Staff > Notes
- Export the staff details to Excel can be done by a Director level staff member at the organization (the organization is the controller of those details). Export the details to Excel by:
- Open the staff record to the details page.
- Select the '...' button > choose the 'Export staff to excel' option.
- An excel file with the staff general details is downloaded by your browser.
Tip:
- The Staff notes and Staff documents are not exported to the excel file. If these details have been entered / uploaded, then a manual extract of these details would need to be completed by the System Administrator at that organization.
- If a profile picture is shown for a contact record in Synergy, the user has setup that picture in their own personal profile. They control what image is shown for themselves within Synergy. If they have not uploaded a profile picture then we use a letter image that is created by default using the initials entered in their name.
- Contact data
- Contact details can be seen after logging into Synergy in:
- Contacts area - Use the organization drop down menu and select the contacts option. Select a contact from the list to view the details.
- List views - When a contact is shown as a column in the list in Synergy you can click the name if it is shown in green / teal color to open a pop-up page with the contact details listed. e.g. Project list page, Invoices list page and more have the column contact included in the default view.
- Contacts can be added and updated by any staff members that work at that Synergy organization.
- The contacts can have personal data stored under these sub menu options:
- Contact > Details
- Contact > Documents
- Contact > Notes
- To receive an extract of this data, please contact your controlling organization which can extract the data for you (using the export to excel)
- Export the contact details to Excel can be done by a Director level staff member at the organization (the organization is the controller of those details). Export the details to Excel by:
- Open the contact record to the details page.
- Select the '...' button > choose the 'Export contact to excel' option.
- An excel file with the contact general details is downloaded by your browser.
- Repeat this for each contact record for which you need the details exported to Excel.
- Contact details can be seen after logging into Synergy in:
Tips:
- Synergy has three types of contacts: Companies, personnel, and individuals. Each of these contact types can have the same personal / business details stored within the record.
- If a profile picture is shown for a contact record in Synergy, the user has setup that picture in their own personal profile. They control what image is shown for themselves within Synergy. If they have not uploaded a profile picture then we use a letter image that is created by default using the initials entered in their name.
- The Contact notes and Contact documents are not exported to the excel file. If these details have been entered / uploaded, then a manual extract of these details would need to be completed by the System Administrator at that organization.
B. Right to rectification
Right to rectification in the GDPR means that the individual may request that incomplete data be completed, or that incorrect data be corrected.
In Synergy we can provide the individual their personal data following the extract options listed in part 1 above - right to access. Synergy personal data can then be corrected or updated by:
- Profile data
- To rectify your profile data login to Synergy and use the toolbar menu in the top right of the page and select > edit profile.
- Use the Synergy Profile page to update the details as required. Learn more about using the Synergy profile page.
- Staff data
- To rectify the data in your staff record, please contact System Administrator or Owner of the Synergy organization (controller).
- The controller of the data can login to Synergy and use the Staff feature and sub menus as required to update the details on your staff record in that Synergy organization. Learn more about using Synergy staff records.
- Contact data
- To rectify the data in a contact record, please contact a Staff member or Owner of the Synergy organization (controller).
- The controller of the data can login to Synergy and use the Contacts feature and related sub menus to update the details as required on the staff record. Learn more about using Synergy contact records.
Tips:
- In your Synergy profile you must always have at least one email address listed, and you cannot edit the username setup when you created the account initially.
- Staff records allow you to edit all the general details saved for the record, and the saved record must always have a name and an email address.
- Contact records allow you to edit all the general details saved for the record, and the saved record must always have a name.
C. Right to object
Right to object in the GDPR means that an individual may prohibit certain data from being used.
In Synergy we can provide the individual requesting their personal data following the options in part 1 above - right to access. Synergy personal data can then be updated or removed from Synergy by:
- Profile data
- Most of the personal data in the profile page is optional. Update the fields to be blank to remove the data from Synergy.
- Profiles are required to have a first and last name, and a primary work email address. All other data can be removed as required.
- Learn more about using the Synergy profile page.
- Staff data
- The personal data in the staff record is optional. Staff can contact the System Administrator or Owner at their organization (the data controller) and request that they remove any of the optional personal data stored in their contact record.
- Staff records require that a name and email address is entered on each record.
- Learn more about using Synergy staff records.
- Contact data
- The personal data in the contact record is optional. Contacts can talk to the System Administrator or Owner at their organization (the data controller) and request that they remove any of the optional personal data stored in the contact record.
- Contacts require that a name is entered on each record.
- Learn more about using Synergy contact records.
Tips:
- In your Synergy profile you must always have at least one email address listed, and you cannot edit the username setup when you created the account initially.
- Staff records allow you to edit all the general details saved for the record, and the saved record must always have a name and an email address.
- Contact records allow you to edit all the general details saved for the record, and the saved record must always have a name.
D. Right to be forgotten
Right to be forgotten in the GDPR means that the individual may request that an organization delete all data on that individual as quickly as possible.
In Synergy we can provide the individual requesting their personal data following the options in part 1 above - right to access. Synergy personal data can then be deleted by:
- Profile data
- Synergy users can use the edit profile page and remove any personal data as required.
- Synergy users can delete their profile by:
- Select the profile menu by selecting you profile picture in the toolbar top right corner, then select edit profile.
- Select the '...' button in the top right of the edit profile page > delete.
- Click 'delete' on the confirmation pop-up.
- You will now be logged out of Synergy, as you no longer have a valid account.
- Important note: Deleting a profile doesn't delete any Synergy organizations or project portals. Any content you added into an organization or portal will remain. The content already in the Synergy organization / portal is business related data, and is retained for legal reasons.
- Learn more about using the Synergy profile page.
- Staff data
- Staff members in an organization can contact their employer organization (data controller) to delete their personal data.
- The employing organization (data controller) can change the staff record details in Synergy if they have System Administrator or Director access levels.
- Select the Organization menu and select the staff option.
- Locate the staff member that wants their details updated in the list and click the record to open it.
- Review the record, and click the edit button to remove any personal (non-business related) information in the staff record.
- Delete any notes or documents from the relevant tabs that contain personal information about the staff member as well.
- The employing organization need to retain business related data as required by law.
- The staff record cannot be deleted. It can be set as inactive if the staff member has now left the organization. The organization needs to keep the staff record with at least the employees name and work email address in Synergy, as data has been created in the system linked to that record.
- Learn more about using Synergy staff records.
- Contact data
- Contacts can get in touch with the organization who has them included as a contact record (company / personnel / individual types) (data controller) to delete their personal data.
- The organization (data controller) can get a Synergy staff member to:
- Use the Organization menu and select the Contacts option.
- Locate the contact record in the list to open the record.
- Edit the contact record and review and delete all personal information by making the fields blank. The contact records must remain with at least the 'name' details completed.
- If required also remove any notes or contact documents that contain personal details.
- The contact record can only be deleted if it is not linked to any other Synergy records: Personnel, Projects, Invoices etc. Set the contact as inactive if the contact should no longer be used in Synergy. The organization needs to keep the contact record with at least the name in Synergy, as data has been created in the system linked to that record.
- Learn more about using Synergy contact records.
Tips:
- Your Synergy profile can only be deleted if you are not listed as the 'Owner' of any Synergy subscriptions. If you have any active Synergy subscriptions paid or trial where you are the owner then the record cannot be deleted.
- Staff records cannot be deleted. Mark the staff member as terminated / inactive if they have left the organization. Edit the staff record to remove the personal information. A name and work email address is required to remain on the record.
- Contact records can only be deleted if they are not linked to any personnel, projects, or invoices. Mark the contact as terminated / inactive if they should no longer be part of projects. Edit the contact record to remove the personal information. A name is required to remain on the record.
E. Data portability
Right to data portability in the GDPR means that the individual may request that personal data held by one organization be possible to be transported to another organization.
In Synergy we can provide the individual requesting their personal data following the options in part 1 above - right to access. Synergy personal data can then be exported by:
- Profile data
- Export an extract of the profile data, by:
- Opening the edit profile page.
- Select the '...' button > and choose the 'Export profile to Excel' option.
- An Excel file with all the Synergy profile details will be downloaded.
- Learn more about using the Synergy profile page.
- Export an extract of the profile data, by:
- Staff data
- To receive an extract of your staff record data, please contact your employer. The organization that has the Synergy subscription can export these details to Excel.
- Export the staff details to Excel can be done by a Director level staff member at the organization (the organization is the controller of those details). Export the details to Excel by:
- Open the staff record to the details page.
- Select the '...' button > choose the 'Export staff to excel' option.
- An excel file with the staff general details is downloaded by your browser.
- Learn more about using Synergy staff records.
- Contact data
- To receive an extract of the contact data, please contact the Synergy organization. A staff member at that organization can then export these details to Excel.
- Export the contact details to Excel can be done by a Director level staff member at the organization (the organization is the controller of those details). Export the details to Excel by:
- Open the contact record to the details page.
- Select the '...' button > choose the 'Export contact to excel' option.
- An excel file with the contact general details is downloaded by your browser.
- Repeat this for each contact record for which you need the details exported to Excel.
- Learn more about using Synergy contact records.
Synergy add-on partners and the GDPR
Synergy can export or send contact and staff details to third-party products e.g. accounting interfaces, or other API integrations. If you are using an interface to export Synergy data, then please review the other software company / product website for more details on how they are managing the GDPR requirements.
Comments
0 comments
Please sign in to leave a comment.