GDPR
The ticket system runs on your own server or VPS. Your customers’ data stays with you. For the GDPR it brings the tools you need.
Who is responsible
Under the GDPR, you as the operator are the controller. The ticket system does not take that role off your hands. It does give you the tools for it. This page shows which tools those are and where the manual explains them.
Rights of data subjects
When a person asks for a copy of their data or wants to be erased, you handle it in the interface.
Data export
Art. 15 and 20 GDPR
An administrator downloads everything stored about a person as a ZIP file. It contains the data, the attachments and a readable overview. Every export is logged.
See it in the manualAnonymization
Art. 17 GDPR
The system replaces a person’s name and email address with placeholders. Tickets and figures are kept. You can do it at the push of a button or, if you like, automatically after an account is deleted.
See it in the manualAnonymization survives a restore
Art. 17 GDPR
If you restore an older backup, the system applies the anonymizations again. An anonymized person stays anonymous.
See it in the manualRetention periods
Art. 5(1)(e) GDPR
If you like, the system anonymizes external contacts who have not been in touch for 36 months. It deletes sign-in events after 90 days and administrator actions after 12 months. Archives are cleaned up as well.
See it in the manualStoring only what is needed
What the system does not need, it does not write down in the first place.
History without comment text
Art. 5(1)(c) GDPR
The ticket history only records that a comment was added, edited or deleted. It does not store the wording. A deleted comment therefore does not live on in the history.
See it in the manualServer log without email addresses
Art. 5(1)(c) GDPR
The server log names the ticket or the account instead of the email address. Warnings name the domain at most.
Security of processing
Two-factor sign-in for administrators and encrypted backups are switched on by default.
Two-factor sign-in
Art. 32 GDPR
A new installation requires two-factor sign-in for administrators. You can also require it for agents or for all users. Everyone can switch it on in their own profile.
See it in the manualHTTPS
Art. 32 GDPR
The installer sets up HTTPS: via Let’s Encrypt, with your own certificate or with a certificate that SMITEY generates. If the system runs over HTTP, administrators see a notice.
See it in the manualEncrypted backups
Art. 32 GDPR
Every new backup is encrypted with AES-256. You do not have to switch anything on. Keep the recovery key somewhere other than the server.
See it in the manualSecurity log
Art. 5(2) and Art. 32 GDPR
Failed sign-ins, lockouts and changes administrators make to accounts, roles and settings are recorded in a log. You can filter it and export it as CSV or PDF.
See it in the manualProtected files
Art. 32 GDPR
On the server, only an administrator can read the configuration, the credentials and the backups. The installer and updates set these permissions themselves.
See it in the manualConsent
For the satisfaction survey, the system asks first.
Survey only with consent
ProfessionalArt. 7 and 21 GDPR
People outside your company receive the satisfaction survey only after they have given consent. Customers give consent themselves in the customer portal. The checkbox is never pre-ticked. If they agree by phone, in person or in writing, an agent records it on the ticket. Every survey email contains an unsubscribe link. Consent and unsubscribes are stored as evidence.
See it in the manualWhat we see as the vendor
- Purchased licenses are activated online and checked daily. The license ID, a random installation ID, the product version, the operating system and the number of administrators, agents and teams go to our license server.
- Tickets, names, emails and attachments never leave your installation. We do not process any data on your behalf. That is why you need no data processing agreement with us.
- We delete the IP address, region and city 12 months after the last contact. Only the country is kept.
Data protection guide for operators
Some obligations lie with you as the controller. The guide helps you with them. It contains templates for the records of processing activities, the technical and organizational measures and the retention and deletion policy. It also describes how to handle requests from data subjects and data breaches.
- Guide as PDF
- Template: records of processing activities (Word)
- Template: technical and organizational measures (Word)
- Template: retention and deletion policy (Word)