GDPR

The ticket system runs on your own server or VPS. Your customers’ data stays with you. For the GDPR it brings the tools you need.

Who is responsible

Under the GDPR, you as the operator are the controller. The ticket system does not take that role off your hands. It does give you the tools for it. This page shows which tools those are and where the manual explains them.

Rights of data subjects

When a person asks for a copy of their data or wants to be erased, you handle it in the interface.

Data export

Art. 15 and 20 GDPR

An administrator downloads everything stored about a person as a ZIP file. It contains the data, the attachments and a readable overview. Every export is logged.

See it in the manual

Anonymization

Art. 17 GDPR

The system replaces a person’s name and email address with placeholders. Tickets and figures are kept. You can do it at the push of a button or, if you like, automatically after an account is deleted.

See it in the manual

Anonymization survives a restore

Art. 17 GDPR

If you restore an older backup, the system applies the anonymizations again. An anonymized person stays anonymous.

See it in the manual

Retention periods

Art. 5(1)(e) GDPR

If you like, the system anonymizes external contacts who have not been in touch for 36 months. It deletes sign-in events after 90 days and administrator actions after 12 months. Archives are cleaned up as well.

See it in the manual

Storing only what is needed

What the system does not need, it does not write down in the first place.

History without comment text

Art. 5(1)(c) GDPR

The ticket history only records that a comment was added, edited or deleted. It does not store the wording. A deleted comment therefore does not live on in the history.

See it in the manual

Server log without email addresses

Art. 5(1)(c) GDPR

The server log names the ticket or the account instead of the email address. Warnings name the domain at most.

Security of processing

Two-factor sign-in for administrators and encrypted backups are switched on by default.

Two-factor sign-in

Art. 32 GDPR

A new installation requires two-factor sign-in for administrators. You can also require it for agents or for all users. Everyone can switch it on in their own profile.

See it in the manual

HTTPS

Art. 32 GDPR

The installer sets up HTTPS: via Let’s Encrypt, with your own certificate or with a certificate that SMITEY generates. If the system runs over HTTP, administrators see a notice.

See it in the manual

Encrypted backups

Art. 32 GDPR

Every new backup is encrypted with AES-256. You do not have to switch anything on. Keep the recovery key somewhere other than the server.

See it in the manual

Security log

Art. 5(2) and Art. 32 GDPR

Failed sign-ins, lockouts and changes administrators make to accounts, roles and settings are recorded in a log. You can filter it and export it as CSV or PDF.

See it in the manual

Protected files

Art. 32 GDPR

On the server, only an administrator can read the configuration, the credentials and the backups. The installer and updates set these permissions themselves.

See it in the manual

What we see as the vendor

  • Purchased licenses are activated online and checked daily. The license ID, a random installation ID, the product version, the operating system and the number of administrators, agents and teams go to our license server.
  • Tickets, names, emails and attachments never leave your installation. We do not process any data on your behalf. That is why you need no data processing agreement with us.
  • We delete the IP address, region and city 12 months after the last contact. Only the country is kept.
All details in the guide, chapter E

Data protection guide for operators

Some obligations lie with you as the controller. The guide helps you with them. It contains templates for the records of processing activities, the technical and organizational measures and the retention and deletion policy. It also describes how to handle requests from data subjects and data breaches.

Read the guide online
GDPR: what the ticket system brings for data protection | Smitey