GDPR Compliance
GDPR FREQUENTLY ASKED QUESTIONS
What is the GDPR?
GDPR stands for the General Data Protection Regulation (Regulation (EU) 2016/679). The EU Regulation is a new comprehensive data protection law that updates existing EU laws to strengthen the protection of personal data across 28 EU Member States.
When will the GDPR come into effect?
The GDPR has been approved by the EU Parliament on April 14th 2016 and will come into effect on May 25th 2018. It does not require any enabling legislation to be passed by the state authority and is directly applicable to each Member State’s national law.
Who does the GDPR affect?
The new legal framework applies to all companies dealing with the personal data of individuals residing in the European Union, regardless of the company’s location.
What constitutes personal data?
In a nutshell, the GDPR determines personal data as any information that identifies or can be used in conjunction with other data to identify an individual. The definition of personal data now encompasses not only natural person’s explicit identifiers like Social Security Number, name, email, physical address, but also biometric, demographic and geographic data.
What does “processing” mean?
Processing activities with regard to personal data includes anything that is done to, or with, personal data (collecting, tracking, structuring, storing or deleting, etc.).
What is the difference between a data processor and a data controller?
The GDPR applies to “controllers” and “processors”. A data controller determines the purposes, conditions and means of processing personal data. A data processor is responsible for processing personal data on behalf of and under lawful instructions from a controller. For personal data provided by you directly to Docully at the time of creation of account, Docully is a controller. However with respect to data data stored by clients in a virtual data room (VDR), Docully is a processor. Docully currently uses online data storage facilities provided by Microsoft Corporation (India) Pvt. Ltd. ("MCIPL") by the name of Microsoft Azure. MCIPL acts as a processor to Docully. To understand how Microsoft cloud services protect your personal data, and how you can manage cloud data security and compliance for your organization, please visit
What rights do individuals have under GDPR?
The GDPR expands a set of rights granted to individuals, as outlined below:
- Right to be informed – We will inform you about which of your personal data we collect and how we use it.
- Right of access – Should you be filling out our contact form, we will inform you about purposes of collecting your data and how we will use it.
- Right to be forgotten (also known as the right to erasure) – If we have collected your data for the purposes you are aware of, but you prefer to have all your personal data deleted you can file the request and we will delete it, if there is no compelling reason to continue its processing.
- Right to object – If you do not approve of ways how we use your data you were informed about, you can file a respective request with our support team.
- Right to rectification – You can request supplementing or correcting your personal data. Right to restrict processing – You have the right to request to block or suppress processing of your personal data. This however is not an absolute right and may be declined on a number of grounds.
- Right to data portability – You can receive a copy of your personal data and transfer it to another company.
- Right to not be subject to automated decision making – In certain circumstances, you are entitled not to be the subject of a decision which has either a legal bearing on you, and is based on automated processing. This right however may be declined on a number of grounds.
- Right to lodge a complaint – You can lodge a complaint by contacting us via support@docullyvdr.com.
Please note that the lawful basis for processing of your data can affect which rights are available to you under Docully Services Agreement.
What is the lawful basis for processing and when is consent required?
We are allowed to process personal data as a data controller on one of the following grounds:
- On the basis of your direct consent;
- In order to enter into a contract with you or perform our contractual obligations;
- Our legal obligations require processing customer personal data;
- For our legitimate interests, but only if the balance between our interests and your rights is maintained.
- To protect vital interests of the individuals.
When can personal data be transferred outside the EU? The transfer of personal data outside the EU is allowed only under certain conditions, for example:
- Where the European Commission has designated a third country or an international organization as providing an adequate level of personal data protection; or
- Where model contracts exist based on agreements on transfers made between organizations within a group, called standard data protection clauses or binding corporate rules; or
- Twhere an approved certification mechanism applies, e.g. EU-US Privacy Shield. In addition, a transfer may be made where the individual has provided specific consent.
What are the rules on security under the GDPR?
GDPR safeguards personal data by ensuring they are processed in a manner that provides their security, including protection against unauthorised or unlawful processing as well as against accidental loss, destruction or damage. It requires appropriate technical or organisational measures to have in place to prevent such personal data leaks or unlawful processing.
How do we secure data stored in the VDR?
Data security is our top asset and the primary competence much appreciated and relied on by our clients. All the data uploaded into the encrypted VDR cloud physically resides in ISO and SOC compliant Tier-3 data centers (servers). Data centers act as data processors and all processing activities are performed automatically by Docully’s computer scripts and only on servers protected by firewalls. Data centers’ personnel does not have access to our customers’ data since it is encrypted both at rest and in transfer. Docully’s customers act as data controllers, which means that they can delete the data uploaded into the VDR on their own or file a specific request with Docully’s support team to erase and physically delete all the contents of their VDR.
As an exception, a customer who owns the data stored in the VDR cloud can turn to our technical specialists to look into the structure of the VDR should they be experiencing any technical issues. The eligible specialist will be able to check the file’s details to look into the issue and fix it shortly. All such access is logged for reference and tracking.