- Address: –
			
			4001 W. Parmer Lane, Suite 125 , Austin, TX 78727 
- Type of Services provided by Filestack involving the Processing of Customer Personal Data: –
			
			
			
				- Filestack powerful APIs enable developers to process content at scale and provide an off-the-shelf tech stack from uploading, transforming, understanding, and delivering content within applications and interfaces. Filestack’s low-code platform enables developers to build automated content processing and analysis that dramatically accelerates the development lifecycle. The company’s infrastructure powers billions of file uploads, transformations, and downloads every month for customers in a wide variety of industries, including ed-tech, e-commerce, crowdsourcing, and printing.
 
- Data Protection Officer (DPO) Details: –
			
			VeraSafe, LLC [email protected] 100 M Street S.E., Suite 600, Washington, D.C . 20003 USA 
- EU Data Protection Representative: –
			VeraSafe Ireland Ltd. Unit 3D North Point House North Point Business Park New Mallow Road, Cork T23AT2P Ireland Contact form: https://verasafe.com/public-resources/contact-data-protection-representative  
- UK Data Protection Representative: –
			VeraSafe United Kingdom Ltd. 37 Albert Embankment London SE1 7TL United Kingdom  Contact form: https://verasafe.com/public-resources/contact-data-protection-representative 
- Subject matter and duration: –
			
			The subject matter and duration of the Processing of Customer Personal Data are set forth in the Main Agreement and all amendments, exhibits, schedules, task orders, addenda, SOWs, purchase orders and other documents associated therewith and incorporated therein. 
- Nature and Purpose of Processing: –
			The nature and purpose of the Processing of Customer Personal Data are set forth in the Main Agreement and all amendments, exhibits, schedules, task orders, addenda, SOWs, purchase orders and other documents associated therewith and incorporated therein. 
- Further Processing: –
			No further Processing of Customer Personal Data beyond the Processing necessary for the provision of the Services is allowed. 
- Categories of Data Subjects: –
			Data subjects may include Customer’s representatives, such as employees, contractors, collaborators, partners. Data subject may also include individuals attempting to communicate or transfer Customer Personal Data to users of the Services.  
- Categories of Customer Personal Data: –
			The Categories of Customer Personal Data that Customer authorizes and requests that Filestack Processes include but are not limited to: Personal contact information such as full name, address, mobile number, email address; details including employer name, job title and function, identification numbers and business contact details; goods or services provided; IP addresses and interest data. 
- Special Categories of Customer Personal Data to be Processed (if applicable) and the applied restrictions to the Processing of these Special Categories of Customer Personal Data: –
			n/a 
- Categories of third-party recipients to whom the Customer Personal Data may be disclosed or shared by Idera: –
			Subprocessors; and other Idera Affiliates, if applicable. 
- Frequency of the Transfer of Customer Personal Data: –
			The frequency of the transfer of Customer Personal Data is determined by the Customer. Customer Personal Data is transferred each time that the Customer instructs Filestack to Process Customer Personal Data. 
- Maximum data retention periods, if applicable: –
			The retention period of the Customer Personal Data is generally determined by the Customer and is subject to the term of the DPA and the Main Agreement, respectively, in the context of the contractual relationship between Filestack and the Customer. 
- The basic Processing activities to which Customer Personal Data will be subject include, without limitation: –
			Collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction for the purpose of providing the Services to Customer in accordance with the terms of the Main Agreement. 
- The following is deemed an instruction by the Customer to Filestack to Process Customer Personal Data: –
			
			
				- Processing in accordance with the Main Agreement.
- Processing initiated by Data Subjects in their use of the Services.
- Processing to comply with other reasonable documented instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Main Agreement.
 
-  List of Filestack’s Subprocessors available at https://www.ideracorp.com/legal/filestack/subprocessors
			
		
- Description of technical and organizational security measures implemented by the Filestack: –
			
			
			
				- Measures of pseudonymization and encryption of Customer Personal Data:
				
					
						- Customer creates and manages encryption keys. The AWS platform enforces the customer to maintain an encrytped password.
- Customer encrypts data before transmission.
- Data transmissions to Filestack hosts are through secure HTTP with TLS 1.2 (only strong cipher suites accepted) 
- Data transmissions within Filestack infrastructure are through secure protocols. 
- Customer Scoped Data stays encrypted throughout Filestack infrastructure. 
- Customer Scoped Data stays encrypted at rest. 
- No Filestack employee has customer’s encryption keys.
 
- Measures for ensuring ongoing confidentiality, integrity, availability and resilience of Processing systems and services:
					
						- Restriction of logical access to IT systems that Process transferred Customer Personal Data to those officially authorized persons with an identified need for such access;
- Active monitoring and logging of network and database activity for potential security events, including intrusion;
- Regular scanning and monitoring of any unauthorized software applications and IT systems for vulnerabilities of Filestack;
- Firewall protection of external points of connectivity in Data Importer’s network architecture; and
- Expedited patching of known exploitable vulnerabilities in the software applications and IT systems used by Filestack.
 
- Measures for ensuring the ability to restore the availability and access to Customer Personal Data in a timely manner in the event of a physical or technical incident:
					
						- RTO: 24 hours
- RPO: 12 hours 
 
- Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the Processing
					
						- Software development security test performed daily (using OWASP Orizon)
- Software build vulnerability scans are performed regularly.
- SOC 2 audit performed yearly (independent party)
- Application Penetration Tests are performed yearly (independent party)
- Internal security audit is performed yearly
 
- Measures for user identification and authorization:
					
						- User Access Policy established
- User Access are reviewed when one of the following events occurs:
							
								- Major change in organization structure
- Major change in security architecture
- Major attrition
- Security incident
- Twice a year 
 
 
- Measures for the protection of data during transmission:
					
						- Customer creates and manages encryption keys
- Customer encrypts data before transmission
- Data transmissions to Filestack hosts are through secure HTTP with TLS 1.2 (only strong cipher suites accepted)
- Data transmissions within Filestack infrastructure are through secure protocols.
- Customer Scoped Data stays encrypted throughout Filestack infrastructure.
 
- Measures for the protection of data during storage:
					
						- Customer Scoped Data stays encrypted at rest.
- No Filestack employee has customer’s encryption keys
- Access to network assets is restricted to a small Operations Team’s members
 
- Measures for ensuring physical security of locations at which Customer Personal Data are processed:
					
						- Filestack does not have data centers; all servers are hosted via AWS.
 
- Measures for ensuring events logging:
					
						- All systems and network assets are monitored 24x7. Alert rules are configured to create alert events for any anomaly or unauthorized activities. IDS/IPS service is setup for all critical network assets. 
 
- Measures for ensuring system configuration, including default configuration:
					
						- All systems and network assets are built by codes. Baseline default configurations are embedded in deployment codes.
- Code modifications must go through Filestack standard Change Management Process.
 
- Measures for internal IT and IT security governance and management:
					
						- IT/IS Security Policy and Procedure established.
- All IT personnel are required to complete yearly security and compliance training.
 
- Measures for certification/assurance of processes and products:
					
						- Software build vulnerability scans are performed regularly.
- Application Penetration Tests are performed yearly (independent party).
- SOC 2 audit performed yearly (independent party)
- Internal security audit is performed yearly.
 
- Measures for ensuring data minimization:
					
						- N/A. Filestack does not collect, retain, or use any of Customer Scoped Data.
 
- Measures for ensuring data quality:
					
						- N/A. Filestack does not collect, retain, or use any of Customer Scoped Data.
 
- Measures for ensuring limited data retention:
					
						- N/A. Filestack does not collect, retain, or use any of Customer Scoped Data.
 
- Measures for ensuring accountability:
					
						- Each authorized access is unique and traceable.
- Authorized access is reviewed quarterly
- System audit logs are retained for 180 days.
 
- Measures for allowing data portability and ensuring erasure:
					
						- Customer data is stored on AWS. 
- Customers have the option of storing their data (documents, images, etc.) on the Filestack AWS servers. The contents of the data are determined by the customer (Filestack has no control over the contents of the files). The customer controls when data is deleted).
 
- Other:
					
						-  Internal policies establishing that
							
								- Where Filestack is prohibited by law from notifying Data Exporter of an order from a public authority for transferred Customer Personal Data, Filestack shall take into account the laws of other jurisdictions and use best efforts to request that any confidentiality requirements be waived to enable it to notify the competent Supervisory Authorities;
- Filestack must require an official, signed document issued pursuant to the applicable laws of the requesting third party before it will consider a request for access to transferred Customer Personal Data;
- Filestack shall scrutinize every request for legal validity and, as part of that procedure, will reject any request Data Importer considers to be invalid; and
- If Filestack is legally required to comply with an order, it will respond as narrowly as possible to the specific request.