This article explains in detail where YAMM’s data is stored and how our processing complies with GDPR. It also explains our compliance with GDPR’s International Data Transfer clause.
The legitimacy of our data processing operations
Data Storage
We store and process your user and usage data (refer to the article: [DATA STORAGE] What data is stored by YAMM and how is it used?) in Firebase, the Google cloud-hosted database.
Google manages Firebase, and its servers are located primarily in the United States (refer to the Firebase’s privacy policy for more information).
The physical storage of YAMM data and processing is protected under Data Processing and Security Terms of Google Cloud Platform.
Data Processing
YAMM is GDPR compliant as we don't store or transfer any personal data. That is because your data (mailing list) is stored in your Google Spreadsheets and is never saved in our database.
Can you exercise your right to data portability?
As detailed in our article [DATA STORAGE] What data is stored by YAMM and how is it used?, we don't store any of your customers’ data (mailing lists). So we are not obliged for any data portability requests.
Which Data Transfer mechanisms does YAMM rely on?
Talarian relies on the Standard Contractual Clauses to transfer all of its users’ EEA personal data to a third country (outside the EEA) in compliance with the GDPR. The Standard Contractual Clauses are referenced in and automatically apply through Talarian' Data Processing Addendum, which you can find here.
That means that our users can take comfort that their EEA personal data continues to be protected to European standards in compliance with applicable data protection laws, including GDPR.
HIPAA and BAA
Suppose you intend to use the Service for any purpose or in any manner involving Protected Health Information, as defined in the Health Insurance Portability and Accountability Act (“HIPAA”). In that case, it is your responsibility to (a) execute a Business Associate Agreement with Google related to your HIPAA data stored in your Google Drive, and (b) execute a Business Associate Agreement with us related to your HIPAA data stored by you on the Service. To check what data the Service stores, please refer to this page: YAMM. To request a BAA to us, please fill in this Google Form, and you will automatically receive our standard BAA to sign.