Security, Privacy & GDPR FAQs
Questions about our security, terms of service, privacy policy or GDPR compliance? Read on for our answers.
What is GDPR and is Local Reminder compliant?
The General Data Protection Regulation (GDPR) is designed to help EU citizens protect their personal data. Local Reminder is fully GDPR compliant as of August 1st, 2019.
Are my customers also obliged to comply with GDPR?
Yes, from our end. Of course, if your customers are in a location where the GDPR applies, they need to make sure their own business operations are also compliant.
What personal data do you collect when I register?
When registering you voluntarily provide your name and email address. We also collect: IP address, device ID, device information (model, brand, OS). Name, phone number and gender are optional and not processed. You can update this information at any time in your Account Settings.
Why do you need my data?
The data we collect is required to provide you with our services and to improve Local Reminder. Local Reminder is a Data Processor and controls how your data is processed within GDPR regulations. You retain all rights to your data.
Do you use GDPR-compliant third parties?
Yes. When necessary, we use: Amazon Web Services, Google Analytics, Google Firebase, Zendesk, SendGrid, Mailgun, Fabric (Crashlytics), Baremetrics, MailChimp. We take necessary safeguards when sending or receiving data from third parties.
Where is my data processed?
We process data in Quebec, Canada. We only collect as little data as possible, and all data is encrypted using AES 256 encryption.
Do you sell my data?
No, we never sell data.
What happens to my data if I delete my account?
Upon deleting your account, all your personal data will be removed from our production systems. Only an encrypted copy will remain on backup archives for 180 days, after which it is permanently deleted.
Do you offer a Data Processing Agreement (DPA)?
Yes. We offer a pre-signed DPA on behalf of Local Reminder. Fill out your details and sign it. Contact us for further needs.
Who has access to my personal data internally?
We restrict staff access to personal data to a very small number of employees — only those who need access for specific reasons to improve Local Reminder.
How do you protect data technically?
When stored in servers/databases: AES 256 encryption. When transmitted: TLS 1.1 or above. Backups: AES 256 + RSA 2048-bit signing. Additionally, Local Reminder creates automatic daily backups within the app, protected by a security system that prevents unauthorized access.
My compliance needs are specific — what should I do?
Since GDPR has various requirements, your compliance needs will depend on your precise circumstances. If you have specific questions or needs, please contact our support team.
More questions? Contact our support team.