Backstory promotes transparency and alignment across go-to-market teams while maintaining strong standards for data privacy and security. Our commitment to security, Privacy Shield, and GDPR (General Data Protection Regulation) readiness helps ensure that teams can access the information they need while respecting employee privacy. GDPR is a European Union regulation that protects individuals’ personal data and governs how organizations collect, use, store, and process that data.
With Backstory, you can trust that your data is protected and kept private where necessary.
How Backstory Executes GDPR Compliance
Data Protection by Design and by Default (Article 25)
End-to-end encryption in transit
Encryption at rest across all data storage
Review of data sharing and processing agreements with all partner organizations to ensure compliance with the provisions of the GDPR
Exclusive use of AWS infrastructure for all data processing
Right to Data Portability (Article 20)
Easy user data export in-app
Request user data export via Support
Export activity data via API
Right to Erasure (Article 17)
Also known as “Right to Be Forgotten”
Easy user data removal via Support
Delete activity data via API
Pseudonymisation (Article 5(c))
No PII (or) sensitive information in application logs
All PII (or) sensitive information has been pseudonymized
Breach Notifications (Article 33)
Early notification upon identification of a breach
Details about our commitments are outlined in our EUSA
FYI: There have been no recorded breaches to date.
Sensitive Content
Automated sensitive content flagging and notification
Opt-Outs for All External Communications
All customers have the right and option to opt out of Backstory communications
Employee Training
Mandatory onboarding training on data protection, GDPR, and the rights and freedoms of data subjects
Quarterly engineering training on InfoSec and web application security
Learn More About GDPR
Need Help?
Contact your Customer Success Manager or support@backstory.ai.
