We're now GDPR compliant
The obligatory disclaimer that comes with any mention of GDPR: The information below is not legal advice. If you are concerned about your own compliance with the GDPR, please seek your own legal counsel.
The new European Union data protection laws (GDPR) are now in effect, and we’re happy to say that we’re compliant. These new laws regulate how businesses can collect, use and retain personal information. The European laws are the strictest and most onerous privacy regulations yet, which is why they have become the new global benchmark. Although the GDPR only applies to the data of European users, all DPHOTO users benefit because we apply these privacy practices to all our users.
Compliance with the new laws resulted in very few changes at DPHOTO because we have always followed best practices regarding privacy and security. Our service doesn’t contain advertising, so we have no interest or incentive to harvest your data, to track you, profile you, or target you. Our only interest is providing a great photo sharing service, and hence we only collect the information we actually need, we protect that information, and we only share your information in ways you would expect.
Despite this, the road to GDPR compliance still involved months of rather tedious work - data audits, security checklists, data agreements, and lots of other boring stuff. The vast majority of this work was internal and will never be noticed from the outside – the only visible changes we can point to are listed below:
Privacy Policy
We have a new Terms of Service and Privacy Policy. The Terms of Service is a very standard legal documents that will put most people to sleep, but we put a lot of work into our Privacy Policy to make it clear, readable and informative (for a legal document), so we hope you take the time to read it. It contains details on what personal information we collect, how we collect that information, and who we share it with.Data Processing Addendum
If you are a European business, then you've probably been signing lots of DPAs over the last few months. DPHOTO now has it’s own Data Processing Addendum (DPA), which is a legal contract that stipulates exactly how we handle your data. If you are a European business, then you can review and accept our DPA in the new Legal section of your Account settings page.Cookies
This is something you’ll notice via it’s absence rather than it’s presence. Probably the most noticeable and annoying side-effect of GDPR is the endless popups about ‘Cookies’ that appear on almost every site you visit. We absolutely loathe these, and we went to considerable lengths to ensure you don’t have to deal with these. We hope you enjoy not seeing these warnings on your galleries.
As always, if you have any questions or concerns about how we handle your data, please contact us via support@dphoto.com and we’ll happily answer your queries.