WebBee Global’s Commitment to Data Privacy and GDPR Compliance

At WebBee Global, we take data privacy seriously and are committed to complying with the
General Data Protection Regulation (GDPR). Understanding the different roles involved in
data processing is crucial:

  • Data Subjects: Individuals within the European Union (EU) and European Economic  Area (EEA) whose personal data is protected under GDPR. They have ownership over  their data.
  • Data Controllers: Businesses or organizations that determine how and why personal  data is processed.
  • Data Processors: Entities that handle data on behalf of the Data Controller.

How WebBee Global Handles Your Data

When you use WebBee Global’s eCommerce integration and fulfillment solutions, we act as
a Data Processor, processing data solely based on customer instructions. This means we do
not own, modify, or control the data passing through our systems—we simply facilitate secure,
seamless integrations.

When WebBee Global processes customer data for business operations like sales, marketing,
and customer support, we act as a Data Controller. In this role, we follow GDPR requirements
and ensure that all personal data is handled responsibly under the following lawful processing
conditions:

  • Fulfilling contractual obligations
  • Complying with legal requirements
  • Serving legitimate business interests
  • Protecting vital interests
  • Meeting public interest requirements
  • Obtaining user consent where necessary

Personal Data We May Collect

To support our customers effectively, WebBee Global may process specific personal information for sales, consulting, billing, and support, including:

  • Name
  • Email address
  • Customer ID
  • Order details
  • Payment details (e.g., card expiration date, transaction history)
  • Location information

We do not collect or process sensitive categories of data as outlined by GDPR.

Our Approach to Data Security and Governance

At WebBee Global, safeguarding personal data is a top priority. Our Data Protection Officer
works to ensure compliance across all departments, conducting regular training sessions and reviews to stay up to date on best practices.

Data Mapping & Security Measures

We have conducted Data Mapping exercises to fully understand how data moves within our
systems. To protect your information, WebBee Global implements strict security protocols,
including:

  • Advanced cybersecurity measures (firewalls, encryption, intrusion detection)
  • Access controls to limit unauthorized data exposure
  • Secure handling of physical and digital assets
  • Background screening for employees
  • Data loss prevention strategies
  • Routine security audits across our platforms

Privacy Impact Assessments

WebBee Global conducts Privacy Impact Assessments (PIAs) where necessary to evaluate
and mitigate risks associated with personal data processing.

Your Rights Under GDPR

We respect your rights regarding personal data. If you need access, corrections, or data
deletion, WebBee Global has processes in place to respond within 30 days in compliance with
GDPR.

Handling Data Breaches

In the unlikely event of a data breach, WebBee Global promptly notifies Data Controllers as
required by GDPR regulations. If we act as a Data Controller, we ensure regulatory authorities
are informed within 72 hours, as mandated.

Cookies & Privacy Policies

We prioritize transparency in how we use personal data. Our Privacy Policy outlines details on
data collection, usage, and protection measures.

What You Need to Know as a WebBee Global Customer

As a Data Controller, you hold the responsibility for ensuring compliance when using WebBee
Global’s services. Here are some key considerations:

  • Manage Your Data Responsibly: Only submit necessary data to WebBee Global’s tools  and integrations.
  • Ensure Secure Connections: Always use HTTPS endpoints when integrating with our  services.
  • Understand Data Storage:
  • WebBee Global does not permanently store integration data.
  • Any temporarily stored data is encrypted and automatically deleted within 30 days.
  • Failed transactions remain accessible for retries for up to 30 days.
  • Implement Lawful Data Transfers: If transferring personal data outside the EU, ensure  you have a lawful transfer mechanism.
  • Report Data Breaches Promptly: As a Data Controller, you must report personal data breaches to regulatory authorities within 72 hours.
  • Maintain GDPR Compliance Records: Keep documentation on how personal data is processed within your organization.

Need Assistance?

For any GDPR, security, or compliance-related inquiries, please contact our Data Protection Officer at aj@webbeeglobal.com.

Cookies

Cookies Consent

In order to provide a more relevant experience for you, we use cookies to enable some website functionality. For more information, please review our Privacy Policy.