{"id":3424,"date":"2018-05-25T17:44:27","date_gmt":"2018-05-25T21:44:27","guid":{"rendered":"http:\/\/blog.tlsrv.net\/thinglink-gdpr-compliance\/"},"modified":"2022-11-30T11:47:20","modified_gmt":"2022-11-30T15:47:20","slug":"thinglink-gdpr-compliance","status":"publish","type":"post","link":"https:\/\/www.thinglink.com\/blog\/thinglink-gdpr-compliance\/","title":{"rendered":"ThingLink GDPR Compliance"},"content":{"rendered":"<p><span style=\"font-size: 14px; font-family: arial, helvetica, sans-serif;\"><span style=\"font-weight: 400;\"><img decoding=\"async\" src=\"https:\/\/cdn2.hubspot.net\/hubfs\/603436\/Screen%20Shot%202018-05-25%20at%2011.50.01%20AM.png\" alt=\"Screen Shot 2018-05-25 at 11.50.01 AM\" width=\"1366\" style=\"width: 1366px;\"><\/span><\/span><\/p>\n<p><span style=\"font-size: 14px; font-family: arial, helvetica, sans-serif;\"><span style=\"font-weight: 400;\">As we are sure you are aware, the EU General Data Protection Regulation (GDPR) is now in full effect as of May 25th, 2018. We have clarified our <\/span><a href=\"https:\/\/www.thinglink.com\/terms\"><span style=\"font-weight: 400;\">Privacy Policy and Terms of Service<\/span><\/a><span style=\"font-weight: 400;\"> to let you know about your new rights under this new regulation. Please read and familiarize yourself with them, as you will need to accept them before you continue to use ThingLink.<\/span><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\"><!--more--><\/span><\/p>\n<p><span style=\"font-weight: 400; font-size: 14px; font-family: arial, helvetica, sans-serif;\">We won\u2019t be sending you an email asking you to stay on our mailing lists, because we already asked about that when you first signed up. If you chose to opt-out at that point, we\u2019re not going to bother you unless it\u2019s about invoices or technical problems. Remember that you can always change your preferences in your account settings. Our monthly newsletter is a good source of information and inspiration, as we highlight great content from our users.<\/span><\/p>\n<p><span style=\"font-weight: 400; font-size: 14px; font-family: arial, helvetica, sans-serif;\">The biggest visible change to you that GDPR brings is important: Your images and videos that contain third party embedded content will be showing a popup detailing all the domains that the viewers information may be sent to so that the user can give informed consent. This lets you continue embedding ThingLink content with confidence that your own customers have their privacy protected.<\/span><\/p>\n<p><span style=\"font-weight: 400; font-size: 14px; font-family: arial, helvetica, sans-serif;\"><strong>Pro and Premium users:<\/strong> If you have your own GDPR consent scheme in place on your own site, you can turn off the ThingLink GDPR notification in your account settings under <a href=\"https:\/\/www.thinglink.com\/action\/account#advancedMedia\" rel=\"noopener\" target=\"_blank\">Advanced Media Settings<\/a>.<\/span><\/p>\n<p><span style=\"font-weight: 400; font-size: 14px; font-family: arial, helvetica, sans-serif;\">Implementing GDPR is quite an ordeal for a small company. Luckily, because Thinglink is proudly a Finnish company and therefore has already been subject to EU legislation for quite some time, the necessary changes that we had to do were mostly about going through our practices,\u00a0 legal agreements and writing everything up. <\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\"><strong>Among the things that we have done are:<\/strong><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">1. We internalized all of the Javascript and CSS that we were previously using third party CDNs for (jsdlivr, Google, MaxCDN, etc.) and are now serving all of them from our own infrastructure. This means that your IP address isn\u2019t being leaked all over the place as your browse Thinglink images.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">2. We reviewed all the data we were sending to different analytics services and deleted anything that we didn\u2019t absolutely need, and pseudonymized the rest. Pseudonymization is done also on a per-service basis, so even if two services combined, they wouldn\u2019t be able to figure out who is who.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">3. We looked our internal data gathering and dropped some data collection points that weren\u2019t simply used anymore.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">4. We checked all external services for GDPR compliance and removed the ones that we weren\u2019t actively using anymore or could be replaced with GDPR-compliant ones.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">5. We went through our codebase and added tests to check that when you delete an account, we really do go delete your data from external services as well (where applicable). The good thing is that GDPR compliance means that companies offering services do have to provide an API for this as well, so it\u2019s now actually possible to do that.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">6. We reviewed our security practices and added checks and processes with improved documentation.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">7. We brought our password and signup handling in compliance to NIST 800-63-3 Authenticator Assurance Level (AAL) 1 -standard. This means e.g. that the minimum password length is now 8 characters and we do check on people trying to use \u201c12345678\u201d as their password.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">8. We rewrote our Privacy Policy and our Terms of Service to be GDPR -compliant. Now they address the terms for underage users a lot better than before.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">9. We added a new section about our Privacy Architecture to our Terms of Service-page to describe more exactly what kind of data we collect and where, and how we store and treat your data.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">10. The topic of third-party embeds on images was the most interesting: The main issue with embedding content in a Thinglinked image is that upon viewing the image, your data is shared with the embedded site \u2013 if you embed a YouTube video, YouTube sees when the video opens without you getting a say on the matter. So after looking at different options, we decided to add a new consent screen on images and videos: if, the act of viewing and exploring the image would cause data to be shared with another site, we let you know before you proceed. We store the consent for some time, so you don\u2019t have to keep clicking \u201cAccept\u201d every time you watch the image.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\">11. Finally, we trained the sales, support and developer staff about GDPR.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif; font-size: 14px;\"><strong>If you have any questions,<\/strong> please reach out to support@thinglink.com!<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we are sure you are aware, the EU General Data Protection Regulation (GDPR) is now in full effect as of May 25th, 2018. We have clarified our Privacy Policy &#8230;<\/p>\n","protected":false},"author":4,"featured_media":3425,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","om_disable_all_campaigns":false,"_mi_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[491],"tags":[370,371],"_links":{"self":[{"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/posts\/3424"}],"collection":[{"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/comments?post=3424"}],"version-history":[{"count":1,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/posts\/3424\/revisions"}],"predecessor-version":[{"id":6512,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/posts\/3424\/revisions\/6512"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/media\/3425"}],"wp:attachment":[{"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/media?parent=3424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/categories?post=3424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thinglink.com\/blog\/wp-json\/wp\/v2\/tags?post=3424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}