The EU General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It replaces the existing EU Data Protection law to strengthen the protection of personal data and the rights of an individual. Since our customers' data is of utmost importance to us, HippoRev is strictly GDPR compliant.
We worked for several months to build a robust data protection framework for all our users and underwent a massive overhaul of our processes and product features to ensure we adhered to the new regulatory guidelines. Here are some of the critical steps we took to ensure we met the GDPR obligations:
We have updated our Privacy Policy, Terms of Service, and Cookie Policy with the objective to increase transparency and make it easier for our users to understand what information we collect and why.
We've improved the navigation and organization of these policies to make it easier for you to find what you're looking for. We've also explained our practices in more detail and in a more straightforward language.
Since we use third-party suppliers to make HippoRev more accessible, we have updated our Data Processing Agreements (DPAs) that commit our vendors to uphold the data protection standards defined under GDPR.
We recognize that it's essential for you to control your information. Hence, our team has built the necessary features that give our users greater visibility and control over how we use their data.
This includes an option to opt-out of marketing analytics & communication, deleting account and all data associated with it, and better access to information on how user data is stored and processed.
We recognize that the protection of your data also involves us. Thus, we have completed an internal audit of how we handle the personal data of our users.
The audit covered, in detail, what kind of personal data we process, where that data is stored, and what employees have access to it.
We have also reviewed our vendors who process this data and have made efforts to validate if they are following the GDPR guidelines around data protection. We are also instituting policies around data storage, data access, and data retention.
If you have any further questions, you can reach out to us at team@hipporev.ai
Got questions?
Is Hippo Rev SOC 2 Type II certified?
Yes. Hippo Rev is SOC 2 Type II certified and follows industry-recognized security controls designed to protect customer data, system availability, and operational integrity. Documentation can be shared during your security review process.
Who owns the data processed by Hippo Rev?
Your organization retains ownership of its data at all times. Hippo Rev processes customer information only to provide the contracted services. We do not claim ownership of your business data or use it for purposes outside the scope of our agreement.
Is Hippo Rev ISO 27001 certified?
Yes. Hippo Rev is ISO 27001 certified, demonstrating that our information security management system follows internationally recognized standards for protecting customer information and managing security risks.
Does Hippo Rev use customer data to train public AI models?
No. Customer data is handled according to our contractual commitments and applicable privacy requirements. Data submitted through Hippo Rev is not used to train public AI models without explicit authorization from the customer.
Can Hippo Rev support our vendor security review?
Yes. Our team regularly works with enterprise procurement, IT, legal, and information security teams during the purchasing process. We can provide security documentation, answer technical questionnaires, and participate in vendor risk assessments as needed.
How does Hippo Rev protect customer information?
Hippo Rev uses multiple layers of security controls to help protect customer data, including encryption, secure authentication, role-based access controls, infrastructure monitoring, and regular third-party security assessments. Our security practices are continuously reviewed to help maintain the confidentiality, integrity, and availability of customer information.
Can we request additional legal or security documentation?
Yes. During the evaluation process, Hippo Rev can provide appropriate documentation such as security certifications, compliance information, data processing agreements, and other materials typically requested during enterprise procurement and legal reviews.