Welcome to Merchantile.co website
Merchantile.co created this GDPR section on our website to go over what GDPR means for you and the steps we’ve taken to ensure the protection of your privacy.
The EU General Data Protection Regulation (GDPR) comes into effect on 25 May, 2018 and places new obligations on organizations based in the EEA or which hold or process personally identifiable information (PII) about EU residents.
Our Commitment to Data Security
Article 32 of the GDPR requires that controllers and processors have adequate levels of security in place for ensuring the confidentiality, integrity, availability – and more, of processing and other related activities.
Specifically, Article 32 requires Merchantile.co to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the following as deemed appropriate:
- The pseudonymisation and encryption of personal data.
- The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
- The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.
- A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
Merchantile.co’s commitment to confidentiality, integrity, and availability – known as the CIA triad of information security, consists of the following initiatives:
- Robust set of internal controls relating to the storing, processing and/or transmission of personal data for EU data subjects.
- Comprehensive information security and operational policies, procedures, and processes relating to all core InfoSec domains,
- Access Control
- Anti-Virus and Anti-Malware
- Data and Information Classification
- Data Backup and Recovery
- Database Policy
- Firewall Policy
- Internet Usage Policy
- Remote Access Policy
- Security Management
- Software Development Life Cycle
- Web Server Security Policy
- Workstation Security
- Annual security awareness training for all employees.
- Annual risk assessment initiatives for assessing relevant risks to the organization and taking necessary action for reducing risk exposure.
- Monitoring, as necessary, of all relevant third-party providers for which Merchantile.co has a business relationship with in terms of storing, processing, and/or transmitting personal data for EU residents.
Your Rights as a Data Subject
If Merchantile.co is storing, processing, and/or transmitting personal data for EU data subjects, then you must be made aware of the following rights and privileges under the General Data Protection Regulation (GDPR):
- Right of Access: The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data.
- Right to Rectification: The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. 2Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
- Right to Restriction of Processing: The data subject shall have the right to obtain from the controller restriction of processing when various grounds apply.
- Right to Data Portability: The data subject shall have the right to receive the personal data concerning him or her time frame to be decided by the data controller, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
- Right to Object: The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions? 2The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
GDPR Data Protection Scope
The General Data Protection Regulation (GDPR) was enacted by the European Union to deepen and harmonize personal data protection regulations. Now in effect as of May 25, 2018, it is a comprehensive and clear set of guidelines that acknowledges that different “flavors” of personal data require different levels of protection.
GDPR applies to all business irrespective of the region or jurisdiction, no matter where they are based, who collect and process personal data on EU residents. Non-EU companies have to appoint a GDPR representative and will be liable for all fines and sanctions.
Some of the key requirements of the GDPR are:
- Consent: Organizations must get consent in the form of? Collect personal data, with the level of consent varying according to the type of personal data being collected.
- Data minimization: Responding to years of gratuitous collection of personal data by apps, with no clear purpose in mind, the GDPR stipulates that organizations can only collect personal data that is clearly related to a well-defined business objective. If an organization gathers personal data for one purpose but then decides it wants to use it for another purposes (such as consumer profiling), that could be considered non-compliance.
- Individual rights: Another key feature of the GDPR is the very clear rights that it gives data subjects (i.e., the individuals whose personal data is being collected) to understand why their data is being collected and how it is being processed. They have the right to object, to correct—and they have the right to be erased/forgotten. They also have the right to be notified (individually) if their personal data has been breached in a way that could endanger their freedoms and rights.
We as an organization have taken a number of steps to ensure we are fully compliant with our obligations, and have clear policies and processes to respond to customer and partner questions.
Merchantile.co has comply with applicable? legislation, regulation, statute or order which may apply from time to time relating to the collection, storage and use of Personal Information including (without limitation) the Privacy Act 1988(Cth), the Data Protection Act 1998, the European Union General Data Protection Regulation May 25, 2018 the Privacy and Electronic Communications (EC Directive) Regulations 2003, the Data Protection (Processing of Sensitive Personal Data) Order 2000 and comparable laws, as the case may be in the applicable jurisdiction, or any amendments and/or re-enactments thereof.
How we are compliant with the EU GDPR regulation
This is a notice to inform you of Merchantile.co policy about all information that we record about you. It sets out the conditions under which we may process any information that we collect from you, or that you provide to us. It covers information that could identify you (“personal information”) and information that could not. In the context of the law and this notice, “process” means collect, store, transfer, use or otherwise act on information.
- We regret that if there are one or more points below with which you are not happy, your only recourse is to leave our website immediately.
- Merchantile.co takes seriously the protection of your privacy and confidentiality. We understand that all visitors to our website are entitled to know that their personal data will not be used for any purpose unintended by them, and will not accidentally fall into the hands of a third party.
- Merchantile.co undertakes to preserve the confidentiality of all information you provide to us, and hope that you reciprocate.
- Our policy complies with the U.S. laws accordingly implemented, including that required by the European Union General Data Protection Regulation (GDPR) and data protection regulation.
- The law requires us to tell you about your rights and our obligations to you in regards to the processing and control of your personal data.
- Except as set out below, we do not share, or sell, or disclose to a third party, any information collected through our website.
The operations of Merchantile.co are in accordance with the European Union’s General Data Protection Regulation (GDPR), effective May 25, 2018. Merchantile.co has made the GDPR a priority, and we are and have always been fully aligned with the regulation’s intended result:
Passed in 2016, the new General Data Protection Regulation (GDPR) is the most significant legislative change in European data protection laws since the EU Data Protection Directive (Directive 95/46/EC), introduced in 1995. The GDPR, which becomes enforceable on May 25, 2018, seeks to strengthen the security and protection of personal data in the EU and serve as a single piece of legislation for all of the EU. It will replace the EU Data Protection Directive and all the local laws relating to it.
We support the GDPR and will ensure all Merchantile.co services comply with the GDPR provisions effective from May 25, 2018. Not only is the GDPR an important step in protecting the fundamental right of privacy for European citizens, it also raises the bar for data protection, security and compliance in the industry so therefore Merchantile.co is committed to abide by all Data protection regulation.
Service / website Updates
Our service and website are being updated to help customers comply with the GDPR obligations relating to obtaining and recording consent. Consent approval will be available upon request. Other technology designed to automated data access requests received from users will be released.
Data Security Policy
Merchantile.co has always been committed to ensuring we maintain our customers’ and their customers’ data as securely as possible. Details of our Data Security Policy consistent with our obligations under the GDPR is available on our website terms and condition page.
In the meantime, if you wish to submit a data request under the GDPR, or have any additional queries, please contact our Merchantile.co privacy officer at support@Merchantile.co