{"id":30385,"date":"2022-10-14T09:41:33","date_gmt":"2022-10-14T13:41:33","guid":{"rendered":"https:\/\/blueridgeglobal.com\/legal\/ccpa-annex-2\/"},"modified":"2025-06-17T05:12:41","modified_gmt":"2025-06-17T09:12:41","slug":"gdpr-annex","status":"publish","type":"page","link":"https:\/\/blueridgeglobal.com\/legal\/gdpr-annex\/","title":{"rendered":"GDPR Annex"},"content":{"rendered":"[vc_row type=&#8221;in_container&#8221; full_screen_row_position=&#8221;middle&#8221; column_margin=&#8221;default&#8221; column_direction=&#8221;default&#8221; column_direction_tablet=&#8221;default&#8221; column_direction_phone=&#8221;default&#8221; scene_position=&#8221;center&#8221; text_color=&#8221;dark&#8221; text_align=&#8221;left&#8221; row_border_radius=&#8221;none&#8221; row_border_radius_applies=&#8221;bg&#8221; overflow=&#8221;visible&#8221; overlay_strength=&#8221;0.3&#8243; gradient_direction=&#8221;left_to_right&#8221; shape_divider_position=&#8221;bottom&#8221; bg_image_animation=&#8221;none&#8221;][vc_column column_padding=&#8221;no-extra-padding&#8221; column_padding_tablet=&#8221;inherit&#8221; column_padding_phone=&#8221;inherit&#8221; column_padding_position=&#8221;all&#8221; column_element_direction_desktop=&#8221;default&#8221; column_element_spacing=&#8221;default&#8221; desktop_text_alignment=&#8221;default&#8221; tablet_text_alignment=&#8221;default&#8221; phone_text_alignment=&#8221;default&#8221; background_color_opacity=&#8221;1&#8243; background_hover_color_opacity=&#8221;1&#8243; column_backdrop_filter=&#8221;none&#8221; column_shadow=&#8221;none&#8221; column_border_radius=&#8221;none&#8221; column_link_target=&#8221;_self&#8221; column_position=&#8221;default&#8221; gradient_direction=&#8221;left_to_right&#8221; overlay_strength=&#8221;0.3&#8243; width=&#8221;1\/1&#8243; tablet_width_inherit=&#8221;default&#8221; animation_type=&#8221;default&#8221; bg_image_animation=&#8221;none&#8221; border_type=&#8221;simple&#8221; column_border_width=&#8221;none&#8221; column_border_style=&#8221;solid&#8221;][vc_column_text]<strong>G<\/strong>eneral\u00a0<strong>D<\/strong>ata\u00a0<strong>P<\/strong>rotection\u00a0<strong>R<\/strong>egulation (<strong>GDPR<\/strong>) is a data privacy regulation that went into enforcement on\u00a0<strong>May 25, 2018<\/strong>. GDPR is the updated version of Directive\u00a095\/46\/EC, which was enacted in 1995, and will more effectively address the protection of sensitive information in the current technical landscape.\u00a0 GDPR covers the protection of Personal Identifiable Information (PII) of EU citizens that is processed, stored, and managed by organizations.<\/p>\n<p>All of our Blue Ridge products are classified as \u201cProcessors\u201d under the GDPR guidelines. Since we do not determine the purpose and means of the data that is inputted and processed by our products, we cannot be considered a \u201cController.\u201d If you have any questions or require evidence of our compliance, please reach out to us. We will provide you with the information necessary to demonstrate our full compliance with GDPR across all of our lines of products.<\/p>\n<h3><strong>Blue Ridge Certifications<\/strong><\/h3>\n<p><strong>SOC II Type I<\/strong>\u00a0for all of our products. This is an internationally recognized standard that covers the protection and management of sensitive information and all the various components.<\/p>\n<p><strong>Topic:<\/strong>\u00a0Request from individual to remove their data from Blue Ridge products<br \/>\n<strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0Please reach out to our information security team using the contact information provided on this page. Describe your request (for example, you want PII data removed from an application) and provide your contact information so we can confirm receiving request within 48 hours. Depending on the scope of the request, we may need to contact other resources to complete the process. Once completed, you will be notified that your request is resolved.<\/p>\n<p><strong>Topic:<\/strong>\u00a0Consent Management: GDPR has requirements for explicit consent to be given for controllers.<br \/>\n<strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0The PII required by Blue Ridge products must be entered by the Administrator before processing can begin. It is not possible for the product to track when consent was obtained. This information can be managed as a date field in the product but the product cannot be set up as a requestor of consent.<\/p>\n<p><strong>Topic:<\/strong>\u00a0Right of Erasure \/ Right to be Forgotten: GDPR has extended rights to have PII removed from online storage, with exceptions noted in Article 17.<\/p>\n<p><strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0Blue Ridge has systems in place for Controllers to request PII to be removed. Due to the exceptions in GDPR for the deletion of such data, Blue Ridge is handling any removal request and responding without undue delay. For any removal request, part of our process is to confirm with the Controller that there are no exceptions for the request, including medical data or other legal requirements for data retention.<\/p>\n<p><strong>Topic:<\/strong>\u00a0Right of Rectification: GDPR has extended rights to have PII be corrected by the person.<br \/>\n<strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0PII can be updated in all Blue Ridge products.<\/p>\n<p><strong>Topic:<\/strong>\u00a0Data Portability \/ Right to access data.<\/p>\n<p><strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0Blue Ridge can provide the data upon Controller request.<\/p>\n<p><strong>Topic:<\/strong>\u00a0Breach Notification<\/p>\n<p><strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0Blue Ridge follows breach guidelines outlined in GDPR<\/p>\n<p><strong>Topic:<\/strong>\u00a0Security<br \/>\n<strong>Blue Ridge&#8217;s Response:<\/strong>\u00a0Access control is available from the assignment of roles for the customer interface. For the Blue Ridge side, we have policies in place for control<\/p>\n<h3><strong>Updates\u00a0<\/strong><\/h3>\n<p>Please let us know if you have any questions by emailing our team at\u00a0<a href=\"mailto:privacy@blueridgeglobal.com\">privacy@blueridgeglobal.com<\/a>.<\/p>\n<h3><strong>Frequently Asked Questions<\/strong><\/h3>\n<p><strong>Q: What is a DPO?<\/strong><\/p>\n<p>A: DPO stands for Data Protection Officer and is a requirement for some organizations.<\/p>\n<p><strong>Q: How do I contact Blue Ridge\u2019s DPO?<\/strong><\/p>\n<p>A: Blue Ridge does not meet the requirements for a DPO. All related responsibilities are being carried out by Blue Ridge\u2019s information security team.<\/p>\n<p>You can contact our information security team at:<\/p>\n<p>Blue Ridge Solutions, Inc.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 or\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 privacy@blueridgeglobal.com<\/p>\n<p>Attn: Marketing<\/p>\n<p>11585 Jones Bridge Rd<br \/>\nSte #420 Unit #231<br \/>\nJohns Creek, GA 30022<\/p>\n<p><strong>Q: Where is Personally Identifiable Information (PII) currently stored?<\/strong><\/p>\n<p>A: To the extent that our customers input PII into the products, such data is stored within the applications, which are housed within Amazon Web Services (AWS) (Frankfurt, Germany; N. Virginia, USA).<\/p>\n<p><strong>Q: What about deleting a person\u2019s PII in your applications?<\/strong><\/p>\n<p>A: We have privacy processes in place as part of our privacy policy, so we have the framework already in place to allow someone to opt out.<\/p>\n<p><strong>Q: Can I remove my PII from your products?<\/strong><\/p>\n<p>A: Yes, unless there is an overriding exception as outlined in the GDPR, such as medical record requirements and other legal data record requirements. We have policies in place to verify the storage requirements with the Controller of the data and will work with them to anonymize or delete the data without undue delay.<\/p>\n<p><strong>Q: Are Blue Ridge vendors and sub vendors required to be compliant?\u00a0<\/strong><\/p>\n<p>A: Yes.\u00a0 We work with our vendors to add addendums to our contracts that requires them to be GDPR complaint in addition to the confidentially agreements that are already in place.<\/p>\n<p><strong>Q: We as a company store PII in one or more of your products, how can we comply?<\/strong><\/p>\n<p>A: If you have data that qualifies as being regulated by GDPR (for example, you uploaded a document with PII for a GDPR-covered person or persons) it is up to the customer to remove that data.\u00a0 Since we do not actively access customer data, we do not inherently know if your data is GDPR regulated.\u00a0 Our most significant undertaking to be GDPR compliant concerns data that is uploaded or input by customers. We are working on solutions that will allow customers to anonymize or remove GDPR regulated data using automated solutions but as of today the process would be manual.<\/p>\n[\/vc_column_text][vc_row_inner column_margin=&#8221;default&#8221; column_direction=&#8221;default&#8221; column_direction_tablet=&#8221;default&#8221; column_direction_phone=&#8221;default&#8221; text_align=&#8221;left&#8221; row_position=&#8221;default&#8221; row_position_tablet=&#8221;inherit&#8221; row_position_phone=&#8221;inherit&#8221; overflow=&#8221;visible&#8221; pointer_events=&#8221;all&#8221;][vc_column_inner column_padding=&#8221;no-extra-padding&#8221; column_padding_tablet=&#8221;inherit&#8221; column_padding_phone=&#8221;inherit&#8221; column_padding_position=&#8221;all&#8221; column_element_direction_desktop=&#8221;default&#8221; column_element_spacing=&#8221;default&#8221; desktop_text_alignment=&#8221;default&#8221; tablet_text_alignment=&#8221;default&#8221; phone_text_alignment=&#8221;default&#8221; background_color_opacity=&#8221;1&#8243; background_hover_color_opacity=&#8221;1&#8243; column_backdrop_filter=&#8221;none&#8221; column_shadow=&#8221;none&#8221; column_border_radius=&#8221;none&#8221; column_link_target=&#8221;_self&#8221; overflow=&#8221;visible&#8221; gradient_direction=&#8221;left_to_right&#8221; overlay_strength=&#8221;0.3&#8243; width=&#8221;1\/4&#8243; tablet_width_inherit=&#8221;default&#8221; animation_type=&#8221;default&#8221; bg_image_animation=&#8221;none&#8221; border_type=&#8221;simple&#8221; column_border_width=&#8221;none&#8221; column_border_style=&#8221;solid&#8221;][\/vc_column_inner][vc_column_inner column_padding=&#8221;no-extra-padding&#8221; column_padding_tablet=&#8221;inherit&#8221; column_padding_phone=&#8221;inherit&#8221; column_padding_position=&#8221;all&#8221; column_element_direction_desktop=&#8221;default&#8221; column_element_spacing=&#8221;default&#8221; desktop_text_alignment=&#8221;default&#8221; tablet_text_alignment=&#8221;default&#8221; phone_text_alignment=&#8221;default&#8221; background_color_opacity=&#8221;1&#8243; background_hover_color_opacity=&#8221;1&#8243; column_backdrop_filter=&#8221;none&#8221; column_shadow=&#8221;none&#8221; column_border_radius=&#8221;none&#8221; column_link_target=&#8221;_self&#8221; overflow=&#8221;visible&#8221; gradient_direction=&#8221;left_to_right&#8221; overlay_strength=&#8221;0.3&#8243; width=&#8221;1\/4&#8243; tablet_width_inherit=&#8221;default&#8221; animation_type=&#8221;default&#8221; bg_image_animation=&#8221;none&#8221; border_type=&#8221;simple&#8221; column_border_width=&#8221;none&#8221; column_border_style=&#8221;solid&#8221;][image_with_animation image_url=&#8221;42618&#8243; image_size=&#8221;portfolio-thumb_large&#8221; animation_type=&#8221;entrance&#8221; animation=&#8221;None&#8221; animation_movement_type=&#8221;transform_y&#8221; hover_animation=&#8221;none&#8221; alignment=&#8221;&#8221; border_radius=&#8221;none&#8221; box_shadow=&#8221;none&#8221; image_loading=&#8221;default&#8221; max_width=&#8221;100%&#8221; max_width_mobile=&#8221;default&#8221; img_link=&#8221;https:\/\/verasafe.com\/representative-services\/uk-data-protection-representative-program\/&#8221;][\/vc_column_inner][vc_column_inner column_padding=&#8221;no-extra-padding&#8221; column_padding_tablet=&#8221;inherit&#8221; column_padding_phone=&#8221;inherit&#8221; column_padding_position=&#8221;all&#8221; column_element_direction_desktop=&#8221;default&#8221; column_element_spacing=&#8221;default&#8221; desktop_text_alignment=&#8221;default&#8221; tablet_text_alignment=&#8221;default&#8221; phone_text_alignment=&#8221;default&#8221; background_color_opacity=&#8221;1&#8243; background_hover_color_opacity=&#8221;1&#8243; column_backdrop_filter=&#8221;none&#8221; column_shadow=&#8221;none&#8221; column_border_radius=&#8221;none&#8221; column_link_target=&#8221;_self&#8221; overflow=&#8221;visible&#8221; gradient_direction=&#8221;left_to_right&#8221; overlay_strength=&#8221;0.3&#8243; width=&#8221;1\/4&#8243; tablet_width_inherit=&#8221;default&#8221; animation_type=&#8221;default&#8221; bg_image_animation=&#8221;none&#8221; border_type=&#8221;simple&#8221; column_border_width=&#8221;none&#8221; column_border_style=&#8221;solid&#8221;][image_with_animation image_url=&#8221;42617&#8243; image_size=&#8221;portfolio-thumb_large&#8221; animation_type=&#8221;entrance&#8221; animation=&#8221;None&#8221; animation_movement_type=&#8221;transform_y&#8221; hover_animation=&#8221;none&#8221; alignment=&#8221;&#8221; border_radius=&#8221;none&#8221; box_shadow=&#8221;none&#8221; image_loading=&#8221;default&#8221; max_width=&#8221;100%&#8221; max_width_mobile=&#8221;default&#8221; img_link=&#8221;https:\/\/verasafe.com\/representative-services\/gdpr-article-27-representative-program\/&#8221;][\/vc_column_inner][vc_column_inner column_padding=&#8221;no-extra-padding&#8221; column_padding_tablet=&#8221;inherit&#8221; column_padding_phone=&#8221;inherit&#8221; column_padding_position=&#8221;all&#8221; column_element_direction_desktop=&#8221;default&#8221; column_element_spacing=&#8221;default&#8221; desktop_text_alignment=&#8221;default&#8221; tablet_text_alignment=&#8221;default&#8221; phone_text_alignment=&#8221;default&#8221; background_color_opacity=&#8221;1&#8243; background_hover_color_opacity=&#8221;1&#8243; column_backdrop_filter=&#8221;none&#8221; column_shadow=&#8221;none&#8221; column_border_radius=&#8221;none&#8221; column_link_target=&#8221;_self&#8221; overflow=&#8221;visible&#8221; gradient_direction=&#8221;left_to_right&#8221; overlay_strength=&#8221;0.3&#8243; width=&#8221;1\/4&#8243; tablet_width_inherit=&#8221;default&#8221; animation_type=&#8221;default&#8221; bg_image_animation=&#8221;none&#8221; border_type=&#8221;simple&#8221; column_border_width=&#8221;none&#8221; column_border_style=&#8221;solid&#8221;][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row]\n","protected":false},"excerpt":{"rendered":"<p>[vc_row type=&#8221;in_container&#8221; full_screen_row_position=&#8221;middle&#8221; column_margin=&#8221;default&#8221; column_direction=&#8221;default&#8221; column_direction_tablet=&#8221;default&#8221; column_direction_phone=&#8221;default&#8221; scene_position=&#8221;center&#8221; text_color=&#8221;dark&#8221; text_align=&#8221;left&#8221; row_border_radius=&#8221;none&#8221; row_border_radius_applies=&#8221;bg&#8221; overflow=&#8221;visible&#8221; overlay_strength=&#8221;0.3&#8243; gradient_direction=&#8221;left_to_right&#8221; shape_divider_position=&#8221;bottom&#8221; bg_image_animation=&#8221;none&#8221;][vc_column column_padding=&#8221;no-extra-padding&#8221; column_padding_tablet=&#8221;inherit&#8221; column_padding_phone=&#8221;inherit&#8221; column_padding_position=&#8221;all&#8221; column_element_direction_desktop=&#8221;default&#8221; column_element_spacing=&#8221;default&#8221; desktop_text_alignment=&#8221;default&#8221; tablet_text_alignment=&#8221;default&#8221; phone_text_alignment=&#8221;default&#8221; background_color_opacity=&#8221;1&#8243; background_hover_color_opacity=&#8221;1&#8243; column_backdrop_filter=&#8221;none&#8221; column_shadow=&#8221;none&#8221;&#8230;<\/p>\n","protected":false},"author":36,"featured_media":0,"parent":1555,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-30385","page","type-page","status-publish"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/pages\/30385","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/users\/36"}],"replies":[{"embeddable":true,"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/comments?post=30385"}],"version-history":[{"count":11,"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/pages\/30385\/revisions"}],"predecessor-version":[{"id":42621,"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/pages\/30385\/revisions\/42621"}],"up":[{"embeddable":true,"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/pages\/1555"}],"wp:attachment":[{"href":"https:\/\/blueridgeglobal.com\/wp-json\/wp\/v2\/media?parent=30385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}