ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Register of GDPR InformationIOA
2
3
Purpose of processing (Why are we processing)Categories of personal data (What we are processing)The source of the personal data (Where did we get it from?)Description of Processing Activity (How we are processing)
4
Attendees and sponsors registration and payment for IOAMoots organised by IOA directly
Identity & Profile (email address, name, organisation, occupation (job title, role, sector), IOA experience, languages spoken, dietary requirements, access requirements),
Contact (address, Telegram handle), Party Guest identity and contact (guest name, email & dietary requirements, access requirements), Financial & Transaction (payment details),
Marketing and communications, Technical and Usage (IP address, resource access, traffic)
Data subject (You)Eventsforce events management system - registration, abstract and website management
5
Presentations' admission process run by Event department for IOAMoots organised by IOA directly
(same as above) +
personal presentation, summary of applicable presentations
Data subject (You)Personal data of presentations submitted for IOAMoots by presenters and published on IOA.com/events
6
Sending notifications to IOAMoots attendees that have downloaded the IOAMoot application for the conference
Identity, contact details (name, surname and email), financial, transaction, marketing and communicationsData subject (You)Personal data of Moot participants that download the Eventsforce IOAMoot Global mobile application
7
MOOC participants information
Identity & profile (name, email, city, country, timezone, description, photo - Gravatar or manual upload, additional names, interests, institution, department, phone, address, Twitter, LinkedIn, FaceBook, Google+, ICQ number, Skype ID, AIM ID, Yahoo ID, MSN ID, Web page), activity and contribution, course results, IP address
Data subject (You)Learn IOA https://learn.IOA.org
8
IOA Educator Certification program and facilitator training
Identity & profile (name, email, city, country, timezone, description, photo - Gravatar or manual upload, additional names, interests, institution, department, phone, address, Twitter, LinkedIn, FaceBook, Google+, ICQ number, Skype ID, Yahoo ID, Web page), activity and contribution, course results, IP address
Data subject (You) and IOA Partner that enrols data subjectIOA Educator Certificate (MEC) program - https://education.IOA. com/login/index.php
9
Course hosting service
Identity & profile (name, email, city, country, timezone, description, photo - Gravatar or manual upload, additional names, interests, institution, department, phone, address, Twitter, LinkedIn, FaceBook, Google+, ICQ number, Skype ID, Yahoo ID, Web page), activity and contribution, course results, IP address, Chargebee payments (customer id, invoice number, transaction number), payments (amount, currency, payment gateway - Chargebee)
Data subject (You)IOA Academy https://IOA. academy
10
User registrationDisplay name, email address, location, avatar, header image
Optional inclusion: workplace, origin, political opinions, religious beliefs, gender, sexuality, accessibility requirements
Data subject (You)Registration details
11
Describing communities, collections, or shared resources
Descriptions, language, metadata
Optional inclusion: interests, occupation, location, workplace, location, origin, political opinions, religious beliefs, gender, sexuality, accessibility requirements
Data subject (You)Resource metadata
12
Ensuring the service is accessible to all usersOptional inclusion: accessibility requirementsData subject (You)Accessibility
13
Sharing created courses with other IOA users worldwide
Personal data for course creatorsData subject (You)IOA.Net
14
Sending e-newsletters, leads to PartnersName, email, phone number, country of subscribers, organisation name, organisation type, departmentData subject (You)Personal data on IOA.com (all contact forms) - https://IOA. com/contact/
15
Sending newslettersContact details (name, surname and email)Data subject (You)MailChimp marketing email
16
Nurture EDM'sContact details (name, surname and email), job title, phone, country, organisation nameData subject (You)Salesforce marketing automation solution (Pardot)
17
Project management toolContact details (name, surname and email), phone number, country, organisation name, departmentSite adminProject management using Notion
18
Automation form for sending contact details to the relevant database
Contact details (name, surname and email)Data subject (You)Workflow automation provided by Zapier
19
Google Analytics is used to measure pageviews on all IOA websites and solely for statistical purposes on an aggregated basis
User’s IP address, geographical location and browser informationData subject (You)Google Analytics
20
Register of GDPR Information
21
22
Purpose of processing (Why are we processing)Categories of personal data (What we are processing)The source of the personal data (Where did we get it from?)Description of Processing Activity (How we are processing)
23
Create a IOACloud siteContact details (name, surname and email), location, telephone number (optional)Data subject (You, the IOACloud site admin)Customer signing up to IOACloud
24
Process payments for initial subscriptions, upgrades and renewal
Contact details (name, surname and email), billing country, email (if using Paypal), payment method detailsData subject (You, the IOACloud site admin)Payment processing
25
Manage subscriptions and renewals, calculate and report on required taxes
Contact details (name, surname and email), billing countryData subject (You, the IOACloud site admin)Subscription management and tax calculations
26
Warn IOACloud site owners of impending automatic subscription processing (renewal, cancellation, etc.)
Contact details (name, surname), email address (if using Paypal) and other payment method details (but excluding credit card number and CCV)Data subject (You, the IOACloud site admin)Subscription event processing
27
Sending emails to IOACloud admins regarding the IOACloud service
Contact details (name, surname and email), financial dataData subject (You, the IOACloud site admin)Emails sent by IOACloud
28
Infrastructure and product monitoringCountry, website URLData subject (You, the IOACloud site admin)Internal dashboards
29
Monitoring and troubleshooting IOACloud sites and infrastructure
Location, IP address, contact details (name, surname and email), country, IOA activity dataIOACloud site admins and IOACloud site usersLog aggregation and analysis from LogsHero Ltd.
30
Operational reporting on IOACloud servers and sitesLocation, IP address, IOA activity data when error occurData subject (You, the IOACloud site admin)System monitoring and performance analysis from NewRelic Inc.
31
Messaging between IOACloud site usersContact details (name, surname and email)IOACloud site admins, IOACloud site usersEmail sent from IOACloud sites
32
Conversion of assignments from various formats, as part of expected service
Any personal information submitted within assignments (including contact details (name, surname and email), address, phone number, photographs (if provided)).IOACloud site admins, IOACloud site usersDocument conversion for IOA's Assignment module
33
Offer web conferencing features to IOACloud site users
Any personal information submitted within assignments including contact details (name, surname and email), any data submitted during the sessionIOACloud site usersWeb conferencing and whiteboard from Blindside (Big Blue Button)
34
Keep IOACloud sites users data (eg. files) safe and available for later use
Any personal information submitted within the site or course (including contact details (name, surname and email), address, phone number, photographs (if provided)).IOACloud site admins, IOACloud site usersStorage of IOACloud sites' data
35
Hosting client sites and storing dataUser detailsData subject (You)Amazon AWS
36
Calendar scheduling toolContact details (name, surname, email, phone number)Data subject (You)Scheduling using Calendly software platform
37
Authentication and authorisation softwareLogin session, IP address, user-agent, and the web application name and website addressData subject (You)Authentication and authorisation using Okta
38
Payment gateway
Names, addresses, and websites of Customers and potential customers; an itemised list of all invoices sent to Customers (whether subsequently paid and unpaid), including invoice number, amounts and itemised details with the value of each IOA Service type identified; contracts, bid documents and electronic communications relating to all work proposed or done for all Customers; and any and all documents and correspondence evidencing the software and services provided to Customers
Data subject (You)Payments via PayPal
39
Site managementPerformance details of webpage load time, User agent of the browser,IP address, Unique ID generated for the user, User session detailsData subject (You), system recordsMonitoring using Site24x7
40
Payment gateway
Names, addresses, and websites of Customers and potential customers; an itemised list of all invoices sent to Customers (whether subsequently paid and unpaid), including invoice number, amounts and itemised details with the value of each IOA Service type identified; contracts, bid documents and electronic communications relating to all work proposed or done for all Customers; and any and all documents and correspondence evidencing the software and services provided to Customers
Data subject (You)Payments via Stripe
41
Project managementName and job title, business address, business telephone number, email, IP-address, location dataData subject (You)Teamwork to run projects
42
Time trackingContact details (name, surname, email, phone number), IP addressesData subject (You)Toggl time tracking software
43
Provide supportContact details (name, surname and email), phone number, country, organisation type, organisation name, industry, IOACloud or IOA US site urlData subject (You)FreshDesk (Freshworks Inc) helpdesk software
44
Register of GDPR Information
45
46
Purpose of processing (Why are we processing)Categories of personal data (What we are processing)The source of the personal data (Where did we get it from?)Description of Processing Activity (How we are processing)
47
Provide engineers with information to process escalated requests
Contact details (name, surname and email), phone number, country, organisation type, organisation name, industry, IOACloud or IOA US site urlData subject (You)Issue tracking powered by Tracker (JIRA)
48
Answer sales enquiries and pass on indirect leads to Partners
Contact details (name, surname and email), phone number, address, country, organisation type, organisation name, industry, job title, site url, number of employeesData subject (You)Customer relationship management tool Salesforce, messages sent via Slack
49
Facilitating the signup and control of the IOA Apps Plans Portal account
Contact details (name, surname and email), location, telephone numberIOA Apps Plans Portal site admins (Data controller)Customer signup
50
Manage recurring subscriptions and paymentsContact details (name, surname and email), countryIOA Apps Plans Portal site adminsBraintree Payment and subscription management (Paypal service)
51
Manage recurring subscriptions and paymentsContact details (name, surname and email), billing country, website nameIOA Apps Plans Portal site usersChargebee subscription billing and revenue management platform
52
Clients and subscription management in company's Google Workspace information systems
Contact details (name, surname and email), billing country, website name, test username and password, certificatesBranded IOA App and IOA Apps Plans Portal site usersGoogle Workspace
53
Project managementContact details (name, surname and email)Branded IOA App usersBasecamp - Project Management
54
Sending push notifications to mobile app usersEmailBranded IOA App and IOA Apps Plans Portal site usersAirnotifier application server for sending push notifications
55
Compliance with IOA Partner Certification AgreementName, address, email, phone numberData subject (You) and data subject employerUser profile contact details
56
Access to Partner data on IOA Partner siteUser and activity dataData subject (You) and data subject employerIOA Partner activity on Partner portal
57
Partner marketingPartners' client details, Partner detailsData subject (You), data subject employer, Partner organisationCase study upload
58
Partner meetingsName, voice recording, video/photograph of userData subject (You) and data subject employerZoom meeting recordings
59
Partner organisation profile on IOA Partner portalUser details, Partner organisation detailsIOA PartnerIOA Partner staff on company profile
60
IOA client customer financial data from PartnersClient details, Partner detailsIOA PartnerPartner ́s client data
61
IOA client customer financial data from PartnersClient financial information, Partner detailsIOA PartnerInvoice data of Partner's clients
62
Writing and storage of agreements/contracts/documentation with Partners, and potential Partners
Contact details (name, surname, email, phone number), financial records, staff recordsIOA Partner/ApplicantIOA Partner documentation and agreements
63
General business documentation of meetings including attendees
Partner organisation details, Partner details, Partner employeesData controllerIOA Partner meeting notes
64
General business documentationPartner organisation details, Partner detailsData controllerCommercialisation development and Partnerships program
65
Partner billing, record keeping and communicationsHQ authentication information, contact details (name, surname, email, phone number), IOA Partner contact details, client statistics & invoicingData subject (You)IOA Partners portal
66
Home page for IOA User AssociationProfile data of usersData subject (You)IOAAssociation Site https: //IOAassociation.org/
67
Data collection for applications to be part of the Partner Network
Contact details (name, surname, email, phone number), services and corporate info of applicantsData subject (You)Partner Applications Site https: //IOA.com/become-IOA- partner/
68
Register of GDPR Information
69
70
Purpose of processing (Why are we processing)Categories of personal data (What we are processing)The source of the personal data (Where did we get it from?)Description of Processing Activity (How we are processing)
71
Business development statistics generationHQ authentication information, contact details (name, surname, email, phone number), IOA Partner contact details, client statistics & invoicingWebsite recordsGaining insights via the Tableau server
72
Central code repositoryContact details (name, surname, email, photo), activity and contributionData subject (You)git.IOA.org - Hosted by IOA
73
Community education and feedbackContact details (name, surname, email, photo), activity and contributionData subject (You)https://IOA.org/mod/forum/ - Hosted by IOA
74
Mirror of central code repositoryContact details (name, surname, email, photo), activity and contributionData subject (You)https://github.com/IOA/IOA - Hosted by 3rd party
75
Public IOA code repositoryContact details (name, surname, email, photo), activity and contributionData subject (You)github.com - Hosted by 3rd party
76
Private IOA code repositoryContact details (name, surname, email, photo), activity and contributionData subject (You)gitlab.com - Hosted by 3rd party
77
Developer code repositoryContact details (name, surname, email, photo), activity and contributionData subject (You)Local git repositories on dev machines
78
Sharing of rapid prototypes, research artefacts, usability testing feedback
Contact details (name, surname, email, phone number), activity, contributionEmployee/contractorAn online whiteboard and productivity platform powered by Invision.
79
Conduct user studies, interviews, and surveysContact details, activity (name, surname, email, phone number), contributionEmployee/contractorOptimal Workshop for research on user experience
80
Conduct user surveys, Mobile - support for Airnotifier sites
Contact details (name, surname, email, phone number), form entriesData subject (You)Survey administration powered by Google Forms
81
Scheduler for usability testing & user interviewsContact details (name, surname, email, phone number), schedules, location dataData subject (You)Scheduling using Calendly software platform
82
Host the usability tests and user interview recordingsContact details (name, surname, email, phone number), biometric data including pictures video and voice recordingData subject (You)Youtube
83
Community engagement & recruitment for user studiesName, surname, email, phone number, address, health records, biometric, IP Address, document contents, email contents, usage recordsData subject (You)Messages sent via Slack
84
Community engagement & recruitment for user studiesContact details (name, surname, email, photo), activity and contributionData subject (You)IOAAssociation.org
85
Mobile - training in IOAMootsContact details (name, surname, email, photo), activity and contributionData subject (You)MOBILE IOAcloud demo site - Hosted by IOA in IOACloud
86
Demo most recent version of software to the publicIP addresses and other data may end up in logs, IOA will also display IP data in internal logs which is publically availableData subject (You)QA and Demo sites
87
Testing accessibility features in IOALogin and other personal profile informationData subject (You)Accessibility IOA Site
https://docs.IOA. org/311/en/Accessibility
88
Register of research related to IOAPublished research documents, login details and profileData subject (You)IOA research site https://research.IOA.org
89
Testing of softwareAny non-anonymised data from production instances for testingData subject (You)IOA staging sites
90
Ongoing testing of softwareLogins for staff, possible other data as test casesData subject (You)CI servers for development
91
Distribution of softwareSource code with names in it and IOA profiles for staff and contractorsData subject (You)Download IOA site
92
Allowing security researchers access to an isolated instance for testing purposes
IP address in logs, any user profile details entered by the user (eg email), if they set up custom users instead of using the provided onesData subject (You)
Security testing IOA instance https://sectesting.IOA.com (also https://bugcrowd.IOA.com is an alias for the same site).
93
Use the image made public by a user on GravatarImage/picture of user (biometric)Data subject (You)Gravatar on all IOA Community sites
94
Register of GDPR Information
95
96
Purpose of processing (Why are we processing)Categories of personal data (What we are processing)The source of the personal data (Where did we get it from?)Description of Processing Activity (How we are processing)
97
Public site spam preventionUser contributed content (forum posts)Data subject (You)Akismet anti spam (IOA.org + Academy)
98
Registration of websites using IOA and IOA servicesWebsite URL, name and IT admin email addressData subject (You)Registration of websites on https: //stats.IOA.org/
99
Legacy IOA sitesLogin informationData subject (You)Legacy sites (SMEC2001 Survey learning)
100
Language translations for IOAContact details (name, surname, email, photo), activity and contributionData subject (You)Language translation IOA site (lang.IOA.org)