LogoLogo
Product TourResourcesLog InBook a Demo
  • Welcome to Crobox
  • What's New
  • GETTING STARTED
    • First Steps
      • Crobox Snippet Implementation
        • Manual Snippet Implementation
        • GTM Snippet Implementation
      • Event Tracking Implementation
        • Pushing Events to Crobox
        • Content Security Policy Header
      • Cookie Wall Settings
    • Launch Your First Product Advisor
      • Choosing the Right Product Category
  • How to guides
    • Product Finders
      • Setup your Advisor
      • Manage the Question Flow
      • Finder Editor
        • Page Settings
        • Question Editor
        • Answer Editor
      • Translations
      • Create Activations
      • Activations: Best Practices
      • Product Quality Assurance
      • A/B Testing
      • Publishing & Versions
    • Campaigns
      • Create a Campaign
      • Testing
      • Campaign Performance
      • Adding a Campaign Category
      • What are the differences between Campaign Types?
    • Product Data
      • Setting up a Product Feed
      • Manage and Transform Product Properties
      • Product Data Enrichment
      • How to Create and Edit Product Tags
      • Adding a Property Category
    • Analytics Dashboard
      • Data Confidence
    • Product Recommenders
      • Creating a Recommender
    • FAQ
      • Performance & Security
      • Data & GDPR
      • How do I track the performance of my campaigns?
      • How do I create segments?
      • What are Smart Filters?
      • What's the difference between CTR impact and relative impact?
      • What's the difference between A/B testing, multivariate testing, and AI?
  • TECHNICAL DOCUMENTATION
    • Setting Custom Visitor Properties with Pageview API
    • Product Advisor Event Tracking Integration
    • Pre-selecting Advisor Questions
    • Custom Themes and CSS
  • Security & Compliance
    • Security Managment
    • Data Security
    • Legal
      • Cookie Policy
      • Developer Mode
      • General Terms and Conditions
  • ADMINISTRATION
    • User Management
    • Accounts and Billing
    • Troubleshooting and Support
Powered by GitBook
LogoLogo

Crobox

  • Product Tour
  • Crobox vs. The Competition

About

  • About Crobox
  • Partners
  • Careers
  • Ambassador Program

Resources

  • Trust Center
  • Blog
  • Resources
  • Privacy Policy
On this page
  • 1. How does Crobox define Personal Identifiable Information (PII)?
  • 2. Does Crobox store Personal Identifiable Information (PII)?
  • 3. Does Crobox process Personal Identifiable Information (PII)?
  • 4. How does system and security logging use IP addresses?
  • 5. Does Crobox require a Data Processor Agreement (DPA)?

Was this helpful?

  1. How to guides
  2. FAQ

Data & GDPR

Frequently asked questions regarding Crobox's GDPR and data processing documents.

1. How does Crobox define Personal Identifiable Information (PII)?

PII is defined as any information/data that can be used to uniquely identify a Data Subject within a database or data collection. Legally, this process is often referred to as “singling out” and specifically describes using PII to pinpoint any individual Data Subject within a dataset. Data that cannot be used to single out a Data Subject is, therefore, not considered PII.

PII is made up of “hard data points” such as (personal) names, email addresses, physical addresses, IP addresses, social security numbers, mugshots, avatars, and so forth. This type of data reveals the underlying Data Subject using a one-to-one relation.

It is important to note that while PII is not being explicitly processed, Crobox does work with Universally Unique Identifiers (UUIDs), which are computer-generated sequences of random characters that connect sessions to corresponding visitors. While UUIDs can theoretically be used to single out Data Subjects, it is often not considered PII because:

  1. The UUID uses complex logic to randomly generate a sequence of characters and numbers, making it very difficult to connect a specific Data Subject to a UUID.

  2. The UUID is never exposed to a visitor as it is stored in cookies. Without knowing a UUID, one can never pinpoint his or her own data.

  3. The UUID doesn't have any interpretation, meaning there is no distinction between any two given UUIDs.

2. Does Crobox store Personal Identifiable Information (PII)?

Based on the above explanation of PII and UUID, no, Crobox does not store any PII information on our platform. No database or other persistent data storage contains data that is directly attributable to any Data Subject.

Crobox does store UUIDs. Depending on the legal definition that an organization adopts, and as stated above (see FAQ 1), UUIDs can be considered PII, but this is rarely the case. Crobox requires UUIDs to process events. These UUIDs are stored in our platform and in the cookies within the browser of a visitor.

3. Does Crobox process Personal Identifiable Information (PII)?

The only PII that is temporarily processed and transformed (anonymized) is the IP address belonging to a web or HTTP session. Whenever a visitor enters the website of the Data Controller, Crobox creates a new session that holds information belonging to that specific visitor as long as (s)he is active on the website.

Specifically, Crobox uses the IP address to determine the city/country/region of the respective visitor. Whether this mapping is successful or not, the IP address is immediately discarded, thus, it is not persisted.

4. How does system and security logging use IP addresses?

Crobox’s platform logs all communication that takes place on our platform, as we need this data for system and security purposes. For example, this log is used to detect and protect against Distributed Denial of Service (DDOS) attacks.

This log data is raw system data that doesn’t have any correlation, interpretation, or other enrichment processes involved. However, system logging does include IP addresses, as these are required for security and system logging and thus can’t be excluded. To further minimize any impact, this system data is only stored in the logging infrastructure and is automatically removed after 14 days.

5. Does Crobox require a Data Processor Agreement (DPA)?

A DPA is not required to use Crobox’s platform, as PII is not stored. Therefore, the impact of a data breach is low. However, organizations that wish to have this in place can request Crobox’s DPA.

PreviousPerformance & SecurityNextHow do I track the performance of my campaigns?

Last updated 11 months ago

Was this helpful?