Kindful has two data services to help you with GDPR data requests. Read below to learn more about these options.
In accordance with the GDPR, your customers or donors may request a copy of their data that your organization has collected with Kindful. Some of your customer's data may not be included in this data archive (e.g., data sent to integrated third-party applications).
To get a copy of your customer's/donor’s data, email firstname.lastname@example.org with the subject line “New Request: GDPR Data Copy Request”. In the body of the request include the URL to the contact(s) in question.
After submitting a request you will receive a notification confirming the start of the process. You'll receive your customer's data file within a month of submitting the request. After you've received the notification from Kindful, make sure to do the following:
- Download your customer's data file using the link in the email.
- Confirm the customer's identity and contact details.
- Send the file to your customer using an appropriate method to maintain data security. For larger files you may wish to use a file sharing service you and your customer have agreed on.
- Note that no notification will be sent to your customer or donor from Kindful. As a Kindful Organization Account Owner, it is your responsibility to send the data file.
2. Right to be forgotten: Deleting your customer/donor data
In accordance with the GDPR, your customers or donors may request that you permanently delete their data that has been processed on your Kindful pages except in the cases where you have a legal basis to retain specific data.
- Important: Some customer data may not be deleted in this process.
- Deleting data in Kindful may not remove data sent to integrated third-party applications (e.g., data sent to Mailchimp via the Kindful-Mailchimp integration).
- Due to IRS tax reporting and receipting requirements, it may not be possible to comply with a request to delete all information about a donor.
- US law requires political organizations to retain the personal information necessary to identify individuals who have supported their campaigns.
To delete your customer's data, email email@example.com with the subject line “New Request: GDPR Data Delete Request”. In the body of the request include the URL to the contact(s) in question.
After submitting a delete request you will receive a notification confirming the start of the process. Your customer's data will be deleted (with the exceptions noted above) within a month of your request. Please note that no notification will be sent to your customer or donor from Kindful. It is your responsibility to inform them when their data has been deleted.