GDPR

ShortPoint General Data Protection Regulation (GDPR) Practices

At ShortPoint, protecting the privacy and personal data of our users and customers is a top priority. We are committed to complying with the General Data Protection Regulation (GDPR) and ensuring that both our organization and our customers are operating securely and transparently. As part of our commitment to transparency and compliance, we have outlined our GDPR compliance practices below

SECTION STATUS EXPLANATION
Individual in Charge of GDPR Currently Available Adedolapo Oguntayo
Data Protection Officer (DPO) Currently Available Adedolapo Oguntayo
Purpose of Processing Currently Available We collect limited personal data to activate ShortPoint licenses and provide support. No customer content or tenant data is accessed or stored by ShortPoint. Personal Data is used solely for license management, product usage insights, and communication. For more details, see ShortPoint's Privacy Policy – https://www.shortpoint.com/privacy-policy .
Lawful Basis of Processing and Consent Currently Available Under Article 6 of GDPR (https://gdpr-info.eu/art-6-gdpr), it falls under:
- Consent: Via Terms of Service
- End User License Agreement and Opt-in of Terms and Conditions.
- Contract: Activation and use of ShortPoint requires acceptance of the End User License Agreement
- Legitimate Interest: To provide product support, notify of updates, and ensure service quality.
- Consent: Where required, users are informed and may withdraw via privacy@shortpoint.com .
Withdrawal of Consent / Opt-Out Currently Available Users may request data deletion or opt-out by emailing: privacy@shortpoint.com. Certain support or license services may be impacted.
Cookie Notice Currently Available See our Cookie Policy at https://shortpoint.com/cookie-policy
Deletion Policy Currently Available We do not store or access any content created within SharePoint or Microsoft 365, all design and site data remains fully within the customer's environment and control. If you would like to request the deletion of personal data related to license or support services, you may: Email us at privacy@shortpoint.com.
Data Access / Modification / Portability Currently Available Customers may request access, correction, or deletion of their data by contacting privacy@shortpoint.com. Design data remains within the customer's SharePoint environment.
Data Protection Information Currently Available ShortPoint's platform architecture ensures that customer data is not transmitted to or stored on ShortPoint servers. The only personal data we collect is limited to what's necessary for license activation, product usage analytics, and support communication. Our security program is independently verified through a SOC 2 Type II report, supplemented by annual penetration testing, endpoint protection, and continuous compliance monitoring through Drata
Notification of Breach Currently Available ShortPoint's breach notification procedures are detailed in our Incident Response Policy, and are made available to customers upon request via privacy@shortpoint.com or from our trust centre. We are committed to transparency and operational availability. Customers can monitor real-time system performance and any ongoing incidents via our public status page: https://status.shortpoint.com

Last Updated: July 3, 2025