
Sorry, something went wrong. Can you please try again? Or please send us a note at sales@fylehq.com, and we'll get you started.
In this page, we address our commitment to being GDPR compliant, our opinions on GDPR and how we are implementing it, the review process and the changes we will be making and finally, how these changes will affect you. Dive right in!
The landmark European privacy law - GDPR (the General Data Protection Regulation) came into effect on 25 May 2018, and following Brexit, the UK implemented its own UK GDPR . Both regulations impose comprehensive requirements on companies, government agencies, non-profits, and other organizations that offer goods and services to people in the European Union and United Kingdom, or that collect and analyze data tied to EU and UK residents. The GDPR expands the privacy rights granted to EU individuals, and it places many new obligations on organizations that market to, track or handle EU personal data, no matter where an organization is located. It only reinforces our belief that data privacy is an essential individual right and we’re excited about reviewing and updating our policies to make sure that you and your data are always safe and secure! The changes are being rolled out globally and are made across all accounts, regardless of whether they are in the EEA (European Economic Area) or not.
We believe GDPR is a required step towards the standardization for security measures across all geographical regions. Sage Expense Management has always been committed to ensuring the highest standards for data security and data privacy and GDPR only takes us closer to our goal by standardizing the process.
GDPR is the most noteworthy milestone in the space of Data Privacy Regulations and how we think of it.
The GDPR not only applies to organizations located within the EU/UK but it will also apply to organizations located outside of the EU/UK if they offer goods or services to, or monitor the behaviour of, EU/UK data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union/UK, regardless of the company’s location.
Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer IP address.
A controller is the entity that determines the purposes, conditions and means of the processing of personal data, while the processor is an entity which processes personal data on behalf of the controller. Sage Expense Management is both a data processor and a data controller, depending on the situation. We act as data processors when we handle personal data on behalf of our customers by providing them our products, while we act as data controllers when we are the owner of the personal data we process, for example the data of our prospective customers.
We process personal data on the following legal bases: (a) Consent - where you have given clear consent for us to process your personal data for specific purposes; (b) Contract - where processing is necessary for a contract we have with you; (c) Legal obligation - where processing is necessary for us to comply with the law; (d) Legitimate interests - where processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.
We've updated our terms and conditions, privacy policy and cookie policy to incorporate GDPR's requirements.
Sage Expense Management explicitly asks for consent for activity tracking via cookies and provides opt-in / opt-out mechanisms for promotional emails.
Strong data protection commitments are an essential component of GDPR’s requirements. As a controller, Sage Expense Management has an obligation to only work with data processors that provide sufficient guarantees. As part of our due diligence, we only engage data processors that do provide these guarantees.
You have the right to move your data out of Sage Expense Management to other systems.
Under GDPR and UK GDPR, you have the following rights: (1) Right of access - to obtain confirmation of whether we process your personal data and to receive a copy; (2) Right to rectification - to correct inaccurate or incomplete personal data; (3) Right to erasure (right to be forgotten) - to request deletion of your personal data; (4) Right to restriction of processing - to request that we limit how we use your data; (5) Right to data portability - to receive your data in a structured, commonly used format and transmit it to another controller; (6) Right to object - to object to processing based on legitimate interests or for direct marketing; (7) Rights related to automated decision-making including profiling. To exercise any of these rights, please contact us at globalprivacy@sage.com
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: encryption of data in transit and at rest, regular security assessments and penetration testing, access controls and authentication mechanisms, employee training on data protection, incident response procedures, and regular backups. We conduct Vulnerability Assessment and Penetration Testing exercises regularly.
We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and implementation to ensure compliance with GDPR and UK GDPR requirements. You can contact our DPO at globalprivacy@sage.com
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframes mandated by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, providing information about the nature of the breach and the measures taken to address it.
The content above is provided for informational purposes only. The information shared here is not meant to serve as legal advice. You should work closely with legal and other professional counsel to determine exactly how the GDPR may or may not apply to you.