| Confidentiality |
End-to-end encryption by implementing Autocrypt and Verified groups. User-friendly end-to-end encryption means that the requirements of the GDPR are already implemented at the technical level, Privacy by Design.
|
| Data minimization |
No upload of contact lists from your phone. |
| Data avoidance |
No ArcaneChat servers, no processing of personal data. All data remains with your e-mail provider.
|
| Legal basis |
There is no need to obtain consent for address book matching, Art.7 GDPR, as no address book data is transferred. Therefore, no additional legal basis is required.
|
| Data to third parties |
We only receive the token for the push notification and forward it to the provider of your operating system. If you don't want to receive push notifications, we won't forward a token. |
| Data from third parties |
Easy implementation in companies: ArcaneChat does not process personal data on behalf of the controller and therefore does not require any instruction or data processing agreement. Easy connection with the own corporate e-mail server.
|
|
DPIA
|
No data protection impact assessment needs to be carried out for ArcaneChat Art.35 GDPR, as no specific additional data is processed beyond the e-mail messenger process.
The risk to the rights and freedoms of natural persons is limited to the internal company data processing of the e-mail communication and that of the e-mail providers.
|
|
Documentation
|
Inclusion of the measures implemented by ArcaneChat in the record of processing activities may have a positive impact on possible evidence, Art.30 GDPR as well as certification processes, Art.25 (4) GDPR,Art.42 GDPR.
The documentation of processing activities related to Messenger communication is omitted and shifts only to the record of processing activities of your e-mail provider, Art.30(2) GDPR.
|