GDPR

The General Data Protection Regulation (GDPR) took effect on the 25th of May, 2018. PTValley guarantees that we comply fully with all the changes approved and implemented under GDPR. Our commitment is to protect your personal data and uphold the rights of individuals as defined by GDPR.

Essentials of GDPR for Businesses

  1. Get Consent:
    • The user must agree to be included in your marketing campaigns.
    • If the user has consented to the message and communication channel you are offering, you can continue to send messages. However, if there is no consent, you cannot send them marketing materials or advertise to them. Explicit, unambiguous consent must be obtained from the visitor to send such messages, otherwise, you may face heavy fines.
    • Note: Emails collected using 3rd party apps or during the checkout process may not have a consent record in PTValley, as per European GDPR law, consent must be collected via a 1st party web form. Thus, we cannot confirm that customers have given their consent if the data was not collected by us directly.
  2. Provide Adequate Protection:
    • You must protect the user’s personal data adequately.
    • If a user consents to your storing and processing their personal data (e.g., through personalized marketing or advertising messages), you have the obligation to ensure that the data is adequately protected. Under GDPR, “personal data” is broadly defined as any data that can be used alone or in combination to link to or point to a person.
    • This includes the visitor’s:
      • Name
      • Physical address
      • Demographic data (age, location, etc.)
      • Email address
      • IP address
  3. Delete, Correct, or Restrict When Requested:
    • If the user requests you to delete, correct, or restrict the personal data you have, you must comply promptly.
    • GDPR allows EU citizens and residents to have more control over how their personal data is used. If an EU subscriber or shopper asks you to erase or change it in any way, you must do so within a reasonable amount of time.
    • It’s best to act sooner rather than later to comply with this aspect of GDPR and avoid potential penalties.

How PTValley Helps You Stay GDPR-Compliant

PTValley ensures that all our customers using our platforms are fully covered for GDPR compliance. Our support includes:

  1. GDPR-ready Consent and Re-consent Mechanisms:
    • PTValley provides the necessary tools to obtain and manage user consent according to GDPR requirements.
  2. Right to Be Forgotten:
    • We offer complete removal of user data so that the customer or subscriber is not identifiable in any way. This option is available upon client request or if you request your account and data to be removed.
  3. GDPR-ready Privacy and Cookie Policies:
    • With severe fines and other serious consequences, it is essential that businesses understand the GDPR rules and how they apply to their operations.

Inappropriate Email Addresses

By using PTValley, you agree not to import or send to any email address which:

  • A. You do not have explicit, provable permission to contact in relation to the topic of the email you’re sending.
  • B. You bought, loaned, rented, or acquired from a third party, regardless of what they claim about quality or permission. You need to obtain permission yourself.
  • C. You haven’t contacted via email in the last 12 months.
  • D. You scraped or copy-pasted from the web.

Frequently Asked Questions (FAQ)

  1. What should I do if my contacts don’t have a consent record?
    • European customers must have explicit consent under GDPR law. You can send communication to these contacts at your own risk. For U.S. customers, consent requirements are less strict, but you must still provide an option to unsubscribe from your marketing campaigns.
  2. What is the lawful basis for data processing under GDPR?
    • Under GDPR, an organization must justify each type of data processing activity using one of the six lawful bases of processing. For email marketing, consent often makes sense as the lawful basis used to justify data processing. Organizations using consent as a lawful basis must be able to prove that consent was freely given and must be prepared to share a record of consent if regulators ask.
  3. Can a user withdraw their consent at any time?
    • Yes, data subjects must be able to withdraw consent at any time. If consent is withdrawn, all further processing of the user’s personal data for that specific purpose must cease immediately.

For more detailed information on GDPR and to review your rights, please visit our dedicated GDPR Policy page:

GDPR Compliance

California Consumer Privacy Act (CCPA) Compliance

The California Consumer Privacy Act (CCPA) is another comprehensive data privacy law that impacts how businesses handle personal information. If you are operating in California or engage with California residents, you need to be aware of its requirements. For more information, visit our CCPA Compliance Page.

If you have any additional questions or concerns about GDPR or CCPA, please feel free to contact us at privacy@ptvalley.tech.


This GDPR Compliance Policy was last updated on 25th July 2024. Make sure to check our GDPR and CCPA compliance pages for the most current updates and guidance.