FAQ: FotoWare Data Security
Where does FotoWare store data?
FotoWare SaaS is currently available in the following Microsoft Azure Regions:
- US East
- EU West
- Australia East
Data will not be moved outside these regions.
Note: Under the General Data Protection Regulation, the EU/EEA is defined as a single zone, which means that a data center within the EU is sufficient to meet the GDPR requirements. However, German law dictates that certain businesses must host their data in a German data center, in which case data can be stored in a German Azure data center.
How does FotoWare safeguard customer data in its operational systems?
FotoWare stores all data from its operational systems on FotoWare's own servers in the Azure cloud, or on Azure PaaS Services.
More information on Azure security can be found in Microsoft's documentation: https://www.microsoft.com/en-us/trustcenter/security/azure-security
We also use several subprocessors to provide supportive services for our SaaS offering, among other things for email services and for the services used to operate our customer support center. Your rights of access, to erasure and to portability under GDPR are maintained through your contract with FotoWare.
We are also in the process of implementing a complete security review routine, which will be reviewed and updated regularly to keep us on top of security matters.
How does FotoWare secure customer and user data in the SaaS offering?
FotoWare SaaS runs on the Microsoft Azure cloud platform. FotoWare SaaS customers who upload data to the tenant can rest assured that the data is encrypted in transit and at rest.
If a customer wishes to assign a custom domain name to the tenant, we will assist in installing a trusted certificate on the server infrastructure for secure, encrypted client-server connections. In addition, data is encrypted on the Azure Cloud when it is committed to storage. When the data is requested, it is decrypted on demand.
Additional information on encryption for data at rest can be found in the Microsoft Azure documentation.
Is data replicated?
Yes, all data that is stored on the Azure cloud is made redundant. The data that you upload to your FotoWare SaaS site is thus replicated in multiple copies to prevent data loss in the event of hardware failure.
Can anyone at FotoWare see my data?
FotoWare support personnel has access to the server infrastructure, and as such can access your data from a technical standpoint. However, FotoWare has strict routines and enforces auditing and logging of access to prevent unauthorized access. In cases where the customer has approved such access, for example in connection with a troubleshooting scenario, explicit consent will be obtained. FotoWare enforces strict access control to both its internal systems and its customers' cloud tenants. We maintain administrative, physical, and technical safeguards to protect the security, confidentiality, and integrity of our customers' data. These include, but are not limited to, measures for preventing access, use, modification, or disclosure of customer data except for the purpose of providing FotoWare's services and preventing or address technical problems.
The Data Discipline Declaration signed by all employees states that data must only be used for the purpose for which they were collected, and only for purposes and by users to which the customer/partner has given consent. FotoWare will ensure that access to systems that expose customer data is limited, logged, and audited so we can tell who accessed the server, at what time, and for what purpose. In the event of infrastructure maintenance, FotoWare will advance inform all affected Customers about the allotted service window by email.
The main takeaway is that we will always ask for consent before accessing your personal data.
What happens to my data if I cancel my FotoWare SaaS subscription?
We would be sorry to see you go, naturally. But we'll do our best to make your data migration as smooth as possible. We will help you move your data to a server of choice. Typically, this involves setting up an FTP connection or other means of transfer. After transferring your data, we will delete the tenant and erase all the data you had on our servers.
Will FotoWare help me delete data when a user wants to be erased?
Yes, and we have an obligation to do so under GDPR. That said, customers can easily retrieve data in the SaaS tenant themselves by searching for, retrieving, and deleting content. Typically, one would make sure data fed into the system has sufficient metadata governance to facilitate easy retrieval of the data. This is the very nature of a Digital Asset Management system such as FotoWare. By default, data can only be deleted by archive managers (members of the FotoWeb DAM Managers group). FotoWare can also assist in the retrieval of data by offering guidance on search methods, given that the metadata stored with the assets is sufficient to retrieve them. FotoWare support engineers, who will typically be involved in such an undertaking, will not access your data, or modify or delete it without your explicit prior consent.
Typically, though, FotoWare will assist the customer in implementing a metadata governance scheme at the time of deployment of the service, so that customers can themselves perform data retrieval and deletion without requiring the assistance of FotoWare.
What does FotoWare do to prevent a potential data breach?
A data breach is not something software vendors are hoping for, yet we understand the necessity of having clear guidelines on what to do should such a situation arise. Our customers' privacy is paramount to our business. To that end, we are designing all our solutions with privacy in mind - you may have heard of the concept of Privacy by design - so that the impact of a potential data breach can be kept to an absolute minimum. When we design new features, the protection of data privacy is always a central part of the planning and development process.
We are continually working to hone our routines to better cope with the prospect of a data breach.
While we currently have data security assessment routines in place, we are bringing these in line with GDPR by implementing a fully GDPR-compliant security review to help us stay conscious and alert to areas where we need to improve.