The General Data Protection Regulation 2016/679 concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data (hereinafter "GDPR") was enacted on April 27, 2016, and came into force on May 25, 2018.
The GDPR applies to legal entities, such as European companies, as well as non-EU companies that process data of EU citizens.
It provides better and harmonized protection at the EU member state level for citizens' personal data, giving them greater control over their data. It strengthens and complements the Data Protection framework in France, which has been in place since 1978 under the Information and Freedom Law.
It requires legal entities processing data to adhere to certain key principles.
What are these principles? How can compliance with them be ensured? How is the Skeepers INFLUENCER MARKETING solution a GDPR-Compliant tool?
Security by design
Skeepers ensures adequate security of personal data processed on the INFLUENCER MARKETING platform, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, using appropriate technical or organizational measures (integrity and confidentiality). Request our data security documentation provided by Skeepers (PSSI, PAS, etc.): security@skeepers.io
Privacy by design
A determined, explicit, and legitimate processing purpose: INFLUENCER MARKETING is a SaaS Solution that connects Influencers and Consumers with Clients to create content featuring and/or mentioning the Client's products/services on social networks and/or on the Client’s websites, as per the campaigns selected by the Client. Individuals sign up on the Platform (contractual basis) and agree to the Data Protection Policy for Creators. Their prior consent is required to use their email and phone number before sending any emails and SMS regarding new campaigns and campaigns similar to those they have already participated in. For more information on the processing carried out: Data Processing Agreement (table on p21 and following).
- Data minimization by design: INFLUENCER MARKETING is a solution designed to collect, by design, only accurate, adequate, relevant, and limited data necessary for its Platform that connects Influencers and Consumers with Clients to create content featuring and/or mentioning the Client's products/services on social networks and/or Client websites, according to the campaigns selected by the Client. Some data is therefore mandatory to create an account, while other data is required to participate in an Influencer or Consumer campaign. Mandatory data is distinguished from optional data, including personal data that may be classified as “sensitive data” under GDPR, meaning data that “reveals racial or ethnic origin, […] data concerning health […]”.
The following data is optional:
- Skin color;
- Skin issues.
In full compliance, the INFLUENCER MARKETING Platform does not require these details from Influencers. Influencers can also modify the data they provide at any time from their account.
Finally, if the Client wishes to handle their own product deliveries, only the email address, postal address, and phone number of the individuals will be provided to the Client. If the Client opts out of handling delivery, they will not have access to Consumers’ personal data for “Gifted Reviews” consumer campaigns.
For more information on the data processed: Data Processing Agreement (table on p21 and following)
- Data relevance over time (storage limitation): collected data must be accurate, updated, and retained no longer than necessary for the purposes for which they are processed. Personal data of Influencers and Consumers can be updated by them at any time from their personal space. Data is kept for the duration of their activity on the Platform and will be anonymized six months after account closure. Accounts are deleted after 24 months of inactivity.
- Transparency for data subjects (lawfulness, fairness, transparency): as separate Data Controllers, Skeepers and the Client are subject to the transparency obligation under Articles 12 and following of the General Data Protection Regulation (GDPR).
For Clients:
The Client may inform data subjects about the data processing performed using the INFLUENCER MARKETING Solution when creating campaigns, in the campaign description known as the “Brief” (it is recommended to split the information into two parts by adding a link to your Privacy Policy to avoid information overload).
For Skeepers:
Skeepers, as a separate Data Controller, fulfills its transparency obligation by keeping a Privacy Policy for Influencers and Testers (collectively referred to as Creators) on its website.
Accountability: The GDPR requires maintaining a registry to document the personal data processing you implement (“Record of Processing Activities”). Maintaining a Record allows you to track your data use and assess its relevance to the intended purposes (more information available on the CNIL website). Skeepers can provide a template for the Record of Processing Activities for its Solution by contacting privacy@skeepers.io
Cookies
For Clients who subscribe to the "Shoppable Content" add-on, you must inform users of performance cookie placement and collect prior consent, if necessary, via their Consent Management Platform (CMP), in compliance with applicable data protection regulations.
Name: Skeepers Performance Tracker
Host: client website
Type of cookie: Performance cookie
Legal basis: Consent collected by the Client’s Consent Management Platform (CMP)
Purpose: to generate performance metrics to demonstrate the impact of video presence on customers’ purchase behavior on e-commerce sites.
Processed data: Full IP, Customer ID, pages viewed, average view time, clicks, impressions, number of viewers, audience type, event duration, UserAgent: browser, OS, brand of the connection device, and operating system, cart product IDs, cart amount, transaction content, video display, play, pause (etc.)
Cookie name |
Expiration | Use |
sk_[siteId] | 13 months | Allows to associated actions to a single user through their visits to the site |
sk_first | local storage | Allows to check if it is the first time the user visits the site |
sk_vid | session storage | Visit id associated to the visit |
sk_expiration | session storage | Used to establish the expiration time of the visit id |