Data Privacy Policy of Native Exports for Qualtrics PPT Exports Service

Last updated: October 21st 2024

1. Introduction

Native Exports ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy outlines how we collect, use, store, and protect your information when you use our Qualtrics PPT Exports service to download your Qualtrics survey as a PowerPoint (PPT) file. By using our service, you agree to the terms of this policy, which serves as the basis of our data processing activities.

2. Our Role as a Data Processor

Native Exports acts primarily as a data processor under GDPR for the Qualtrics PPT Exports service. We process personal data on behalf of our clients (the data controllers) solely for the purpose of providing our services. By using our service, you (the client) instruct us to process the personal data necessary to deliver the requested service.

3. Collection and Use of Information

We process your data in accordance with the General Data Protection Regulation (GDPR) and adhere to the principle of data minimization. We collect and process the following data:

1. Raw survey data provided via Qualtrics API access (processed automatically and not stored)
2. Personal data:
- Email address
- Company information
- Qualtrics API key
- PowerPoint design template preferences

We use this data solely for:
1. Providing our core service: converting your Qualtrics survey data into a PPT file
2. Communication between Native Exports and the end user
3. If selected, using the AI subtitle option (which involves sharing aggregated data with our sub-processor, OpenAI Inc.)

4. Legal Basis and Client Responsibilities

As a data processor, we rely on our clients (as data controllers) to have a valid legal basis for processing personal data. By using our Qualtrics PPT Exports service, you confirm that you have obtained necessary consents or have another valid legal basis for processing the personal data you submit to us.

You are responsible for:
1. Ensuring you have the right to share the data with us
2. Informing your end-users about the processing activities carried out by Native Exports
3. Handling data subject requests related to the personal data you control

5. Data Protection and Security Measures

We implement appropriate technical and organizational measures to protect your information, including:
- Processing all data on secure servers located in Germany
- Employing encryption for data in transit and at rest
- Regular security audits and staff training
- Strict access controls and authentication measures

6. Data Retention

We retain your data only for as long as necessary to provide the Qualtrics PPT Exports service you have requested, typically for the duration of your use of our services. Once you have finished using our services or once this retention period has expired, we delete your data in accordance with GDPR's principle of storage limitation.

7. Sub-processors

We may use sub-processors to assist in providing our services. Currently, our only sub-processor is OpenAI Inc., used for the AI subtitle option. We ensure that our sub-processors provide sufficient guarantees to implement appropriate technical and organizational measures in compliance with GDPR.

8. International Data Transfers

We do not transfer your personal data outside the European Economic Area (EEA) except when using the AI subtitle option. In this case, data is transferred to OpenAI Inc. in the United States under appropriate safeguards as required by GDPR.

9. Client's End-User Rights

As a data processor, we will assist you in fulfilling your obligations to respond to requests for exercising the data subject's rights under GDPR. However, primary responsibility for handling these requests lies with you as the data controller.

10. Data Breach Notification

In the event of a personal data breach, we will notify you without undue delay after becoming aware of the breach, providing all relevant information as required under GDPR.

11. Audits and Inspections

Upon request, we will make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of GDPR and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: support@native-exports.com
Address: Arne Lienemann - Schubertstraße 5 - 30161 Hannover, Germany

Data Protection Officer: support@native-exports.com

14. Governing Law and Jurisdiction

This policy is governed by and construed in accordance with the laws of Germany. Any disputes arising under or in connection with this policy shall be subject to the exclusive jurisdiction of the courts of Hannover, Germany.