GDPR & Compliance
How Bento handles GDPR compliance, data requests, the DPA, security practices, and breach reporting.
Resources
Jump to the documents and actions people ask for most.
- Contact Support
Request Data
Email support to access, update, delete, or restrict personal information.
- View DPA
Data Processing Agreement
Review the DPA, or sign it in Settings after you log in.
- Open Trust Center
Trust Center
SOC 2 reports, security controls, and compliance documentation.
- Read Policy
Subprocessors
Third parties that process customer data on our behalf.
- Read Overview
Security
Infrastructure, encryption, authentication, and security policies.
- View Status
Data Breaches
Breach history and how we notify customers.
Compliance Checklist
Where we stand on lawful basis, security, accountability, and privacy rights.
Lawful Basis and Transparency
Data Security
- Take data protection into account at all times, from the moment you begin developing a product to each time you process data.Completed
- Have a process in place to notify the authorities and your data subjects in the event of a data breach.Completed
- Encrypt, pseudonymize, or anonymize personal data wherever possible.Completed
- Create an internal security policy for your team members, and build awareness about data protection.In Progress
- Know when to conduct a data protection impact assessment, and have a process in place to carry it out.In Progress
Accountability and Governance
- Designate someone responsible for ensuring GDPR compliance across your organization.Completed
- Sign a data processing agreement between your organization and any third parties that process personal data on your behalf.Completed
- If your organization is outside the EU, appoint a representative within one of the EU member states.In Progress
- Appoint a Data Protection Officer (if necessary)Not Applicable
Privacy Rights
- It's easy for your customers to request and receive all the information you have about them.Completed
- It's easy for your customers to correct or update inaccurate or incomplete information.Completed
- It's easy for your customers to request to have their personal data deleted.Completed
- It's easy for your customers to ask you to stop processing their data.Completed
- It's easy for your customers to receive a copy of their personal data in a format that can be easily transferred to another company.Completed
- It's easy for your customers to object to you processing their data.Completed
- If you make decisions about people based on automated processes, you have a procedure to protect their rights.Completed
Contact
Questions about GDPR, data requests, or the DPA can go to our data protection contact.
Frequently Asked Questions
Common questions about GDPR, data handling, security, and your rights when using Bento.