Which Personal Identifiable Information (PII) is stored in the Piano systems?
This depends on the client's Piano ID configuration. A basic set of collected data is described here. If there are specific fields in custom fields that are collected, then these are stored as well.
How is this information / database encrypted?
All data is encrypted at rest. Moreover, all data is encrypted in transit.
How long does Piano retain PII after the client submits a deletion request?
Data is anonymised within 30 days of receiving the request for deletion. Moreover, there is an API method prepared for deletion requests, which our clients can use: https://docs.piano.io/api/?endpoint=post~2F~2Fpublisher~2Fgdpr~2Fdelete
What encryption methods are used to pass the data?
SSL and TLS 1.2 and higher.
What is your request intake process (e.g., web intake form or email)?
Email.
How do you perform access requests?
We provide the data controller with a password-encrypted CSV of the data.
What PI will be pulled from your systems (e.g., account profiles, activity logs, etc.)?
Account profiles, transaction data.
For updated security information, or if you have further questions, contact security@piano.io.