Trust and security at Improvado
Everything on this page is backed by a document Improvado publishes, and each section links to it. If your review needs something that is not here, write to security@improvado.io.
SOC 2 Type II
An attestation is an independent auditor's report on whether a company's security controls really operated the way the company describes them, checked over a stretch of time rather than on one day.
Improvado holds a SOC 2 Type II report, examined by BARR Advisory. The examination reviewed Improvado's controls for security, availability, and confidentiality, based on the Trust Services Criteria, and the latest audit was completed with no findings.
The report is made available to current and prospective customers upon request, subject to the appropriate non-disclosure agreements. The report itself is requested through the Improvado Trust Center, which hosts the live security posture and the compliance documents under NDA; for anything else, write to security@improvado.io, the address published on the Legal Center.
HIPAA and Business Associate Agreements
A Business Associate Agreement (BAA) is the contract a healthcare organization signs with a vendor that will handle protected health information (PHI). It sets out what the vendor may do with that data and what it owes when something goes wrong.
Improvado offers Business Associate Agreements to customers who require them, and takes on the responsibilities of a Business Associate under that contract: safeguards for the confidentiality, integrity, and availability of PHI, and timely reporting of breaches or security incidents. The rule is simple: no BAA, no PHI.
What that looks like in practice for a healthcare marketing team is on the healthcare solution page. The full commitment is written up under "HIPAA: BAA-backed" on the Legal Center.
Data processing
When you use Improvado, you decide what personal data goes in and why; Improvado processes it on your instructions. The Data Processing Agreement (DPA) is the contract that says so, and it includes the Standard Contractual Clauses adopted by the European Commission where they apply.
Read the Improvado Data Processing Agreement.
Sub-processors
A sub-processor is another company Improvado uses to deliver the service and that may touch your data, such as the cloud that hosts it.
The current list is Exhibit 2 of the DPA, so there is one list and it is contractual: List of Authorized Sub-Processors. Before adding one, Improvado notifies you in writing at least thirty (30) days in advance, and you have twenty (20) days after that notice to object on reasonable grounds.
Privacy
The Privacy Policy covers the data Improvado holds about you, rather than the data you bring to the platform: what is collected when you visit the site, subscribe, or use the product, how it is stored and shared, and how to get at it.
Read the Improvado Privacy Policy, and the Cookie Policy for what runs in your browser.
GDPR and CCPA
Improvado is committed to complying with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), and gives customers transparency and control over their personal data, including the ability to access, rectify, and delete it.
A Data Protection Officer is appointed for these regulations and answers questions about them at dpo@improvado.io. The commitment in full is on the Legal Center.