← All security

GDPR And Customer Data In A No Storage Tool

GDPR asks a business to explain, in plain language, what it does with personal data. For a tool like Ziikly the answer is short: it does not store customer data, and the personal data it handles during a lookup exists only for the moments it takes to search and display a profile. The customer data stays in your tools, and you remain the controller of it. Ziikly acts as a processor, holding only your connection configuration and encrypted keys. This page covers controller and processor roles, how deletion requests work, and the records of processing that small firms should keep.

Gdpr customer data saas shown in the Ziikly customer profile

Processor And Controller Roles Explained

Under GDPR, the controller decides why and how personal data is processed, and the processor handles data on the controller's behalf. When you use Ziikly, you remain the controller of your customer data because that data never leaves the tools you own and control. The purpose of each lookup is yours: answering a support ticket, checking a payment or preparing an invoice.

Ziikly is the processor. It processes personal data only to deliver the lookup you asked for, and it does not use that data for its own purposes, does not sell it and does not keep a copy of it. The arrangement is the same processor relationship you have with your other software vendors, with the difference that the data passes through rather than being stored.

How Deletion Requests Are Handled

A customer asks you to delete their data. In a storage tool, that request means finding the record, deleting it and often telling you where copies live in backups. In Ziikly there is no stored customer record, so the request is answered by the tools that hold the data, and Ziikly does not add a second copy you need to hunt down.

What you delete inside Ziikly is configuration, not customer data. Remove the connection and the encrypted key, and no lookup for that customer is possible from your workspace anymore. The actual deletion of the customer's data happens in the source tools, exactly where that data is stored and subject to their deletion processes.

Records Of Processing For Small Firms

Article 30 of GDPR asks controllers to keep records of processing, but it exempts businesses with fewer than 250 employees, unless the processing is regular, large-scale or involves special categories of data. Many small firms therefore keep a simple record: what personal data they hold, where it lives and who they share it with.

For a Ziikly user, that record is easy to keep accurate. List your source tools as the places customer data is held, and note that Ziikly processes it only on demand for lookup purposes and stores none of it. A short inventory like this satisfies the spirit of Article 30 without a compliance project.

Data processing roles in the Ziikly integrations panel

Frequently asked questions

Do I Need A Data Processing Agreement?

If you are a controller and Ziikly processes personal data on your behalf, a data processing agreement with Ziikly is the correct safeguard, just as with any processor. Because Ziikly stores no customer data, the agreement covers configuration, encrypted keys and the live lookups that pass through during a search.

Who Is The Controller Of Customer Data In Ziikly?

You are. The customer data you search stays in the tools you connect, and you decide why and how it is processed. Ziikly is the processor: it handles the data only for the lookup you request and stores no copy of it.

See it on your own customers

Connect your tools with read-only keys and search a real customer in minutes. Ziikly is free for everyone right now.

Get started free

Keep reading