Spektra Systems is committed to protecting the privacy of its users and ensuring no unnecessary data is collected other than the required information for providing the services. Spektra Systems does not collect any sensitive data from its users.
To ensure the utmost assurance of privacy for our valued clients and users, we have meticulously crafted a comprehensive Company Privacy Policy. Developed under the careful guidance of our management, this policy takes into consideration the interests of all stakeholders and interested parties. It offers a transparent overview of our Data Collection, Handling, Retention, Cookie Policy, and Data Subject Rights processes.
Our privacy policy is dynamic and reviewed periodically to adapt to the changing needs of the tech environment, without compromising the core principles of Data Privacy.
Each year, all our products undergo rigorous third-party Vulnerability Assessment and Penetration Testing (VAPT) to bolster their security measures. Root-level identification and elimination of potential threats are prioritized, while we also actively encourage and value suggestions from external parties to further fortify our systems.
Our products are further assured through recognized compliances, audited by independent third-party assessors. Reports are available upon request for interested parties.
According to the General Data Protection Regulation (GDPR), contractual clauses ensuring appropriate data protection safeguards can be used as a ground for data transfers from the EU to third countries. This includes model contract clauses – so-called standard contractual clauses (SCCs) – that have been “pre-approved” by the European Commission. Spektra is a cloud service provider, and all our data is hosted in Cloud Services across different regions of the world. SCCs are in place with our European partners (Data Controllers) to ensure transparency in our Data processing activity. In most scenarios, Module 2 (Controller to Processor) of the SCCs is engaged, as Spektra plays the role of the processor.
Spektra’s adherence to GDPR standards offers reassurance to our partners and users that their data, entrusted to us, is meticulously protected and secured. Upholding data privacy empowers both our partners and individuals, granting them control over their personal information. This control allows them to dictate how their data is gathered, utilized, and shared. By honoring individual autonomy, we ensure that personal information remains safeguarded against exploitation or misuse.
Spektra Systems and Products are annually audited and attested by Deloitte Shared Services for SOC 2 Type 2 and GDPR Compliance. Additionally, on a monthly basis, the SOC 2 Controls are tested internally to ensure continuous compliance.
Through SOC 2 Type 2 Compliance, we assure the following to our Partners:
Spektra has adopted the CCPA regulation for all its products to meet the business needs of our Californian clients. Our CCPA Privacy Notice is built on the “Shine The Light” Law and provides detailed information on the various rights that Californian consumers can exercise with us. Annually, we are audited and attested by Deloitte Shared Services to ensure compliance with the CCPA.
The CCPA offers the advantage of enhanced customer loyalty. By proactively anticipating their needs and devising a well-planned communication strategy, we effectively engage with customers, keeping their brand top of mind. Well-timed and informative communications are essential to building and nurturing ongoing customer relationships and fostering loyalty and trust.
In addition to the above compliances, our product CloudLabs, has been audited and attested to the following:
CloudLabs is a trusted service provider offering various services to Microsoft. Our relationship with Microsoft is built on trust, and this trust is ensured through our annual compliance with the SSPA Program. A self-attestation is performed annually in alignment with Microsoft’s data protection requirements, following which CloudLabs is audited by Microsoft-nominated assessor A-Lign.
Customers in the US sign up for CloudLabs and CloudEvents (Hackathons). The CloudLabs platform facilitates hands-on labs, test drives, and Proof of Concepts (POCs) across various scenarios on a large scale. Tailored for organizations and educational institutes of all sizes, CloudLabs delivers an impactful learning experience with minimal to zero management overhead. CloudLabs’ compliance with FERPA and practices can be referred to the FERPA Privacy Notice. CloudLabs has been tested and certified to iKeepSafe’s FERPA Certification Certified Products – iKeepSafe.
FERPA compliance instills confidence among educators and parents who utilize our platform, assuring them that student data is securely handled. We offer straightforward insights into our product data practices via the product profile, ensuring transparency and peace of mind for our users.
product data practices through the product profile.
The certification has assessed CloudLabs for compliance with the federal and California laws governing student data privacy, including:
Spektra upholds its commitment to protecting the data of children under the age of 13, as outlined in our COPPA Privacy Notice. This notice provides detailed insights into our data collection practices for children, our relationships with third parties, and the procedures for obtaining Verifiable Parental Consent (VPC). Please note that children under 13 years old cannot access services from CloudLabs and CloudEvents (Hackathons) without official consent from their parents or guardians. We’re proud to announce our achievement of the iKeepsafe COPPA Safe Harbor Certification, underscoring our dedication to compliance and data security.
iThe iKeepsafe COPPA Safe Harbor Certification gives parents and teachers confidence that CloudLabs adheres to COPPA regulations, guaranteeing the safety and privacy of their children’s data. As a result, CloudLabs has become their go-to solution for all their educational needs.
In addition to the above, the Spektra Systems Data Privacy ecosystem is governed by policies and procedures ranging from Information Security, Business Continuity, and Disaster Recovery. The following provides an insight into the various technological and organizational measures taken to ensure Data Privacy and Information Security across our products and services.
Privacy@spektrasystems.com is the door to shine a light on our Data privacy and Compliance practices.
Request Demo