Our goal is to use as few third-party providers as possible, and to keep the majority of the data in one single place. We chose Google Cloud as our core computing and storage facility, using Google Ireland for our EU-based clients, and Google USA for everyone else. All employee-specific data like name, email, gender and also their reviews, feedback and recognition data stays in the Google Cloud. The only true exception is email: We do send emails to staff when something new has happened, like a praise from a peer, or their manager signed their review, or a 1:1 is about to start. Those mails contain some confidential data (name, email, content snippets). Most of these mails can get deactivated by the client, and for EU clients we use an EU-based email provider.
Beyond this, we make use of a few additional sub-processors to help deliver our service. We ensured to pick only respectable companies that put a major focus on security, encrypting data in transit and at rest. We use these providers to communicate with customers, to charge for our services, to analyze usage patterns, or to deliver in-app notifications.
We don’t share confidential data of “regular employees” with these systems. But we do share names and email addresses of SI admin users or business contacts, and those who specifically reach out to us. Otherwise we’d not be able to create bills, respond to support inquiries, or communicate product news. We also share high-level usage data (“company X has 12 review cycles with 934 reviews in total”) with select subprocessors so we can offer client assistance proactively, and so we can analyze usage and trends to help improve our product offering.
Defaults and Options
New clients are by default hosted on the US Google servers, unless they Clients on the EU server automatically use SendInBlue rather than Sendgrid as an email provider.
By default our clients are hosted on the US Google server and make use of Sendgrid for email delivery. New clients may immediately sign up using our EU server at https://eu.small-improvements.com. Existing clients can be easily transferred to the EU Google datacenter by requesting a move via firstname.lastname@example.org, and will then automatically make use of SendInBlue, a French email sending system.
Most emails can be adjusted or deactivated by clients in case they don’t want to share some of this content via email at all.
Additional integrations like with Slack, Google Calendar or HRIS tools can be set up by clients on their own. We don’t list these optional processors below, since it’s up to every organization if they for instance whish to send confidential data to Slack.
|System||Data shared||Default Vendor||EU Alternative||Opt-Out possible?|
All sensitive data is hosted here, including
|Email Delivery||User names and email addresses|
Excerpts of confidential data like praise, 1:1 notes and more.
|No, but most mails can get deactivated by the client|
|Customer Relationship ||Company names and usage statistics|
Names and email addresses of admins and business contacts
25 First Street, 2nd Floor
|May 2021 (see below)|
|Customer Invoicing||Company name and billing information|
Business contact names
Staff headcounts and coarse usage statistics
340 S Lemon Ave #1537
|Yes: Manual invoice creation possible at surcharge. |
Please let us know upfront.
|Customer phone support||Customer phone numbers only|
|Landline phone services||Outbound: We only call US clients with Aircall|
Inbound: Use our landline office number to call us
|Support Desk||Company name|
Administrator names and emails
Potentially confidential information that is sent to us via mail
May 2021 (see below): EU clients can email us at email@example.com
|Cloud Spreadsheet services||Company names|
Anonymized usage statistics
Survey results from admin users
|In-app User guidance||Company names and statistics|
Admin names and email addresses
54 Canal Street # 324
Boston, MA 02114, USA
|May 2021 (see below)|
| Internal Statistics|
Company names and usage statistics
Our plan is that as of May 2021 clients will be able to deactivate information-sharing with our CRM Hubspot and with our User Guidance tool Appcues.
As of May 2021 we also plan to provide a dedicated EU-based helpdesk system.
The systems which clients can’t opt our from (and for which no EU-based alternative exists) only store highly anonymized data about clients.