Seen CRM
Vendor Management Policy
| Document number | SEEN-POL-06 |
|---|---|
| Version | 1.0 |
| Effective date | On approval |
| Policy owner | Seen CRM Management |
| Approved by | Seen CRM Management |
| Classification | Public |
| Next review | Within 12 months of the effective date |
1. Purpose
This policy ensures that third parties that process customer data on Seen CRM's behalf protect it to the standard Seen CRM requires.
2. Scope
This policy applies to every service provider that stores or processes customer data (sub-processors).
3. Policy
- Selection. Providers are selected on the strength of their security, privacy and reliability.
- Contractual protection. A provider may process customer data only under written data-processing terms.
- Data minimisation. Each provider receives only the data it needs to deliver its service.
- Approval. Management approves every new provider before it receives customer data.
- Review. Providers are reviewed at least once a year.
- Transparency. The list of sub-processors is available to customers on request.
4. Responsibilities
Management approves and reviews providers.
5. Exceptions
Any exception must be approved in writing by management, with a stated reason and an end date.
6. Review
This policy is reviewed at least once a year.
7. Contact
Questions about this policy: info@seencrm.com