Data Protection - e2open supply chain software

Our Commitment

We demonstrate our commitment to data privacy and protection by meeting the industry standards for ISO 27001 and SSAE-18 SOC 2 Type 2. We also have strong data processing agreements that meet the requirements of the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). e2open® complies with GDPR, CCPA and other applicable data processing regulations (eg. Canadian privacy law within the PIPEDA Act).

e2open has been reviewed and verified by TrustArc (formerly known as TRUSTe). e2open (and each of its affiliates) utilizes the Standard Contractual Clauses for the international transfer of data. e2open continues to voluntarily adhere to the EU/Swiss-US Privacy Shield Framework, which is a set of principles established by the American Department of Commerce, along with the European Union.

Privacy and security protections are built into our services and contracts to help in compliance with privacy legislation for our customers. Examples of these are:

Some of our applications have a different level of personal data collection, usage, storage and disposal. We have defined the purview of personal data for each of these applications and document the various sources of data to provide a roadmap for compliance. We analyze how customer information is being processed, stored, retained and deleted.

At this time, there are no third parties with whom we share our customers’ personal data except banks for the purpose of paying rebates.