Product-specific-gdpr-guidelines
Product-specific GDPR guidelines
Optimizely considers data privacy and protection when designing products and continuously assesses data security in its products. Optimizely uses encryption and pseudonymization wherever possible and designs products to simplify the design of active consent forms.
Optimizely Campaign
When using Optimizely Campaign, you should use the double opt-in method, where users are sent an email with an opt-in link. The user must click this link to be added to a recipient list, receive email newsletters, and so on.
Optimizely Commerce Connect
Contact Data – Ecommerce customer registers or is registered by the Customer Service Department. Order Data – Ecommerce customer completes a purchase or is registered by the Customer Service Department.
Optimizely Community API
If your application uses Optimizely Community API (formerly Social), you should ensure that consent is given before accepting user-generated content or allowing participation in digital communities. Clearly state the purpose and guidelines of your community features, and only collect PII data appropriate to that community's purpose.
Optimizely Content Management System
Optimizely Content Management System (CMS) Core logs system activities such as events and system errors. From CMS Core 11.
Optimizely Forms
Optimizely Forms collects the data subject's user name (of the currently authenticated user on the website) and the browser IP address to perform those features if you configure Optimizely Forms to \- not Allow anonymous submissions \- not Allow multiple submissions from the same IP/cookie You should inform the data subject about this, using the Form description or Form confirmation message, before the data subject submits the form. Any page that uses Optimizely Forms to request PII data input should use HTTPS protocol, TLS 1.
Optimizely Recommendations
For Optimizely Product Recommendations and Optimizely Email Product Recommendations, Optimizely Customized Commerce checks the do not track (DNT) header on the request to enable tracking when a data subject visits the website. If the DNT field is set to 1, the Customized Commerce system stops calling the Personalization tracking API.
Optimizely Search & Navigation
Indexing – By default, the data collected in Optimizely Search & Navigation is the same data stored in the Optimizely Content Management System (CMS) and Customized Commerce database. To learn how to filter PII data from being indexed by Optimizely Search & Navigation, see Filter PII data from being indexed .