At Branch, our goal is to help our partners meet both the letter and the spirit of GDPR in a simple and straightforward way. We believe GDPR is not just a regulation; respecting the privacy rights of all partners and their users (regardless of origin) is the right thing to do.
Branch has updated its platform to meet GDPR standards worldwide, and we will continue to invest in industry-leading data privacy initiatives.
If you are a European data subject and wish to exercise your GDPR rights, the process to follow depends on the nature of your relationship with Branch.
If you have a direct relationship with Branch, you will be able to submit requests using our self-service portal beginning on May 25, 2018. Examples of direct relationships include:
You may also use this portal to make requests on behalf of your end users, as discussed further below.
If your relationship with Branch is via companies that use our services, your request must be submitted directly to them. This is because Branch acts as a service provider on behalf of those companies, and they are responsible for authenticating your request and ensuring it is communicated to all service providers.
Branch is committed to working with our partners to honor data subject requests to the full extent required by GDPR.
Under GDPR, your users have the right to object to data processing. Branch makes it simple for you to stop tracking users after they object, though it is important for these users to understand that they may experience degraded functionality. We recommend working with your legal team to keep users informed as you implement the processes required by GDPR.
If you have determined that a user does not want to be tracked by third-party data processors, and that this preference extends disabling elements of your core functionality, the Branch SDKs allow you to honor this right. You can flag in the Branch SDK that a particular user has requested that his or her data not be processed by Branch, in which case Branch will no longer process engagement data on your behalf for that user.
After you use the SDK to inform us that a user has requested not to be tracked by Branch, it will still be possible for that user to generate and share Branch links. Basic deep linking will also continue to work. However, since all further activities must occur without passing any identifiable user information on to Branch, these users will no longer benefit from the seamless customer journeys Branch helps you build with cross-platform data.
To learn more about configuring your SDK implementation, visit our documentation portal.
When your end-users exercise their rights under GDPR, Branch is committed to working with you to fulfill these requests, provided the request comes directly from you.
To submit a GDPR end-user request to our team after May 25, 2018, reach out to us through our GDPR portal and we will work with you to fulfill your end-user’s request. Please include in that request the end-user’s advertising identifier (e.g., IDFA/GAID), and the date you received the end-user’s request.
We maintain a list of vendors that process personal data on Branch's behalf, and the purpose for which we share data with each of these vendors.
Branch provides a Data Processing Addendum (DPA). If applicable to your GDPR compliance process, please return a countersigned copy to firstname.lastname@example.org.