Gain your client’s trust with consents. Let them choose their privacy preferences.
In this article will provide an overview of how you can seek consents from contacts and how the CRM can help your business in conforming to the contact preferences.
Note! GDPR feature is available in Starter, Professional, Enterprise Edition.
- For Starter and Professional edition users Vtiger Privacy Guard is available as an add-on from the Extension Store.
- For Vtiger One Professional, Vtiger One Enterprise Edition users the Vtiger Privacy Guard extension is readily available and needs to install from Extension Store.
- To get started with the Vtiger Privacy Guard, please write to support@vtiger.com
There are two reasons why consent is essential:
Avoid Penalties
With increasing concerns about invasion of personal privacy, Governments around the world have stepped in to enact laws to protect individuals rights. For instance:
European Union will start enforcing GDPR from May 25, 2018, with stiff penalties for businesses that violate the law.
United States enacted CAN-SPAM act in 2009 with stiff penalties for sending commercial messages that do not follow the stated guidelines. It has become imperative for businesses to heed these laws or risk huge fines.
Gain trust from your clients by being transparent on how your business uses their data.
If you are sure that none of your contacts or leads resides in Europe or is citizens of EU countries, then you might not need to use Consents.
Warning!
If you have a webform that is publicly available, then European residents might have submitted the webform and shared their personal details like an email address. That is sufficient for your business to be liable for GDPR violations.
As per GDPR, a business storing personal information should offer the following rights to the individuals.
Consents module in Vtiger CRM makes it easy for your business to grant these rights to individuals and seek consent for storing and using their personal data and tracking their engagement.
The data you need to seek consent for varies from one business to another. A business should only need to seek consent for data that is not required for the operational purpose.
EMail address, Phone number, Marital Status, Religion, etc., are all considered Personal information. But some of this personal information might be required for operational reasons. For example, if an individual has bought services from your business, then you will need to retain the individual name and address on invoices and orders for record keeping and auditing purposes.
Classify which of the personal information is essential for operational purpose, and which information is not essential and is only kept for marketing purposes.
Non-essential personal information needs consents. You will be selecting these in the Data section of the Consents page.
How do you use personal data?
To prevent multiple consent requests going to the same individual, it is necessary to skip duplicate contact records (& lead records) that have the same email address. This can be an arduous task if you have thousands of contacts. Fortunately, Vtiger makes it easy by automatically flagging the duplicate contacts as “Duplicate” (Contact Status value will be set to “Duplicate”) and retaining the last modified Contact as the primary one. An administrator will be prompted to approve this automated process while enabling the Consents feature.
Consent request emails will go from the Email address that you choose along with the selected FROM name. You should configure this in “Double opt-in and Consent Emails” section of the Settings > Email Settings page.
Existing “Contact Status” value will be overwritten with “Duplicate” for the duplicate contacts.
If consent is deleted for a field, the field is also removed from the Layout editor.
There are three types of consents
Note! Data Limits in GDPR compliance Add-on
- Personal fields - No limits
- Encryption fields - 5 fields per module
- Data consents - 10 fields per module
- Custom consents - 10 fields per module
To set up consents, please follow these steps:
In the Pre-requisites pop-up window, enable the checkbox to confirm to deduplicate the contact records
If you have setup your Email Settings, then you are allowed to proceed. If you haven’t configured the Email Settings to send out opt-in emails, please configure and start the process again from Step 1.
Finally, confirm the Consents Prerequisites and click Save.
You will have to enable the checkbox again to configure the Consents.
When adding any consent, you need to configure the following:
By default, any fields marked as sensitive will be added to the Consents page. You can add additional fields by clicking the “Add CRM field” button.
To add a custom consent, click on “Add New Custom Consent” button, and enter the text defining the purpose.
For example, “Your contact details (email address & phone number) will be shared with a local partner to follow up.”
Vtiger provides the ability to track document and email engagement. You can configure to whom these consents should be shown. If the customer, mark as “No”, then you cannot send any email or track the document.
Note!
Email Tracking will not work if
- Email client doesn’t fetch & display images (Some email clients hide images by default and only fetch if the recipient clicks to load images)
- Consent for tracking is revoked by the contact
GDPR requires that you give contacts the ability to opt out of processing entirely or erase their personal identifying data from the system.
Consent Notification settings govern how the contacts are informed.
When ad-hoc emails are sent from CRM, the link to the Preferences page is included in the footer. But, when you include a user as CC/BCC, the Preferences page link is not included.
For each Data, Custom and Tracking consent that applies to a contact, the Consents block within the Contact record will show the consent value.
Consent Value | Data field | What it indicates |
---|---|---|
Not Applicable | Editable | consent does not apply to the contact |
Applicable | Not Editable | consent applies, but has not been requested yet (consents process runs once a day at 10 AM) |
Waiting | Editable if default consent value = “yes”, non-editable if default consent value is “no”. (if there are any existing values, it will be erased) | A request has been sent (until the contact saves the preferences, the value will remain as waiting) |
Granted | Editable | Contact has granted this consent |
Not Granted | Not Editable (Existing value if any will be erased) | Contact has revoked this consent |
What if we delete consent for a field?
Can I send an invoice to contact that has requested to stop processing?
Can I send workflow email to contact that has requested to stop processing?
Can I send an invoice to contact that has requested data erasure?