Knowledge Base Article

Personal Data Inventory for Khoros Subscription Services

This document captures a complete inventory of personal data points used throughout Khoros products. Khoros relies on performance of a contract and/or legitimate interests in order to process the personal data contained in this document.

Please scroll down to the charts below or simply click on one of the following product links to be redirected to the corresponding chart:

 

 

MARKETING

Data Element Source

Subprocessor Recipients (If blank, none)

Country Locations of subprocessors can be found here

Retention/Deletion

Campaigns/Initiatives

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Roles

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Approvals

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Labels

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Credentials

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Notifier

  • Recipient Email
User-created   Aurora - indefinitely until 30 days post-contract

User Profile

  • ID
  • first name
  • last name
  • email
  • avatar image
  • mobile phone
User-created   Aurora - indefinitely until 30 days post-contract

Directory Service Customer/Company

  • User ID
Company Administrator-created   Aurora - indefinitely until 30 days post-contract

FINEX (Financial Industry Export)

  • outgoing content (publishing posts and care replies)
  • snapshots of company user profile details in the system
  • user approvals
Generated nightly by the marketing system.   AWS filesystem - 1 day (deleted and regenerated nightly)

Suite navigation data

  • User ID
Captured by Pendo as users navigate the product suite.   Indefinitely at Pendo until 30 days post-contract)

Promotion Accounts

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Promotions

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Care analytics data

  • User ID
Generated by the Marketing system as user actions occur.  

Aurora - indefinitely until 30 days post-contract

Redshift - 30 days

Care Rules

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

whodex profiles

  • Social Handles
  • Name
  • Profile Image
  • Location Coordinates
  • Country Code
  • Follower Count
  • Following Count
Sourced from supported social networks via API   Aurora - indefinitely until 30 days post-contract

whodex profile author notes

  • user id
  • author notes
User-created   Aurora - indefinitely until 30 days post-contract

export logs

  • User ID
Generated by the Marketing system as user actions occur.   Kibana - 30 days

analytics dashboards

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

plans

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

messages

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Content Center assets

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

auto-labeling rules

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

comments

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

replies

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

retweets

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

streams

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

Stream Entities

  • Author
  • Bio
  • Full Name
  • profile Picture:
  • username
  • social network user id
  • Post Contents
Sourced from supported social networks via API.  

Aurora - indefinitely until 30 days post-contract

Cassandra - 7 days

Memcached - 1 day

User

  • user id
  • twitter handle
  • full name
Company Administrator-created   Aurora - indefinitely until 30 days post-contract

visualizations

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

spaces

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

spotlight reports

  • User ID
User-created   Aurora - indefinitely until 30 days post-contract

post search results

  • Author
  • Bio
  • Full Name
  • profile Picture:
  • username
  • social network user id
  • Post Contents
Sourced from supported social networks via API   Cassandra - indefinitely until 30 days post-contract

Stream Items

  • Author
  • Bio
  • Full Name
  • profilePicture:
  • username
  • social network user id
  • Post Contents
Sourced from supported social networks via API   Cassandra - indefinitely until 30days post-contract

Influencers

  • whodex profile id
User-created   Aurora - indefinitely until 30 days post-contract

TeamQueue data

Generated by the Marketing system as user actions occur.   Cassandra- 30 days post contract

 

CARE

Data Element Source

Third-Party Recipients

Country Locations can be found here

Retention/Deletion
Id
Name
Screenname
Profile picture
Bio
Location
TWITTER: Consumer data is retrieved through Twitter APIs after the company authenticates their Twitter Handle(s) with Care. All consumer data is subject to Twitter's Terms of Service.  Yes Deleted within 30 days of end of customer contract.
Tweets deleted in Twitter will also be deleted in Care based on Twitter notification.
Id
Name
Picture
First name
Last name
FACEBOOK: Consumer data is retrieved through Facebook APIs after the company authenticates their Facebook Page(s) with Response. All consumer data is subject to Facebook's Terms of Service.  Yes Deleted within 30 days of end of customer contract.
User comments deleted in Facebook will also be deleted in Care based on Facebook notification.
Id
Username
INSTAGRAM: Consumer data is retrieved through Instagram APIs after the company authenticates their Instagram Handle(s) with Response. All consumer data is subject to Instagram's Terms of Use. Yes Deleted within 30 days of end of customer of contract.
Id GOOGLE BUSINESS MANAGER: Consumer data is received through streaming updates after company authenticates Business messages with Care. All consumer data is subject to Google's Business Messages Terms of Service. Yes Deleted within 30 days of end of customer contract.
Name
Username

GOOGLE MY BUSINESS: Consumer data is received through Google MyBusiness APIs after company authenticates with Care. All consumer data is subject to Google's Terms of Service.

Yes Deleted within 30 days of end of customer contract.
Name RSS: Consumer data is received through RSS APIs after company authenticates with Care. Yes Deleted within 30 days of end of customer contract.
Id
Display name
Profile image url
YOUTUBE: Consumer data is retrieved through YouTube APIs after the company authenticates their YouTube Channel(s) with Response. All consumer data is subject to YouTube's Terms of Service. Yes Deleted within 30 days of end of customer contract.

Id

APPLE BUSINESS CHAT:Consumer data is received through streaming updates after company authenticates Apple Business Chat with Care. All consumer data is subject to Apple's Terms of Service.

Yes Deleted within 30 days of end of customer contract.

Id
First name
Last name

WEB MESSANGER (SMOOCH): Within a secure chat, provided by Sunshine Conversations, consumers will share unstructured PII (i.e. the information will be shared within a chat conversation). This data will be ingested into Care. Yes Deleted within 30 days of end of customer contract.
Id
Name
WECHAT: Consumer data is retrieved through WeChat's APIs after the company authenticates their WeChat Account(s) with Response. All consumer data is subject to WeChat's Terms of Service. Yes

Deleted within 30 days of end of customer contract.

Phone number SMS: Consumer data is retrieved through Twilio APIs after the company authenticates their SMS numbers with Care. All consumer data is subject to Twilio's Terms of Service. Yes

Deleted within 30 days of end of customer contract.

Phone number
First name
Last name

WHATSAPP: Consumer data is retrieved through Smooch APIs after the company authenticates their WhatsApp numbers with Care. All consumer data is subject to WhatsApp's Terms of Service. Yes

Deleted within 30 days of end of customer contract.

Name
Device information

GOOGLE PLAY STORE REVIEWS Yes

Deleted within 30 days of end of customer contract.

Id
Name
Profile image url

NETBASE Yes

Deleted within 30 days of end of customer contract.

Name

IOS APP STORE REVIEWS Yes

Deleted within 30 days of end of customer contract.

Id
First name
Last name
Bio
Profile image

LINKEDIN: Consumer data is retrieved through LinkedIn APIs after the company authenticates their LinkedIn Page(s) with Response. All consumer data is subject to LinkedIn's Terms of Service. Yes

Deleted within 30 days of end of customer contract.

 

RADIAN 6: This is a general listening integration that can bring in content from all of the other networks listed. We should no longer be using this provider. Yes

Deleted within 30 days of end of customer contract.

Id
Name
Profile image url

YELP: Consumer data is retrieved through LinkedIn APIs after the company authenticates their Yelp Location(s) with Response. All consumer data is subject to Yelps Terms of Service. Yes

Deleted within 30 days of end of customer contract.

Id
Display name
Email
Profile image url

KHOROS COMMUNITY Yes

Deleted within 30 days of end of customer contract.

 

KHOROS BOT

Data Element Source

Third-Party Recipients

Country Locations can be found here

Retention/Deletion
  • Name
  • Timezone
  • Language
  • Profile picture
  • Chat related data that can include personal data (Specified by customer in custom DPA)
Facebook messenger
  • MongoDB
  • Google cloud
  • On project removal
  • On applied data retention policy
  • Phone number
  • Name
  • Chat related data that can include personal data (Specified by customer in custom DPA)
WhatsApp
  • MongoDB
  • Google cloud
  • On project removal
  • On applied data retention policy
  • IP address
  • Browser version
  • Browser language
  • Chat related data that can include personal data (Specified by customer in custom DPA)
Web Widget
  • MongoDB
  • Google cloud
  • On project removal
  • On applied data retention policy
  • Any shared files are removed after 90 days
  • Name
  • Chat related data that can include personal data (Specified by customer in custom DPA)
Khoros
  • MongoDB
  • Google cloud
  • On project removal
  • On applied data retention policy
  • Phone number
  • Chat related data that can include personal data (Specified by customer in custom DPA)
Twilio
  • MongoDB
  • Google cloud
  • On project removal
  • On applied data retention policy
  • Phone number in case of WhatsApp or SMS
Analytics metadata
  • Google cloud
  • On project removal

 

COMMUNITY

Data Element Source

Third-Party Recipients

Country Locations can be found here

Retention/Deletion
  • Author
  • login (username)
  • email address (except privacy guide)
  • salted password hash (except SSO)

SSO - from SSO identity provider (usually customer's propitiatory identity system via SSO cookie).

Local with migration - from PS team or Administrator importing the info

Local without migration - from users through initial registration

Yes

Mysql, Elasticsearch, Cassendra - indefinitely.

Redis - 24 hours

  • Author
  • userId
Created during the first initial interaction to the system, may it be SSO or import or registration Yes

Mysql, Elasticsearch, Cassendra - indefinitely.

Redis - 24 hours

  • Author
  • ICQ (optional)
  • AIM (optional)
  • Skype (optional)
  • MSN (optional)
  • Yahoo (optional)
  • Bio (optional)
  • Custom personal data fields (customizable per community)

Except required custom fields, all are optional not related to any feature supported

Entered by user either through initial registration or sub-sequential interaction with the community.

For custom personal data fields, it could also possible be from SSO cookie.

Yes

Mysql, Elasticsearch, Cassendra - indefinitely.

Redis - 24 hours

  • Author
  • Twitter access token

Supported Feature: Twitter Integration

Entered by user either through initial registration or sub-sequential interaction with the community Yes Mysql - indefinitely.
  • Author
  • Facebook access token

Supported Feature: Facebook connect and integration

Entered by user either through initial registration or sub-sequential interaction with the community Yes Mysel - indefinitely.
  • Supported Feature: Profile picture
  • Author
  • profilePicture
Entered by user either through initial registration or sub-sequential interaction with the community Yes

Mysql - indefinitely.

Redis - 24 hours

  • Author
  • IP address
  • browser cookie string
  • user agent
  • http referrer headers
From the http requests to the community Yes

Mysql - indefinitely.

Redis - 24 hours

Community User Metrics

  • Total Messages Posted
  • Total Page Views
  • Total Messages Read
  • Board Topics Started
  • Board Replies Blog
  • Articles Posted Blog
  • Comments Posted
  • Ideas Posted Idea
  • Comments Posted
  • Questions Posted
  • Q&A Replies Posted
  • Answers Posted Q&A
  • Comments Posted
  • Total Board Views
  • Total Logins Total
  • Minutes Online
Created by the community Yes

Mysql, Elasticsearch indefinitely.

Redis - 24 hours

 

CX INSIGHTS

Data Element

Source

Third-Party Recipients

Country Locations can be found here

Retention/Deletion

Audio Recordings:

  • Name
  • Phone number
  • Email address
  • Physical address
  • Dates directly related to an individual (birth, death, admission, etc.)
  • Gender
  • Username
  • Security code/PIN
  • Security questions
  • Account number
  • IMEI number
Audio files provided by Khoros clients
  • Amazon Web Services
Earlier of 24 months after the audio recording was created or Agreement termination date

Audio Recordings:

  • Name
  • Phone number
  • Email address
  • Physical address
  • Dates directly related to an individual (birth, death, admission, etc.)
  • Gender
  • Username
  • Security code/PIN
  • Security questions
  • Account number
  • IMEI number
Audio files provided by Khoros clients
  • Amazon Web Servies
  • MongoDB
  • Google Cloud Platform
Earlier of 24 months after the audio recording was created or Agreement termination date

Conversation transcripts:

  • Name
  • Phone number
  • Email address
  • Physical address
  • Dates directly related to an individual (birth, death, admission, etc.)
  • Gender
  • Username
  • Security code/PIN
  • Security questions
  • Account number
  • IMEI number
Text-based conversation transcripts provided by Khoros clients
  • Google Cloud Platform
Earlier of 24 months after the audio recording was created or Agreement termination date

Product Reviews and Surveys:

  • Name
  • Phone number
  • Email address
  • Physical address
  • Gender
  • Age
  • Username
  • Account number
  • IP address
  • MAC address
Text-based product/service review data provided by Khoros clients
  • Amazon Web Services
  • MongoDB
  • Google Cloud Platform
Earlier of 24 months after the audio recording was created or Agreement termination date

Social Media Posts:

  • Social network user ID
  • Name
  • Username
  • Post contents
From social networks via API, provided by Khoros clients, or third-party data aggregation sources
  • Amazon Web Services
  • MongoDB
  • Google Cloud Platform
Earlier of 24 months after the audio recording was created or Agreement termination date

Web Session Data:

  • Username
  • IP address
  • MAC address
  • Email address
Web session recording applications
  • Amazon Web Services
  • MongoDB
Earlier of 24 months after the audio recording was created or Agreement termination date

User Access Data:

  • Email address
  • IP address
User created activity
  • Okta
Three (3) months from the date of the user session

User Access Data:

  • Name
  • Email address
User created activity
  • Zendesk
Indefinitely at Zendesk until 90 days post-contract termination

User Access Data:

  • Email address
  • IP address
User created activity
  • Alienvault
  • Sumo Logic
Twelve (12) months from the date of the user session

User Access Data:

  • Name
  • Email address
User created activity
  • Pendo.io
Indefinitely at Pendo.io until 30 days post-contract termination
Updated 3 months ago
Version 19.0
No CommentsBe the first to comment