This document provides the full list of systems that will be in scope of OneTrust’s Privacy Rights Automation module, for which there will be an automation of the process of data deletion and data access upon request by a guest through our mobile app/ website.
The list is subject to be updated over time, if other systems are added to the Privacy Rights scope.
Systems in scope:
AWS (RBI guest database)
Snowflake (RBI reporting)
Datadog (logging)
LogRocket (session replay)
mParticle (customer data platform)
Customer engagement platform - if this system is contracted by the Franchisee
Amplitude - if this system is contracted by the Franchisee
Branch (deep links) - if this system is contracted by the Franchisee
Payment service providers - however, we are still investigating (a) whether PSP’s are in scope for data deletion and (b) if “yes” who is responsible for the deletion
Backups
Note: Forter is out of scope for Privacy Rights because it would interfere with their ability to detect fraud. They have a GDPR exemption.