Compliance

Meeting Global Regulatory Requirements

Arvelo Built CRM is committed to compliance with global data protection regulations, industry standards, and security frameworks. We help our customers meet their compliance obligations through robust security controls, data protection measures, and comprehensive audit capabilities.

1. Data Protection Regulations

GDPR COMPLIANT

European Union General Data Protection Regulation (EU 2016/679)

CCPA COMPLIANT

California Consumer Privacy Act

LGPD COMPLIANT

Brazilian General Data Protection Law

PIPEDA COMPLIANT

Canadian Personal Information Protection and Electronic Documents Act

1.1 GDPR Compliance (European Union)

We comply with the General Data Protection Regulation (GDPR) for all EU users:

1.2 CCPA Compliance (California)

We comply with the California Consumer Privacy Act (CCPA):

2. Industry Standards & Certifications

SOC 2 Type II CERTIFIED

Annual audits of security, availability, and confidentiality controls

ISO 27001 ALIGNED

Information security management system standards

NIST CSF ALIGNED

Cybersecurity Framework alignment

OWASP Top 10 PROTECTED

Protection against top web application security risks

2.1 SOC 2 Type II

Service Organization Control 2 Type II certification demonstrates:

2.2 ISO 27001 Alignment

Our security practices align with ISO/IEC 27001 standards:

3. Industry-Specific Compliance

3.1 Healthcare (HIPAA)

For healthcare customers handling Protected Health Information (PHI):

3.2 Financial Services

Support for financial services compliance:

3.3 Government & Public Sector

Support for government compliance requirements:

4. Data Processing & Transfer

4.1 Data Processing Agreements (DPAs)

We provide Data Processing Agreements for enterprise customers:

4.2 International Data Transfers

Secure international data transfers:

5. Audit & Reporting

5.1 Audit Capabilities

Comprehensive audit trail for compliance:

5.2 Compliance Reporting

Reporting capabilities for compliance audits:

6. Data Subject Rights

6.1 Right to Access

Users can access their personal data:

6.2 Right to Rectification

Users can correct inaccurate data:

6.3 Right to Erasure ("Right to be Forgotten")

Users can request deletion of their data:

6.4 Right to Data Portability

Users can receive their data in a portable format:

7. Vendor & Subprocessor Management

7.1 Subprocessor List

We use the following subprocessors to provide our Service:

All subprocessors are contractually obligated to protect your data and comply with applicable regulations.

7.2 Vendor Security

We ensure all vendors meet security and compliance requirements:

8. Compliance Certifications & Documentation

8.1 Available Documentation

We provide the following compliance documentation:

9. Compliance Contact

For compliance-related inquiries or to request compliance documentation:

Arvelo Built CRM - Compliance Team
Email: compliance@arvelobuilt.com
Phone: 1-800-ARVELO-1
Address: 123 Business Park Drive, Suite 400, San Francisco, CA 94105

Data Protection Officer (EU):
Email: dpo@arvelobuilt.com
For GDPR-related inquiries and data subject requests

10. Continuous Compliance

Compliance is an ongoing commitment. We: