GDPR Compliance

GDPR Compliance.

We build and operate to EU data-protection standards by default, for our own data and for the systems we deliver.

1. Our role

We act as data controller for our own business data and as data processor when handling personal data on behalf of clients. Processor engagements are governed by our Data Processing Agreement.

2. Principles we apply

  • Lawfulness, fairness and transparency.
  • Purpose limitation and data minimisation.
  • Accuracy, storage limitation and accountability.
  • Integrity and confidentiality by design and by default.

3. Data subject rights

We support access, rectification, erasure, restriction, portability and objection. Requests are handled within one month as required by Article 12.

4. Breach response

We maintain a breach procedure and, where required, notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

5. Systems we build

AI, automation and data systems we deliver are engineered with privacy-by-design: least-privilege access, data minimisation, and configurable retention.