GDPR Compliance
We build and operate to EU data-protection standards by default, for our own data and for the systems we deliver.
We act as data controller for our own business data and as data processor when handling personal data on behalf of clients. Processor engagements are governed by our Data Processing Agreement.
We support access, rectification, erasure, restriction, portability and objection. Requests are handled within one month as required by Article 12.
We maintain a breach procedure and, where required, notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
AI, automation and data systems we deliver are engineered with privacy-by-design: least-privilege access, data minimisation, and configurable retention.