GDPR Compliance
We build and operate to EU data-protection standards by default, for our own data and for the systems we deliver.
Our role
We act as data controller for our own business data and as data processor when handling personal data on behalf of clients. Processor engagements are governed by our Data Processing Agreement.
Principles we apply
- Lawfulness, fairness and transparency.
- Purpose limitation and data minimisation.
- Accuracy, storage limitation and accountability.
- Integrity and confidentiality by design and by default.
Data subject rights
We support access, rectification, erasure, restriction, portability and objection. Requests are handled within one month as required by Article 12.
Breach response
We maintain a breach procedure and, where required, notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
Systems we build
The websites, stores, applications and dashboards we deliver are engineered with privacy-by-design: least-privilege access, data minimisation, and configurable retention.