1. Our two roles
Under the GDPR we act in two distinct roles, and the difference matters for responsibility.
- Controller — for the data of website visitors, prospects and our own client contacts.
- Processor — for personal data inside client infrastructure that we build, operate or support on the client's documented instructions.
2. Lawful bases we rely on
- Pre-contractual steps and contract performance — enquiries, proposals and delivery of agreed services.
- Legitimate interests — website security, abuse prevention, service improvement, balanced against your rights.
- Legal obligation — accounting, tax and statutory record keeping.
- Consent — only where required, for example any future analytics or marketing cookies; withdrawable at any time.
3. Data processing agreement
For engagements where we touch personal data in your systems, we sign a Data Processing Agreement under Article 28. It defines subject matter and duration, processing purposes, data categories, our confidentiality duties, security measures, subprocessor rules, assistance with data subject requests, breach notification and end-of-engagement deletion or return.
4. Subprocessors
We use a limited set of subprocessors — hosting, communication and business tooling providers. Each is bound by written data protection terms. We provide the current list on request and notify clients before adding a subprocessor that affects their data, giving a reasonable objection window.
5. International transfers
Where personal data is transferred outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses, complemented by technical and organisational measures: encryption in transit and at rest, key management, access control and audit logging.
6. Technical and organisational measures
- Least-privilege and role-based access, reviewed regularly.
- Multi-factor authentication and short-lived credentials; OIDC federation instead of long-lived cloud keys where possible.
- Secrets in managed secret stores, never in repositories.
- Encryption in transit and at rest, with documented key handling.
- Centralised audit logging, monitoring and alerting on privileged actions.
- Change management: code review, pipeline gates and traceable production changes.
- Backup and restore procedures that are tested, not assumed.
7. Data minimisation in engineering work
We design pipelines and environments so that personal data does not spread where it is not needed: anonymised or synthetic datasets in test environments, log redaction of identifiers and secrets, and retention tiers so logs and backups expire on schedule rather than accumulating indefinitely.
8. Data subject requests
As controller we handle requests directly within 30 days. As processor we do not respond to your users on our own initiative — we forward the request to you without undue delay and provide the technical assistance needed to locate, export, correct or delete the data.
9. Personal data breaches
We run documented incident response. Acting as processor, we notify the client without undue delay after becoming aware of a personal data breach, with the facts known at that point, the likely impact and the containment steps taken, and we support the client's notification to the supervisory authority within the 72-hour window.
10. Records and accountability
We maintain records of processing activities for our controller-role data, keep security documentation for engagements, and can support client audits or security questionnaires within reasonable scope and notice.
11. End of engagement
On termination, and at the client's choice, we return or delete personal data we processed on the client's behalf, revoke our access, and confirm deletion in writing, except where retention is required by law.