Data protection and GDPR

Two different questions

This page is about YOUR data when we work for you. What we do with a visitor's data on this website is a separate matter, and it is in our privacy statement.

When we build or review a system for you, you are the controller and we are the processor. You decide what personal data exists and why; we act on your instructions and on nothing else.

Before any work starts

We sign a data processing agreement under Article 28 GDPR. It names the categories of data and the purpose, sets the duration, obliges us to confidentiality, and says what happens to everything at the end: returned or destroyed, your choice.

We ask for a processing agreement even when the engagement seems not to involve personal data. Systems tend to grow one, and an agreement signed at the start is a formality where one signed later is a negotiation.

How we work with what you give us

We prefer not to hold your production data at all. Most of what we do — architecture, review, threat modelling, building — can be done against a schema, a synthetic set, or an anonymised extract, and we will propose that first.

Where real data is unavoidable it stays in YOUR environment wherever possible: we work in your accounts, under your logging, with access that expires. Where it must come to us, it is encrypted in transit and at rest, access is limited to the named people on the engagement, and it is deleted on the schedule the agreement sets.

Where it is

Our own systems are inside the European Union. We do not transfer personal data outside it without telling you first and having a lawful basis for the transfer.

We keep a current list of our sub-processors and give it to you on request. We tell you before we add one to an engagement, so you can object before it happens rather than discover it afterwards.

Sub-processors and your suppliers

Where we build on infrastructure you already use, your agreements with those suppliers govern it and we work inside them. Where we bring something, it is named in the processing agreement before it is used.

If something goes wrong

We tell you without undue delay and in any case within 24 hours of becoming aware of a personal data breach affecting your data — earlier than the GDPR requires of us, because your own 72-hour clock to the regulator starts when you know, and you cannot start it if we have not told you.

You get what we know, what we do not yet know, what we are doing, and what we recommend you do. We do not wait for a complete picture before the first message.

Helping you answer your own obligations

If one of your users asks for access, correction, erasure or a copy of their data, we help you answer within your deadline, at no charge for the first request in any month.

We can also help design the systems so that these requests are cheap to answer: that is a design decision made early, not a feature added under time pressure. The regulation calls it data protection by design, and it is mostly a data model question.

Asking us anything

Write to [email protected]. We are not required to appoint a data protection officer and have not; a person who knows the answer will reply.