Data Protection
Last reviewed: 2026-04-20 · v2.2.1-D
GDPR coverage
| Article | Coverage |
|---|---|
| Art. 5 | Principles (lawfulness, fairness, purpose limitation, minimisation) |
| Art. 6 | Lawful basis (contract + legitimate interest + consent where required) |
| Art. 13-14 | Transparency notices — privacy policy + in-product prompts |
| Art. 15-22 | Data subject rights — DSAR portal + automated fulfilment < 30 days |
| Art. 25 | Privacy by design — default retention 90d, RLS on every table |
| Art. 28 | Processor obligations — DPA with every subprocessor on request |
| Art. 32 | Security of processing — encryption at rest + in transit, SOC 2 in progress |
Other jurisdictions
- CCPA / CPRA — California consumer rights honoured globally via the same DSAR portal.
- PIPEDA — Canadian consent + breach notification obligations met.
- UAE-PDPL — UAE data residency option via Frankfurt→Dubai data corridor (on request).
- CASL — Anti-spam consent recorded on every marketing touchpoint.
Data residency
- EU (Frankfurt, default for EU tenants)
- US-East (N. Virginia)
- UAE (Dubai) — Enterprise tier