Security and Privacy

    DataDoc Trust Center

    Transparency is fundamental to trust. This page details how we protect your data, the security controls we maintain, and the compliance standards we operate against.

    Security Overview

    DataDoc implements defense-in-depth security controls across infrastructure, application, and data layers.

    Data Encryption

    AES-256 encryption at rest for all stored data. TLS 1.2+ enforced for all data in transit. Database-level encryption managed by Supabase with automatic key rotation.

    Access Controls

    Role-based access control (RBAC) with organisation-level isolation. Multi-factor authentication (MFA) supported. Row-level security (RLS) enforced at the database layer.

    Infrastructure

    Cloud-hosted on enterprise-grade infrastructure with automatic failover. EU data residency by default. Regular automated backups with point-in-time recovery.

    Monitoring and Logging

    Continuous monitoring of application and infrastructure health. Audit logging for all data access and administrative actions. Anomaly detection for security events.

    Vulnerability Management

    Regular dependency scanning and automated security updates. Static code analysis integrated into the development pipeline. Responsible disclosure programme in place.

    Incident Response

    Documented incident response plan with defined roles and escalation procedures. Commitment to notifying affected customers within 72 hours of a confirmed data breach, in line with GDPR Article 33.

    Compliance and Certifications

    We align our operations to recognised privacy and security frameworks. Below is the current status of each.

    GDPR

    Compliant

    Full compliance with the General Data Protection Regulation, including lawful basis documentation, data subject rights processes, and cross-border transfer safeguards.

    ICO Registration

    Registered

    Registered with the UK Information Commissioner's Office as a data controller and processor.

    SOC 2 Type II

    Aligned

    Controls aligned to SOC 2 Trust Service Criteria covering security, availability, and confidentiality.

    ISO 27001

    Aligned

    Information Security Management System aligned to ISO 27001:2022 requirements and Annex A controls.

    Cyber Essentials

    In Progress

    Pursuing Cyber Essentials certification to demonstrate baseline security controls.

    Sub-processors

    The following third-party services process data on our behalf. We maintain Data Processing Agreements with each sub-processor and conduct regular due diligence reviews.

    Sub-processorPurposeData ProcessedLocation
    SupabaseDatabase, authentication, and file storageUser accounts, uploaded documents, analysis resultsEU (Frankfurt)
    OpenAIAI-powered document analysis and policy generationDocument content (processed, not stored)United States
    StripePayment processing and subscription managementPayment details, billing informationUnited States / EU
    VercelApplication hosting and content deliveryApplication traffic (no PII at rest)Global CDN (EU primary)
    ResendTransactional email deliveryEmail addresses, notification contentUnited States

    Data Handling

    We process only the data necessary to deliver our services. Below is an overview of how customer data is managed throughout its lifecycle.

    Data Processing

    Documents uploaded for compliance analysis are processed by AI models to generate reports and recommendations. Document content is sent to the AI provider for analysis but is not used for model training or retained by the provider beyond the request lifecycle.

    Organisation metadata (name, sector, frameworks) is stored to personalise analysis and recommendations.

    Data Retention

    Customer data is retained for the duration of the active subscription. Upon account closure or written request, all customer data including uploaded documents, analysis reports, and organisation data is permanently deleted within 30 days.

    Backups are purged within 90 days of deletion from the primary database.

    Data Portability

    Customers can export their compliance reports, policies, and analysis data at any time through the platform's built-in export functionality (PDF, Excel). Bulk data export requests can be submitted via the contact page.

    Data Isolation

    Each organisation's data is logically isolated using row-level security (RLS) policies enforced at the database layer. Users can only access data belonging to their own organization. Administrative access is restricted and audited.

    Policies and Documents

    Our legal and privacy documentation is publicly available for review.

    Privacy Policy

    How we collect, use, and protect personal data

    Terms of Service

    Terms governing use of the DataDoc platform

    Cookie Policy

    How we use cookies and similar technologies

    Contact / DPA Enquiries

    Request a Data Processing Agreement or raise a query

    Penetration Testing and Audits

    We conduct regular security assessments to identify and remediate vulnerabilities.

    DataDoc undergoes periodic penetration testing conducted by independent third-party security firms. Findings are triaged, remediated, and verified within defined SLAs based on severity.

    Automated dependency scanning runs on every deployment to detect known vulnerabilities in third-party libraries. Critical and high-severity findings are addressed before release.

    Summary penetration test reports and security posture documentation are available to enterprise customers and prospects under NDA. To request access, please contact us via the link below.

    Security Contact

    For security-related enquiries, vulnerability reports, or to request compliance documentation, please get in touch.

    security@datadoc.uk

    For security enquiries and vulnerability reports

    Contact Us