Legal

GDPR and data processing

Information for the legal and compliance teams at customer organisations: our role, our security measures, our subprocessors and how to get a data processing agreement signed.

Last updated 1 September 2026Version 1.0 — draft

5. Technical and organisational measures (Art. 32)

AreaMeasures
EncryptionTLS on all connections; encryption at rest in the database and object storage
Access controlRBAC with four roles, least privilege, stronger authentication on administrative accounts, support for SAML and OAuth 2.0 SSO
IsolationData segregated per organisation, enforced at the data layer and verified in the API, not only in the interface
TraceabilityAudit logs of sensitive actions with actor, timestamp and previous value; monitoring with alerting
Secure developmentCode review, separate development, staging and production environments, penetration testing before each major release
ContinuityRegular backups with tested restores; recovery objectives RPO/RTO
PeopleConfidentiality agreements and data protection training for everyone with access to customer data

6. Data subject requests

Requests for access, rectification, erasure, restriction, objection or portability should go to the controlling organisation. If a data subject contacts us directly, we forward the request without delay and tell them we have done so.

We support the organisation with the platform's own tools — user data export, profile rectification, account deletion — and with manual help where needed.

7. Data breaches

If we detect a personal data breach, we notify the controlling organisation without undue delay and, where possible, within 24 hours of becoming aware, with what we know: the nature of the breach, the approximate number of data subjects and records, likely consequences and measures taken.

It falls to the organisation, as controller, to notify the supervisory authority within 72 hours and, where applicable, the affected individuals.

8. Retention, return and deletion

During the contract, retention periods are those configured by the organisation, within the limits described in the Privacy Policy.

After termination, the organisation has N days to export its data. After that we delete or anonymise production copies within N days and backup copies on the normal rotation cycle, which does not exceed N days. We provide a written confirmation of deletion on request.

9. Records, audits and impact assessments

  • We keep records of the processing activities carried out on behalf of each customer, under Article 30(2).
  • We make available the information needed to demonstrate compliance with Article 28 and allow audits, on reasonable notice and subject to confidentiality, once a year or following an incident.
  • We support the organisation in carrying out data protection impact assessments by supplying the technical information we hold.
  • CERTIFICATIONS: ISO 27001, SOC 2 — STATE WHETHER HELD OR PLANNED

10. Data protection contacts

For the DPA, compliance questions or data subject requests: privacy@3lsystems.cv. Data Protection Officer: NAME AND CONTACT, IF APPOINTED.

Contact

Back to top