Security & Trust Centre

Your data is safe.
We practise what we preach.

Datavacy is a GDPR compliance platform — so holding your data to the highest security standards isn't just a promise. It's non-negotiable.

Encrypted in transit & at rest
ICO Registered — ZC137164
UK GDPR Compliant
No ad trackers, ever
🔒

Enterprise-grade infrastructure

Built on Vercel and Railway — the same cloud platforms trusted by thousands of global businesses.

🇬🇧

UK GDPR compliant by design

Datavacy was built for UK GDPR from day one — not retrofitted. Compliance is in our DNA.

🚫

Zero advertising trackers

We don't run ad pixels, third-party analytics, or marketing cookies. What you do on Datavacy stays on Datavacy.

📜

Solicitor-reviewed legal docs

Our Terms, Privacy Policy, Cookie Policy, and Data Processing Agreement are all professionally reviewed.

Data Protection
How we protect
your data

Every piece of data you store in Datavacy is protected by multiple layers of security — from the moment it leaves your browser to where it's stored in our database.

🔐

Encryption in transit

All data travelling between your browser and our servers is encrypted using TLS (HTTPS). No unencrypted connections are ever accepted. Your data cannot be intercepted in transit.

🗄️

Encryption at rest

Your stored data lives in a PostgreSQL database on Railway's secure cloud infrastructure, with encrypted disk storage. Even if someone accessed the physical hardware, your data would be unreadable.

🧱

Secure authentication

Logins are handled by Clerk — a specialist authentication provider. Passwords are never stored in plain text. Brute-force attacks are blocked automatically, and multi-factor authentication is available.

🏦

No payment data stored

We never see, store, or touch your card details. All payments are processed entirely by Stripe — a PCI-DSS Level 1 certified provider, the highest level of payment security available.

🏢

Isolated customer data

Every organisation on Datavacy has its own isolated data space. Your compliance records, consent logs, and SAR data are never visible to other customers — full stop.

🚦

Rate limiting & abuse protection

Our API is protected against automated attacks, brute-force attempts, and data scraping. Unusual access patterns are detected and blocked before they can cause harm.

Infrastructure
Built on providers
you can trust

We don't build our own data centres — we stand on the shoulders of enterprise-grade platforms that specialise in security, uptime, and reliability.

Vercel
Frontend
Our application frontend is hosted on Vercel's global edge network. Vercel provides automatic HTTPS, DDoS protection, and 99.99% uptime SLA. Used by companies including Airbnb, The Washington Post, and GitHub.
Railway
API & Database
Our backend API and PostgreSQL database run on Railway's secure cloud platform. Data is stored with encrypted disks, daily backups, and isolated network environments. Railway is SOC 2 compliant.
Clerk
Authentication
All user authentication is handled by Clerk, a dedicated authentication provider. Clerk manages password hashing, session tokens, MFA, and brute-force protection so we never have to handle raw credentials ourselves.
Stripe
Payments
Payments are processed by Stripe — PCI-DSS Level 1 certified, the highest tier in the payments industry. Your card number, CVV, and billing details are never transmitted to or stored on Datavacy's systems.
Resend
Email
Transactional emails (alerts, reminders, invitations) are sent via Resend, which uses DKIM and SPF authentication to prevent email spoofing. We have also configured DMARC on our domain to protect against phishing attacks that impersonate Datavacy.
Cloudflare
DNS & Landing
Our website domain is protected by Cloudflare, which provides DDoS mitigation, DNS security, and web application firewall protection at the network edge.
Legal & Compliance
Our legal obligations
to you

As a UK GDPR compliance platform, we are held to the same standards we help you meet. Here is exactly how we fulfil our legal obligations as your data processor.

ICO Registered

We are registered with the ICO and legally accountable

Datavacy Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZC137164, valid until April 2027. This means we are legally required to handle your data lawfully, transparently, and in accordance with UK GDPR at all times.

Article 28-compliant Data Processing Agreement available at signup
Privacy Policy reviewed by a qualified UK solicitor
Cookie Policy — strictly necessary cookies only
Terms & Conditions professionally reviewed
UK Trade Mark registered — UK00004373201
Data subject rights honoured within statutory deadlines
Our Practices
What we do — and
what we never do

Transparency is part of how we operate. Here is exactly what you can expect from us when it comes to your data.

01

We never sell your data

Your data belongs to you. We do not sell, rent, or share your compliance data or customer information with any third party for commercial purposes. Ever.

02

No advertising trackers

Unlike most SaaS tools, we run no Meta pixels, Google Analytics, or third-party advertising cookies on our app. What you do inside Datavacy is private.

03

Minimal data collection

We only collect what we need to run the service — your name, email, organisation details, and the compliance data you actively enter. Nothing more.

04

You can export your data

Your data is never held hostage. You can download your compliance records and data register at any time directly from your dashboard.

05

Breach notification policy

In the unlikely event of a security incident affecting your data, we will notify you promptly — and in accordance with our obligations under UK GDPR Article 33.

06

Subprocessors are disclosed

Our full list of subprocessors (Vercel, Railway, Clerk, Stripe, Resend) is documented in our Data Processing Agreement, which is available to all customers.

"We built Datavacy to help small businesses take GDPR seriously — so it would be completely at odds with our mission to cut corners on our own security. We hold ourselves to the same standard we ask of you."

— Leon Morgan, Founder, Datavacy Ltd

Still have questions?

If you'd like more detail about our security practices, data processing, or to request a copy of our Data Processing Agreement, we're happy to help.

Contact Us Privacy Policy