Data Protection Policy
This is our internal standard. It is published because a customer assessing us is entitled to see it rather than take it on trust.
Principles
We apply the principles in the Data Protection Act, 2012 (Act 843): personal data is processed lawfully and fairly, for a specified purpose, kept no longer than necessary, kept accurate, kept secure, and processed with accountability for each of those.
Access
- Access to production systems is limited to named staff who need it.
- Access to a customer's instance data requires a reason recorded at the time — a support request, an incident, or a restore.
- Administrative access uses individual credentials, never shared ones.
- Access is removed the day a person's role no longer requires it.
Security measures
- Traffic to instances is encrypted in transit with certificates we manage and renew automatically.
- Instances are isolated from one another: separate databases, separate file stores, and network policy restricting what an instance may reach.
- Backups are taken on a schedule, held separately from the primary, and periodically restored to prove they can be.
- Platform components are monitored continuously, with the monitoring designed to report when it has not measured something rather than assume health.
Suppliers
A supplier who will handle personal data is assessed before use and engaged under written terms limiting them to our instructions. The current list is published as Sub-processors, and we give notice before adding one.
If something goes wrong
A suspected breach is investigated immediately and contained first. Where a breach is likely to harm the people affected, we notify the Data Protection Commission and the affected customers without undue delay and within seventy-two hours of becoming aware, telling you what happened, what data was involved, what we have done, and what you should do.
We will not delay telling you because an investigation is incomplete. A partial account, promptly, is more useful than a complete one late.
Review
This policy is reviewed annually and after any incident.