GDPR & Data Protection
How we meet UK GDPR as a processor for our customers, what we can evidence, and what the platform gives you to meet your own obligations.
Last updated 30 July 2026
Who this page is for
This page is written for the person who has to sign off ActiveManage — a DPO, an information governance lead, a procurement team working through a security questionnaire. If you are an individual wanting to exercise your rights, the Privacy Policy is the page you want.
Controller and processor
For data inside the applications you run on ActiveManage, you are the controller and we are your processor. You decide what is collected and why; we act only on your documented instructions. We do not use your data for our own purposes, we do not mine it, and we do not use it to train models.
We are the controller only for our own business data — your staff's contact details, our contract with you, and the operational logs we need to run the service securely.
Data Processing Agreement
We enter into a written DPA with every customer, meeting the Article 28 requirements. It covers subject matter and duration, the nature and purpose of processing, the types of data and categories of data subject, and our obligations as processor. Ask info@activemanage.co.uk for a copy, or send us yours — we are used to signing customer paper.
Our DPA commits us to: process only on your instructions; impose confidentiality on everyone with access; apply the Article 32 security measures; engage sub-processors only with your authorisation and on equivalent terms; assist you with data subject requests, DPIAs and breach notification; and delete or return the data at the end of the contract.
Sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| Amazon Web Services | Infrastructure — compute, storage, networking, backup | eu-west-2 (London) by default |
| Stripe | Payment processing where an application takes payments | UK / EU / US |
| Analytics, and Maps, reCAPTCHA or advertising where an application enables them | US, under the UK extension to the EU–US Data Privacy Framework |
We give notice before adding a sub-processor, and you may object. Nothing is added to this list without a DPA and a security review.
Data residency and transfers
UK hosting is the default. Your data sits in the AWS London region, and stays there unless you ask otherwise — EU and US hosting are available where you need them. Where any transfer outside the UK is involved, we rely on the UK extension to the EU–US Data Privacy Framework or on the IDTA / SCC Addendum, supported by a transfer risk assessment.
What the platform gives you
Meeting UK GDPR is easier when the tooling is built in rather than bolted on. Every tenant has:
- A consent ledger recording what each person agreed to and when
- Configurable retention policies per datastore, so data expires instead of accumulating
- Right-to-erasure tooling that removes or anonymises a subject across related records
- Portability exports in machine-readable form, to answer a subject access request
- A tamper-evident audit trail on every datastore — who changed what, when, and the before and after
- Field-level, default-deny permissions so staff see only what their role requires
- A live security report flagging weak configuration before it becomes an incident
Article 32 security measures
| Measure | What we do |
|---|---|
| Encryption | AES-256 at rest, TLS 1.3 in transit |
| Access control | Role-based, default-deny, down to individual fields; 2FA available and SSO via SAML 2.0, Active Directory, Azure AD or Google Workspace |
| Resilience | Automated backups, monitored uptime, documented restore procedure |
| Testing | CREST-certified penetration testing on every major release; continuous dependency and configuration review |
| Personnel | UK-based engineering team, vetted, with access granted on need and logged |
| Application security | OWASP Top 10 controls, parameterised queries, output encoding, CSP and HSTS headers |
Breach notification
If we become aware of a personal data breach affecting your data we will tell you without undue delay, with what we know about what happened, who is affected, the likely consequences and what we are doing about it — so that you can meet your own 72-hour duty to the ICO. We maintain incident response runbooks and an on-call rotation.
Helping you answer data subject requests
Requests from your data subjects should come to you, as controller. If one reaches us directly we will not action it — we will forward it to you promptly and wait for your instruction. Where you need help locating or extracting data, the portability and search tooling in the platform is usually enough, and our support team will assist where it is not.
What we can evidence
| Framework | Status |
|---|---|
| UK GDPR and Data Protection Act 2018 | Compliant — DPA, consent ledger, retention, erasure and DPIA support available |
| Cyber Essentials | Certified, renewed annually with an independent assessor |
| NHS Data Security & Protection Toolkit | Submitted annually; we host clinical applications for multiple NHS trusts |
| Crown Commercial G-Cloud | Approved supplier — procurable via the Digital Marketplace |
| ISO 27001 | Controls mapped to Annex A; control matrix available on request |
| PCI-DSS | SAQ-A — card data is tokenised by Stripe and never stored by us |
We are happy to complete your security questionnaire, support a DPIA, or talk to your information governance team. Email info@activemanage.co.uk.