Our commitment
We design and operate our services with the UK GDPR and Data Protection Act 2018 principles in mind: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. This page describes our approach, while our Privacy Notice explains how we use personal information as a controller.
Controller and processor roles
We act as a controller for our business relationships, website and service administration. When a client uses our platform or managed services to process personal information under its own purposes and instructions, the client is normally the controller and we act as its processor. The contract and data processing terms define the roles for each engagement.
Data protection by design
- We assess privacy and security risks during service design and material change.
- We limit access according to role and business need.
- We support data minimisation, configurable retention and secure deletion.
- We keep appropriate processing, risk, supplier and decision records.
- We carry out data protection impact assessments where processing is likely to create high risk.
Security and incident response
Our measures are selected according to risk and may include encryption in transit and at rest, identity and access controls, logging, monitoring, vulnerability management, backups, staff confidentiality and incident procedures. If we identify a personal data breach, we assess it promptly, support affected controllers and notify regulators or individuals where the law requires.
Suppliers and international transfers
We assess suppliers that process personal information, put appropriate contracts in place and limit their access to what is needed. Where information is transferred outside the UK, we use an available lawful transfer mechanism and proportionate supplementary measures. Clients can request relevant subprocessor and transfer information for their service.
Individual rights and client assistance
We maintain procedures for data protection requests and assist client controllers with requests relating to information processed on their behalf. If your request concerns a client-controlled workspace, contacting that client first will often be the quickest route. You can still contact us and we will route the request appropriately.
Data processing terms
Clients that require a data processing agreement, security schedule, subprocessor information or support with a due-diligence review can request these through their account contact or at hello@kellions.com. Contractual documents take priority over this general commitment.
Need to speak to us?
Contact our team if you have a question about this notice or how it applies to you.
Contact The Kellions