Data residency in the EEA, transparent transfer mechanism
Primary processing happens in EEA datacenters (Frankfurt and Bucharest). Where any data crosses outside the EEA (e.g., support tickets handled by an analyst working remotely), the legal mechanism is the UK ICO's International Data Transfer Agreement (IDTA) or the EU SCC. The mechanism in use is documented in the DPA appendix.
EEA primary · UK IDTA + EU SCC · Documented in DPA
Cyber Essentials guidance applied operationally
We do not currently hold the Cyber Essentials or Cyber Essentials Plus certificate — we say that plainly. We do apply the five controls operationally: secure configuration, boundary firewalls, access control, malware protection, patch management. Documentation of each control is available for due diligence under NDA.
CE/CE+ controls applied · Not certified · Docs under NDA
Audit log immutability for FOI and accountability
All application logs and infrastructure access logs ship to S3 with object-lock enabled — written today, immutable until retention expires. Standard retention is 7 years to match common UK public sector record-keeping requirements; configurable per workload up to 25 years for projects with longer regulatory horizons.
S3 + object-lock · 7-year default · Up to 25 years configurable
Sub-processor list and 30-day change notice
Sub-processor list (currently four entries: AWS for S3 backup target, Cloudflare for CDN, Hetzner for backup datacenter, Stripe for payments) is published and versioned. Any addition or replacement triggers a 30-day written notice with opportunity to object for material changes. Public sector procurement teams can request the current version with version hash for their assurance pack.
Versioned · 30-day notice · Material-change opt-out
Exit support without lock-in
End-of-contract data return is part of the standard MSA. Full database exports (Postgres custom format, MySQL mysqldump, MongoDB BSON), file system tarballs, and configuration manifests delivered to your nominated S3 bucket or sent on encrypted physical media. No charge for the export — exit data is returned within 30 days of notice.
Full data return in 30 days · Standard formats · No exit fee
Pricing in GBP with public sector VAT-recoverable invoicing
Invoicing in pounds with VAT shown on a separate line at the standard 20 % rate. Public sector buyers using the VAT recovery mechanism for outsourced services (Contracted-Out Services COS Direction) can use our invoices directly. PO references can be embedded into every invoice for your finance system.
GBP invoicing · VAT 20 % line · PO number per invoice · COS-recoverable