Data protection
Data processing
Who does what with personal data, where it lives, how long it is kept and how we support your obligations as a controller.
Controller and processor roles
- RODMENA as controller
- For this website and our own business correspondence, covered by our Privacy Policy.
- RODMENA as processor
- When we operate or support systems holding your users’ personal data under contract, governed by a signed Data Processing Agreement (Article 28 UK GDPR).
Sub-processors
Services that may process data on RODMENA’s behalf. Customers with a DPA are notified of changes to this list in advance.
| Provider | Purpose | Location |
|---|---|---|
| OVH SAS (OVHcloud) | Managed virtual servers hosting the production database tier and its encrypted off-site backups | United Kingdom, France and Germany |
| Self-managed virtual servers on company-owned hardware | Website and application hosting, administered by RODMENA | United Kingdom |
| GitHub, Inc. | Source code hosting and CI | USA (Standard Contractual Clauses) |
Processing locations and international transfers
We are UK-based and process data in the United Kingdom by default. Customer deployments run wherever the customer chooses, commonly the customer’s own infrastructure or UK and EU cloud regions. Where any transfer outside the UK occurs (for example GitHub, Inc. for source-code hosting), it is protected by appropriate safeguards: UK adequacy, the UK Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement.
Retention and deletion
As processor, we retain personal data only for the duration of the contract and delete or return it, at the controller’s choice, when the engagement ends, certifying deletion on request. Retention for our own controller processing is described in the Privacy Policy. See also exit & portability.
Data-subject requests
We assist controllers in meeting data-subject rights (access, rectification, erasure, restriction, portability, objection) within the statutory one-month window. Requests relating to data we control: gdpr@rodmena.co.uk.
Breach handling
Personal-data breaches are contained, investigated and documented. As processor we notify the affected controller without undue delay after becoming aware; as controller we notify the ICO within 72 hours where required and affected individuals where the risk demands it.
DPA requests: legal@rodmena.co.uk · data-protection questions: privacy@rodmena.co.uk · see the DPA summary and Trust Centre.