Skip to content
RODMENA

Data protection

Data processing

Who does what with personal data, where it lives, how long it is kept and how we support your obligations as a controller.

Controller and processor roles

RODMENA as controller
For this website and our own business correspondence, covered by our Privacy Policy.
RODMENA as processor
When we operate or support systems holding your users’ personal data under contract, governed by a signed Data Processing Agreement (Article 28 UK GDPR).

Sub-processors

Services that may process data on RODMENA’s behalf. Customers with a DPA are notified of changes to this list in advance.

Sub-processors, their purpose and location
ProviderPurposeLocation
OVH SAS (OVHcloud)Managed virtual servers hosting the production database tier and its encrypted off-site backupsUnited Kingdom, France and Germany
Self-managed virtual servers on company-owned hardwareWebsite and application hosting, administered by RODMENAUnited Kingdom
GitHub, Inc.Source code hosting and CIUSA (Standard Contractual Clauses)

Processing locations and international transfers

We are UK-based and process data in the United Kingdom by default. Customer deployments run wherever the customer chooses, commonly the customer’s own infrastructure or UK and EU cloud regions. Where any transfer outside the UK occurs (for example GitHub, Inc. for source-code hosting), it is protected by appropriate safeguards: UK adequacy, the UK Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement.

Retention and deletion

As processor, we retain personal data only for the duration of the contract and delete or return it, at the controller’s choice, when the engagement ends, certifying deletion on request. Retention for our own controller processing is described in the Privacy Policy. See also exit & portability.

Data-subject requests

We assist controllers in meeting data-subject rights (access, rectification, erasure, restriction, portability, objection) within the statutory one-month window. Requests relating to data we control: gdpr@rodmena.co.uk.

Breach handling

Personal-data breaches are contained, investigated and documented. As processor we notify the affected controller without undue delay after becoming aware; as controller we notify the ICO within 72 hours where required and affected individuals where the risk demands it.

DPA requests: legal@rodmena.co.uk · data-protection questions: privacy@rodmena.co.uk · see the DPA summary and Trust Centre.