At Borderless, safeguarding personal data and maintaining compliance with data protection regulations - especially the UK GDPR - is a top priority.
π Systems and Services Security
Weβve implemented strict access controls, encryption, and infrastructure safeguards to ensure data confidentiality, integrity, and availability.
Hosting Infrastructure: Our platform is hosted on AWS and GCP, both using UK-based data centres with high availability and data replication across multiple zones.
Ongoing Risk Assessments: Regular security assessments and Data Protection Impact Assessments (DPIAs) are conducted.
Disaster Recovery: We have daily backups, data replication, and a disaster recovery plan targeting a recovery time objective (RTO) of 5 working days.
π€ Data Subject Rights Compliance
We provide transparent and accessible ways for data subjects to exercise their rights.
A Privacy Portal offers clear information about data usage.
Individuals can request access, correction, deletion, or portability of their data via: [email protected]
We maintain and regularly review Records of Processing Activities (ROPA) in compliance with the UK GDPR.
β Consent-Based Processing
User consent is managed clearly and transparently.
Our interfaces are designed to capture explicit and informed consent, with options to withdraw consent easily.
All consents are logged for audit purposes.
π Legal Safeguards for Data Transfers
Data is currently stored in the UK, within the AWS and GCP UK regions.
Contracts with cloud providers include standard contractual clauses (SCCs) for any future data transfers outside the UK.
ποΈ Records of Personal Data Processing
We maintain comprehensive data processing records in line with GDPR. This work is overseen by our compliance partner, Privasee, and managed under our Records Retention Policy.
π§ Technical & Organisational Measures
Regular penetration testing and security audits assess and improve system defences.
Our GDPR compliance manager at Privasee ensures continuous monitoring and process refinement.
βοΈ Regulatory Status
No ICO enforcement or penalty notices have been issued to Get Borderless Ltd or any of our sub-processors in the past three years.
π§βπ» Third-Party Data Processors
Primary data processors: AWS and GCP, both under GDPR-compliant contracts.
We strictly vet all third-party vendors for data protection alignment.
π§ Staff Access to Data
Access is limited to Borderless-owned devices, protected by secure login protocols.
We have the ability to remote wipe or revoke access in case of loss or theft.
π Security Measures
We apply leading practices to prevent and mitigate data breaches:
Multi-factor authentication (MFA)
One-time passwords (OTP)
Regular user access reviews
No data breaches to date
π ISO 27001 Accreditation
We leverage GCP and AWS, both of which are ISO/IEC 27001 certified.
Certifications cover infrastructure, data centres, applications, personnel, and security processes.
If you have any questions about our data protection and compliance practices, feel free to reach out to our team at [email protected].