Skip to main content

How safe is my data on Borderless?

Overview of the robust systems, policies, and safeguards we have in place.

S
Written by Sam Helm
Updated this week

At Borderless, safeguarding personal data and maintaining compliance with data protection regulations - especially the UK GDPR - is a top priority.

πŸ”’ Systems and Services Security

We’ve implemented strict access controls, encryption, and infrastructure safeguards to ensure data confidentiality, integrity, and availability.

  • Hosting Infrastructure: Our platform is hosted on AWS and GCP, both using UK-based data centres with high availability and data replication across multiple zones.

  • Ongoing Risk Assessments: Regular security assessments and Data Protection Impact Assessments (DPIAs) are conducted.

  • Disaster Recovery: We have daily backups, data replication, and a disaster recovery plan targeting a recovery time objective (RTO) of 5 working days.

πŸ‘€ Data Subject Rights Compliance

We provide transparent and accessible ways for data subjects to exercise their rights.

  • A Privacy Portal offers clear information about data usage.

  • Individuals can request access, correction, deletion, or portability of their data via: [email protected]

  • We maintain and regularly review Records of Processing Activities (ROPA) in compliance with the UK GDPR.

βœ… Consent-Based Processing

User consent is managed clearly and transparently.

  • Our interfaces are designed to capture explicit and informed consent, with options to withdraw consent easily.

  • All consents are logged for audit purposes.

🌍 Legal Safeguards for Data Transfers

  • Data is currently stored in the UK, within the AWS and GCP UK regions.

  • Contracts with cloud providers include standard contractual clauses (SCCs) for any future data transfers outside the UK.

πŸ—‚οΈ Records of Personal Data Processing

We maintain comprehensive data processing records in line with GDPR. This work is overseen by our compliance partner, Privasee, and managed under our Records Retention Policy.

πŸ”§ Technical & Organisational Measures

  • Regular penetration testing and security audits assess and improve system defences.

  • Our GDPR compliance manager at Privasee ensures continuous monitoring and process refinement.

βš–οΈ Regulatory Status

  • No ICO enforcement or penalty notices have been issued to Get Borderless Ltd or any of our sub-processors in the past three years.

πŸ§‘β€πŸ’» Third-Party Data Processors

  • Primary data processors: AWS and GCP, both under GDPR-compliant contracts.

  • We strictly vet all third-party vendors for data protection alignment.

🧍 Staff Access to Data

  • Access is limited to Borderless-owned devices, protected by secure login protocols.

  • We have the ability to remote wipe or revoke access in case of loss or theft.

πŸ” Security Measures

We apply leading practices to prevent and mitigate data breaches:

  • Multi-factor authentication (MFA)

  • One-time passwords (OTP)

  • Regular user access reviews

  • No data breaches to date

πŸ“„ ISO 27001 Accreditation

  • We leverage GCP and AWS, both of which are ISO/IEC 27001 certified.

  • Certifications cover infrastructure, data centres, applications, personnel, and security processes.

If you have any questions about our data protection and compliance practices, feel free to reach out to our team at [email protected].

Did this answer your question?