Resources · Compliance

Compliantby design.

We design products, contracts, and partner setups so the rules can hold. Legally sound, operationally real.

GDPR · EU-GDPR · DPA · TOMS · EVIDENCE

Straight talk

Certificates live with the infrastructure. Our work sits in between.

What we hold: delivery that follows the rulebooks. Data processing agreements (DPAs), technical and organisational measures (TOMs), privacy by design, clear roles and evidence trails. And clear standards for partners and data centres: where a standard matters for your data, they must bring the certification. We connect product, contracts, and stack. Precise and accountable.

Three layers

Where compliance actually sits.

Honest split: what we run, what partners must prove, what the product has to carry.

01

Contracts that bind

Data processing agreements, processor chains, and purpose limits. Written so counsel and ops can both use them.

02

TOMs in the product

Access, encryption, logging, backups, retention. Technical and organisational measures you can operate, not only annex.

03

Certified where data lives

Hosting and infrastructure partners are selected so relevant certifications are required. Not decorative, not optional.

04

Evidence without theater

Documents and routines that survive questions from clients, auditors, and your own team, without freezing the build.

Standards

Standards the stack has to withstand.

The standards below are benchmarks for the infrastructure of our specialised partners, and the reference grid for how we shape architecture, process, and proof. Our contribution sits in between: DPAs, TOMs, access models, retention, and incident paths that make those standards usable in your product.

ISO 27001GDPRSOC 2

ISO 27001

Risk & gap clarity

Map where regulation meets your systems, before a buyer or auditor does it for you.

ISO 27017

Policies that travel

Living policy frames tied to the product: updates when law or scope moves. Not a PDF that sits in a drawer.

ISO 27018

Incident paths

Who acts, who is informed, what gets logged. Rehearsable response instead of improvised panic.

GDPR / DSGVO

Data subject rights

Access, rectification, erasure, portability. As a process that meets deadlines, not a form in the footer.

EU Data Processing

Strictly in the EU

Processing only in the Union. Storage, backups, logs, Germany as the seat. No third country, no transfer as the default.

Related

Sustainability belongs here too.

Efficient systems, durable products, and honest measurement. Without greenwashing.

Read sustainability
Next step

Bring the rulebook. We’ll implement it.

You bring the requirements. We put them into product, contracts, and stack — operational, not just on paper.