Our commitment to protecting your data
Credensa takes its responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 seriously. This statement describes the organisational and technical measures we take to ensure personal data processed through our platform is handled lawfully, fairly and transparently.
1. Data protection principles
We are committed to processing data in accordance with our responsibilities under data protection law. Personal data shall be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; adequate, relevant and limited to what is necessary; accurate and kept up to date; retained only for as long as necessary; and processed in a manner that ensures appropriate security.
2. Our roles
In respect of account and billing information, Credensa acts as a data controller. In respect of documentation and personal data uploaded to the platform by agents and suppliers, Credensa acts as a data processor, processing that data only on the documented instructions of the customer.
3. Technical measures
All data is encrypted in transit using TLS and at rest using industry-standard encryption. Access to production systems is restricted to authorised personnel on a least-privilege basis, protected by multi-factor authentication and logged. We maintain regular, encrypted backups and test restoration procedures periodically.
4. Organisational measures
All staff receive data protection training on joining and refresher training annually. We maintain internal policies covering acceptable use, access control, incident response and data breach notification. Third-party processors are vetted before engagement and bound by written data processing agreements.
5. Data breach procedures
In the event of a personal data breach, we will assess the risk to individuals’ rights and freedoms and, where required, notify the Information Commissioner’s Office within 72 hours of becoming aware of the breach, and affected customers without undue delay.
6. Data subject requests
We support our customers in responding to requests from individuals exercising their rights under data protection law. Any data subject request received directly by Credensa relating to data processed on behalf of a customer will be forwarded to that customer promptly.
7. Contact
Questions about this statement or our data protection practices should be directed to our data protection lead via the contact page or by writing to Credensa, 26 Cowper Street, London EC2A 4AP.