Data protection
Data protection is part of how we build.
Integration, cloud and AI projects touch sensitive information. Organisations with the highest standards, including the public sector, need a partner that treats data protection as a design requirement, not an afterthought.
Last updated: 14 September 2026
Our roles
For our own website, enquiries and business relationships, HDT Software Limited is the controller. Our privacy notice explains that processing.
In client projects we usually act as a processor. We sign a data processing agreement that meets Article 28 GDPR, or Article 29 of Regulation (EU) 2018/1725 when the client is an EU institution, body, office or agency, and we process personal data only on the client’s documented instructions.
Our commitments as a processor
Documented instructions
Personal data is processed only for the client’s purposes, on documented instructions, under a signed data processing agreement.
EU data residency by default
Project data stays in the European Union: in the client’s own environment or in EU regions of Microsoft’s cloud. Any transfer outside the EEA requires the client’s prior written approval and appropriate safeguards.
Confidentiality and need-to-know
Everyone working on client data is bound by confidentiality and only gets access to what the task requires, for as long as it requires.
Security measures
Encryption in transit and at rest, multi-factor authentication, least-privilege access and activity logging on the systems we use.
Privacy by design in automation and AI
Integrations and AI workflows are designed for data minimisation, with pseudonymisation where possible. Client data is never used to train third-party AI models.
Breach notification
We notify clients without undue delay after becoming aware of a personal data breach, with the details they need to meet their own notification duties.
Controlled sub-processors
We use a short, published list of sub-processors and inform clients in advance of any addition or replacement, so they can object.
Assistance and audits
We help clients answer data subject requests, carry out data protection impact assessments and verify our compliance, including through audits.
Return and deletion
At the end of an engagement we return or delete client personal data, as the client decides, unless the law requires us to keep it.
Sub-processors
Service providers that may process personal data for HDT.
Microsoft Ireland Operations Limited
- Service
- Microsoft 365: email, documents, collaboration
- Data location
- European Union (EU Data Boundary)
- Transfer safeguards
- EU storage; EU-U.S. Data Privacy Framework and Standard Contractual Clauses for limited transfers
Microsoft Ireland Operations Limited
- Service
- Microsoft Azure: cloud hosting and services for project workloads
- Data location
- EU regions
- Transfer safeguards
- EU storage; EU-U.S. Data Privacy Framework and Standard Contractual Clauses for limited transfers
Netlify, Inc.
- Service
- Website hosting and contact form (no client project data)
- Data location
- United States
- Transfer safeguards
- EU-U.S. Data Privacy Framework; Standard Contractual Clauses (2021/914)
Sub-processors specific to a project, such as tools a client asks us to use, are listed in that project’s data processing agreement.
Questions, requests and security reports
Write to privacy@hdt-software.com for data protection questions, to request our data processing agreement, or to report a security issue.
