Where your data is held
Hosting locations available are the United Kingdom and the European Economic Area, and you choose which applies to your instance: UK-only, EEA-only, or a combination of UK and EEA locations on request. Whichever you select, all of your data — production, replicas, backups and disaster-recovery copies — is stored and processed only in the location you have selected, and none is held outside it.
Each customer has a dedicated containerised instance. We own no data centre and hold no customer data on our own premises or servers.
Who processes your data
| Sub-processor | Purpose | Location |
|---|---|---|
| Primary compute and hosting provider | Compute and hosting | United Kingdom or EEA, according to your selected hosting location |
| Secondary compute and hosting provider | Compute and hosting | United Kingdom or EEA, according to your selected hosting location |
| Object storage provider | Object storage | United Kingdom or EEA, according to your selected hosting location |
| Edge protection provider | Edge protection only — DDoS mitigation and web application firewall. No application hosting, no data storage | Edge network |
| BONDAP Sp. z o.o. (Gdańsk) — Bondap group development and support team | Software development, engineering and second-line technical support, working against your hosted environment | Poland (EEA) |
No hyperscale cloud provider is used. The identity of each sub-processor is set out in the Data Processing Agreement, and customers are notified of any change. No customer data is stored outside the hosting location you have selected, and all access that can grant or elevate other people's access rights is held in the UK.
The terms we process your data under
You are the data controller. Bondap is your processor, acting only on your documented instructions, under a UK GDPR Article 28 Data Processing Agreement forming part of the contract. We are registered with the ICO, registration ZB411849.
Your data is used solely to deliver the service to you. We do not use it for analytics, cross-customer benchmarking, profiling, marketing or product development, and we do not use it to train, fine-tune or evaluate AI or machine-learning models. We do not send your data to any third-party AI service. This restriction binds our sub-processors by flow-down and survives termination.
The Data Processing Agreement is available on request.
Information classified at OFFICIAL
The service is designed and operated to support information classified at OFFICIAL, including material carrying the OFFICIAL-SENSITIVE handling caveat. We do not hold, and do not claim, a government accreditation for the service.
| Control | Position |
|---|---|
| Data location | Hosting and data sovereignty in the location you select — UK-only, EEA-only, or UK/EEA on request — including replicas, backups and DR copies |
| Encryption in transit | HTTPS only, TLS 1.2 enforced minimum, TLS 1.3 preferred, HSTS enabled |
| Encryption at rest | AES-256, with additional field-level encryption of personal data; keys held in a managed key vault separate from the data |
| Authentication | MFA on all accounts including administrative accounts — federated identity with your own MFA and conditional access, or local TOTP / FIDO2 |
| Privileged access | We hold no standing access to customer data. Privileged access is granted only for a specific approved task, is time-limited, and every use is recorded in an audit log |
| Audit logging | Full audit trail — when, who, what and how changed — written to immutable storage, retained at least 12 months, with real-time customer access to both user and supplier activity |
| Personnel | Pre-employment screening in line with the Baseline Personnel Security Standard before any access is granted |
| Certification | Certified to ISO/IEC 27001:2022 by Technical Standards Institute, valid to September 2027, and Cyber Essentials Plus |
Retention and disposal
Retention and disposal rules are configurable per module, per record type and per document class, expressed as a period from a defined trigger event, so that incident records, risk assessments, certificates and attachments can each follow your own retention schedule. Rules are set by your administrators, not by us.
When a rule expires, the record is either flagged for review or destroyed automatically, according to how you have set the rule. Every destruction is recorded in the full audit trail.
Deletion is secure: storage is explicitly overwritten before reallocation, and deleted data cannot be directly accessed. Equipment disposal follows a recognised standard.
Production data is never replicated into or stored in non-production environments. Development and testing use synthetic or anonymised data only.
Export and exit
During the contract. Your users export from any module, on filtered entries, using built-in export functionality — CSV, ODF, TXT, JSON, Excel/Word and PDF. This is standard functionality within your licence and carries no charge.
At exit. Included in the price:
| Step | What happens |
|---|---|
| Extract | An encrypted archive of your full data in SQL and/or CSV, with a data dictionary describing fields and dependencies; attached documents, photos and video in their original formats |
| Transfer | The archive is made available to you through a secure transfer mechanism agreed with you |
| Destruction date | A date for destruction of your data is agreed with you |
| Destruction | Once you confirm you have received your data, all of it is securely destroyed on all systems we control, and written confirmation of destruction is provided on request |
Only departures from that standard are chargeable: delivery in non-standard file formats, or with transformations applied, is charged at the published rate card.
Security incidents and breach notification
All incidents we discover are registered, including minor ones, and are automatically escalated to a fortnightly director review. Our target is to resolve the most serious compromises within 12 hours and others within approximately 72 hours.
Where an incident affects you, we notify your nominated contact by email, or another channel you specify, without undue delay — so that you can meet your own 72-hour duty to notify the ICO. As your processor we do not notify the ICO or data subjects on your behalf unless you instruct us to. Where an incident concerns data for which Bondap is itself the controller, we notify the ICO where notification applies.
Questions about how we handle your data, or to request the Data Processing Agreement: gc@bondap.com
© BONDAP LTD. This document is the property of Bondap and is published for information only. It may not be copied, reproduced, adapted, distributed or used for any purpose without our prior written consent.