RaptorFM does not claim "GDPR Certified" status. UK GDPR certification is a formal, ICO-recognised scheme tied to specific processing activities, and we will only use that language if and when we are certified under an approved scheme. Until then, this page describes our compliance programme — the policies, registers and processes we are building and maintaining.
Every document and control in our compliance programme, with its current status.
Public-facing notice explaining what personal data we collect and why.
Commercially usable DPA, available at signup for every customer.
Internal policy setting out our data protection principles and responsibilities.
Defines how long each category of data is kept and how it is deleted.
Documented process for handling access requests within statutory timeframes.
Internal steps for containing, assessing and remediating a breach.
Process for notifying the ICO and affected data subjects where required.
Record of Processing Activities across every system and workflow.
Maintained list of every subprocessor with access to customer data.
End-to-end map of how personal data flows through RaptorFM.
Category-by-category retention periods tied to the retention policy.
Standard method for assessing risk before high-risk processing begins.
UK GDPR-compliant arrangements for any cross-border data transfer.
The combined technical and organisational controls protecting personal data.
Contractual confidentiality obligations covering all staff with data access.
Governs who can access what data, and how that access is reviewed.
Defines encryption standards for data in transit and at rest.
Defines backup frequency, retention and recovery testing.
Cross-functional plan for detecting, escalating and resolving security incidents.
Due diligence process applied before onboarding any subprocessor or vendor.
Operational process for deleting customer data on request or at contract end.
Lets customers export their data on request or ahead of offboarding.
Core policies drafted: Privacy Policy, Data Protection Policy, RoPA, Subprocessor Register, TOMs.
Legal review of all drafted policies and the DPA; DSAR, breach response and vendor risk procedures written.
DPA finalised and published; retention schedule, DPIA methodology and transfer mechanism signed off.
Our Data Processing Agreement is commercially usable today. Request it — or the full GDPR compliance pack — under NDA where required.