← Security and Trust Centre
Framework 2 of 4

GDPR

A structured compliance programme covering data protection, retention, deletion and data-subject rights across RaptorFM.

COMPLIANCE PROGRAMME IN PROGRESSBuild target: 2–6 weeks
A NOTE ON LANGUAGE

RaptorFM does not claim "GDPR Certified" status. UK GDPR certification is a formal, ICO-recognised scheme tied to specific processing activities, and we will only use that language if and when we are certified under an approved scheme. Until then, this page describes our compliance programme — the policies, registers and processes we are building and maintaining.

RaptorFM GDPR Compliance Pack

Every document and control in our compliance programme, with its current status.

Privacy Policy

Public-facing notice explaining what personal data we collect and why.

IN PROGRESS
Data Processing Agreement (DPA)

Commercially usable DPA, available at signup for every customer.

IN PROGRESS
Data Protection Policy

Internal policy setting out our data protection principles and responsibilities.

IN PROGRESS
Data Retention & Deletion Policy

Defines how long each category of data is kept and how it is deleted.

PLANNED
Data Subject Access Request (DSAR) procedure

Documented process for handling access requests within statutory timeframes.

PLANNED
Data Breach Response procedure

Internal steps for containing, assessing and remediating a breach.

PLANNED
Data Breach Notification procedure

Process for notifying the ICO and affected data subjects where required.

PLANNED
Data Processing Register / RoPA

Record of Processing Activities across every system and workflow.

IN PROGRESS
Subprocessor Register

Maintained list of every subprocessor with access to customer data.

IN PROGRESS
Data Processing Map

End-to-end map of how personal data flows through RaptorFM.

PLANNED
Data Retention Schedule

Category-by-category retention periods tied to the retention policy.

PLANNED
Data Protection Impact Assessment (DPIA) methodology

Standard method for assessing risk before high-risk processing begins.

PLANNED
International Data Transfer mechanism

UK GDPR-compliant arrangements for any cross-border data transfer.

PLANNED
Technical and Organisational Measures (TOMs)

The combined technical and organisational controls protecting personal data.

IN PROGRESS
Employee confidentiality obligations

Contractual confidentiality obligations covering all staff with data access.

IMPLEMENTED
Access control policy

Governs who can access what data, and how that access is reviewed.

IMPLEMENTED
Encryption policy

Defines encryption standards for data in transit and at rest.

IN PROGRESS
Backup & recovery policy

Defines backup frequency, retention and recovery testing.

PLANNED
Incident response plan

Cross-functional plan for detecting, escalating and resolving security incidents.

PLANNED
Vendor / third-party risk management process

Due diligence process applied before onboarding any subprocessor or vendor.

PLANNED
Data deletion process

Operational process for deleting customer data on request or at contract end.

PLANNED
Customer data export process

Lets customers export their data on request or ahead of offboarding.

IN PROGRESS
Build timeline
Week 1–2

Core policies drafted: Privacy Policy, Data Protection Policy, RoPA, Subprocessor Register, TOMs.

Week 3–4

Legal review of all drafted policies and the DPA; DSAR, breach response and vendor risk procedures written.

Week 5–6

DPA finalised and published; retention schedule, DPIA methodology and transfer mechanism signed off.

Request the DPA or full compliance pack

Our Data Processing Agreement is commercially usable today. Request it — or the full GDPR compliance pack — under NDA where required.

Request the pack →