Skip to content
HDT Software

Data protection

Data protection is part of how we build.

Integration, cloud and AI projects touch sensitive information. Organisations with the highest standards, including the public sector, need a partner that treats data protection as a design requirement, not an afterthought.

Last updated: 14 September 2026

Our roles

For our own website, enquiries and business relationships, HDT Software Limited is the controller. Our privacy notice explains that processing.

In client projects we usually act as a processor. We sign a data processing agreement that meets Article 28 GDPR, or Article 29 of Regulation (EU) 2018/1725 when the client is an EU institution, body, office or agency, and we process personal data only on the client’s documented instructions.

Read the privacy notice

Our commitments as a processor

  • Documented instructions

    Personal data is processed only for the client’s purposes, on documented instructions, under a signed data processing agreement.

  • EU data residency by default

    Project data stays in the European Union: in the client’s own environment or in EU regions of Microsoft’s cloud. Any transfer outside the EEA requires the client’s prior written approval and appropriate safeguards.

  • Confidentiality and need-to-know

    Everyone working on client data is bound by confidentiality and only gets access to what the task requires, for as long as it requires.

  • Security measures

    Encryption in transit and at rest, multi-factor authentication, least-privilege access and activity logging on the systems we use.

  • Privacy by design in automation and AI

    Integrations and AI workflows are designed for data minimisation, with pseudonymisation where possible. Client data is never used to train third-party AI models.

  • Breach notification

    We notify clients without undue delay after becoming aware of a personal data breach, with the details they need to meet their own notification duties.

  • Controlled sub-processors

    We use a short, published list of sub-processors and inform clients in advance of any addition or replacement, so they can object.

  • Assistance and audits

    We help clients answer data subject requests, carry out data protection impact assessments and verify our compliance, including through audits.

  • Return and deletion

    At the end of an engagement we return or delete client personal data, as the client decides, unless the law requires us to keep it.

Sub-processors

Service providers that may process personal data for HDT.

  • Microsoft Ireland Operations Limited

    Service
    Microsoft 365: email, documents, collaboration
    Data location
    European Union (EU Data Boundary)
    Transfer safeguards
    EU storage; EU-U.S. Data Privacy Framework and Standard Contractual Clauses for limited transfers
  • Microsoft Ireland Operations Limited

    Service
    Microsoft Azure: cloud hosting and services for project workloads
    Data location
    EU regions
    Transfer safeguards
    EU storage; EU-U.S. Data Privacy Framework and Standard Contractual Clauses for limited transfers
  • Netlify, Inc.

    Service
    Website hosting and contact form (no client project data)
    Data location
    United States
    Transfer safeguards
    EU-U.S. Data Privacy Framework; Standard Contractual Clauses (2021/914)

Sub-processors specific to a project, such as tools a client asks us to use, are listed in that project’s data processing agreement.

Questions, requests and security reports

Write to privacy@hdt-software.com for data protection questions, to request our data processing agreement, or to report a security issue.

Email privacy@hdt-software.com