Privacy and data protection built into the operating framework.

CommsPliant maintains a documented UK GDPR and data-protection framework covering how personal data is processed, retained, deleted and protected, and how client processing responsibilities are handled.

UK GDPR

CommsPliant operates a documented UK GDPR compliance framework covering data mapping, records of processing, data processing agreements, retention and deletion, data-subject rights, DPIA screening, subprocessor governance, incident handling and client offboarding.

Implemented

ICO Registration

Alpha Creative Solutions, which operates CommsPliant, is registered with the UK Information Commissioner's Office.

Current

Customer Data & Data Use

Customer data is processed for the communication task, not retained by default.

CommsPliant receives the data needed to generate a communication, processes it for that purpose and returns the completed output to the client.

Personally identifiable information is not retained by default. If a client requires CommsPliant to store completed communications or related customer data, this is enabled only through a separate agreed retention arrangement.

Access to customer data is restricted to authorised personnel and only where necessary for controlled operational or support purposes.

Implemented

Data Map

CommsPliant maintains a Data Map showing how personal data and client information move through the service.

Documented View Data Flow

Records of Processing Activities

Controller and Processor Records of Processing Activities are maintained for the processing CommsPliant carries out as controller and processor.

Documented

Data Processing Agreement

An approved Data Processing Agreement baseline is available for client onboarding. Client-specific processing details are completed before live client processing begins.

Approved

Retention & Deletion

Retention rules are documented by data type and operational purpose.

Customer personal data used for communication generation is not retained by default. Longer-term storage of completed communications or related customer data is used only where separately agreed with the client.

Approved

Data Subject Rights

A documented procedure covers how data-subject rights requests are received, assessed and supported.

Approved

DPIA Screening

Changes in processing can be screened to determine whether a full Data Protection Impact Assessment is required.

Documented

Client Offboarding & Deletion

A documented process covers client data return/export and deletion when the service ends.

A controlled mock offboarding has been completed, and permanent tenant purge capability is implemented and tested by Engineering.

Tested

Subprocessor Governance

Relevant subprocessors are recorded and reviewed for privacy, security, contractual and international-transfer considerations.

A client-facing Subprocessor List is maintained separately.

Implemented View Subprocessors

Privacy FAQ

Still have questions?

If you need more detail about CommsPliant's privacy, data protection or UK GDPR position, contact us and we'll help.

Request more information

Privacy Resources

Resource Availability Action
Data Map Controlled · On request Request access
Controller ROPA Controlled · On request Request access
Processor ROPA Controlled · On request Request access
Data Processing Agreement Client onboarding Request access
Retention and Deletion Schedule Controlled · On request Request access
Data Subject Rights Procedure Controlled · On request Request access
DPIA Screening Controlled · On request Request access
Client Offboarding, Export and Deletion Procedure Controlled · On request Request access
Security and Privacy Risk Register Controlled · On request Request access
Subprocessor and International Transfer Register Controlled · On request Request access
Privacy Notice Public View document

A request does not automatically mean the full internal document is shared. Where appropriate, CommsPliant may provide a client-facing version, extract, summary or controlled evidence instead.