Legal draft

Data Protection and GDPR

A draft overview of the data-protection approach to be completed with Renvoxa’s actual processes and suppliers.

Status: Draft — requires Renvoxa and legal review before launch.

Our approach

Renvoxa intends to process personal data lawfully, fairly and transparently, only for defined purposes and with appropriate data minimisation.

Roles and responsibilities

[RENVOXA TO CONFIRM: circumstances in which Renvoxa acts as controller or processor, and the responsible privacy lead].

Client data and AI services

[RENVOXA TO CONFIRM: approved description of service data flows, instructions, access controls, training-data position and deletion process].

Security measures

[RENVOXA TO CONFIRM: approved technical and organisational security measures. Do not publish unsupported certifications].

Sub-processors

[RENVOXA TO CONFIRM: current approved sub-processor list, locations and notification process].

Data-subject requests

[RENVOXA TO CONFIRM: verified request channel, identity-checking process and internal response procedure].

Incidents

[RENVOXA TO CONFIRM: incident-response and breach-notification process].

Data processing agreements

Client data-processing terms and responsibilities should be documented in an appropriate agreement before services begin.

[RENVOXA TO CONFIRM: effective date and version owner]