EU GDPR compliance.
How Abscode is built to comply with the EU General Data Protection Regulation (GDPR), so you can serve customers and end users across the EU, EEA, UK, and the rest of the world on one platform.
The GDPR (Regulation (EU) 2016/679) governs the processing of personal data of individuals located in the EU and EEA, regardless of where the processing organisation is established. If your product reaches EU/EEA users, GDPR applies to you, and to the vendors you build on. Abscode Technologies LLP, established in India, is built to be GDPR-ready so you can adopt it without re-architecting for EU data protection.
EU data residency, available today
Choose an EU processing region so EU/EEA personal data is stored and processed inside the EU. Combined with auto-purge, a signed DPA, and the EU Standard Contractual Clauses for any onward transfer, this gives EU and worldwide customers a single, compliant setup.
1. Roles & responsibilities
When you use Abscode to process personal data of EU/EEA individuals:
- You are the Controller, you decide why and how personal data is processed
- Abscode Technologies LLP ("Abscode"), established in India, is your Processor, we process personal data only on your documented instructions
A GDPR-compliant Data Processing Agreement (DPA), incorporating the Article 28 processor terms, is available, request it from legal@abscode.com.
2. Lawful basis & instructions
As Controller, you determine the lawful basis under Article 6 (and, where special-category data is involved, the Article 9 condition) for each processing activity. Abscode does not determine purposes or means: we act only on your documented instructions set out in the DPA, and we will inform you if an instruction appears to infringe the GDPR.
3. EU data residency
- EU/EEA customers' data hosted in GCP Belgium (europe-west1) by default
- Single-region pinning available, data does not leave the chosen EU region during processing
- No transfer outside the EU/EEA unless you explicitly choose a non-EU region
- Region is selectable per API key; Enterprise customers can enforce it organisation-wide
4. International data transfers
Abscode Technologies LLP is established in India, a country that does not currently have an EU adequacy decision. Even when you select the EU storage region, operating and supporting the service may involve access by our India-based team, and choosing a non-EU region stores data outside the EU/EEA. Every such transfer is a "restricted transfer" protected by appropriate safeguards under Chapter V GDPR:
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporated into our DPA
- UK International Data Transfer Addendum for UK GDPR transfers
- Swiss addendum for transfers subject to the Swiss FADP
- A Transfer Impact Assessment (TIA) and supplementary measures documentation available on request
5. Data subject rights
GDPR grants data subjects the rights of access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection, and rights relating to automated decision-making. As your Processor, Abscode helps you meet these requests by:
- Providing data export APIs to retrieve a data subject's records on request
- Supporting forced deletion within 7 days of your instruction
- Maintaining audit logs of access, correction, and deletion actions
Because Abscode acts on your instructions, end users should address rights requests to you (the Controller); we will assist you in responding within the GDPR timelines.
6. Data minimisation & document handling
- Documents auto-purged within 24 hours of API response delivery (default); optional 5-minute purge per API key
- Documents and personal data are never used to train models
- TLS 1.3 in transit, AES-256-GCM at rest, keys rotated via cloud KMS
- PII Masking API available to redact personal data before archival
- Processing limited to what is necessary to deliver the requested API/SDK result
7. Sub-processors
We use a limited set of vetted sub-processors (cloud hosting, AI inference, and payments). Each is bound by data-protection terms no less protective than our DPA. We maintain a current sub-processor list and give 30 days' notice before adding or replacing one, during which you may object. Request the list from privacy@abscode.com.
8. Personal data breach notification
- Abscode notifies affected customers without undue delay and within 72 hours of becoming aware of a personal data breach
- Notification includes enough detail for you to meet your own Article 33 / 34 obligations to your supervisory authority and data subjects
- Report or query a security incident: security@abscode.com
9. Cross-border status & EU representative (Article 27)
Abscode Technologies LLP is established in India and has no office or establishment in the EU or EEA. Where Article 27 GDPR requires a non-EU organisation to designate a representative in the Union for a given processing activity, we will appoint one and publish its details here. In the meantime, EU/EEA data subjects and supervisory authorities can contact our Data Protection Officer at dpo@abscode.com, who will handle or route the enquiry.
10. Data Protection Officer
GDPR queries, DPA and SCC requests, sub-processor lists, and breach reports: dpo@abscode.com. See also our Privacy Policy, Security overview, and India DPDP compliance.
Need a DPA + SCCs in place before you go live?
Enterprise customers receive a pre-signed DPA with SCCs as part of contract negotiation. Standard self-serve customers can request our standard DPA from legal@abscode.com, usually executed within 5 business days.