Skip to main content

Last updated: 18 July 2026

GDPR Readiness

Secuvon includes controls that can support GDPR work, but use of the product is not a GDPR certification or a substitute for legal analysis.

Controller/processor roles, lawful bases, hosting region, subprocessors, transfer mechanisms, and retention must be confirmed for the specific deployment and documented in the applicable contract.

1. Roles and scope

A managed Secuvon operator may act as processor for customer-provided scan data and as controller for its own account, security, and billing records. In a self-hosted installation where no data is sent to Techbunk Limited, the customer controls that environment and Techbunk may have no processor role. The signed terms determine the actual role.

2. Product controls

  • Authenticated export of a user's account and scan data.
  • Password-confirmed account deletion and erasure workflows.
  • Configurable retention for scans, reports, evidence, and audit logs.
  • Role-based access, MFA support, audit trails, and encrypted provider credentials.
  • Deployment controls for TLS, secure cookies, trusted hosts, and offsite backups.

These capabilities support an organisation's process; they do not by themselves establish a lawful basis, satisfy a data-subject request, or prove compliance.

3. Location and transfers

Data residency is deployment-specific. Self-hosted operators select their region. Managed customers should rely only on the region, subprocessor schedule, and transfer mechanism stated in their signed agreement. Model scan content is transmitted to each AI provider the customer selects.

4. Personal-data incidents

Incidents are assessed under the documented response plan. Where Secuvon is a processor, it must notify the controller without undue delay as required by the applicable DPA. Where it is a controller and a breach is likely to risk people's rights and freedoms, the competent supervisory authority must be notified without undue delay and, where feasible, within 72 hours after awareness. High-risk impacts can also require notice to affected people without undue delay.

5. Requests, DPOs, and DPIAs

Privacy requests can be submitted through the contact form. Secuvon does not claim that a statutory DPO has been appointed or that a DPIA has been completed. Those steps are required only in the circumstances set by law and must be assessed from the actual processing.

Individuals may lodge a complaint with the supervisory authority that is competent for their situation. See the European Commission's GDPR obligations guidance.