Ownership · Data handling · GDPR · DORA · EU AI Act
Your code. Your data. Your call.
You own the code and the system. No licensing, no lock-in, no source held back. Controls scale with the build.
Last updated: August 27, 2026 · This page is a summary; the Privacy Policy and DPA govern.
Standards
We do not claim compliance certifications we don't hold. We do build systems that pass them. Systems can be designed to support applicable DORA, EU AI Act and security requirements. Regulatory obligations and certification remain scope-specific.
ISO 27001
Not certified
We hold no ISO 27001 certification and don't claim one. We use the 2022 standard as a control reference where a client's procurement needs that vocabulary.
DORA
Design reference
Operational-resilience controls — continuity, incident handling, third-party risk — designed in where a financial-services client's obligations require them.
EU AI Act
Scope-specific
Risk classification, technical documentation and human-oversight controls, built into AI systems whose intended use brings them into scope.
GDPR
Contractual basis
DPA on file, data minimisation by default. Infrastructure is hosted in the UK and EU. Data residency is agreed per engagement.
GDPR roles
Under GDPR, responsibilities differ depending on whether an organisation is a Controller or a Processor. SerSan can act in either capacity depending on the engagement.
Our own operations
SerSan as Controller
- Website inquiries and lead handling
- Marketing communications to opted-in business contacts
- Hiring and contractor records
- Internal product and service improvements (analytics, logging)
Client AI engagements
SerSan as Processor
- Processing data on client instructions under a signed DPA
- Application data, model inputs/outputs, telemetry from client systems
- Client determines the purposes; we implement technical and organisational controls
- Access limited to the engagement team, audit-logged
Note: Data subjects whose data we process on a client's behalf should direct rights requests to the client (the Controller). We will route any request we receive to the relevant client without undue delay, and tell you we have.
How data flows
Compliance wired in, not stuck on at the end.
When a system handles sensitive or regulated data, this is the shape we build it in. Simpler systems need fewer of these stages; the diagram shows the full set.
GDPR · EU AI Act · DORA · ISO 27001 — the reference each checkpoint maps to, not a certification we hold.
Technical controls
Controls are scaled to the system: a workflow automation and a regulated production platform do not carry the same overhead.
Data minimisation
We request the narrowest read access required to do the work, prefer redacted samples over full datasets, and delete engagement data within 30 days of contract termination unless the DPA specifies otherwise.
Access control
Access limited to the people working on your engagement, and logged on the systems we operate. Systems you own keep your own logging. Credentials are revoked at the end.
Encryption
Encryption at rest and in transit on the systems we operate — AES-256 and modern TLS as standard. Systems you own keep the controls you already have.
Subprocessors
Site-collected data: Vercel (hosting, forms, cookieless analytics) and Resend (email delivery). No site database. Engagement data: cloud hosting (AWS, Google Cloud, Azure) and model APIs (Anthropic, OpenAI, Google), scoped per project. Named in the DPA, no NDA required.
AI stop path
Agentic systems ship with a documented way to stop them, operable by a named person on your side.
Eval gates
AI changes are graded against a test set before release, not judged by feel.
Output review
Human review paths for AI output wherever it reaches a customer or a regulator.
Frequently asked questions
Under a DPA, with data minimisation by default, documented retention and a named contact for rights requests. Infrastructure is hosted in the UK and EU. Data residency is agreed per engagement.
You do. Code, documentation and deliverables transfer to you on full payment, with no licence back to us. We keep only our pre-existing know-how, frameworks and internal tooling — never your system.
No. Most of what we build carries no sector regulation at all. Controls are scaled to the system: a workflow automation and a regulated production platform do not carry the same overhead. Where we host the work, it runs on cloud providers in the UK and EU, encrypted at rest and in transit, under its own project and credentials.
Retention
Engagement data is deleted within 30 days of contract end, unless the DPA specifies a longer regulatory hold. Lead data is retained for 24 months from last contact, then purged. Hiring data is retained for 6 months unless the candidate consents to a longer hold.
Contact
For DPA requests, security questionnaires or data subject requests, write to us directly. A founder answers, whether you have a procurement team or not.