Trust & security
GDPR Compliance
Protecting your data. Respecting your privacy. Building trust.
Data protection as a foundation of trust
At SupportSages, we understand that data protection is more than a compliance requirement — it is a fundamental part of building trust with our customers.
As a provider of CloudOps, DevOps, TechOps, managed infrastructure, technical support and security services, we may process customer information and personal data while delivering our services.
Our data protection practices are designed to support applicable requirements of the General Data Protection Regulation (GDPR) and to help our customers maintain appropriate security and privacy controls across their environments.
Your data remains your responsibility. Protecting it is ours.
Our commitment to GDPR
SupportSages follows a privacy- and security-focused approach to handling customer information. Where we process personal data on behalf of our customers, we generally act as a Data Processor, while the customer determines the purpose and means of processing as the Data Controller.
We process personal data only as required to deliver the contracted services, maintain and support customer environments, respond to incidents, and fulfil applicable contractual or legal obligations.
Our approach is built around key GDPR principles such as:
- Lawful and transparent processing
- Purpose limitation
- Data minimisation
- Appropriate data retention
- Confidentiality and security
- Controlled access
- Accountability
- Respect for data-subject rights
How SupportSages protects customer data
01
Data access based on business need
Access to customer systems and information is restricted to authorised personnel who require it to perform their assigned responsibilities. We apply appropriate access controls and permissions based on the nature of the service and customer environment. Where supported by the customer's platform, access permissions may be reviewed periodically to help ensure that access remains appropriate.
02
Confidentiality
Customer information is treated as confidential and is accessed only for legitimate business and service-delivery purposes. Personnel who are authorised to access customer information are subject to applicable confidentiality obligations. We do not use customer data for purposes unrelated to the contracted service unless otherwise authorised or required by applicable law.
03
Secure credentials & privileged access
Cloud, server and infrastructure management may require access to privileged accounts. SupportSages uses appropriate security practices for managing privileged credentials, including secure credential-management or secrets-management mechanisms where applicable. Access methods and security controls are agreed with customers based on the environment, service requirements and available platform capabilities.
Technical & organisational security measures
We apply appropriate technical and organisational safeguards based on the nature of the service and the risks associated with the processing. Depending on the service, these measures may include:
- Role-based access controls
- Least-privilege access
- Secure authentication mechanisms
- Credential and secrets management
- Secure remote access
- System patching and vulnerability management
- Logging and monitoring
- Change management
- Backup and recovery controls
- Incident detection and response
- Secure handling of customer information
- Access reviews and operational controls
The specific controls applicable to a customer environment may be defined through the relevant service agreement, statement of work or Data Processing Agreement.
Processing personal data on your behalf
When SupportSages processes personal data as part of providing services to a customer, processing is performed according to the customer's documented instructions and the applicable contractual terms. The exact categories of personal data processed depend on the services and systems involved.
The scope of processing may include information such as:
- Business contact information
- Usernames and account information
- Support tickets
- Server and application logs
- IP addresses
- System metadata
- Access records
- Infrastructure information
- Other information required to provide the contracted service
Data Processing Agreements
Clear responsibilities. Transparent processing. Where applicable, SupportSages can enter into a Data Processing Agreement (DPA) with customers. A DPA can define relevant responsibilities relating to:
- Subject matter and duration of processing
- Nature and purpose of processing
- Categories of personal data
- Categories of data subjects
- Confidentiality obligations
- Security measures
- Subprocessor requirements
- Assistance with data-subject requests
- Security incidents and breach response
- Data retention and deletion
- Return or deletion of personal data at the end of the service
Our goal is to provide customers with the contractual clarity they need when outsourcing infrastructure, cloud and technical operations.
Supporting data-subject rights
GDPR provides individuals with rights relating to their personal data. Depending on the applicable circumstances, these may include rights relating to:
- Access to personal data
- Correction or rectification
- Erasure
- Restriction of processing
- Objection to processing
- Data portability
When SupportSages processes personal data on behalf of a customer, we assist the customer with applicable data-subject requests in accordance with the relevant agreement and applicable requirements. If the personal data concerned belongs to one of our customers, the individual should generally contact the relevant customer or Data Controller first.
Data retention & deletion
We do not retain customer data indefinitely. Customer data is retained only for as long as required to provide the contracted services, fulfil legitimate operational requirements, meet contractual obligations or comply with applicable legal requirements.
At the end of the applicable service, customer data may be returned or deleted in accordance with the applicable agreement and legal retention requirements.
Security incident & data breach response
Security incidents can happen despite preventive controls. What matters is how quickly and responsibly they are identified and managed. SupportSages maintains processes for responding to security incidents that may affect customer environments or information.
- Detect→
- Contain→
- Investigate→
- Remediate→
- Communicate
Where an incident involving personal data occurs, SupportSages will follow the applicable contractual, legal and regulatory requirements for assessment, escalation and notification. Where required, we work with the relevant customer to support their obligations regarding personal-data breaches.
Subprocessors & third-party providers
Some services may rely on third-party cloud platforms, infrastructure providers, software vendors or other service providers. Where subprocessors are applicable to the processing of customer personal data, relevant requirements concerning authorisation, contractual safeguards, security and data protection responsibilities are addressed in accordance with the applicable agreement.
Customers can contact SupportSages for information regarding subprocessors relevant to their services.
International data transfers
SupportSages may provide services involving infrastructure, platforms, personnel or service providers located in different countries. Where personal data is transferred across jurisdictions and GDPR requirements apply, appropriate contractual, technical and organisational safeguards are considered based on the circumstances of the transfer.
Where applicable, recognised mechanisms such as appropriate contractual safeguards may be used to support lawful international data transfers.
Privacy by design & data minimisation
We believe that protecting data should begin before data is processed. Where applicable, our service design and operational practices consider:
- What information is actually required
- Who needs access
- How long information needs to be retained
- How access can be restricted
- How information can be protected
- How unnecessary data exposure can be reduced
Our objective is to minimise unnecessary access to customer information while maintaining effective service delivery.
GDPR across our services
Our data protection approach applies across the services we provide.
CloudOps
Secure cloud infrastructure management, monitoring, incident response, migration and optimisation.
Learn more →DevOps
Secure CI/CD practices, infrastructure automation, deployment management and operational support.
Learn more →TechOps
Server management, technical support, monitoring, patching, troubleshooting and operational maintenance.
Learn more →Security services
Security hardening, vulnerability management, monitoring, incident response and security-focused operational practices.
Learn more →Managed & white-label support
Confidential technical support delivered as an extension of your organisation or service team.
Learn more →Built for trust. Designed for security.
When you outsource your cloud, infrastructure or technical operations, you are not simply choosing a service provider. You are choosing a partner that may have access to critical systems, infrastructure and information. At SupportSages, we take that responsibility seriously.
Our GDPR-aligned data protection practices are designed to help customers reduce data-protection risks while maintaining reliable, secure and responsive IT operations.
Your customers trust you with their data. You can trust us to treat it with the same responsibility.