Overview
The EU General Data Protection Regulation governs how the personal data of people in the EU is collected, used, and protected, and gives individuals rights over their data. It separates the data controller, who decides why and how data is processed, from the processor, who handles it on the controller’s behalf. How ControlBird relates to GDPR depends on how you run it. Self-hosted, you are the sole controller and the data never leaves your infrastructure. On the managed cloud, you remain the controller of your operational data while we act as its processor, and as controller only for the account and billing details needed to run the service. ControlBird is designed to support both paths; it does not replace your own GDPR programme.
Key requirements
- Lawful, transparent processing
- Collect personal data for clear purposes, tell people what you collect and why, and keep it to what you actually need.
- Data subject rights
- Let individuals access, correct, delete, and port their personal data, and object to processing.
- Security of processing
- Protect personal data with appropriate technical and organisational measures.
- Controlled transfers and processors
- Know your sub-processors and control transfers of personal data across borders.
How ControlBird aligns
- Self-hosting keeps you in control
- Run ControlBird on your own infrastructure and you are the sole data controller. The operational data, user records, and history stay on your systems and never reach us. You decide where it is hosted, how long it is kept, and when it is deleted, which makes the lawful-basis, residency, and transfer questions yours to answer directly. This is the most direct way to keep personal data inside your own GDPR boundary.
- Data minimisation on the managed cloud
- When we host ControlBird for you, the personal data we hold is limited to what running the service requires: your account details such as email and sign-in identity, and the billing reference for your subscription. Payment card details are handled by our payment processor, not stored by us, and we do not sell personal data.
- Exercising data subject rights
- Self-hosted, you serve access, correction, deletion, and export requests directly from your own database and backups. On the managed cloud you remain the controller of your operational data, and you can ask us to access, correct, or delete the account data we hold by contacting our privacy team. Our privacy policy sets out these rights and the contact route.
- Security of personal data
- Account access is protected by hashed passwords, role- and attribute-based access control enforced in the data layer, and TLS in transit, and sign-in can run through your own directory or identity provider. The same access controls that protect the system protect the personal data within it.
- Sub-processors and your own programme
- Running the managed service uses a small set of sub-processors for payments, email, and optional single sign-on, described in our privacy policy. GDPR ultimately governs your organisation’s processing, so your records of processing, lawful basis, any data protection impact assessments, and any data processing agreement remain yours to maintain. ControlBird is not GDPR certified, and self-hosting keeps the personal data on your side of that boundary.
Need this for a tender?
We can provide deployment-specific detail and supporting documentation for procurement and security reviews.