Compliance
Optivance's compliance posture against UK GDPR, EU GDPR, the Data Protection Act 2018, and industry standards.
Last updated: 30 June 2026
Compliance overview
We design Optivance to meet the data protection obligations that apply to a UK SaaS provider, and to help our customers meet theirs. The status of each standard is shown below and on our Trust Center. We state our position honestly and never claim a certification we do not hold.
Status definitions — Compliant: we meet the requirements of this law or standard. Supported: we provide features and controls that help you meet it. In Progress: work is actively underway. Planned: on our roadmap. Not Applicable: it does not apply to our service today.
UK GDPR — Compliant
The UK General Data Protection Regulation is the primary law governing the processing of UK individuals' personal data. Why it matters: it sets the lawful bases, individual rights, and accountability obligations for handling personal data. We process personal data lawfully, transparently, and for limited purposes, maintain records of processing, and provide a Data Processing Agreement to all customers.
EU GDPR — Compliant
The EU GDPR applies when we process personal data of individuals in the EU/EEA. Why it matters: it is required for serving EU customers and for lawful cross-border transfers. We apply the same controls and rights-handling for EU data subjects, supported by appropriate transfer safeguards.
Data Protection Act 2018 — Compliant
The DPA 2018 supplements the UK GDPR with UK-specific provisions and defines the powers of the ICO. Why it matters: it completes the UK data protection framework we operate under.
PCI DSS — Supported
The Payment Card Industry Data Security Standard governs the handling of cardholder data. Why it matters: it applies wherever card payments are processed. Our position: card payments are processed by Stripe, a PCI DSS Level 1 certified provider. Cardholder data is handled entirely by Stripe and never stored on our systems, which minimises our PCI scope.
Cyber Essentials — Planned
A UK government-backed certification covering five core technical controls. Why it matters: it demonstrates baseline cyber hygiene and is often expected by UK public-sector buyers. Our position: Cyber Essentials is on our certification roadmap; the underlying controls are already in place.
ISO/IEC 27001 — Planned
The international standard for an Information Security Management System. Why it matters: it provides independent assurance that information security is managed systematically. Our position: we operate to ISO 27001-aligned practices and intend to pursue formal certification as we scale. We will publish the certifying body and scope here once certified.
SOC 2 — Planned
An AICPA attestation against the Trust Services Criteria. Why it matters: it is frequently requested by enterprise and US customers during procurement. Our position: planned. We will not reference a SOC 2 report until an independent auditor has issued one.
HIPAA — Not Applicable
US healthcare rules for protected health information. Why it matters: relevant only when serving US healthcare customers handling PHI. Our position: Optivance is not marketed to, and is not used by, US healthcare customers handling PHI, so HIPAA does not currently apply.
Our roadmap
Our compliance roadmap prioritises Cyber Essentials, followed by ISO/IEC 27001 certification. We will update the statuses above as each milestone is reached, and never ahead of it.
Questions about this? Contact our security & privacy team.
Contact us