Trust Center
Security & trust, in the open.
How Optivance protects your data, the regulations we follow, and where we stand on industry standards — written plainly, with no certification claimed that we don't hold.
Compliance status
Updated regularly. Statuses are stated honestly — we never claim a certification we don't hold.
| Standard | Why it matters | Status |
|---|---|---|
| UK GDPR The UK General Data Protection Regulation governs how the personal data of UK individuals is processed. | It is the primary data protection law for any business handling UK customer or user data. | ● Compliant |
| EU GDPR The EU General Data Protection Regulation applies when processing personal data of individuals in the EU/EEA. | Required for serving EU customers and for lawful cross-border data transfers. | ● Compliant |
| Data Protection Act 2018 The UK law that sits alongside and supplements the UK GDPR. | Defines UK-specific rules and the Information Commissioner's Office (ICO) powers. | ● Compliant |
| PCI DSS Payment Card Industry Data Security Standard for handling cardholder data. | Applies wherever card payments are processed. | ● Supported |
| Cyber Essentials UK government-backed scheme covering five core technical security controls. | Demonstrates baseline cyber hygiene; often expected by UK public-sector buyers. | ● Planned |
| ISO/IEC 27001 International standard for an Information Security Management System (ISMS). | Independent assurance that information security is managed systematically. | ● Planned |
| SOC 2 AICPA Trust Services Criteria report on security, availability, and confidentiality. | Commonly requested by enterprise and US customers during procurement. | ● Planned |
| HIPAA US healthcare rules for protected health information (PHI). | Relevant only when serving US healthcare customers handling PHI. | ● Not Applicable |
Security & privacy FAQ
Who owns the data I put into Optivance?+
You do. You retain full ownership of all data you and your customers create on the platform. We process it solely to provide the service, under your instructions, as set out in our Data Processing Agreement (DPA).
Is my data encrypted?+
Yes. Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed through Google Cloud Key Management Service (KMS).
Where is my data stored?+
Customer data is hosted on Google Cloud Platform in the London region (europe-west2), within the United Kingdom.
Do you comply with UK GDPR?+
Yes. We process personal data in line with the UK GDPR and the Data Protection Act 2018. Our Privacy Policy and DPA set out the details.
Are you ISO 27001 or SOC 2 certified?+
Not yet. We operate to recognised security practices and are building towards formal certification — our Compliance page shows the current status of each standard, stated honestly. We never claim a certification we do not hold.
Do you offer a Data Processing Agreement (DPA)?+
Yes. A DPA is available to all customers and forms part of our standard terms. Request a signed copy at privacy@optivance.co.uk.
How are passwords stored?+
Passwords are never stored in plain text. They are hashed using bcrypt with a per-user salt, and we screen against known-breached credentials.
Do you support multi-factor authentication (MFA)?+
Yes. MFA is available on all accounts and can be enforced organisation-wide.
Do you support Single Sign-On (SSO)?+
SSO via SAML 2.0 and OpenID Connect is available on our Business plan. Contact us to enable it for your organisation.
How often do you back up data?+
Backups run automatically every day, are encrypted, and are stored separately from production with a 35-day retention period.
What is your uptime target?+
Our target availability is 99.9%. Business customers can request a contractual SLA. Live status is published at our status page.
What happens to my data if I cancel?+
You can export your data at any time. After a 30-day grace period following termination, we securely delete customer data from production systems, and backups expire on the standard 35-day cycle.
Can I export my data?+
Yes. You can export your data at any time in a structured, machine-readable format from your account or via our API.
Can I request deletion of my personal data?+
Yes. UK GDPR requests, including erasure, can be made to privacy@optivance.co.uk. We respond within the statutory timeframe (normally one month).
Do you transfer data outside the UK/EU?+
Customer data is stored in the UK. Some sub-processors (e.g. AI, payments, telephony) are based in the US; those transfers are protected by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
Which sub-processors have access to my data?+
Only those needed to run the service: Google Cloud (hosting), Anthropic (AI), Stripe (payments), and Twilio (calls and SMS). Each is bound by data protection terms, and we notify customers in advance of material changes.
How do you handle security incidents?+
We maintain a documented incident response plan. Affected customers are notified without undue delay, and we notify the ICO within 72 hours of becoming aware of a qualifying personal data breach.
How can I report a security vulnerability?+
See our Responsible Disclosure Policy and email security@optivance.co.uk. We acknowledge reports within three business days and will not pursue good-faith researchers.
Do you use cookies?+
We use strictly necessary cookies to run the service and, with your consent, privacy-focused analytics cookies. See our Cookie Policy to manage your preferences.
Do you use my data to train AI models?+
No. We do not use your data to train shared or third-party AI models. AI processing is performed only to deliver the feature you requested, under your instructions, and our AI provider does not train on data sent through the API.
Can I get audit logs of activity in my account?+
Yes. Audit logs of key actions are available and can be exported for your own monitoring and compliance needs.
Do you support IP allowlisting?+
Yes, on our Business plan, letting you restrict access to approved networks.
Need our security pack for procurement?
We're happy to share our DPA, sub-processor list, and answer your security questionnaire.