Data Protection and GDPR

CDE Sync is provided strictly to organisations. No individual can register for or purchase the service: user accounts exist only where a customer organisation provisions them, and sign-in federates through that organisation's own Microsoft Entra tenant. We never see or store passwords.

Our roles

For customers subject to the UK GDPR or EU GDPR, Utopia Digital is the controller of organisational user account data (name, business email, Entra object ID), organisation contact details, and audit logs, collected to operate and secure the service, and the processor of file content synchronised between your connected systems, governed by our Data Processing Agreement. File content is transferred, not stored: our zero-persistence architecture retains no customer content.

What we hold and what we don't

We hold: names, business email addresses, Entra object identifiers, audit records, and connection usernames. We do not hold: special category data, criminal offence data, passwords, or payment card details. Our application sets no cookies. Our website sets analytics cookies only if you accept them through the cookie banner; you can decline them, and change your choice at any time through Cookie Preferences.

Where your data lives

File content is processed and staged in your contracted service region (Australia East, North Europe, or East US) and moves between regions only when you explicitly move it. Account and audit data is stored on secured infrastructure in Azure Australia East: private endpoints, Microsoft Entra-only authentication, TLS 1.2 in transit, encryption at rest.

International transfers

Australia is not covered by a UK or EU adequacy decision, so our DPA incorporates the EU Standard Contractual Clauses (Module Two) and the ICO's UK International Data Transfer Addendum for customers subject to either regime. We provide the information you need for your transfer risk assessment.

Representatives

We have assessed that Article 3(2) of the UK GDPR and EU GDPR does not apply to our own processing: we offer services only to organisations, and our website analytics are consent-based and used for aggregate measurement only, with no advertising features and no profiling. No Article 27 representative is required. The assessment is reviewed annually.

Analytics

Our website analytics are consent-based. Google Analytics and Squarespace Analytics set cookies only if you accept them through the cookie banner, and you can decline or withdraw your consent at any time through Cookie Preferences. Unless you consent, no analytics cookies or device identifiers are set: Google Analytics runs in cookieless consent mode, no individual is tracked across pages, and Google discards IP addresses at ingestion. We use analytics for aggregate site measurement only, with no advertising features and no profiling. Google is certified under the EU-US Data Privacy Framework and its UK Extension.

Individual rights

For personal data we process on your organisation's behalf, direct requests to your organisation. We support its response under the DPA. For account data we control, contact security@utopiadigital.io.

Breach notification

We notify affected customers without undue delay under the DPA and support your 72-hour notification obligations to the ICO or your supervisory authority.

Documents

All security and compliance documentation is available through our Security Trust Portal www.utopiadigital.io/security-trust-portal: the Data Processing Agreement (including the EU SCCs and UK Addendum), the sub-processor list, our security policies, SOC 2 Type II report, and penetration testing results.

Questions: security@utopiadigital.io

Last updated: 17 August 2026