We build compliance tooling, so we hold ourselves to the standards we help you meet. This page sets out how we protect the information you and your team put into PrivMatrix, who we rely on to run the service and how to get the documents your procurement and legal teams will ask for.
Encryption in transit, least-privilege access, passwordless sign-in and optional two-factor for every account.
A short, named list of sub-processors, each vetted and used only to run the service you signed up for.
Our Data Processing Agreement is ready to review and counter-sign, and it references this live sub-processor list.
The controls that protect your assessment answers, intake and generated packs.
All traffic to and from the service runs over TLS (HTTPS). Sign-in links and download links use unguessable, single-purpose tokens.
Only the people who need to operate the service can reach production data, and administrative access is role-based and logged.
Customers sign in with a one-time email link, never a reusable password. Any account can add app-based two-factor authentication.
Sign-ins, team changes, security changes and billing actions are recorded in an internal audit trail we can review if a question arises.
We keep each type of data only as long as it is needed, then delete it on a published schedule (see below), not indefinitely.
The product does not load third-party advertising or analytics trackers, and it does not sell personal data.
A straight answer on where we stand, because you are trusting us with your compliance data.
We are not yet certified to ISO 27001 or SOC 2. We operate the equivalent controls set out on this page - encryption in transit, least-privilege access, audit logging, defined retention and a breach response plan - and we are happy to walk your security team through them.
Formal ISO 27001 certification is on our roadmap as we grow. We would rather tell you plainly where we are than imply a certificate we do not yet hold.
Our documents are built from primary-source law, market by market. Our methodology page sets out the laws behind each market, the grade system and our currency process.
Found a vulnerability? Email info@privmatrix.com with the details and we will respond promptly. Please give us a reasonable window to fix it before any public disclosure.
Hosting location and the legal entity responsible for the service.
When you buy a compliance pack, you are the controller of the personal data inside your own intake answers and we act as your processor to generate the documents. Our Data Processing Agreement sets out that relationship in full.
The third parties that help us run PrivMatrix. Each is bound by contract to protect your data and to use it only to provide their service to us. We update this list before adding a new sub-processor.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Cloud hosting provider | Runs the application and database that store your account, intake answers and generated packs | Account details, assessment and intake data, generated documents | United Kingdom |
| Transactional email provider | Delivers sign-in links, invoices, pack notifications and receipts | Name and email address, message content | Provider network |
| Stripe | Processes card payments and issues invoices | Billing name, email, payment details (handled by Stripe, not stored by us) | Stripe global infrastructure |
The specific hosting and email vendors are named in the signed Data Processing Agreement. To be notified of changes to this list, email info@privmatrix.com and ask to be added to our sub-processor notice list.
How long we keep each type of data before deletion.
| Data | Kept for | Then |
|---|---|---|
| Assessment answers and contact details | Up to 2 years from last activity | Marked deleted and removed from working systems |
| Your generated pack and its download link | 90 days from creation (live download) | Archived for 30 more days for re-issue, then permanently deleted at 120 days |
| Intake answers behind a paid order | Kept with your order so you can review and regenerate | Deleted with the order under the limits above |
| Invoices and payment records | As required by tax and accounting law | Retained only for that legal obligation |
Full detail, including the legal bases we rely on, is in our Privacy Notice.
Everything your procurement, security and legal teams typically ask for.
Our standard controller-to-processor DPA, ready to review and counter-sign. Read the DPA →
Send us your standard questionnaire and we will complete and return it.
This Trust Center describes our current practices and is provided for information. It does not vary the signed agreement between us, which governs if there is any conflict. See also how we build packs.
Cookie consent, data requests, the Trust Center and monitoring all read from the same compliance core - your markets, your documents and your obligations, defined once and shared across every module.