GDPR & Security

    Your trust, our priority.

    At ACEVO and GenderGov, data privacy and security are built into everything we do. We design our consulting services and digital platforms in line with GDPR principles of privacy by design and by default.

    Our goal is to give organisations confidence that their data is handled responsibly, securely, and transparently.

    GDPR Compliance

    Privacy by Design

    All platforms are structured to minimise personal data collection.

    Data Subject Rights

    We support clients in responding to access, correction, export, or deletion requests under GDPR.

    Data Hosting in Europe

    Client data is stored on secure European servers that meet recognised international standards (ISO 27001, SOC 2).

    Data Retention

    We retain only what is necessary for service delivery and client obligations.

    Security Practices

    We take a layered approach to data protection, focusing on encryption, access control, and monitoring.

    Encryption

    • Data in transit: Encrypted with TLS 1.2+ protocols.
    • Data at rest: Secured with AES-256+ disk encryption.

    Access Control

    • Role-based access ensures only authorised users can view sensitive data.
    • Internal access for ACEVO staff follows the principle of least privilege.
    • Two-factor authentication is enforced for admin systems.
    • Access rights are reviewed and promptly revoked when no longer required.

    Logging & Monitoring

    • All user and admin actions are logged.
    • Alerts are in place to detect abnormal activity.
    • Security logs are regularly reviewed.

    Data Centre Security

    • Our platforms are hosted on leading European cloud providers with ISO 27001 and SOC 2 certifications.
    • Facilities include protections against fire, power loss, and unauthorised physical access.

    Independent Assurance

    We are committed to continuous improvement. Our roadmap includes:

    • Regular vulnerability scans.
    • Independent penetration testing as the platform scales.
    • Security self-assessments for transparency with clients.

    Transparency

    We provide clients with clear documentation on our data handling and security posture.

    Our Data Processing Agreement (DPA) and list of sub-processors are available on request.

    Contact Information

    For further details about our GDPR compliance and security practices, please contact:

    ACEVO Global Advisory Pvt. Ltd.
    📧 support@acevoglobal.com
    🌐 www.acevoglobal.com