GDPR & Security
Your trust, our priority.
At ACEVO and GenderGov, data privacy and security are built into everything we do. We design our consulting services and digital platforms in line with GDPR principles of privacy by design and by default.
Our goal is to give organisations confidence that their data is handled responsibly, securely, and transparently.
GDPR Compliance
Privacy by Design
All platforms are structured to minimise personal data collection.
Data Subject Rights
We support clients in responding to access, correction, export, or deletion requests under GDPR.
Data Hosting in Europe
Client data is stored on secure European servers that meet recognised international standards (ISO 27001, SOC 2).
Data Retention
We retain only what is necessary for service delivery and client obligations.
Security Practices
We take a layered approach to data protection, focusing on encryption, access control, and monitoring.
Encryption
- Data in transit: Encrypted with TLS 1.2+ protocols.
- Data at rest: Secured with AES-256+ disk encryption.
Access Control
- Role-based access ensures only authorised users can view sensitive data.
- Internal access for ACEVO staff follows the principle of least privilege.
- Two-factor authentication is enforced for admin systems.
- Access rights are reviewed and promptly revoked when no longer required.
Logging & Monitoring
- All user and admin actions are logged.
- Alerts are in place to detect abnormal activity.
- Security logs are regularly reviewed.
Data Centre Security
- Our platforms are hosted on leading European cloud providers with ISO 27001 and SOC 2 certifications.
- Facilities include protections against fire, power loss, and unauthorised physical access.
Independent Assurance
We are committed to continuous improvement. Our roadmap includes:
- Regular vulnerability scans.
- Independent penetration testing as the platform scales.
- Security self-assessments for transparency with clients.
Transparency
We provide clients with clear documentation on our data handling and security posture.
Our Data Processing Agreement (DPA) and list of sub-processors are available on request.
Contact Information
For further details about our GDPR compliance and security practices, please contact:
ACEVO Global Advisory Pvt. Ltd.
📧 support@acevoglobal.com
🌐 www.acevoglobal.com
