Enterprise GRC Platform
Data Protection & Privacy
End-to-end encryption, data residency options, GDPR compliance, and privacy-first architecture.
Data Classification & Handling
Compliance data is treated with the highest security standards.
Data Classification
- Highly confidential data encrypted end-to-end
- Separate encryption keys per customer
- Audit data encrypted separately
- No shared encryption keys across customers
Data Retention & Deletion
- Customer-controlled retention policies
- Cryptographic erasure for deleted data
- Backup encryption and deletion
- Right to deletion honored within 30 days
Data Residency & Sovereignty
Your data stays where you need it.
Tyndora offers flexible data residency options to meet regulatory and compliance requirements:
Data stored in AWS US regions (us-east-1, us-west-2)
Data stored in AWS EU regions (eu-west-1) for GDPR compliance
Data never leaves the region unless explicitly requested for backup/disaster recovery
DPA included with all contracts for regulatory compliance
GDPR & Privacy Compliance
Privacy-first design with regulatory requirements built in.
GDPR Compliance
- Data Protection Impact Assessments (DPIA)
- Privacy by design (PbD)
- User data portability
- Consent management
Privacy Rights
- Right to access your data
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to restrict processing
Sub-Processors & Vendors
Transparent vendor management.
All sub-processors handling customer data are approved and listed in our DPA. We maintain transparency about all third parties with access to compliance data.
Current Sub-Processors:
- • Amazon Web Services (AWS) — Cloud infrastructure
- • Datadog — Monitoring and logging
- • SendGrid — Email delivery
- • Stripe — Payment processing
- Updated sub-processor list available upon request
Privacy Questions?
Our privacy team is available to discuss data protection, residency, GDPR compliance, or to sign a DPA.
Contact us