Help  /  Security

GDPR overview

Our role

You are the data controller. Accolade is the data processor. You decide what data to collect, we process it on your instructions.

Data Processing Agreement (DPA)

A signed DPA is available free on Enterprise and Agency. Email privacy@accolade.live to request.

Subject access requests

If a nominee, judge, or guest asks you for their data, search their email in Accolade and export the result. Takes 2 minutes per request.

Right to be forgotten

You can delete any individual's records on demand. We support hard-delete (no soft-delete recovery) for GDPR erasure requests.

Data residency

All data hosted in the EU (Frankfurt + London). No transfers outside the EU/UK.

Sub-processors

List of every third party that touches your data (Aiven, Render, Stripe, Claude, etc) is at our GDPR page. We notify of any changes 30 days in advance.