GDPR
Last updated: July 28, 2026
1. What GDPR is
The General Data Protection Regulation is the EU law that governs how personal data of people in the EEA is collected and used. It gives people specific rights over their data and requires organisations that handle that data to have a lawful basis for doing so, to be transparent about it, and to keep it secure. The UK has its own equivalent (UK GDPR), which we treat the same way.
2. Status Quo 247's role
Two different roles apply depending on the data:
- Controller — for personal data collected on our marketing site at statusquo247.com (for example, when you fill in the contact form). We decide the "why" and the "how" for that data.
- Processor — for personal data captured through the Status Quo 247 product about a customer's employees. The employer is the controller and instructs us. See our Data Processing Agreement for the details.
3. Legal bases we rely on
- Contract (Art. 6(1)(b)): to respond to a demo request, to run a trial, or to deliver the Status Quo 247 service to a paying customer.
- Consent (Art. 6(1)(a)): for non-essential analytics cookies on the marketing site.
- Legitimate interests (Art. 6(1)(f)): to secure our systems, prevent abuse, and understand which parts of our site are useful. We keep this narrow.
- Legal obligation (Art. 6(1)(c)): to meet tax, accounting, and lawful-request obligations.
When the Status Quo 247 product processes employee data, the employer chooses the legal basis under EU law (commonly Art. 6(1)(b) employment contract, Art. 6(1)(c) legal obligation for payroll and tax, or Art. 6(1)(f) legitimate interests for reasonable workplace monitoring, with the safeguards local law requires).
4. Your rights and how to use them
Under GDPR you have the following rights:
- Right of access — to know what personal data we hold about you and to get a copy.
- Right to rectification — to have inaccurate data corrected.
- Right to erasure ("right to be forgotten") — to have your data deleted where the law allows.
- Right to restriction — to have processing paused in certain circumstances.
- Right to data portability — to receive your data in a common machine-readable format, and to have it transferred to another controller where technically feasible.
- Right to object — to processing based on legitimate interests, and to direct marketing at any time.
- Right regarding automated decisions — not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you.
- Right to withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal.
If you're a site visitor and your data is with us as controller (for example, you filled in the contact form), email privacy@statusquo247.com. We aim to respond within one month.
If you're an employee of an Status Quo 247 customer, your employer is the controller. Please contact your employer first — they decide what happens to your data. If they instruct us, we will act. Our DPO can be contacted at dpo@statusquo247.com for support, but we cannot delete or export employer-controlled data without the employer's instruction.
5. International data transfers
Where personal data leaves the EEA or the UK to a country without an adequacy decision, we use the European Commission's Standard Contractual Clauses (and the UK Addendum where UK data is involved), together with encryption in transit and role-based access controls, as our transfer safeguard.
6. Data Protection Officer
Our Data Protection Officer can be reached at dpo@statusquo247.com, or by post at [Company address — to be filled], attn: DPO.
7. Complaining to a supervisory authority
You have the right to lodge a complaint with the data protection authority in the EEA member state where you live, where you work, or where the alleged infringement took place. In the UK, that authority is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address any concern first, but this right is unaffected by asking us.
8. Retention
| Category | Retention period |
|---|---|
| Contact-form submissions (marketing site) | Up to 24 months from last interaction |
| Site request logs (IP for rate limiting) | 30 days |
| GA4 analytics | 14 months |
| Screenshots (product) | 90 days by default, configurable by employer |
| Session recordings (product) | 30 days by default, configurable by employer |
| Attendance and activity metrics (product) | Term of the customer's account, then return-or-delete under the DPA |
| Payroll records (product) | As required by the employer's applicable tax and labour law |
9. Sub-processors
The current list of sub-processors is maintained in Annex III of our Data Processing Agreement. We give customers at least 30 days' notice before adding or replacing a sub-processor.