Skip to main content

UK GDPR Compliance

Lawful basis, data minimisation, sub-processors, and your rights.

GDPR Compliance

CrownSync LTD processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how CrownSync Playbooks handles personal data, the lawful bases for processing, sub-processors used, and your rights as a data subject.

Lawful Basis for Processing

CrownSync processes personal data under the following lawful bases:

  • Contract performance (Article 6(1)(b))— Processing necessary to provide the CrownSync Playbooks service, including account management, playbook personalisation, and feature delivery.
  • Legitimate interests (Article 6(1)(f))— Processing necessary for security monitoring, audit logging, fraud prevention, and service improvement. A legitimate interest assessment has been conducted for each activity.
  • Legal obligation (Article 6(1)(c))— Processing necessary to comply with legal requirements, such as financial record-keeping and responding to lawful requests from authorities.

Data Minimisation

CrownSync collects only the personal data necessary to provide the service:

  • Account information: name, email address
  • Organisation details: company name, registration number, address
  • Usage data: actions performed on the platform (for the audit log)
  • Technical data: IP addresses (for security and audit purposes)

CrownSync does not collect sensitive personal data (special category data) as part of its service. If users include personal data within playbook content or incident records, they are responsible for ensuring appropriate safeguards.

Sub-Processors

Sub-ProcessorPurposeLocation
ResendTransactional email deliveryUnited States
HetznerCloud hosting infrastructureGermany (EU)
CloudflareCDN, DDoS protection, DNSGlobal (with EU data processing)

For sub-processors based outside the UK/EU, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.

User authentication is not a sub-processor: it is handled by CrownSync's own self-hosted Authentik identity provider, running on the same UK-managed infrastructure as the platform.

Data Retention

CrownSync retains personal data only for as long as necessary:

  • Account data— Retained while the account is active and for 30 days after deletion to allow for account recovery
  • Audit log data— Retained for the lifetime of the organisation account for compliance purposes
  • Incident data— Retained while the organisation account is active
  • Transactional emails— Delivery logs retained for 30 days by Resend

Your Rights

Subject Access Request (SAR)

You have the right to request a copy of all personal data CrownSync holds about you. Submit a SAR by emailing [email protected]with the subject line "Subject Access Request". Requests are fulfilled within one calendar month.

Right to Erasure

You can request deletion of your personal data by contacting [email protected]. Please note that audit log entries may be retained where there is a legal obligation or legitimate interest in maintaining the compliance record.

ICO Registration

CrownSync LTD is registered with the Information Commissioner's Office under registration number ZC109210. If you have concerns about how your data is processed, you have the right to lodge a complaint with the ICO.

Was this page helpful?