Standards, regulations & privacy.
Our Commitment to Data Protection
At essensys, we respect your privacy and are committed to protecting your personal data. This compliance statement outlines our ongoing dedication to the General Data Protection Regulation (GDPR) and explains how we ensure data privacy across our business operations.
1. Lawful, Fair, and Transparent Processing
We collect and process personal data only when we have a legal basis to do so. We are transparent about why we collect information—whether it is to provide a service, fulfill a contract, or comply with legal obligations.
2. Data Security Measures
We implement robust technical and organizational security measures to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and system updates
- Strict access controls limiting internal data visibility to authorized personnel
3. Third-Party Processors
We work only with trusted third-party service providers and partners who offer sufficient guarantees of GDPR compliance. We establish formal Data Processing Agreements (DPAs) with every vendor to ensure your data remains protected when shared externally.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the specific purposes outlined at the time of collection, or to satisfy legal, accounting, and reporting requirements. Once data is no longer needed, it is securely deleted or anonymized.
5. Your Data Subject Rights
Under the GDPR, individuals have significant control over their personal data. You have the right to:
- Access the personal data we hold about you
- Rectify or correct inaccurate or incomplete data
- Erasure (request that we delete your data)
- Restrict or Object to our processing of your data
- Data Portability (receive your data in a structured format)
- Withdraw Consent at any time where processing relies on consent
Contact Us
If you have questions about this statement, wish to exercise your data rights, or need to contact our Data Protection team, please reach out to us at:
- Email: dpo@essensys.tech
- Address: 61 Whitechapel High St, London E1 7PE
essensys Information Security Policy
essensys has set forth in our business plan information security objectives consistent with ISO 27001. Department and project managers are informed and trained on these objectives for incorporation into their respective roles and teams.
We stand by the following on-going security objectives:
- Information is only accessible to authorised persons from within or outside the organisation and levels of access are determined by CIO or by delegated authority.
- Confidentiality, integrity and availability of information and systems are maintained.
- Business continuity plans are established, maintained and tested.
- All personnel are trained on information security and are informed that compliance with the policy is mandatory.
- All breaches of information security and suspected weaknesses are to be reported to the CIO and investigated and appropriate actions taken.
- Relevant procedures exist to support the policies in place.
- Regular audits of the processes and policies are conducted to ensure continuous review and improvement of the IBMS.
- New systems or services are deployed in a controlled and secure manner
- As far as is possible, essensys avoids breaches of legal, regulatory and contractual requirements.
Whilst the above company objectives are high-level, we have further analysed and categorised these into our Risk & Opportunities Matrix. In some cases, this may allow for specific objectives to be set across different functions. This demonstrates how we measure and set targets in meeting the high-level objectives.