Home UK GDPR Statement
Statutory Compliance

UK GDPR Statement & Data Processing Terms

Last Updated: September 2026 · BIZZLOOP LTD (Company No: 17319641)

Commitment to Data Sovereignty: BIZZLOOP LTD (Company No: 17319641) is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018. We operate with strict data protection by design and by default across all our managed business platforms.

1. Our Dual Role Under UK GDPR

Under the UK GDPR, BizzLoop operates under two well-defined capacities:

Data Controller

For our website visitors, commercial subscribers, partner applicants, and administrative billing records. See our Privacy Policy.

Data Processor (Article 28)

When hosting, maintaining, and managing our clients' own customer lists, enquiry records, and operational databases inside their BizzLoop workspace.

2. Article 28 Data Processor Commitments

When acting as a Data Processor on behalf of our business clients, BIZZLOOP LTD binds itself to the statutory obligations of UK GDPR Article 28:

  • Documented Instructions: We process client customer data strictly in accordance with documented instructions from the client, as set out in the service contract.
  • Staff Confidentiality: Every team member authorized to access systems is bound by strict statutory non-disclosure and confidentiality agreements.
  • Technical & Organisational Measures (TOMs): We enforce rigorous security including TLS 1.3 encryption in transit, AES-256 database encryption at rest, regular vulnerability reviews, and principle of least privilege access.
  • Vetted Sub-processors: Sub-processors (such as certified UK hosting facilities and secure payment gateways) are bound by equivalent data protection obligations under formal written agreements.
  • Assistance with Data Subject Rights: We provide our clients with the technical tools and assistance required to fulfill Subject Access Requests (SARs), rectifications, and deletions for their end-customers.
  • 72-Hour Breach Notification: In the event of a confirmed security incident impacting client personal data, BizzLoop will notify the affected client without undue delay and within 72 hours of becoming aware.
  • Data Return & Deletion: Upon termination of services, all customer data is either exported to the client or permanently and securely sanitized from our systems in accordance with client instructions.
  • Audit & Compliance Verification: We make available all information necessary to demonstrate compliance with UK GDPR Article 28 obligations.

3. UK Data Residency & Sovereignty

We recognize the paramount importance of data sovereignty for British firms. All primary client production databases and automated backups are hosted in ISO 27001 / SOC 2 certified data centres physically located within the United Kingdom.

4. Data Protection Contact

For questions regarding our UK GDPR compliance, Data Processing Agreements (DPA), or security audits, contact:

BIZZLOOP LTD - Data Protection Lead

Company No: 17319641

Email: [email protected]