Data Protection Policy
This policy describes how HEDj meets its obligations under the EU GDPR, the Irish Data Protection Act 2018, the UK GDPR and the UK Data Protection Act 2018. It is distinct from our customer-facing Privacy Policy, which tells you how we use your personal data.
1. Purpose and scope
This policy sets out HEDj's commitment to protecting personal data and the controls we apply. It applies to all staff, contractors and partners who process personal data on HEDj's behalf, and to all systems and processes that handle personal data.
2. Roles and responsibilities
- Data controller: HEDj Financial Risk Management Ltd.
- Data Protection Officer: Gearoid Keegan (support@hedj.eu), owns this policy, advises on compliance, is the contact point for the DPC/ICO and data subjects, and maintains our records.
- Engineering leads: responsible for embedding data protection by design into systems.
- All staff: must follow this policy and report suspected breaches immediately.
3. Data protection principles
We process personal data:
- Lawfully, fairly and transparently: with a valid legal basis and clear privacy information.
- For specified, explicit and legitimate purposes: and not in incompatible ways.
- Minimised: only what is necessary.
- Accurately: kept up to date.
- For no longer than necessary: per our retention schedule.
- Securely: with appropriate technical and organisational measures.
- Accountably: we can demonstrate compliance.
4. Lawful basis and consent management
- Every processing activity is mapped to a lawful basis in our Record of Processing Activities (ROPA).
- Consent is required for: AI-assisted processing, marketing cookies/communications, anonymised-data research (opt-in), access to locally stored customer data, and sharing with ancillary product partners. Consent must be freely given, specific, informed, unambiguous, recorded with a timestamp, and as easy to withdraw as to give.
- A non-AI equivalent remains available for substantially all functionality so that consent to AI processing is genuinely optional.
5. Data protection by design and by default
New systems, features and significant changes follow our internal compliance controls, including a screening assessment and, where triggered, a Data Protection Impact Assessment (DPIA).
6. Records we maintain
- Record of Processing Activities (ROPA).
- Consent records (what, when, how, and version of notice).
- Data Processing Agreements (DPAs) with all processors/sub-processors.
- Transfer Impact Assessments and safeguards (SCCs/UK Addendum) for any non-EEA transfer.
- DPIAs for high-risk processing.
- Breach register.
7. Retention
Default retention: account life + 6 years after account closure, to meet financial/tax/legal record-keeping obligations. Anonymised research data may be kept indefinitely. The full retention schedule is maintained by the DPO and reviewed annually.
8. International transfers
Hosting and AI inference are kept within the EEA (AWS eu-north-1; AWS Bedrock EU region). Any transfer of personal data outside the EEA/UK requires a documented safeguard (adequacy, SCCs + UK Addendum) and a Transfer Impact Assessment, approved by the DPO before go-live.
9. Processors and partners
- All processors must be under a written DPA before they receive personal data.
- AISP/PISP and ancillary product partners must be appropriately authorised for the regulated activity they perform; data is shared only as necessary to deliver the requested service, and (for ancillary products) only on the customer's request/consent.
- New sub-processors are assessed and added to the sub-processor list; customers are notified where required.
10. Personal data breaches
- All suspected breaches must be reported to the DPO immediately.
- The DPO assesses risk and, where required, notifies the DPC and/or ICO within 72 hours, and affected individuals without undue delay where the risk is high.
- All breaches are logged in the breach register with cause, impact and remediation, whether or not they are notifiable.
11. Data subject rights
We action access, rectification, erasure, restriction, portability, objection and consent-withdrawal requests within one month (extendable for complexity). The DPO owns the request-handling process and log.
12. Training and awareness
All staff receive data protection training at induction and at least annually. Engineering teams are trained on our compliance controls.
13. Review
This policy is reviewed at least annually and whenever there is a material change in processing, technology, or law.