Legal & Policies

Data Protection Policy

HEDj Financial Risk Management Ltd · Last updated 15 June 2026 · Version 1.0

This policy describes how HEDj meets its obligations under the EU GDPR, the Irish Data Protection Act 2018, the UK GDPR and the UK Data Protection Act 2018. It is distinct from our customer-facing Privacy Policy, which tells you how we use your personal data.

1. Purpose and scope

This policy sets out HEDj's commitment to protecting personal data and the controls we apply. It applies to all staff, contractors and partners who process personal data on HEDj's behalf, and to all systems and processes that handle personal data.

2. Roles and responsibilities

3. Data protection principles

We process personal data:

  1. Lawfully, fairly and transparently: with a valid legal basis and clear privacy information.
  2. For specified, explicit and legitimate purposes: and not in incompatible ways.
  3. Minimised: only what is necessary.
  4. Accurately: kept up to date.
  5. For no longer than necessary: per our retention schedule.
  6. Securely: with appropriate technical and organisational measures.
  7. Accountably: we can demonstrate compliance.

5. Data protection by design and by default

New systems, features and significant changes follow our internal compliance controls, including a screening assessment and, where triggered, a Data Protection Impact Assessment (DPIA).

6. Records we maintain

7. Retention

Default retention: account life + 6 years after account closure, to meet financial/tax/legal record-keeping obligations. Anonymised research data may be kept indefinitely. The full retention schedule is maintained by the DPO and reviewed annually.

8. International transfers

Hosting and AI inference are kept within the EEA (AWS eu-north-1; AWS Bedrock EU region). Any transfer of personal data outside the EEA/UK requires a documented safeguard (adequacy, SCCs + UK Addendum) and a Transfer Impact Assessment, approved by the DPO before go-live.

9. Processors and partners

10. Personal data breaches

11. Data subject rights

We action access, rectification, erasure, restriction, portability, objection and consent-withdrawal requests within one month (extendable for complexity). The DPO owns the request-handling process and log.

12. Training and awareness

All staff receive data protection training at induction and at least annually. Engineering teams are trained on our compliance controls.

13. Review

This policy is reviewed at least annually and whenever there is a material change in processing, technology, or law.