GDPR Compliance
Last updated: January 1, 2026
Table of Contents
This page explains how UnivoCorp complies with the General Data Protection Regulation (GDPR) and helps our customers meet their GDPR obligations.
1. Our Commitment to GDPR
UnivoCorp is fully committed to compliance with the General Data Protection Regulation (GDPR). We have implemented comprehensive measures to protect the personal data of EU residents and ensure their rights are respected.
2. Data Controller vs Data Processor
When you use UnivoCorp, your organization is typically the Data Controller—responsible for determining how and why personal data is processed.
UnivoCorp acts as a Data Processor—we process personal data on behalf of your organization according to your instructions and our Data Processing Agreement.
3. Lawful Basis for Processing
We process personal data based on the lawful bases defined in GDPR Article 6. For our customers, processing is typically based on contractual necessity or legitimate interests.
For employee data that our customers store in UnivoCorp, the lawful basis is determined by the customer as the Data Controller.
4. Data Subject Rights
GDPR grants individuals specific rights over their personal data. These include the right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection.
UnivoCorp provides tools within the platform to help you respond to data subject requests. Employees can also access and update their own data through self-service.
5. International Data Transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place as required by GDPR.
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for such transfers. We also assess the data protection laws of the destination country.
6. Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by GDPR Article 32.
These measures include encryption, access controls, regular security assessments, employee training, and incident response procedures.
7. Data Processing Agreement
We provide a Data Processing Agreement (DPA) to all customers that meets GDPR requirements. The DPA covers our obligations as a data processor, including sub-processors, security measures, and data breach notification.
8. Data Breach Notification
In the event of a personal data breach, we will notify affected customers without undue delay. We have established procedures to detect, report, and investigate breaches as required by GDPR.
9. Sub-Processors
We use third-party sub-processors to help deliver our services. A list of our sub-processors is available in our Trust Center. We ensure all sub-processors meet GDPR requirements through appropriate contracts.
10. Data Protection Officer
If you have questions about our GDPR compliance or wish to exercise your rights, please contact our Data Protection team at dpo@univocorp.com.
Questions?
If you have any questions about this gdpr compliance, please contact us at legal@univocorp.com