UK GDPR, Data Sovereignty & Storage Practices

FYER Ltd — Company No. 16920035 Registered in England & Wales

FYER operates in full alignment with UK GDPR, the Data Protection Act 2018, and current UK data sovereignty requirements. We ensure that all personal and organisational data is handled lawfully, securely, and transparently.

1. UK GDPR Compliance

FYER follows the UK GDPR framework retained after Brexit, enforced by the Information Commissioner’s Office (ICO). Our processing activities follow the principles of:

  • lawfulness, fairness and transparency
  • purpose limitation
  • data minimisation
  • accuracy
  • storage limitation
  • integrity and confidentiality

2. Data Storage & Sovereignty

FYER stores data in:

  • UK‑based or EEA‑based data centres where possible
  • Secure cloud environments with region‑locked storage
  • Platforms that provide encryption at rest and in transit

We do not store client data on consumer cloud platforms or unmanaged devices.

3. International Data Transfers

Where data must move outside the UK/EEA, FYER uses:

  • UK International Data Transfer Agreement (IDTA)
  • UK Addendum to EU Standard Contractual Clauses
  • Adequacy decisions where applicable

These safeguards ensure compliance with post‑Schrems II requirements.

4. Cloud Platforms & Security

FYER uses secure cloud platforms that support:

  • region selection
  • encryption
  • MFA
  • access controls
  • audit logging
  • privacy‑by‑design

5. Your Rights

Under UK GDPR, you have the right to:

  • access
  • rectification
  • erasure
  • restriction
  • objection
  • portability

You may contact FYER to exercise any of these rights.

6. ICO Contact

If you have concerns, you may contact the ICO: https://ico.org.uk/concerns