Home/Knowledge Base/Security & Compliance/GDPR Compliance in UniAsset
Back to Security & Compliance

GDPR Compliance in UniAsset

4 minIntermediateLast updated: January 2, 2026

GDPR compliance in UniAsset

The roles

Your organization is the data controller. UniAsset is the data processor.

You decide what personal data is collected and why. UniAsset processes it on your instructions.

The Data Processing Agreement

Acceptance is recorded immutably — a new record per acceptance, capturing the agreement version, the accepting person by name and email, IP address, user agent, and timestamp.

The accepting person's name and email are captured by value, so the record survives their account being deleted.

A published subprocessor list is maintained.

Right to erasure (Article 17)

Satisfied by organization deletion.

ACTIVE ──► PENDING DELETION ──(30 days)──┐
   │                                      ├──► permanent erasure
   └──► ANONYMIZED (immediate) ───────────┘

After permanent deletion, no customer file remains.

The erasure pipeline:

  1. Verifies the organization is eligible.
  2. Erases every file before any database record is removed.
  3. Aborts if file erasure fails — the database is left intact and the next run retries. Retaining data is preferred over leaving orphaned personal files behind.
  4. Removes the organization record, cascading to everything it owns.

After deleting the files it knows about, erasure then sweeps the entire organization's storage prefix and removes anything still present, so no orphan can survive.

The whole pipeline is safe to run twice.

See How to delete your organization.

Storage limitation (Article 5(1)(e))

Satisfied by permanent deletion after the grace period. Data is not retained indefinitely after an organization is deleted.

Data portability

Assets, reports, and the Fixed Asset Register export to CSV, Excel, and PDF.

See How to export your data.

Anonymization

Available immediately, without waiting out the grace period. User identifiers are scrubbed and connected sign-in accounts detached at once; file erasure and record removal follow.

What personal data is held

  • User names and email addresses
  • Person records — name, phone, employee ID, designation
  • Login logs with IP address and a coarse derived location
  • Whatever your team places in free-text fields

What is deliberately not deleted

Provider-hosted documents that do not live in UniAsset's storage: invoice and receipt links, hosted invoice documents, and any webhook URL you configured pointing at your own systems.

Consent

No non-essential cookie or tracking script loads before consent is granted, in line with UK GDPR, PECR, and Google Consent Mode v2. Consent can be withdrawn at any time, and a policy change re-prompts rather than inheriting an old decision.

See Data privacy.

What your organization is responsible for

As the controller, you decide:

  • What personal data goes into UniAsset. Free-text fields will hold whatever your team types.
  • Who has access. Assign the minimum role each person needs.
  • How long you keep it. Archive and delete according to your own retention policy.
  • Responding to data subject requests from your own staff and contractors.

Related articles

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support