Legal
GDPR Compliance Statement
Last updated: 10 August 2026
Leckware is an Irish business based in the European Union, and we treat the EU General Data Protection Regulation (GDPR) as the baseline for how we handle data. This statement explains how we comply and what you can expect from us as your software provider for DESKREG.
1. Our commitment
We are committed to protecting personal data and to complying with the GDPR and the Irish Data Protection Act 2018. For us, data protection is not a compliance checkbox; it is how you treat people.
2. Our role
We act as a Data Controller for the personal data we process to operate, bill, and administer DESKREG. We act as a Data Processor for the data your organisation submits into the platform about its employees or operations. Where we act as a Processor, you are the Controller and we process personal data strictly on your documented instructions.
3. Lawful bases
We rely on performance of contract to provide the Service, legitimate interests for security and service improvement, legal obligation where required, and explicit consent where needed. These are detailed further in our Privacy Policy.
4. Data minimisation and purpose limitation
We collect only the data needed to run the Service and use it strictly for the purposes described in our Privacy Policy. We do not sell personal data, and we do not use your customer data for advertising.
5. Data residency
Primary customer data is stored in the European Union. Where limited operational sub-processors process data outside the EEA, we ensure appropriate legal safeguards under Chapter V of the GDPR (such as Standard Contractual Clauses or the EU-US Data Privacy Framework) are in place.
6. Security measures
- Encryption: Data in transit (TLS 1.2+) and at rest (AES-256).
- Access Control: Role-based access controls and principle of least privilege.
- Tenant Isolation: Logical data isolation ensuring strict separation between customer accounts.
- Authentication: Support for multi-factor authentication and standard SSO providers.
- System Integrity: Controlled access to production systems and routine security audits.
7. Data subject rights
Under the GDPR, individuals have the right to access, rectify, erase, restrict, and object to the processing of their personal data, alongside the right to data portability. These rights can be exercised through the Service or by contacting us at [email protected]. Complaints may also be lodged with the Irish Data Protection Commission (DPC) or your local supervisory authority.
8. Sub-processors and data processing agreements
Every sub-processor we engage is bound by a written contract imposing strict GDPR-compliant obligations. A current list of sub-processors is available upon request or in our DPA. Our standard Data Processing Agreement is incorporated into our Terms of Service and applies automatically to all customer accounts.
9. Breach notification
In the event of a personal data breach impacting customer data, we will inform affected customers (as Controllers) without undue delay, assisting them in fulfilling their notification obligations to supervisory authorities and data subjects.
10. Contact
For any data protection inquiries or to request legal documents, contact us at [email protected].