Privacy Policy
GembaDocs Privacy Policy
How GembaDocs Limited collects, uses and protects personal data
Effective date: 30th July 2026 | Version: 2.0 | Last reviewed: 30th July 2026
1. Introduction
This Privacy Policy explains how GembaDocs Limited (“GembaDocs”, “we”, “us” or “our”) collects, uses, shares and protects personal data. It applies to visitors to our website, to individuals who register for or use the GembaDocs platform and mobile applications, and to prospective customers and other people who interact with us. GembaDocs is a cloud-based (SaaS) platform for creating and managing standard operating procedures (SOPs) and digital work instructions.
We are committed to protecting personal data and handling it in line with the UK General Data Protection Regulation (“UK GDPR”), the EU General Data Protection Regulation (“EU GDPR”) and the Data Protection Act 2018.
2. Our two roles: controller and processor
Depending on the data involved, we act in one of two capacities:
- As a data controller for the personal data we decide how and why to process — for example account and contact details of the people who register for or administer the service, website-visitor data, and sales and marketing contacts. This Policy governs that processing.
- As a data processor for the content our customers upload to the platform (“customer content”), which may include personal data about our customers’ own employees or users. We process that data only on our customers’ documented instructions. This processing is governed by our Data Processing Agreement (DPA) with each customer under Article 28 of the UK GDPR, not by this Policy. In that relationship the customer is the controller and GembaDocs is the processor.
3. Personal data we collect and why
3.1 Account and contact data
When you register for, are invited to, or administer the service, we collect information such as your name, work email address, job role, employer, and login credentials. We use this to create and secure your account, provide and support the service, and communicate with you about it.
3.2 Usage and log data
When you use the service we automatically collect technical data such as IP address, device and browser type, operating-system version, app configuration, and the date, time and nature of your activity. In the event of an error, diagnostic log data may be collected through third-party tooling. We use this to operate, secure, troubleshoot and improve the service.
3.3 Support and correspondence
If you contact us for support or otherwise correspond with us, we keep a record of that contact and its contents so we can help you and improve our service.
3.4 Sales and marketing data
If you enquire about GembaDocs or engage with our marketing, we process your contact details and communication preferences to respond and, where permitted, to send you relevant information. You can opt out of marketing at any time.
We do not intentionally collect special-category personal data (such as health data) or payment-card details within the platform, and the service is not intended to process such data on our customers’ behalf.
4. Our lawful bases for processing
Where we act as controller, we rely on the following lawful bases under the UK/EU GDPR:
- Performance of a contract — to provide the service to you and your organisation.
- Legitimate interests — to secure, operate, improve and market our service, balanced against your rights.
- Consent — for certain marketing communications and non-essential cookies, which you can withdraw at any time.
- Legal obligation — to meet our legal, regulatory and tax obligations.
5. Service providers and sub-processors
We use carefully selected third-party providers to help us deliver the service (for example cloud infrastructure and transactional email). These providers may process personal data on our behalf and are bound by written contracts requiring appropriate security and confidentiality, and permitting them to use the data only to perform services for us.
Our platform is hosted on Amazon Web Services (AWS), with transactional email handled by a specialist email provider. The current, authoritative list of sub-processors — which we keep up to date and notify customers of in advance of any material change — is maintained in our Data Processing Agreement. We do not sell personal data.
6. International data transfers
Some of our providers, including AWS, may process data on infrastructure located outside the UK/EEA (including in the United States). Where personal data is transferred internationally, we put appropriate safeguards in place to ensure a lawful transfer under the UK/EU GDPR, including the ICO-approved Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by encryption in transit and at rest, strict access controls, and periodic transfer risk assessments.
7. Data retention
We retain personal data for as long as needed to provide the service and for a reasonable operational period afterwards to support system integrity, account reactivation, audit logs and compliance obligations. On written request, or following termination of the service, we securely delete or anonymise personal data, subject to any legal or regulatory retention requirements. Residual copies held in encrypted backups are overwritten in line with our standard backup retention cycle (backups are retained for 30 days). Confirmation of deletion can be provided on request.
8. How we protect personal data
Security is built into how GembaDocs is designed, developed and run. Our controls include:
- Encryption of all data in transit (TLS 1.2 or higher) and at rest (AES-256), with keys held in a dedicated key-management service.
- Access control on a role-based, least-privilege basis, with multi-factor authentication and quarterly access reviews.
- Independent assurance — a completed SOC 2 Type II examination, annual third-party penetration testing, and monthly vulnerability scanning.
- Monitoring and response — 24×7 security monitoring and a documented incident-management process, including notifying affected customers of a personal-data breach without undue delay.
No method of transmission or storage is completely secure, but we maintain a formal information-security programme aligned to recognised frameworks to keep the risk low.
9. Your data-protection rights
Subject to certain conditions, you have the right to:
- Access the personal data we hold about you.
- Ask us to correct inaccurate or incomplete data (rectification).
- Ask us to delete your data (erasure), where applicable.
- Restrict or object to certain processing.
- Request a copy of your data in a portable format (portability).
- Withdraw consent where we rely on it, at any time.
To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office (ICO) at ico.org.uk. Where GembaDocs acts as a processor (customer content), we will refer or assist data-subject requests to the relevant customer (the controller), who is responsible for responding.
10. Cookies and analytics
Our website and app may use cookies and similar technologies, including those set by third-party libraries, to enable core functionality, remember your preferences and understand how the service is used. You can control non-essential cookies through your browser settings or any cookie banner we provide; refusing some cookies may affect how parts of the service work.
11. Children’s privacy
GembaDocs is a business tool intended for use by organisations and their staff. It is not directed at children and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version on this page and, where changes are material, take reasonable steps to notify you. Please review it periodically.
13. Contact us
If you have any questions about this Policy or how we handle personal data, or wish to exercise your rights, please contact:
GembaDocs Limited
Privacy contact: support@gembadocs.com
Registered office: Unit 4G Shivers Business Park, Toomebridge, County Antrim
Company number: NI713726