← Back to Home
ShowOps
ShowOps

🇪🇺 GDPR & Data Compliance

Last updated: July 15, 2026

ShowOps is fully compliant with the General Data Protection Regulation (GDPR) as applicable to operations in the UK and European Economic Area (EEA). We process all personal information securely as a data processor on behalf of our client workspaces.

1. Core GDPR Compliance Principles

We handle data according to the core principles of GDPR:

  • Lawfulness, Fairness, and Transparency: We process staff lists only for operational shift requirements.
  • Purpose Limitation: Data is never processed for secondary marketing profiles.
  • Data Minimization: We restrict staff collection records to name, email, phone, and role.
  • Accuracy: Account metrics can be corrected directly via the Workspace Manager.
  • Storage Limitation: Inactive records can be deactivated or deleted by Super Admins.

2. Cross-Border Data Transfers

All customer databases, tables, and session metrics are hosted securely on servers located within the EEA / UK. We ensure that any subprocessors maintain compliance and protect your rights through standard contractual clauses (SCCs).

3. Security Controls & Data Access

Our platform restricts database access through role-based access controls (RBAC) and workspace isolation rules. Only authorized organisers and system administrators can manipulate staff profiles and shift rotas.

4. Data Breaches Notification

In the event of a security breach compromising your personal data, ShowOps will notify the relevant supervisory authority and affected workspace contacts within 72 hours of discovery.

5. Contact Our Data Protection Officer

If you have questions regarding GDPR, data portability, or subject access requests, please contact our support team at: dpo@showops.co.uk.