GDPR Compliance protecting your data rights
How SimpleKPI meets its obligations under UK and EU data protection law. Last updated 6 August 2026.
What is GDPR?
The General Data Protection Regulation (GDPR) came into effect on 25 May 2018, placing stronger obligations on businesses and giving individuals greater rights over how their data is stored and used. Following Brexit, the UK retained the regulation as UK GDPR, and SimpleKPI complies with both.
The main objectives of GDPR are to:
- Strengthen the security and protection of personal data.
- Harmonize data protection laws across the European Union.
- Give people more control over how their data is used.
- Increase accountability to ensure that companies take responsibility for complying with data protection regulations.
GDPR applies to any business or organization that collects, stores, or processes personal information from individuals in the EU or UK, wherever that business is based.
Our approach
From the very beginning, SimpleKPI has held your data and privacy in the highest regard. We do not sell your data, we do not share it with third parties beyond the sub-processors needed to run the Service, and we do not use your data to train AI models. Your data is your data, and we use it only to provide SimpleKPI and its supporting services to you. Full details are in our Privacy Notice and on our Security page.
What we have done
- Clear, readable Privacy Notice and Terms of Service, including disclosure of our sub-processors and AI data handling.
- Straightforward processes for deleting trials and accounts and their associated data, with defined retention windows.
- Export tools so you can take your data with you at any time (Excel export and the Developer API).
- Internal processes that restrict who can access customer data, and a data mapping exercise tracking how customer data flows across the application and support services.
- A Data Processing Agreement, available to all customers.
Questions
Where does SimpleKPI store data?
The Service is hosted in Microsoft Azure data centers in the European Union, which handle replication and redundancy across the platform. A small number of supporting services, such as email delivery and support, run elsewhere. Each one, with its location and the safeguard that applies to it, is listed in our Data Processing Agreement. Backups are retained for a limited period before secure deletion, as set out in our Privacy Notice.
How does SimpleKPI handle international data transfers?
Some of our sub-processors process data outside the UK and EEA, including in the United States. Where that happens we rely on an appropriate safeguard under UK and EU data protection law, and we never transfer without one. Which safeguard applies to which sub-processor, and the mechanics behind each, are set out in our Data Processing Agreement.
What security measures protect my data?
SimpleKPI is hosted on Microsoft Azure, with encryption in transit and at rest, role-based access control, and passwordless sign-in. Payments are handled entirely by Stripe, a PCI DSS Level 1 certified payment provider, so card data never touches SimpleKPI's servers. Our Security page sets out the measures in full, and Annex II of our Data Processing Agreement commits to them contractually. For the underlying infrastructure, see Microsoft's Azure security overview.
What if there is a security breach?
If a personal data breach affects your account, we will notify you without undue delay, and in any event within 24 hours of becoming aware of it, including the nature of the breach, the data involved, and any information provided to us by our infrastructure providers. That commitment is set out in full in clause 9 of our Data Processing Agreement, which also covers what the notification must contain and how we support your own reporting obligations.
What are my rights, and how do I use them?
Under UK and EU GDPR you have the right to access your data, correct it, have it deleted, restrict or object to how it is used, and receive it in a portable format. Where we hold the data as our own controller, contact privacy@simplekpi.com and we will respond within one month. Where your data was put into SimpleKPI by a company using our Service, that company is the controller and we will point you to them. Section 7 of our Privacy Notice sets each right out in full. You can also complain to the Information Commissioner's Office in the UK, or your local supervisory authority in the EEA.