Skip to content

GDPR Compliance protecting your data rights

How SimpleKPI meets its obligations under UK and EU data protection law. Last updated 16 July 2026.

What is GDPR?

The General Data Protection Regulation (GDPR) came into effect on 25 May 2018, placing stronger obligations on businesses and giving individuals greater rights over how their data is stored and used. Following Brexit, the UK retained the regulation as UK GDPR, and SimpleKPI complies with both.

The main objectives of GDPR are to:

  1. Strengthen the security and protection of personal data.
  2. Harmonize data protection laws across the European Union.
  3. Give people more control over how their data is used.
  4. Increase accountability to ensure that companies take responsibility for complying with data protection regulations.

GDPR applies to any business or organization that collects, stores, or processes personal information from individuals in the EU or UK, wherever that business is based.

Our approach

From the very beginning, SimpleKPI has held your data and privacy in the highest regard. We do not sell your data, we do not share it with third parties beyond the sub-processors needed to run the Service, and we do not use your data to train AI models. Your data is your data, and we use it only to provide SimpleKPI and its supporting services to you. Full details are in our Privacy Notice and on our Security page.

What we have done

  • Clear, readable Privacy Notice and Terms of Service, including disclosure of our sub-processors and AI data handling.
  • Straightforward processes for deleting trials and accounts and their associated data, with defined retention windows.
  • Export tools so you can take your data with you at any time (Excel export and the Developer API).
  • Internal processes that restrict who can access customer data, and a data mapping exercise tracking how customer data flows across the application and support services.
  • A GDPR Data Processing Agreement (version July 2026), available to all customers.

Questions

Where does SimpleKPI store data?

All data storage and hosting is provided by Microsoft Azure data centers, which handle replication and redundancy across the platform. Archival backups are retained for a limited period before secure deletion, as described in our Privacy Notice.

How does SimpleKPI handle international data transfers?

Some of our sub-processors process data outside the UK and EEA, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards under UK and EU data protection law, such as adequacy decisions (including the UK-US Data Bridge and EU-US Data Privacy Framework where the recipient is certified), the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses. Our sub-processors are listed in the Privacy Notice.

What security measures protect my data?

SimpleKPI is hosted on Microsoft Azure with encryption in transit and at rest, secrets managed in Azure Key Vault, role-based access control, and secure sign-in. Payments are handled entirely by Stripe, a PCI DSS Level 1 certified payment provider, so card data never touches SimpleKPI's servers. See our Security page for the full picture, and Microsoft's Azure security overview for the underlying infrastructure.

What if there is a security breach?

If a personal data breach affects your account, we will notify you without undue delay, in line with GDPR requirements, including the nature of the breach, the data involved, and any information provided to us by our infrastructure providers.

Additional information

SimpleKPI support portal
GDPR Data Processing Agreement (version July 2026)

Get started with your KPI Software

Get started for free