Solutions
Services Our Process Our Methodology
Platform & Resources
Voice AI Platform Case Studies Free Tools Blog Resources
Company
About Us Careers Book Free Consultation →
Compliance

Compliance: what we actually do and what we do not

A transparent map, not a certification claim: the obligations we operate under, the controls we deliver, and where we are on certification.

GDPR / UK GDPR HIPAA (BAA) SOC 2 Type 1 (in progress) PCI DSS (advisory) DPDP Act 2023 UAE PDPL

Honest framing: read this first

We design and deliver compliance-ready architecture. Systems we build are engineered to the technical requirements of SOC 2, HIPAA, GDPR, and PCI DSS: encryption, access control, audit logging, breach procedures, and data minimisation by default.

We do not currently hold active SOC 2, ISO 27001, or HIPAA "certifications" of our own corporate environment. SOC 2 Type 1 is in progress with an auditor, target Q4 2026; ISO 27001 is on the roadmap for 2027. HIPAA is not a certification anyone can hold: there is only the Security Rule and a signed Business Associate Agreement (BAA), both of which we operate under when handling PHI.

We sign BAAs and DPAs. Where required: a Business Associate Agreement (HIPAA), a Data Processing Agreement (GDPR / UK GDPR / DPDP / PDPL), and client-specific addenda. Our standard DPA template is downloadable.

If procurement asks "are you certified?", the honest answer is: not yet for SOC 2, targeting 2026. If that is a deal-breaker, tell us early.

GDPR and UK GDPR

Our role. RG INSYS LLP is typically a processor under Article 4(8); you are the controller. We process personal data only on your documented instructions, captured in the Statement of Work and the DPA.

DPIA support. For Data Protection Impact Assessments under Article 35 we contribute the technical chapters: data flows, retention, safeguards, and the residual-risk register. You sign off as controller.

Data subject rights workflow. Systems ship DSAR-ready: every personal-data field tagged at design time, export and erasure routines unit tested, complete subject record on demand. 30-day response window from a verified request, optional 60-day extension supported.

Sub-processor list. Listed on the security page. Material changes notified at least 30 days in advance, with a right of objection.

International transfers. India is not on the EU adequacy list. EEA→India transfers use the EU Standard Contractual Clauses, Module Two (controller-to-processor), June 2021 set; UK→India transfers use the UK International Data Transfer Addendum (IDTA) or the UK Addendum to the EU SCCs. Supplementary measures documented per project: encryption in transit and at rest, access logging, refusal of bulk government requests absent valid legal process, and notification of any request we are not legally barred from disclosing.

Article 32 technical and organisational measures. AES-256 at rest, TLS 1.3 in transit, pseudonymisation where appropriate, RBAC + MFA, regular testing (SAST/DAST/pen test), and documented incident response. Detailed in our DPA Schedule 2.

Breach notification. Breaches likely to risk data subjects are notified to the controller within 72 hours of awareness (Article 33(2)): nature, categories and approximate numbers of subjects and records, likely consequences, and measures taken.

HIPAA

Honest framing. "HIPAA certified" is not a thing; there is no certification body. There is the HIPAA Security Rule (45 CFR §164.300), the Privacy Rule, and a signed Business Associate Agreement (BAA): we operate under the Security Rule and sign BAAs.

BAA available on request. We sign your BAA or our standard one before any Protected Health Information (PHI) is shared. No signed BAA, no PHI.

Technical safeguards (45 CFR §164.312).

  • Access control: unique user IDs, automatic logoff after 15 minutes idle, PHI encrypted at rest and in transit.
  • Audit controls: append-only logs of all PHI access, exports, and admin actions.
  • Integrity: checksums and write-ahead logging on PHI stores; tamper-evident audit trail.
  • Person or entity authentication: MFA required for any user accessing PHI.
  • Transmission security: TLS 1.3 with strict cipher suites, no PHI over unencrypted channels.

Administrative safeguards (45 CFR §164.308). Workforce security clearance, role-based access, periodic access review, sanction policy, written incident procedures, contingency plan, and recurring training. Documentation on request.

Physical safeguards (45 CFR §164.310). PHI workloads deploy only into HIPAA-eligible services under the provider's own BAA (AWS, Google Cloud, Azure). Workstation security enforced via MDM and full-disk encryption.

What we do not do. No PHI in non-HIPAA-eligible tools (Notion, Linear, Slack, Sentry public tier). Logs that may contain PHI are redacted at the edge, or monitoring runs entirely inside the HIPAA boundary.

SOC 2

Status. Type 1 in active progress with a CPA firm, target completion Q4 2026. We cannot yet provide a SOC 2 report.

Trust Services Criteria implemented. Our control environment is built against the AICPA 2017 Trust Services Criteria:

  • Security (CC1 through CC9): control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, risk mitigation.
  • Availability (A1.1, A1.2, A1.3): capacity planning, environmental protections, recovery and backup procedures.
  • Confidentiality (C1.1, C1.2): identification and protection of confidential information; disposal procedures.

Policy bundle on request. Information security, access control, change management, vendor management, incident response, and acceptable use policies, shared under NDA: the same documents the auditor reviews.

What we will not say. Nothing that implies a completed audit. Until the report exists, it is "Type 1 in progress", nothing more.

PCI DSS

Our position is advisory only. RG INSYS LLP is not a merchant, payment processor, or registered service provider in the PCI DSS programme, and does not store, process, or transmit cardholder data on its own infrastructure.

What we do for clients. We design payment integrations to minimise your PCI scope: tokenisation through a PCI-validated provider (Stripe, Adyen, Braintree, Worldpay) using hosted fields, Payment Element, or redirect flows. Cardholder data never touches your servers, qualifying most clients for Self-Assessment Questionnaire A (SAQ A).

For heavier scope (custom checkout, in-app card capture, server-side card processing) we advise on segmentation, key management, and audit logging, working alongside your Qualified Security Assessor (QSA).

If you need a partner who is themselves a PCI Level 1 service provider, we are not that partner, and we will say so on the first call.

DPDP Act 2023 (India)

As an Indian company we are directly subject to the Digital Personal Data Protection Act 2023, regulated by the Data Protection Board of India, operating as a Data Processor for clients who are Data Fiduciaries.

  • Consent management. Granular, withdrawable consent capture with a consent log per data principal.
  • Data fiduciary obligations awareness. Engineering support for section 8 obligations: notice, accuracy, retention, security, and breach reporting.
  • Breach notification. Pre-built notification workflows and breach assessment runbooks to meet the 72-hour window for notifying the Board and affected principals.
  • Children's data. Verifiable parental consent flows for under-18 data, behavioural tracking disabled by default.
  • Cross-border transfers. Transfers allowed except to Government-notified restricted countries; infrastructure respects client-specific localisation requirements.

UAE PDPL and free-zone regimes

For UAE clients we work under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and the UAE Data Office executive regulations, plus the local free-zone regime where applicable:

  • ADGM: Abu Dhabi Global Market Data Protection Regulations 2021.
  • DIFC: Dubai International Financial Centre Data Protection Law (DIFC Law No. 5 of 2020).

Both regimes are GDPR-aligned, so the same technical and organisational measures apply, including breach notification within the regulator-defined window.

We have delivered systems for clients regulated by the UAE Central Bank, Dubai Health Authority, and free-zone-licensed entities.

Standard DPA template

Our standard Data Processing Agreement is downloadable for legal review: Schedule 1 (subject matter and duration), Schedule 2 (technical and organisational measures), Schedule 3 (sub-processor list), and Annex I to the EU SCCs.

Your DPA template works too: we have signed those of UK NHS trusts, US health systems, large UK recruitment groups, and UAE financial-services clients.

Download DPA template →

Free consultation, no commitment

Want to dig deeper?

Talk to a senior engineer. We answer compliance and security questionnaire items live on the call.

Book Consultation