GDPR Compliance

Last updated July 17, 2026

Attenzo is built to help organizations operating in the EU/EEA meet their GDPR obligations.

1. Controller & processor roles

Your organization is the data controller for employee data entered into Attenzo. Attenzo acts as the data processor, processing data only on your instructions.

2. Data Processing Agreement

A DPA covering our sub-processors and security commitments is available to every customer on request — contact privacy@attenzo.com.

3. Data residency

EU customers can opt into EU-region data storage on Business plans. Contact sales to configure this before onboarding.

4. Data subject rights

Admins can export or delete an individual employee's data directly from the dashboard, fulfilling access and erasure requests without contacting support.

5. Breach notification

We notify affected organizations within 72 hours of confirming a data breach, per Article 33.