GDPR Compliance
Last updated July 17, 2026
Attenzo is built to help organizations operating in the EU/EEA meet their GDPR obligations.
1. Controller & processor roles
Your organization is the data controller for employee data entered into Attenzo. Attenzo acts as the data processor, processing data only on your instructions.
2. Data Processing Agreement
A DPA covering our sub-processors and security commitments is available to every customer on request — contact privacy@attenzo.com.
3. Data residency
EU customers can opt into EU-region data storage on Business plans. Contact sales to configure this before onboarding.
4. Data subject rights
Admins can export or delete an individual employee's data directly from the dashboard, fulfilling access and erasure requests without contacting support.
5. Breach notification
We notify affected organizations within 72 hours of confirming a data breach, per Article 33.