Security & GDPR

Security-first data workflow

Public form

The public form is for project context and optional small anonymized samples only. Samples should be limited to the minimum needed to understand structure, columns, errors and import blockers.

Private upload workspace

Complete customer files are exchanged only through an agreed private project workspace after scope, confidentiality, transfer method and processing terms are in place. The workspace is limited to the project and closed after delivery according to the agreed retention period.

Contract before production data

When ImportReady Data processes personal data on behalf of a customer, the work is governed by a Data Processing Agreement under GDPR Article 28, with documented customer instructions.

Access and deletion

Project files are handled with limited access, confidentiality, secure deletion and no secondary use. Customer data is not used for model training, resale, marketing lists or unrelated projects.

Project files are kept only for the duration of the work and deleted from our environments after project close, unless a different written agreement or legal obligation applies.

European infrastructure

For customers in the European Union or European Economic Area, project files are handled on infrastructure located in the EU or EEA unless a different location is agreed in writing for a specific project.

Analytics

The site is designed to work without Google Analytics. If visitor analytics are enabled, the preferred setup is Matomo configured for privacy-focused, cookieless analytics with IP anonymization and no advertising profiling.

Important note

This page describes the intended security workflow. Customer-specific contracts, Data Processing Agreements and security annexes control the actual project terms.