Data protection
Data processing
Our role with personal data, where it is held, how long it is kept and how we support your obligations as a controller.
Controller and processor roles
- RODMENA as controller
- For this website and our own business correspondence, as set out in our Privacy Policy.
- RODMENA as processor
- Where we operate or support systems holding your users’ personal data under contract, the work is governed by a signed Data Processing Agreement (Article 28 UK GDPR).
Sub-processors
The providers below process personal data for RODMENA, each named by the company we contract with. We give customers with a signed DPA at least 30 days’ notice of an intended change, by email and in the sub-processor feed, and a customer may object before the change takes effect.
| Provider | Company | Purpose | Where data is processed | Transfer safeguard |
|---|---|---|---|---|
| OVHcloud | OVH Limited, England and Wales, company 05519821 | Virtual servers for the production database tier and some application services, and object storage for encrypted backups | United Kingdom, France and Germany | France and Germany are covered by UK adequacy regulations |
| iDNet | Infinity Developments Ltd, England and Wales, company 03105579 | Virtual servers for the website and application services, and the office connection | United Kingdom | None needed: processing stays in the United Kingdom |
| Cloud Nord | Cloud Nord Limited, England and Wales, company 13394754 | Servers for a build runner, alerting and the partner portal | United Kingdom | None needed: processing stays in the United Kingdom |
| Google Workspace | Google Cloud EMEA Limited, Ireland | Staff email, calendars and documents, including correspondence with customers | Ireland, United States and other Google locations | UK Extension to the EU-US Data Privacy Framework (Google LLC), and EU Standard Contractual Clauses with the UK International Data Transfer Addendum |
| Anthropic | Anthropic Ireland, Limited, Ireland | Claude Enterprise, the AI assistant RODMENA engineers use to operate its systems, which can see operational logs and data | United States | EU Standard Contractual Clauses with the UK International Data Transfer Addendum, in Anthropic’s data processing addendum |
| GitHub | GitHub, Inc., United States | Source code hosting and continuous integration | United States | EU Standard Contractual Clauses with the UK International Data Transfer Addendum |
Changes to this register
5 October 2026
InferX removed
InferX, which serves language-model inference behind Prism, was listed in error: no customer personal data is sent to it. It now appears under the external services that process no personal data.
5 October 2026
Register completed
iDNet, Cloud Nord, Google Workspace, Anthropic and InferX were already in use and were missing from the earlier list, which also named the wrong OVHcloud company and described the iDNet servers as company-owned. Each provider is now listed by its contracting company, with where it processes data and the transfer safeguard.
External services that process no personal data
RODMENA cmi5 anchors its audit chain with a public RFC 3161 timestamp authority. That service receives a SHA-256 digest of a signed chain head, about every fifteen minutes, and only for a customer whose chain has changed. No personal data, no identifiers and no learning records are sent to it. When it cannot be reached, learning, launches, statements and evidence export are unaffected, and anchoring retries on the next pass.
Prism, RODMENA’s model gateway, sends requests to InferX Technologies, Inc. (United States) for language-model inference. No customer personal data is sent to it. Before Prism is used with customer personal data, the model will be hosted in the United Kingdom or provided under a contract with transfer safeguards.
Our domain registrar and DNS provider holds only domain and zone records.
RODMENA cmi5 as a processor
- Role
- A processor acting for the learning management system customer, which is the controller. Article 28 terms are on the Data Processing Agreement page.
- What is processed
- The learner identifier the customer’s system supplies, as an xAPI account of home page and name, and the learning records a course sends, including results and scores. Email-style identifiers are refused.
- How it is held
- Each customer’s data is separated by rules the database enforces. Records are encrypted at rest, learner identifiers are stored only as keyed tokens, and client IP addresses are never stored.
- Retention
- Per tenant and contractual. The defaults are 1,095 days for registrations and statement bodies, configurable down to one day.
- Optional flows
- All inside RODMENA, with no new sub-processor. When a customer switches it on, saved-state and learner-preference documents, which can hold anything a course stores, including free-text answers, are copied one way to the RODMENA LRS and deleted there with the original or at retention. On request, statements are cross-checked against the LRS copy for the evidence pack. Statements cmi5 writes itself can carry RODMENA’s xAPI signature, removed with the statement at retention or erasure.
- Webhooks
- Sent only to HTTPS endpoints the customer registers, signed with HMAC-SHA256, carrying ids the customer already holds and timestamps. No learner identifier and no learning record is sent. Events are kept for 30 days.
- Erasure
- A learner’s records are pseudonymised in cmi5 immediately, their document copies in the LRS are stopped and removed, and the erasure is handed to the RODMENA LRS with a recorded receipt, so one request reaches both systems. After a database restore, every erasure is re-applied from sealed records kept outside the database, as a step of the restore procedure. The reason recorded for it is a ticket reference or a code, never free text about a person.
- Return and deletion
- Under Article 28(3)(g), a customer’s export runs only after a second person approves it, is encrypted to the customer’s own key and carries a signed manifest of every table the customer owns. At the end of the contract every record and stored object version is removed, and the customer receives a signed, timestamped deletion certificate stating what was deleted, what is kept and why, and what it does not cover: backups and logs within their retention, and LRS data, which has its own erasure hand-off.
- Location
- The same database tier stated above, in the United Kingdom, France and Germany, with no other transfer. Course packages and erasure records are encrypted on our host before they are uploaded to object storage.
Processing locations and international transfers
RODMENA is based in the United Kingdom. Our own systems and their data are hosted in the United Kingdom, France and Germany. Some providers in the register process data elsewhere: Ireland, the United States and other Google locations. Customer deployments run wherever the customer chooses, commonly on the customer’s own infrastructure.
Each provider that processes data outside the United Kingdom, and the safeguard for that transfer, is shown in the register above: OVHcloud, Google Workspace, Anthropic and GitHub. Our Terms are governed by the law of England and Wales.
Retention and deletion
As processor, we retain personal data only for the duration of the contract. When the engagement ends we delete or return it, as the controller chooses, and certify deletion on request. Retention for our own controller processing is described in the Privacy Policy. See also exit & portability.
Data-subject requests
We help controllers respond to data-subject rights requests (access, rectification, erasure, restriction, portability, objection) within the statutory one-month period. Requests about data we control go to gdpr@rodmena.co.uk.
Breach handling
Personal-data breaches are contained, investigated and documented. As processor, we notify the affected controller without undue delay after becoming aware of a breach. As controller, we notify the ICO within 72 hours where required, and affected individuals where the risk demands it.
DPA requests: legal@rodmena.co.uk · data-protection questions: privacy@rodmena.co.uk · see also the DPA summary and the Trust Centre.