Lowp tae content

Data protection

Data processing

Oor role wi personal data, whaur it is haudit, hoo lang it is keepit an hoo we support yer obligations as a controller.

Roles o Controller an Processor

RODMENA as controller
For this wabsteid an oor ain business correspondence, as set oot in oor Privacy Policy.
RODMENA as processor
Whaur we operate or support seestems haudin yer users' personal data unner contract, the wark is governed by a signed Data Processing Agreement (Article 28 UK GDPR).

Sub-processors

The providers ablow process personal data for RODMENA, ilk ane named by the company we contract wi. We gie customers wi a signed DPA at least 30 days’ notice o an intendit chynge, by email an in the sub-processor feed, an a customer may object afore the chynge taks effect.

Sub-processors: provider, contractin company, purpose, whaur data is processed an the transfer safeguard
ProviderCompanyPuposeWhaur data is processedTransfer safeguard
OVHcloudOVH Limited, England an Wales, company 05519821Virtual servers fur the production database tier an some application services, an object storage fur encrypted backupsUnitit Kinrick, France and GermanyFrance an Germany ir covered bi UK adequacy regulations
iDNetInfinity Developments Ltd, England an Wales, company 03105579Virtual servers fur the wabsteid an application services, an the office connectionUnitit KinrickNane needit: processin bides in the Unitit Kinrick
Cloud NordCloud Nord Limited, England an Wales, company 13394754Servers fur a build runner, alertin an the partner portalUnitit KinrickNane needit: processin bides in the Unitit Kinrick
Google WorkspaceGoogle Cloud EMEA Limited, IrelandStaff email, calendars an documents, includin correspondence wi customersIreland, Unitit States and ither Google locationsUK Extension til the EU-US Data Privacy Framework (Google LLC), an EU Standard Contractual Clauses wi the UK International Data Transfer Addendum
AnthropicAnthropic Ireland, Limited, IrelandClaude Enterprise, the AI assistant RODMENA engineers uise tae operate its systems, that can see operational logs an dataUnitit StatesEU Staundart Contractual Clauses wi the UK Internaitional Data Transfer Addendum, in Anthropic’s data processin addendum
GitHubGitHub, Inc., Unitit StatesSource code hostin an continuous integrationUnitit StatesEU Standard Contractual Clauses wi the UK International Data Transfer Addendum

Chynges tae this register

  1. 5 October 2026

    InferX remuived

    InferX, that serves language-model inference ahint Prism, wis leetit in error: nae customer personal data is sent tae it. It nou appears unner the external services that process nae personal data.

  2. 5 October 2026

    Register complete

    iDNet, Cloud Nord, Google Workspace, Anthropic an InferX war already in uise an war missin fae the earlier list, whilk forbye named the wrang OVHcloud company an descrieved the iDNet servers as company-awned. Ilk provider is noo listed bi its contractin company, wi whaur it processes data an the transfer safeguard.

External services that process nae personal data

RODMENA cmi5 airs its audit chain wi a public RFC 3161 timestamp authority. That service gets a SHA-256 digest o a signed chain heid, aboot ivery fifteen meenits, an only fur a customer whase chain has chynged. Nae personal data, nae identifiers an nae learning records is sent tae it. Whan it cannae be reached, learning, launches, statements an evidence export isnae affected, an anchoring retries on the next pass.

Prism, the model gateway o RODMENA, sends requests tae InferX Technologies, Inc. (Unitit States) fur language-model inference. Nae customer personal data is sent tae it. Afore Prism is uised wi customer personal data, the model will be hostit in the Unitit Kinrick or provydit unner a contract wi transfer safeguards.

Oor domain registrar an DNS provider hauds only domain an zone records.

RODMENA cmi5 as a processor

Role
A processor acting for the learning management system customer, which is the controller. Article 28 terms are on the Data Processing Agreement page.
Whit is processed
The learner identifier the customer’s system supplies, as an xAPI account o hame page an name, an the learnin records a coorse sends, includin results an scores. Email-style identifiers is refused.
Hou it is haud
Ilka customer’s data is separatit by rules the database enforces. Records is encryptit at rest, learner identifiers is stored only as keyed tokens, an client IP addresses is niver stored.
Keepin
Per tenant an contractual. The defaults is 1,095 days fur registrations an statement bodies, configurable doon tae ae day.
Optional flows
Aa inside RODMENA, wi nae new sub-processor. Whan a customer switches it on, saved-state an learner-preference documents, that can haud onythin a coorse stores, includin free-text answers, are copied yin wye tae the RODMENA LRS an deleted there wi the oreeginal or at retention. On request, statements are cross-checked agin the LRS copy for the evidence pack. Statements cmi5 writes itsel can cairry RODMENA’s xAPI signature, remuived wi the statement at retention or erasure.
Webhooks
Sent onlie tae HTTPS endpoints the customer registers, signed wi HMAC-SHA256, cairryin ids the customer already haes an timestamps. Nae learner identifier an nae learning record is sent. Events is keepit for 30 days.
Erasure
A learner’s records are pseudonymised in cmi5 straucht awa, their document copies in the LRS are stapped and taen oot, and the erasure is haunded tae the RODMENA LRS wi a recordit receipt, sae ae request reaches baith systems. Efter a database restore, ilka erasure is reapplied frae sealed records keepit ootside the database, as a step o the restore procedure. The reason recordit for it is a ticket reference or a code, never free text aboot a person.
Return and deletion
Under Article 28(3)(g), a customer’s export runs only efter a second person approves it, is encrypted tae the customer’s ain key an cairries a signed manifest o ivery table the customer awns. At the end o the contract ivery record an stored object version is remuived, an the customer gets a signed, timestamped deletion certificate statin whit wis deleted, whit is keepit an why, an whit it disna cover: backups an logs within their retention, an LRS data, whilk haes its ain erasure hand-off.
Location
The same database tier statit abune, in the Unitit Kinrick, France an Germany, wi nae ither transfer. Course packages an erasure records are encryptit on oor host afore they are uplaidit tae object storage.

Processin locations an international transfers

RODMENA is based in the Unitit Kinrick. Oor ain systems an their data are hostit in Unitit Kinrick, France and Germany. Some providers in the register process data elsewhere: Ireland, Unitit States and ither Google locations. Customer deployments run whauriver the customer chooses, commonly on the customer's ain infrastructure.

Ilka provider that processes data ootwi the Unitit Kinrick, an the safeguard fur that transfer, is shawn in the register abuin: OVHcloud, Google Workspace, Anthropic and GitHub. Oor Terms are govrened bi the law o England an Wales.

Keepin an deletin

As processor, we haud personal data ainly for the duration o the contract. Whan the engagement ends we delete or gie it back, as the controller chooses, an certify deletion on request. Retention for oor ain controller processing is descrived in the Privacy Policy. See forby exit & portability.

Data-subject requests

We help controllers respond tae data-subject rights requests (access, rectification, erasure, restriction, portability, objection) within the statutory one-month period. Requests aboot data we control gang tae gdpr@rodmena.co.uk.

RODMENA Requests is the ae place tae mak a data protection complaint, a data richts request, a complaint or feedback aboot oor service, or a request fae a public authority. Onybody can uise it by web form, email, post or phone, an ivery request gets a reference nummer.

Follae a request wi its reference · Prentable form fur requests by post

Breach handling

Personal-data breaches are contained, investigated and documented. As processor, we notify the affected controller without undue delay after becoming aware of a breach. As controller, we notify the ICO within 72 hours where required, and affected individuals where the risk demands it.

DPA requests: legal@rodmena.co.uk · data-protection questions: privacy@rodmena.co.uk · see also the DPA summary and the Trust Centre.