Security & Compliance
We are committed to protecting your data across our AI products and research platform, maintaining the highest standards of security, compliance, and responsible AI governance.
UK GDPR Compliant
As a UK company we operate under the UK GDPR and Data Protection Act 2018, alongside the EU GDPR for EU users. Gradespace LTD is registered with the Information Commissioner's Office (ICO). We provide tools to help you manage your data subject rights, and sign a Data Processing Agreement with customers whose data we process.
Data Protection Governance
Privacy by design across every product
Our privacy programme is overseen by a designated Privacy & Data Protection Lead, with a documented record of processing activities, data protection impact assessments for higher-risk processing — including children's data in TargetGrade and health and social-care data in CareMaSym — and a tested data breach response procedure aligned to the UK GDPR 72-hour ICO notification timeframe.
Data Processing Agreement
Our processor terms for customer data in TargetGrade, CareMaSym, AccountGrade, and BuildGrade.
Sub-processor Register
Every third-party service we use, with locations and international transfer safeguards.
Privacy Policy
How we handle personal data as a controller, and how to exercise your rights.
Security First
Built on a foundation of trust
Our platform is designed with security at its core, ensuring your data is protected at rest and in transit.
- Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3.
- Access Controls
Role-based access control (RBAC) and Multi-Factor Authentication (MFA) ensure only authorized users can access data.
- Regular Audits
We conduct regular security audits and penetration testing to identify and address vulnerabilities.