Compliance
DgiDgi maintains compliance with industry standards and regulations for secure multi-tenant SaaS operations.
Compliance Framework
| Regulation/Standard | Status | Scope |
|---|---|---|
| GDPR | Compliant | EU user data |
| UK-GDPR | Compliant | UK user data |
| CCPA | Compliant | California consumers |
| HIPAA | Enterprise | Healthcare (US) |
| SOC 2 Type II | In Progress | Platform operations |
| ISO 27001 | Planned | Information security |
| LGPD | Compliant | Brazil user data |
| PIPEDA | Compliant | Canada user data |
| PDPA | Compliant | Singapore user data |
| APPI | Compliant | Japan user data |
| DPDP | Compliant | India user data |
| POPIA | Compliant | South Africa user data |
| PDPL | Compliant | Middle East (UAE/KSA) |
| PIPA | Compliant | South Korea user data |
| PDPO | Compliant | Hong Kong user data |
| Privacy Act | Compliant | Australia user data |
| PCI DSS | N/A | No payment card storage |
Global Compliance Coverage
DgiDgi provides data residency compliance across 15 regions worldwide:
Americas
| Region | Compliance |
|---|---|
| US East (Virginia) | CCPA, HIPAA, SOC2 |
| US West (Los Angeles) | CCPA, HIPAA, SOC2 |
| Canada (Toronto) | PIPEDA |
| South America (São Paulo) | LGPD |
Europe, Middle East, Africa
| Region | Compliance |
|---|---|
| EU West (Frankfurt) | GDPR |
| EU West UK (London) | GDPR, UK-GDPR |
| EU North (Stockholm) | GDPR |
| Middle East (Dubai) | PDPL |
| Africa (Johannesburg) | POPIA |
Asia Pacific
| Region | Compliance |
|---|---|
| Singapore | PDPA |
| Tokyo | APPI |
| Mumbai | DPDP |
| Sydney | Privacy Act |
| Hong Kong | PDPO |
| Seoul | PIPA |
GDPR Compliance
Lawful Basis for Processing
| Processing Activity | Lawful Basis |
|---|---|
| Account management | Contract performance |
| Service delivery | Contract performance |
| Security monitoring | Legitimate interest |
| Analytics | Legitimate interest |
| Marketing (opt-in) | Consent |
Data Subject Rights
| Right | Implementation | Response Time |
|---|---|---|
| Access | Data export feature | 30 days |
| Rectification | Account settings | Immediate |
| Erasure | Account deletion | 30 days |
| Portability | JSON/ZIP export | 30 days |
| Restriction | Account suspension | Immediate |
| Object | Marketing opt-out | Immediate |
How to Exercise Rights:
- Self-service via account settings
- Email: privacy@dgidgi.one
- Response within 30 days (extendable to 90 for complex requests)
Data Processing Agreements
- Standard DPA available for all customers
- Sub-processor list maintained and updated
- Notification of sub-processor changes
International Data Transfers
| Transfer Mechanism | Application |
|---|---|
| EU-US Data Privacy Framework | US-based processors (where certified) |
| Standard Contractual Clauses (SCCs) | All other international transfers |
| Supplementary Measures | Encryption, access controls, data minimization |
Data Localization Options (Enterprise):
- EU-only data residency
- Region-specific processing
SOC 2 Compliance
Trust Service Criteria
| Criteria | Status | Controls |
|---|---|---|
| Security | Implemented | Access control, encryption, monitoring |
| Availability | Implemented | Redundancy, backups, incident response |
| Processing Integrity | Implemented | Input validation, error handling |
| Confidentiality | Implemented | Encryption, access restrictions |
| Privacy | Implemented | Data handling, consent management |
Key Controls
Security Certifications
Infrastructure Certifications
Our infrastructure providers maintain:
| Provider | Certifications |
|---|---|
| Cloudflare | SOC 2, ISO 27001, PCI DSS |
| Supabase | SOC 2, HIPAA (optional) |
| Fly.io | SOC 2 |
Annual Assessments
- Penetration testing (annual)
- Vulnerability assessments (continuous)
- Security audits (annual)
Audit Logging
Events Logged
| Category | Events Logged |
|---|---|
| Authentication | Login, logout, failed attempts, MFA events |
| Authorization | Permission changes, role assignments |
| Data Access | Reads of sensitive data (configurable) |
| Data Modification | Creates, updates, deletes |
| Configuration | Settings changes, integration updates |
| Security | Secret access, key rotation, exports |
| Administrative | Member management, billing changes |
Log Format:
{
"timestamp": "2024-01-15T10:30:00Z",
"tenant_id": "tenant_abc",
"user_id": "user_123",
"action": "secret.accessed",
"resource": "tenant_secret:456",
"ip_address": "192.168.1.1",
"user_agent": "...",
"result": "success"
}
Log Retention
| Log Type | Retention | Access |
|---|---|---|
| Security audit logs | 1 year | Admin + Compliance |
| Access logs | 90 days | Admin |
| Application logs | 30 days | Developers |
| Debug logs | 7 days | Developers |
Data Residency
Available Regions
| Region Code | Location | Compliance | Availability |
|---|---|---|---|
us-east | Virginia, USA | CCPA, HIPAA, SOC2 | All Plans |
us-west | Los Angeles, USA | CCPA, HIPAA, SOC2 | All Plans |
ca-central | Toronto, Canada | PIPEDA | Growth+ |
sa-east | São Paulo, Brazil | LGPD | Growth+ |
eu-west | Frankfurt, Germany | GDPR | All Plans |
eu-west-uk | London, UK | GDPR, UK-GDPR | All Plans |
eu-north | Stockholm, Sweden | GDPR | Growth+ |
me-south | Dubai, UAE | PDPL | Enterprise |
af-south | Johannesburg, SA | POPIA | Enterprise |
ap-southeast | Singapore | PDPA | All Plans |
ap-northeast | Tokyo, Japan | APPI | All Plans |
ap-south | Mumbai, India | DPDP | Growth+ |
ap-southeast-au | Sydney, Australia | Privacy Act | Growth+ |
ap-east | Hong Kong | PDPO | Growth+ |
ap-northeast-kr | Seoul, South Korea | PIPA | Growth+ |
Regional Data Handling
Configure data residency via tenant settings or API:
PATCH /api/v1/regions/preferences/{tenantId}
{
"primaryRegion": "eu-west",
"dataResidencyRequired": true,
"dataResidencyRegion": "eu-west",
"complianceLevel": "gdpr"
}
Enterprise customers can configure:
- Primary data storage region
- Secondary region for failover
- Data residency enforcement (data never leaves region)
- Bring Your Own Storage (BYOS) for full data ownership
Incident Response
Classification
| Severity | Description | Response Time |
|---|---|---|
| Critical | Data breach, service down | 1 hour |
| High | Security vulnerability, degraded service | 4 hours |
| Medium | Minor security issue, partial outage | 24 hours |
| Low | Minor issue, no security impact | 72 hours |
Notification
Compliance Documentation
Available Documents
| Document | Availability |
|---|---|
| Privacy Policy | Public |
| Terms of Service | Public |
| DPA (Data Processing Agreement) | On request |
| Security Whitepaper | On request |
| Sub-processor List | On request |
| SOC 2 Report | Enterprise (NDA required) |
Request Documentation
Contact: compliance@dgidgi.one