GDPR & Compliance
Last updated
Local processing changes the compliance picture significantly. This page explains what that means for your assessment, and what documentation we provide.
Why local processing matters for your assessment
Under GDPR, a transfer occurs when personal data is made available to another party. When you use the browser-based tools, your file is read and written by code running on your own device. No personal data in the file is transmitted to us.
In practical terms this means using those tools is not a processing operation you need to record us as a processor for, in the same way that opening a file in Excel does not make Microsoft your processor for its contents.
This is the single most common reason regulated teams choose us over upload-based converters.
Where we are a processor
Two cases:
- Account data — your email, plan and audit log. We are the controller for this.
- AI features — where you explicitly use an AI tool, we process the schema and sample rows you send, and Anthropic processes them as our sub-processor. We are your processor for this data.
If your AI use involves personal data, request a DPA before enabling those features.
Data Processing Agreement
Business plan customers receive a signed DPA covering Article 28 requirements, including sub-processor lists, security measures, audit rights and breach notification within 72 hours. Request one at support@exceltoolkitpro.com.
Data subject requests
Access, rectification, erasure, restriction, portability and objection are all supported. Email support@exceltoolkitpro.com; we respond within 30 days at no charge. Account deletion is immediate and self-service.
Because we never hold your file contents, a data subject request about a spreadsheet you processed here has no data for us to return — a point worth documenting in your own records.
Security measures
- Encryption in transit (TLS 1.3) and at rest (AES-256) for all stored account data.
- Bcrypt password hashing with a work factor of 12.
- Optional two-factor authentication via TOTP.
- Role-based access control with least-privilege defaults for our own staff.
- Audit logging of authentication and administrative actions.
- Rate limiting and brute-force protection on all authentication endpoints.
- Annual third-party penetration test; report available under NDA to Business customers.
International transfers
Our primary infrastructure is EU-hosted. Where a sub-processor is outside the EEA, transfers rely on Standard Contractual Clauses plus a transfer impact assessment, available on request.
Breach notification
We will notify affected customers within 72 hours of becoming aware of a personal data breach, with the information Article 33 requires.
Other frameworks
We align with UK GDPR, CCPA/CPRA (we do not sell or share personal information as those terms are defined), and are working towards SOC 2 Type II. Ask for the current status if it is relevant to your procurement.