Security & Data Protection | Global 4D Tool

Security & Data Protection

How the Global 4-Domain Communication Skills Rating Tool™ protects your data, from infrastructure to deletion.

At a Glance

Where We Stand Today

Control AreaStatus
Encryption in transit (TLS v1.3)In place
Encryption at restIn place
Data residency — dedicated virtual server, GermanyIn place
Data Processing AgreementSigned before access is granted
Personal data deletion on requestWithin 30 days
Multi-tenant data isolationEnforced at the query layer
Role-based access controlEnforced at the application layer
Password policyMinimum length & complexity enforced
Audit loggingInsert-only
SOC 2 Type IIPlanned for the next phase
ISO 27001Aligned to principles — planned for the next phase

Infrastructure & Encryption

Where Your Data Lives

The platform runs on a dedicated virtual server, hosted in Germany. Data does not leave this hosting environment except as described in the Data Processing Agreement.

Encryption

All data in transit is encrypted using TLS. All data at rest is encrypted. This applies across the entire platform. For institutional/organisational tiers, this is governed by the Data Processing Agreement, and for the Individual tier by our Terms & Conditions and Privacy Policy, under which Global 4-Domain Communications Limited acts as Controller.

Platform Availability

Platform availability

The G4D platform targets 99.97% monthly uptime across all deployments, matching the uptime of the single dedicated server that hosts all clients.

SLA-backed guarantees

Formal service-level commitments, including guaranteed uptime and 4-hour critical response times, apply to Organisational and Global Enterprise tiers as set out in the Order Form. Strategic Partner terms are negotiated individually and take this baseline into account.

Data Isolation & Access Control

Tenant Isolation

Multi-tenant data isolation is enforced at the query layer, not left to interface-level filtering alone. A request for another organisation's data returns a 404 response rather than a filtered result. The separation exists below the presentation layer, where a misconfigured screen or report cannot bypass it.

Role-Based Access

Internal access to platform data is controlled by a role-based permission system enforced at the application layer, with defined boundaries between roles. Access is scoped by design, not solely by policy.

Licence-Scoped Access

Partner and enterprise access to participant data is limited to the scope and duration of the licence agreement and enforced at the application layer. Where a client elects to export their data upon termination, access is retained for 30 days for that purpose; otherwise, access is revoked in accordance with the Data Processing Agreement.

Audit Logging

Insert-Only Records

Access and administrative activity are recorded in an insert-only audit log. Entries cannot be edited or deleted after the fact, which preserves a reliable record for internal review and supports the compliance information we provide to clients on request under the Data Processing Agreement.

Data Protection & Your Rights

Data Processing Agreement

A Data Processing Agreement is signed by the client's designated primary contact via a secure link provided during onboarding before any platform credentials are issued.

Applicable Law

Data protection obligations are governed by UK GDPR, EU GDPR, and the Data Protection Act 2018, together with any other data protection law applicable to a client's own jurisdiction.

Deletion on Request

Personal identifiers — name, email address, and contact details — are deleted or permanently anonymised within 30 days of a verified request. Full details on how this applies to individual participants and organisational deployments are set out in our Governance Framework.

Breach Notification & Compliance Information

Notification & Information Rights

In the event of a confirmed personal data breach, clients are notified within 72 hours. Clients may also request information reasonably necessary to demonstrate our ongoing compliance with the Data Processing Agreement.

Sub-Processors

Current List

A current list of sub-processors is published and maintained on our Sub-Processors page.

Security Roadmap

The following controls are not yet in place. We state this directly as a matter of institutional integrity and in alignment with our commitment to accuracy.

SOC 2 Type II

Not currently available. Planned for the next phase, as part of the enterprise security roadmap.

ISO 27001

Practices are aligned to ISO 27001 principles. Formal certification is not yet held and is planned for the next phase.

SSO, MFA & API Access

Single sign-on and API access are not available at launch. We would build these in our next development phase, prioritised once a specific client's requirement makes them necessary. Multi-factor authentication would be considered alongside the single sign-on offering.