Legal

Data protection policy

The internal data protection framework applied by NioX covering accountability, records of processing, impact assessments, processors, breach handling and audit.

Version 1.0. Last updated 15 September 2026. This document is published in English and the English version prevails over any translation.

At a glance

  • NioX acts as a controller of personal data and at times as a processor, and everyone who works here follows this framework.
  • Seven principles steer every handling of data, running from lawful use through to answerability.
  • Processing is logged in a living register and screened by an impact assessment before any high risk work begins.
  • A breach travels through four steps, namely contain, assess, notify and remediate.

1. Purpose and scope

This document describes the way NioX discharges its duties when it acts as a controller of personal data and, in the situations where that applies, as a processor. Its reach extends to all staff, contractors and officers of NioX, and to every system, tool and workflow through which personal data passes.

Read this policy as the inward facing partner to the privacy policy. Where the privacy policy tells individuals what happens to their data, this document sets out how the organisation is arranged internally so that those promises are actually kept.

2. Data protection principles

All handling of personal data at NioX is anchored to the principles set out below.

  1. Lawful, fair and transparent handling. No processing activity proceeds without a documented legal basis, and each one is made clear to the person concerned.
  2. A defined purpose. Data is gathered for stated and legitimate reasons and is never reused later in ways that clash with those reasons.
  3. Restraint in collection. NioX takes only the data that is suitable, relevant and confined to what the task genuinely requires.
  4. Correctness. Records are held accurately and refreshed when needed, and anything found to be wrong is put right promptly.
  5. Time limited storage. Data that can identify a person is retained in that form only for as long as a real need exists.
  6. Security and confidentiality. Personal data is guarded by measures suited to the risk.
  7. Answerability. NioX carries responsibility for observing these principles and can show, on request, that it does so.

3. Roles and responsibilities

The chart below shows who holds which part of the data protection remit.

FunctionDuty held
BoardSigns off this policy, takes reports on data protection risk and sets aside the resources it needs.
Data protection officer or responsible officerGuides the business on its obligations, keeps watch over compliance, serves as the point of contact for supervisory authorities and for individuals, and reports upward to the board.
ComplianceRuns screening and monitoring inside the boundaries this policy sets and deals with requests from authorities.
EngineeringBuilds the technical safeguards, keeps access control in order and supports data subject requests.
All staffAbide by this policy, finish the required training and raise any suspected breach at once.

4. Record of processing activities

NioX keeps a standing register of its processing activities. Every entry captures the purpose, the kinds of individual and personal data involved, the classes of recipient, any movement of data beyond the country where it was gathered together with the safeguard that supports it, how long the data is kept and a broad account of the security measures in place.

This register is revisited no less than once a year, and also each time a fresh processing activity begins or an existing one shifts in a significant way.

5. Data protection impact assessments

Before starting any processing that could pose a high risk to the rights and freedoms of individuals, NioX runs an impact assessment first. Such cases take in large scale systematic monitoring, the handling of biometric data to single out one person, and the adoption of new technology in a manner that alters the risk picture.

Each assessment lays out the processing, weighs whether it is necessary and proportionate, pinpoints the risks and records the steps taken to blunt them. If a high risk still lingers after that work, NioX puts the matter to the supervisory authority before any processing starts.

6. Data protection by design and by default

Data protection needs are weighed while a system or process is still being designed, rather than bolted on once it already exists. As the standing default, only the personal data a given purpose truly calls for is processed, entry is limited to the people who need it, and retention is set up to lapse on its own.

Any change that brings in a new class of personal data, a new recipient or a new transfer has to pass review before it ships.

7. Processors and sub processors

NioX brings on a processor only when that party can offer solid assurances of fitting technical and organisational measures. Checks are made before the relationship begins and are run again from time to time.

A written contract frames every such relationship. It obliges the processor to work solely from documented instructions, to bind its own people to confidentiality, to keep security suited to the risk, to lend a hand with data subject requests and breach notification, to seek authorisation before taking on a sub processor, and to hand back or erase personal data once the work is done.

8. Handling requests from individuals

When someone asks to exercise a right, the request is recorded the moment it arrives and confirmed back to them. NioX establishes who they are before releasing any personal data. A reply follows inside one month, a window that may stretch by a further two months when the matter is complex, and the person hears of any such extension during that first month.

Should a request be turned down, whether fully or in part, the individual is given the reason, is pointed to the right to lodge a complaint with a supervisory authority and is pointed to the right to seek a remedy through the courts.

9. Personal data breach

Anyone who suspects a breach must flag it internally to the responsible officer straight away. From there the response moves through four stages.

  1. Contain. Halt the breach and hold back any wider exposure.
  2. Assess. Work out the classes and rough number of individuals and records touched, the probable fallout and the risk to rights and freedoms.
  3. Notify. Where the breach is likely to create a risk, tell the supervisory authority without undue delay and, where it can be done, inside seventy two hours of learning of it. Where the risk runs high, tell the affected individuals without undue delay.
  4. Record and remediate. Write down the facts, the effects and the response, then fix the underlying cause.

10. International transfers

Where data would move to a country that has not been judged to offer an adequate standard of protection, NioX proceeds only on a lawful transfer mechanism, backed by a transfer risk assessment that looks at the law and the practice of the receiving country along with any extra measures that may be called for.

11. Training and awareness

All staff work through data protection training when they join and then at least once in every year that follows. Those whose roles carry heightened access take further training matched to what the role demands. Every completion is logged.

12. Monitoring and audit

NioX keeps an eye on how well this policy is followed by periodically going over the record of processing activities, reviewing access, checking retention and putting the breach response to the test. What these reviews surface goes to the board, each item tied to an owner for the fix and a date to hit.

The policy itself is looked over at least once a year, and again whenever the law, the services on offer or the systems in use shift in a material way.