legal · uk gdpr · eu gdpr

UK & EU data protection

The details UK and EU privacy law asks for: our roles, representatives, transfers and how to complain.

Last updated 28 September 2026

Our roles

Representatives (Article 27)

Shorward isn't established in the EU or the UK. Our representatives are:

You can contact them, or us directly at [email protected], about anything to do with your personal data.

International transfers

FromMechanism
EEAEU-US Data Privacy Framework where the recipient is certified. Otherwise the Standard Contractual Clauses (Commission Decision 2021/914), Modules 2 and 3 as applicable
UKUK Extension to the Data Privacy Framework where the recipient is certified. Otherwise the ICO's International Data Transfer Addendum to the SCCs
SwitzerlandSwiss-US Data Privacy Framework where certified. Otherwise the SCCs as adapted for Swiss law

We assess each transfer and apply supplementary measures such as encryption in transit and at rest, access controls and data minimization.

Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. Shorward makes no such decisions about individuals. We respond within one month.

Complaints

We'd like the chance to fix a problem first: [email protected]. You can also complain to a supervisory authority:

Other EU rules

How the EU AI Act applies to us is on How we use AI. Shorward isn't itself an essential or important entity under NIS2. Customers subject to NIS2 or DORA can use our reports as supporting evidence in their own risk management.