GDPR
Last updated 21 July 2026
Our Privacy Policy explains what we do with your data. This page is about something different: when you run your business on Arthur, you take on duties under the GDPR too. Here is how the responsibility splits, and how we help you meet yours.
On this page
1 Who is responsible for what
The GDPR splits responsibility between the controller, who decides why data is collected, and the processor, who handles it on the controller's instructions. With Arthur it works in two directions:
You are the controller
For the data you put into your workspace: your staff, their roles and shifts, and anything you record about your own customers. You decide what goes in. We only act on your instructions.
We are the controller
For your own account with us: your name, email, sign-in details, and billing. We decide how that is handled, and our Privacy Policy covers it.
This matters in practice. If a member of your staff asks to see or delete their data, that request goes to you first, because it is your workspace. We are here to help you answer it.
2 The processing agreement
Where we act as your processor, the GDPR requires a written agreement between us. We have one, and it applies automatically when you use Arthur, so you do not have to chase us for paperwork.
It sets out what we may do with your data, the security we keep, who else is involved, how we help with requests and breaches, and what happens to your data when you leave.
Data Processing Agreement
The full Article 28 agreement, including the annexes on processing details, security measures, and sub-processors.
3 Our sub-processors
These are the providers that help us run Arthur. We keep the list short on purpose.
We will always update this list and give notice before a new sub-processor starts handling your data, so you have a chance to object.
4 Where data is held
We aim to keep your data inside the European Economic Area. Where a provider we use handles data outside it, we rely on the safeguards the law allows, such as the European Commission's standard contractual clauses.
5 How we secure it
- Data is encrypted in transit.
- Passwords are salted and hashed, never stored in readable form.
- Roles limit what each person in a workspace can see and do.
- Changing a password signs out other sessions, so a lost device can be cut off.
- Repeated failed sign-ins are slowed down to blunt brute-force attempts.
The full list of measures is in Annex 2 of the DPA.
6 If something goes wrong
If we become aware of a personal data breach affecting your workspace, we will tell you without undue delay, and within 72 hours of becoming aware of it. We will tell you what happened, what data was involved, what we are doing about it, and what we suggest you do.
We will not sit on bad news. You cannot make good decisions about your business or your staff if we hide a problem from you.
7 Helping you answer requests
If someone asks you to see, correct, export, or delete their data, Arthur is built so you can act on most of it yourself, directly in your workspace. Where you need more, write to us and we will help you within a timeframe that lets you meet your own one-month deadline.
For your own personal data held by us, see the rights section of our Privacy Policy. You can also complain to the Greek supervisory authority, the Hellenic Data Protection Authority, at dpa.gr.
8 Contact us
For anything about GDPR, the DPA, or your data, write to and a real person will get back to you.
