Data security
Last updated: 10 October 2025
- Company:
- AcouBatt LTD (“we”, “us”, or “our”)
- Registered office:
- 83 Ellerton Road, London SW18 3NH, United Kingdom
- Company number:
- 16409471
This page describes the technical and organisational measures AcouBatt uses to protect Customer Data, consistent with our obligations as a data processor under Article 32 UK GDPR. It complements our Privacy Policy, which explains what personal data we collect and your rights over it.
1. Our Approach
Acoustic and process data are sensitive to our customers’ operations. AcouBatt is built so that Customer Data is encrypted in transit and at rest, access is scoped and audited, and edge deployment keeps raw signals on your infrastructure where required. Security is treated as a design constraint, not an afterthought.
2. Technical and Organisational Measures
In line with Article 32 UK GDPR, we maintain the following measures:
- Encryption of Customer Data in transit (TLS) and at rest
- Role-based access control, scoped to the minimum access needed for a given role
- Network segmentation between customer environments and internal systems
- Logging and monitoring of access to production systems and Customer Data
- Regular penetration testing and internal security audits
- Mandatory staff security training and signed confidentiality agreements
- Documented ability to restore availability and access to Customer Data in a timely manner following an incident
3. Deployment Options
Cloud, on-premises, and edge deployments are supported. Sensitive workloads can be kept fully within your network, with only the classifications you choose to share leaving the site — supporting data minimisation by design rather than by policy alone.
4. Data Processing Agreements and Sub-Processors
Where we process Customer Data containing personal data on a customer’s behalf, we enter into a Data Processing Agreement (DPA) reflecting the requirements of Article 28 UK GDPR. A copy is available on request via the contact form.
Where a customer chooses an on-premise or edge deployment, Customer Data is processed on the customer’s own infrastructure and is not shared with any cloud sub-processor. Where a customer chooses a cloud-hosted deployment, we rely on Amazon Web Services (compute) and Hetzner (data storage) to deliver the Services, each engaged under confidentiality and data protection obligations consistent with this page. We also use Google Workspace and Slack for our internal business operations and correspondence. Where Customer Data is transferred outside the UK or EEA, we ensure adequate protection through Standard Contractual Clauses or equivalent safeguards, as set out in our Privacy Policy.
5. Incident Response and Breach Notification
We maintain internal incident response procedures to detect, contain, and investigate security incidents. Where a personal data breach is likely to result in a risk to individuals, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 UK GDPR. Where a breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay, in accordance with Article 34 UK GDPR. Affected customers will be notified promptly so they can meet their own notification obligations.
6. Certifications and Audits
AcouBatt does not yet hold formal third-party security certifications (such as SOC 2 or ISO 27001). We are working towards recognised certifications as the business scales, and in the meantime rely on the technical and organisational measures described above, verified through regular internal and third-party penetration testing. This section will be updated as certifications are obtained.
7. Contact
If you have questions about our security practices, would like a copy of our Data Processing Agreement, or need to report a suspected vulnerability or security incident, contact us at admin@acoubatt.ai or via the contact form on this website.