Trust & compliance
The enterprise review pack: GDPR, DPA, sub-processors and security documents.
- Trust CentreOne place for the security, privacy and compliance information your legal and security teams need to approve Laya.
- Security programmeThe technical and organisational measures protecting Laya: encryption, access control, authentication, monitoring and secure development.
- GDPR complianceHow Laya meets the UK GDPR and EU GDPR: controller and processor roles, lawful bases, data subject rights and processor obligations.
- Data Processing AgreementThe Article 28 processor terms governing Laya’s handling of customer personal data, including sub-processing, security, transfers and deletion.
- Sub-processorsThe third parties that may process Laya customer data, what each is used for, where it processes, and how changes are notified.
- International data transfersWhere Laya hosts data, the transfer mechanisms relied on for moving personal data out of the UK and EEA, and the safeguards applied.
- Data retention and deletionWhat Laya keeps, for how long, what deletion actually removes, and how to export your data before you go.
- Incident responseHow Laya detects, contains and communicates security incidents, including personal data breach notification commitments.
- Privacy rights requestsHow to exercise access, correction, erasure, portability and objection rights with Laya, and how requests are handled.
- Security questionnaire answersPre-answered responses to the questions vendor security assessments ask most often, so a review can be completed without a call.