Legal

GDPR Compliance.

How rendrOS meets its obligations under the EU and UK General Data Protection Regulation. Practical, plainly written, and signed off by our legal team.

Updated 1 May 2026SLA 30 daysRegion UK & UAE

Overview

rendrOS is built for CGI studios that work with European, UK, and UAE clients — many of whom must demonstrate GDPR compliance up the chain. This page summarises how we meet our GDPR obligations as a data controller for our marketing site and as a data processor for studio content.

// At a glance
We are GDPR-compliant by default. We sign DPAs with every customer who needs one. We never sell data. We host in the UK or UAE region you choose. You retain ownership of every shot, comment, and asset you upload.

Our role

Data subject rights

Under Articles 15–22 of the GDPR, individuals can exercise the following rights:

RightWhat it meansHow to exercise
Access (Art. 15)Get a copy of your dataEmail us — 30 day SLA
Rectification (Art. 16)Correct inaccurate dataIn-app or by email
Erasure (Art. 17)Delete your account & dataSettings → Delete account
Restriction (Art. 18)Pause processingEmail us
Portability (Art. 20)Export your data in JSON/CSVIn-app export
Object (Art. 21)Stop marketing or profilingUnsubscribe link or email

International data transfers

Studio data is region-locked. UK studios are hosted in eu-west-2 (London). UAE studios are hosted in me-central-1 (Dubai). Where data must leave these regions for limited operational reasons, we rely on:

Breach notification

In the unlikely event of a personal data breach we will notify the relevant supervisory authority within 72 hours as required by Article 33, and notify affected customers without undue delay where the breach is likely to result in high risk to their rights.

Data Protection Impact Assessments

We conduct DPIAs for any new feature that involves systematic profiling, large-scale processing, or new categories of personal data. Summaries are available to enterprise customers under NDA.

Data Protection Officer

While we are not formally required to appoint a DPO under Article 37, we have nominated a Privacy Lead who is the single point of contact for all data protection matters. Reach them at hello@getrendros.com.

Certifications & commitments

Contact

GDPR enquiries, DPA requests, or breach notifications

hello@getrendros.com