Security and data protection
Last updated: 30 July 2026
We build production systems that businesses rely on, so data protection and security are part of how we work, not an afterthought. This page explains how we handle personal data, the agreements we sign, where your data lives, and the practices we follow. For how we handle data on this website specifically, see our Privacy Policy.
Our GDPR commitment
OBJECTSINGLE, UNIPESSOAL LDA is based in Lisbon, Portugal, and operates under the EU General Data Protection Regulation (GDPR). For our own website and enquiries we act as the data controller. When we build or run systems for you, your organisation is the controller and we act as your data processor, handling personal data only on your documented instructions and only for the agreed purpose.
Data Processing Agreement (DPA)
Before we process personal data on your behalf, we enter a Data Processing Agreement that sets out the subject matter, duration, and purpose of processing, the types of data and data subjects, our obligations as a processor, the use of sub-processors, and how data is returned or deleted at the end of the engagement. For international transfers we rely on the European Commission Standard Contractual Clauses (SCCs).
Need our DPA for your procurement or legal review? Email [email protected] and we will send it over.
Where your data lives
We default to EU-based hosting and data residency wherever the project allows. Some providers may process data outside the European Economic Area; where that happens we rely on appropriate safeguards such as the SCCs. The exact hosting region and providers for your project are agreed with you and recorded in the DPA.
Sub-processors
We work with a small set of vetted providers who process data on our behalf under appropriate agreements. For this website these are the providers listed in our Privacy Policy. For client engagements, the sub-processors depend on what we build and are listed in your project's DPA. These commonly include hosting and content-delivery providers, an application database, and, where AI features are in scope, the AI model providers we use. We tell you before adding a new sub-processor that affects your data.
Security practices
Our baseline practices across engagements include:
- Encryption in transit. Traffic is served over HTTPS/TLS. Data at rest is encrypted where our providers support it.
- Least-privilege access. Access to systems and data is limited to the people who need it, and removed when it is no longer required.
- Secrets management. Credentials and API keys are stored in secure secret stores, never in source code.
- Secure development. Code review, dependency management, and environment separation (development, staging, production).
- Backups and recovery. Where we operate the infrastructure, we maintain regular backups and recovery procedures.
- Incident response. If a personal-data breach affects your data, we notify you without undue delay and support the required GDPR notifications.
Specific measures are scoped per engagement and recorded in the DPA.
Ownership and handover
You own everything we build: source code, designs, documentation, data, and infrastructure. There is no lock-in. When we hand over or an engagement ends, we return or delete data as agreed and revoke our access to your systems.
Reporting a security concern
If you believe you have found a security vulnerability or have a concern about how data is handled, please email [email protected] and we will respond promptly.