Idukki
GDPR

Every byte, accounted for.

When a creator’s photo lands in Idukki, we know exactly where it sleeps, who can wake it, and who’s allowed to ask for it back. Below: our GDPR role as processor, the rights you and your customers can exercise, who else in the supply chain touches the data, and how to delete it on demand.

SOC 2 Type II· ISO 27001· EU data residency available

Last updated · January 2026

  1. Creator posts

    #yourbrand · IG

    01
  2. AES-256 at rest

    EU region · ringfenced

    02
  3. Rights cleared

    consent · audit row

    03
  4. Delete on demand

    < 30 days · DSR portal

    04
DPA signed automatically on every new workspace Compliant

Our role under GDPR

Data processor

For the UGC + content you publish through us

When you connect your social channels, run a hashtag campaign or ingest reviews, Idukki acts as a data processor. You — the brand — are the data controller. We only process this data on your documented instructions and per our Data Processing Agreement.

Data controller

For your Idukki account itself

When you sign up, log in, get billed or contact support, Idukki is the data controller for that account-level personal data. Our processing here is governed by our Privacy Policy.

What we process

As processor (for you)

  • UGC posts, captions, hashtags, comments (from public sources you connect)
  • Creator handles and avatar URLs
  • Rights-request conversation logs
  • Email addresses of customers who submit UGC via your QR portal or photobooth
  • IP address + user-agent of widget viewers (for analytics + bot filtering)
  • Event-funnel data (view → click → cart → purchase) — keyed by anonymised cookie ID

As controller (about you)

  • Account holder name + email
  • Company name + billing address
  • Login credentials (passwords are bcrypt-hashed)
  • IP + user-agent of dashboard sign-ins
  • Payment method tokens (held by Stripe, not Idukki)

We do not sell personal data. We do not train AI models on customer content. We do not use your data to enrich any other product or service.

Your rights as a data subject

Anyone whose personal data Idukki holds can exercise the following rights at any time. Email privacy@idukki.io and we’ll respond within 30 days (usually 72 hours).

You also have the right to lodge a complaint with your supervisory authority — in the UK, that is the ICO. We’d ask you to talk to us first, but we’ll never get in the way of you exercising that right.

Sub-processors

The vendors below process personal data on our behalf. Each is bound by a written agreement that mirrors our own GDPR obligations. We notify customers at least 30 days before adding or replacing any sub-processor.

VendorRegionPurpose
Amazon Web Services (AWS)EU (Frankfurt, Ireland)Application hosting, object storage, queueing
CloudflareGlobal (with EU isolation)CDN, edge runtime, DDoS protection
PostmarkEUTransactional email delivery
StripeEU + US (SCC-covered)Billing + payment processing
SentryEU (Frankfurt)Application error monitoring
PostHog Cloud EUEUProduct analytics (EU-hosted)
Twilio / SendGridEU + US (SCC-covered)SMS + transactional channels
OpenAI (Enterprise — no-train)US (SCC-covered, no training)Caption + alt-text + tagging inference

Subscribe to sub-processor updates at privacy@idukki.io.

International transfers

Our production environment is hosted in the EU (AWS Frankfurt + Ireland). Some sub-processors are based in the US. Where data leaves the EEA, we rely on the European Commission’s Standard Contractual Clauses (2021/914) as well as supplementary technical and organisational measures — encryption in transit and at rest, no-train commitments, audit rights and breach notification timelines tighter than the regulation requires.

For customers on our Enterprise plan, we offer EU-only data residency: all data — including derived AI embeddings — stays inside the EU at all times.

Retention + deletion

Security measures

Read the full security overview

Data Processing Agreement

Our DPA is pre-signed by Idukki and incorporated into every customer agreement. It includes the updated Standard Contractual Clauses (Modules 2 and 3) and the UK Addendum. No negotiation needed for the standard terms.

Contact our DPO

Talk to a human — typically the same day.

Idukki’s Data Protection Officer can be reached at dpo@idukki.io for any GDPR question, data subject request, breach report or audit. We respond within 72 hours, usually faster.

4-min setup1,400+ brands37 KB runtime5.0 G2

Stop renting six tools. Ship one.

Spin up your first widget in 4 minutes. Migrate from Bazaarvoice, EmbedSocial, Tolstoy or Videowise in a day. Your CFO will love us. Your CRO already does.

  • No credit card
  • Cancel anytime
  • SOC 2 + GDPR

Where Idukki ships

Same data model. Every surface a shopper meets.