Getting StartedSecurity & Compliance

Security & Compliance

How Fisar handles your data, where responsibility sits under UK GDPR, and the controls around access, delivery and identity documents.

Controller and processor

Under UK GDPR, the split is straightforward:

PartyRole
Your organisationData controller
FisarData processor

A Data Processing Agreement is issued by Fisar before go-live and must be signed before the platform is activated.

Access control

Fisar separates duties between two account types.

  • Organisation administrators manage DPOs, subscriptions and email configuration. They cannot run SARs.
  • Data Protection Officers run and review requests. They cannot manage the organisation.

Each DPO is invited individually by email and sets their own password. Multi-factor authentication can be configured when the account is set up.

Every organisation gets its own subdomain in the form https://[your-subdomain].app.fisar.co.uk.

Connecting systems

Connectors are authorised through single sign-on with your own administrator account - Fisar never asks for or stores end-user passwords.

Connecting a system requires a tenant or workspace administrator to grant consent. A DPO cannot authorise a connector on their own.

The data Fisar can reach is bounded by the permissions you grant, your licensing, and your retention settings. Narrowing consent narrows what a SAR can find.

Secure delivery

Responses are delivered as a password-protected archive:

  • The password is set by the DPO when the request is created
  • It is deliberately not a password used anywhere else
  • It is shared with the requester separately from the download link
  • Links expire after 30 days

Never send the archive password in the same email as the download link. Use a phone call or a separate channel.

Identity documents

Identity documents supplied to verify a requester are checked, the outcome is recorded against the request, and the documents are destroyed immediately afterwards.

Human oversight

No response leaves Fisar without a person approving it. Redactions are proposed by the platform and confirmed by your DPO, who explicitly takes ownership of the release at the point of verification.

Every request carries an audit trail: what was found, what was redacted, who verified it and when.