Skip to content

Compliance & Governance

GDPR Data Protection

Our operational approach to privacy-by-design and data-subject rights under European data-protection law.

Last updated:3 October 2026

Privacy by design

We aim to minimise personal data, define its purpose before collection, restrict access, and select architectures that support deletion, auditability, and controlled data movement. Technical controls are matched to the context and risk of each system.

Website contact data

  • Only the fields needed to understand and answer a professional inquiry are requested.
  • The form uses server-side validation and Cloudflare Turnstile abuse protection.
  • Submissions are delivered to a restricted business inbox and are not stored in a separate website database.
  • Data-subject requests can be sent to office@empirist.com.

Project work

For client and research projects, controller and processor roles, lawful basis, retention, subprocessors, data location, security controls, and incident responsibilities are documented for the specific engagement. This website statement does not replace a project-specific data-processing agreement.

International processing

Where a service requires personal data to be processed outside the European Economic Area, we assess the transfer mechanism and supplementary safeguards appropriate to that service and engagement.

Questions about this statement can be sent tooffice@empirist.com.