Back to Home

Compliance & Data Protection

Technspire is a Swedish B2B consultancy. We keep this page honest: it describes how we actually work with data protection and security, which assurances come from the platforms we build on, and how we help clients meet their own regulatory requirements.

Our approach

We are a small, specialised team, and our compliance posture reflects that. GDPR is the legal foundation for everything we do with personal data. Our internal security practices are informed by ISO 27001 controls, without us holding a certification, and we say so plainly rather than implying otherwise.

Client work runs on Microsoft Azure and Microsoft 365. That matters for compliance: the infrastructure carries Microsoft’s certifications and audit reports, and we design deployments so those platform controls actually apply to your workload.

GDPR

  • Data processing agreements (DPA) available for all client engagements
  • Personal data processed in EU/EEA regions by default (Sweden Central where possible)
  • Data minimisation: we only access the data an engagement requires
  • Subprocessors are limited to major cloud platforms (Microsoft Azure); a current list is available on request
  • Breach notification procedures aligned with GDPR Articles 33–34
  • Data subject requests honoured and supported in client systems we build

Information security

  • Security practices informed by ISO 27001 controls (not certified; we do not claim certification)
  • Microsoft Entra ID with MFA for all internal systems
  • Least-privilege access to client environments, removed at engagement end
  • Encryption in transit and at rest for anything we store
  • Endpoint management and disk encryption on all work devices

Platform certifications (Microsoft’s, not ours)

Azure and Microsoft 365 hold certifications including ISO 27001, ISO 27017/27018, SOC 1/2/3, and are covered by the EU Data Boundary. These attest to Microsoft’s infrastructure and services. When we deploy your workload on Azure, it inherits those platform controls, our job is configuring residency, identity, networking, and logging so the inheritance is real rather than theoretical.

EU AI Act

We follow the AI Act closely (our blog covers it in depth) and build client systems with its obligations in mind: transparency for AI systems that interact with people, logging and human oversight for higher-risk use, and honest capability claims. For our own site and tools, AI-generated content is produced under editorial review with verified sources.

Helping you with your compliance

Much of our work is helping clients meet their obligations: GDPR-compliant AI architectures, EU AI Act readiness, NIS2-aware operations, and audit-friendly logging and documentation on Azure. If your organisation is certified (ISO 27001, SOC 2) or regulated (financial services, public sector), we work within your control framework and produce the evidence your auditors ask for.

What we can provide

  • Signed DPA and subprocessor list
  • Security practices overview for vendor assessments
  • Engagement-specific security and data-flow documentation
  • Azure compliance documentation for your deployed architecture (via Microsoft’s Service Trust Portal)

Contact

Questions about data protection, vendor assessments, or a specific regulatory requirement? Email hello@technspire.com, we respond within two business days.

Last updated: September 1, 2026