Official Corporate Compliance Documentation

Data Sovereignty & Compliance Statement

UK GDPR / Data Protection Act 2018

1. Executive Summary

Accountigo Global operates under a strict “Zero-Data-Exfiltration” architecture. While certain operational tasks are executed by qualified personnel located in our offshore delivery centres (UAE and India), at no point does client data leave the geographical and legal jurisdiction of the United Kingdom.

All client data remains resident on secure UK-based infrastructure. Remote workers interact only with a real-time visual broadcast of the data, with physical and digital transfer completely blocked.

2. Infrastructure & Data Residency Architecture

  • Sovereign UK Storage 100% of client data, databases, and application files are hosted exclusively within Tier-3 data centres physically located inside the United Kingdom, including AWS/Azure UK Regions or sovereign UK-managed private cloud environments.
  • Ephemeral Pixel Streaming (VDI) Offshore personnel interact with client systems solely through secure Virtual Desktop Infrastructure (VDI). Corporate laptops supplied to offshore personnel function strictly as thin clients or “dumb terminals.” Only encrypted screen pixels are streamed to remote devices while underlying data remains entirely within UK infrastructure.

3. Endpoint & Technical Control Framework

To eliminate the risk of local data downloading, saving, or unauthorized transmission, Accountigo Global enforces strict technical controls through centralized Mobile Device Management (MDM).

  • Zero Local Storage & Drive Isolation VDI drive redirection is permanently disabled. The UK-hosted environment cannot access, map, or interact with local hard drives located in UAE or India, making local downloads technically impossible.
  • Bi-directional Clipboard Block Clipboard redirection is fully disabled. Personnel cannot copy text, files, or data from the secure UK environment into local systems or third-party applications.
  • Hardware Port Lockout All USB and peripheral data ports on company-issued laptops are disabled using hardware-level device policies. External storage devices, flash drives, and smartphone connections are blocked entirely.
  • Network & Email Restrictions
    • Local operating systems run in locked “Kiosk Mode” with internet browsers and unrestricted web access removed.
    • Within the UK virtual environment, firewalls block public webmail services such as Gmail and Yahoo, alongside unauthorized external domains.
    • Corporate email systems operate under aggressive Data Loss Prevention (DLP) policies prohibiting unauthorized file transfers or attachments to external recipients.
  • Peripheral Prevention Local printing functionality is fully disabled from the virtual desktop environment, preventing the creation of physical data copies overseas.

4. Physical & Operational Security

  • Clean Room Environments Accountigo Global delivery centres in India and the UAE maintain strict physical security standards, including biometric access logs, monitored production zones, and enforced “Clean Desk Policies.” Personal smartphones, recording devices, and written notes are prohibited within operational areas.
  • Session Monitoring Remote sessions are continuously audited using digital watermarking, activity monitoring, and screen-capture prevention systems designed to deter and detect unauthorized photography or data exposure.

5. Legal & Contractual Assurances

Accountigo Global remains fully liable for all client data processed by our workforce. All offshore entities and personnel are bound by strict intra-group Data Transfer Agreements incorporating UK International Data Transfer Agreements (IDTAs) and/or Standard Contractual Clauses (SCCs).

We extend a full Right to Audit to your compliance and IT security teams to independently verify our VDI configurations, MDM policy logs, and physical facility security controls at any mutually agreed time.

```