Official Corporate Compliance Documentation
Data Sovereignty & Compliance Statement
UK GDPR / Data Protection Act 2018
1. Executive Summary
Accountigo Global operates under a strict
“Zero-Data-Exfiltration” architecture. While certain operational tasks are
executed by qualified personnel located in our offshore delivery centres
(UAE and India), at no point does client data leave the geographical and
legal jurisdiction of the United Kingdom.
All client data remains resident on secure UK-based infrastructure.
Remote workers interact only with a real-time visual broadcast of the data,
with physical and digital transfer completely blocked.
2. Infrastructure & Data Residency Architecture
-
Sovereign UK Storage
100% of client data, databases, and application files are hosted
exclusively within Tier-3 data centres physically located inside the
United Kingdom, including AWS/Azure UK Regions or sovereign
UK-managed private cloud environments.
-
Ephemeral Pixel Streaming (VDI)
Offshore personnel interact with client systems solely through secure
Virtual Desktop Infrastructure (VDI). Corporate laptops supplied to
offshore personnel function strictly as thin clients or “dumb terminals.”
Only encrypted screen pixels are streamed to remote devices while
underlying data remains entirely within UK infrastructure.
3. Endpoint & Technical Control Framework
To eliminate the risk of local data downloading, saving, or unauthorized
transmission, Accountigo Global enforces
strict technical controls through centralized Mobile Device Management (MDM).
-
Zero Local Storage & Drive Isolation
VDI drive redirection is permanently disabled. The UK-hosted
environment cannot access, map, or interact with local hard drives
located in UAE or India, making local downloads technically impossible.
-
Bi-directional Clipboard Block
Clipboard redirection is fully disabled. Personnel cannot copy text,
files, or data from the secure UK environment into local systems or
third-party applications.
-
Hardware Port Lockout
All USB and peripheral data ports on company-issued laptops are
disabled using hardware-level device policies. External storage devices,
flash drives, and smartphone connections are blocked entirely.
-
Network & Email Restrictions
-
Local operating systems run in locked “Kiosk Mode” with
internet browsers and unrestricted web access removed.
-
Within the UK virtual environment, firewalls block public
webmail services such as Gmail and Yahoo, alongside
unauthorized external domains.
-
Corporate email systems operate under aggressive Data Loss
Prevention (DLP) policies prohibiting unauthorized file
transfers or attachments to external recipients.
-
Peripheral Prevention
Local printing functionality is fully disabled from the virtual desktop
environment, preventing the creation of physical data copies overseas.
4. Physical & Operational Security
-
Clean Room Environments
Accountigo Global delivery centres in India and the UAE maintain
strict physical security standards, including biometric access logs,
monitored production zones, and enforced “Clean Desk Policies.”
Personal smartphones, recording devices, and written notes are
prohibited within operational areas.
-
Session Monitoring
Remote sessions are continuously audited using digital watermarking,
activity monitoring, and screen-capture prevention systems designed
to deter and detect unauthorized photography or data exposure.
5. Legal & Contractual Assurances
Accountigo Global remains fully liable
for all client data processed by our workforce. All offshore entities and
personnel are bound by strict intra-group Data Transfer Agreements
incorporating UK International Data Transfer Agreements (IDTAs) and/or
Standard Contractual Clauses (SCCs).
We extend a full Right to Audit to your compliance and IT security
teams to independently verify our VDI configurations, MDM policy logs,
and physical facility security controls at any mutually agreed time.