Security
You need to know where your clients’ data goes. Here is the full answer.
Gatheroo hosts client data in Australia. That makes a transfer from the UK a restricted transfer under UK GDPR. This page sets out the legal position, what we provide, and what sits with you.
Restricted transfer
properly documented
ISO/IEC 27001:2022 certified
independently audited
Data processing agreement
already in place
Transfer risk assessment
support provided
The short version
We help the protection travel with the data.
UK GDPR does not require personal data to stay in the UK. It requires that when data leaves, the protection travels with it. Where a country has no UK adequacy regulations, you use an approved safeguard instead. That is what the International Data Transfer Agreement and the UK Addendum exist for, and they are used routinely by UK businesses transferring data to Australia, Canada, India and elsewhere.
Transferring data to Gatheroo is lawful, it requires documentation, and we provide it.
Why this is a restricted transfer
The legal position
Compliance through documentation
UK GDPR permits transfers to Australia
Article 46 UK GDPR applies and an appropriate safeguard is required.
Gatheroo is a processor
Your practice is the controller
The obligation to have a safeguard in place and to carry out a transfer risk assessment sits with you. Our job is to give you what you need to do it properly.
February 2026 changes
The Data (Use and Access) Act 2025
New transfer risk assessment rules took effect in February 2026 requiring the satisfaction of a “not materially lower” test.
Documentation
What you need from us and what we hand over.
Data Processing Agreement
Already in place, nothing to chase.
Part B of our Terms and Conditions, applying automatically from the moment you have an account. It sets your role as controller and ours as processor, and covers sub-processors, breach notification and retention.
Transfer mechanism
Completed and ready to issue.
We hold a completed International Data Transfer Agreement for UK customers. Email security@gatheroo.io and we will send it with the supporting information for your transfer risk assessment.
Transfer risk assessment support
Most of it is already published.
Our hosting, sub-processors, encryption and certification are all on the security page and in the Trust Centre. Anything further your assessment needs, including Australian government access, just ask.
Need this for a vendor assessment?
Send your security questionnaire, transfer risk assessment template, or procurement pack to security@gatheroo.io and we will return it completed with supporting evidence.
Beyond the paperwork
A transfer safeguard is a contract. These are the controls behind it.
A safeguard only means something if the technical measures stand up.
What protects the data
Hosted on AWS in Australian data centres, with no data leaving Australia in the ordinary course of operating the service
Certified to ISO/IEC 27001:2022, certificate 1357-I-1, issued under JAS-ANZ accreditation, with Gatheroo inside the certified scope
TLS 1.2 in transit. Uploaded files encrypted at rest with AES-256. Sensitive text fields encrypted at rest with field-level AES-128-GCM
Role-based, least-privilege, multi-factor authenticated production access, fully logged
Every request carries a timestamped activity log
Named, published sub-processor list
FAQ
Questions we get asked a lot.
Security FAQs: ISO 27001, encryption, data hosting and more.
Documentation
Can we see your ISO 27001 certificate?
Yes, on request, along with relevant extracts from our Statement of Applicability. Email security@gatheroo.io.
Do you complete security questionnaires?
Yes, regularly, as part of client procurement.
Will you sign our own data processing agreement?
Send it over. Our DPA covers the standard processor obligations, but we will review yours.
Transfers and residency
Do we need to do this every year?
Your assessment should be reviewed when circumstances change, including changes to our sub-processors or to the relevant legal environment. We notify customers of sub-processor changes.
Does our data leave Australia once it is there?
No, not in the ordinary course of operating the service. That commitment is written into our DPA.
Is it lawful for a UK practice to use Gatheroo?
Yes, with a transfer safeguard in place. UK GDPR permits transfers to countries without adequacy regulations where an Article 46 mechanism applies. That is what the IDTA and UK Addendum are for.
Our client is a public body with a UK-only data policy. What then?
Then Gatheroo is not the right fit for that engagement today, and we would rather say so early. Tell us anyway, it informs the roadmap.
What about the EU, not just the UK?
EU GDPR works the same way in principle, using EU standard contractual clauses and a transfer impact assessment instead. Talk to us if you have an EU entity as well as a UK one.
Who is responsible for the transfer risk assessment?
You are, as controller and exporter. We supply the information you need to complete it, and we will complete your template if you send it to us.