Skip to content
Skyie GlobalInfoTech
A stunning view of the University of Greenwich's iconic architecture in London, UK under a clear sky.
Compliance

Compliance is the product, not the paperwork after it.

Our regulatory posture and the frameworks we help customers meet — UK GDPR and the Data Protection Act 2018, ISO/IEC 27001, Cyber Essentials, SOC 2, NIS2, DORA and the EU AI Act.

Skyie Global InfoTech Ltd is a company registered in England and Wales (no. 17294509), registered with the Information Commissioner's Office (ref. ZC180480), and building for sectors where the regulator is part of the audience.

This page does two things. It sets out our own regulatory posture, with links to the public records so you can verify it rather than take our word for it. And it sets out the frameworks our assurance practice helps customers reach — which is a longer list, deliberately kept separate from the first.

Verifiable

Our own position

What Skyie Global holds and operates to today. Where a claim is independently verifiable, it links to the official public record.

ICO registered

Registered · ZC180480

Registered with the Information Commissioner's Office as a data controller under the Data Protection (Charges and Information) Regulations 2018.

Verify on the public record

UK GDPR & Data Protection Act 2018

Operating standard

Lawful basis, transparency, minimisation, retention and data-subject rights designed into the platform. A UK GDPR Article 28 data processing addendum is published, not held back for negotiation.

UK data residency

Architectural default

Customer data — including backups, logs and telemetry — is hosted in the United Kingdom. Sub-processors are chosen and contracted on that basis.

ISO/IEC 27001 aligned

Aligned, not certified

We operate to an ISO/IEC 27001:2022-aligned control set, with an assurance practice led by a certified ISO/IEC 27001 Lead Auditor. We will describe the company as certified only when a certificate is held and can be evidenced.

HMRC anti-money laundering supervision

Supervised · ACSP

Supervised for anti-money laundering purposes as an accountancy service provider. Verifiable on HMRC's money-laundering supervised-business register by business name and postcode.

Verify on the public record

Companies House

Registered · 17294509

Skyie Global InfoTech Ltd, a private company limited by shares, registered in England and Wales.

Verify on the public record

HMRC VAT registration

Registered · GB 522 8591 81

Registered for UK VAT. Every invoice we issue carries the registration number and the VAT particulars required by the VAT Regulations 1995. The number is verifiable on HMRC's public checker.

Verify on the public record
Advisory

Frameworks we help you meet

Delivered through our assurance practice — readiness, internal audit and remediation. We prepare and evidence; accredited certification bodies certify.

ISO/IEC 27001:2022

Readiness, internal audit & Statement of Applicability

Gap analysis against clauses 4–10 and the 93 Annex A controls, the clause 9.2 internal audit programme, risk methodology and management review inputs.

Cyber Essentials & Cyber Essentials Plus

Readiness & remediation

The five technical controls assessed against your real estate, gaps scoped and closed before the assessment rather than during it.

UK GDPR & data protection

Programme design & audit

Records of processing activities, DPIAs, lawful basis mapping, retention schedules, subject-rights handling, international transfer mechanisms and processor due diligence.

ISO/IEC 27701

Privacy information management

A privacy information management system extending an ISO 27001 ISMS, mapped to UK GDPR controller and processor obligations.

ISO/IEC 42001 & the EU AI Act

AI governance

AI management systems, use registers, risk classification against EU AI Act tiers, human-oversight design and model documentation.

SOC 2

Readiness

Trust services criteria mapped to your existing controls, evidence collection designed to be continuous, and the gaps closed before an examination period starts.

NIS2 & DORA

Readiness assessment

Scope determination, governance, incident reporting timelines, third-party risk and operational resilience testing for in-scope entities and their suppliers.

ISO 22301 & operational resilience

Continuity programme

Important business services mapped, impact tolerances set, dependencies and third parties tested, and recovery rehearsed rather than documented.

In practice

How the obligations are actually carried

01

Lawful basis & transparency

Every processing activity has an identified lawful basis and a plain-language explanation of what happens to the data and why.

  • Records of processing activities maintained under Article 30
  • Privacy notice written to be read, not to be survived
  • Purpose limitation enforced in the data model, not just in policy
02

Minimisation & retention

We hold the least data that makes the product work, for the shortest period the obligation allows.

  • Retention schedules set per data category and enforced automatically
  • Deletion and anonymisation paths tested, not assumed
  • Customer-configurable retention on the Estate engagement model
03

Data subject rights

Access, rectification, erasure, restriction, portability and objection are handled as a documented operational process with defined timescales.

  • Identity verified before any right is actioned
  • One-month statutory response window tracked
  • Requests reaching us as processor are routed to you as controller
04

Processors & international transfers

Every sub-processor is assessed, contracted and published. Where a transfer outside the UK is unavoidable, it is on a lawful mechanism and documented.

  • Article 28 terms with every processor
  • UK International Data Transfer Agreement or the UK Addendum to the EU SCCs
  • Transfer risk assessments retained
  • Sub-processor list published and change-notified
05

Evidence & audit trail

Accountability under Article 5(2) means being able to show it. Our products generate the evidence as a by-product of normal use.

  • Append-only audit trails on access, signing and document events
  • Time-stamped, exportable records for regulators and clients
  • Continuous posture evidence through Trustiey
06

Breach management

A documented process from detection through assessment to notification, rehearsed rather than written once.

  • Severity classification and defined escalation roles
  • 72-hour ICO notification path where the threshold is met
  • Controller notification without undue delay under our DPA
  • Post-incident review with corrective actions tracked to closure
Evidence

The documents

Common questions

Questions we get asked.

Are you a data controller or a data processor?

Both, in different contexts. For our own website, marketing and business operations we act as a controller. For customer data inside our products we act as a processor on your instructions, governed by our published data processing addendum.

Will you sign our DPA rather than yours?

We will review it. Our published addendum already reflects the Article 28 requirements and is written to be signable as it stands, which usually shortens procurement considerably.

Do you transfer personal data outside the UK?

Not as a matter of routine. Where a specific service makes it unavoidable, it is disclosed on the sub-processor list and covered by the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.

Can you help us pass a client's security due-diligence questionnaire?

Yes. That is a common starting point for our assurance practice — we close the real gaps first, then help you answer accurately rather than optimistically.

Is this legal advice?

No. We describe what our products do and how our services help you meet a framework. For a legal position on your specific obligations, take advice from a qualified adviser.

Book a walkthrough

Built to be trusted before it is sold.

See how the portfolio carries your compliance obligations — in thirty focused minutes.