Taxomind · Trust & Compliance
The Compliance Dossier
An honest register of where we actually stand on data protection and regulation — the rights that ship today, the practices we follow, and the formal audits we haven’t completed yet. No badges we haven’t earned.
Register I · Regulations & Standards
Where we stand on the standards that matter
GDPR data rights
Access, export, and deletion of your data are built into the product
CCPA data rights
California Consumer Privacy Act data rights for US users
FERPA principles
Built with the privacy expectations of educational records in mind. Not a formal certification.
SOC 2 Type II audit
Independent audit of security controls — on our roadmap, not yet completed
ISO 27001
Information security management certification — not yet started
Register II · Standing Practices
How we protect your data every day
Encryption
Data is encrypted in transit using TLS. Passwords are hashed with bcrypt and never stored in plain text.
Payment Isolation
Payments are processed by Stripe. Card details never reach or persist on our servers.
Access Control
Role-based access with separate admin and learner authentication, on a least-privilege model. Multi-factor authentication is available for admin accounts.
Data Rights & Retention
You can export or permanently delete your account and data at any time from your settings.
Sub-Processors
We keep a short, listed set of sub-processors that handle data on our behalf — no more than the product needs. The full list is below.
Breach Notification
If we confirm a breach affecting your data, we aim to notify affected users promptly, in line with GDPR expectations.
Register III · Sub-Processors
Third-party services on the record
The services that process data on our behalf, listed in full.
- 01RailwayHosting & managed PostgreSQLUnited States
- 02StripePayment ProcessingUnited States
- 03AnthropicAI ProcessingUnited States
- 04OpenAIAI ProcessingUnited States
- 05Google (Gemini)AI ProcessingUnited States
- 06DeepSeekAI ProcessingInternational
Filing IV · Data Processing Agreement
Request our standard DPA
If you need a Data Processing Agreement (DPA) for GDPR or other regulatory purposes, get in touch and we’ll work through it with you.
The Registrar
Compliance questions?
We’re happy to answer compliance questions and share what documentation we have.