Ticketing as a Service Meets GDPR Compliance Standards
- Marc (TeamsWork)

- May 10, 2024
- 4 min read
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect in May 2018, harmonizing data privacy rules across Europe and strengthening EU citizens' data privacy rights. GDPR applies not only to organizations located within the EU, but also to organizations outside the EU that offer goods or services to, or monitor the behavior of, EU data subjects.
Data protection and security are questions we hear often from organizations evaluating Ticketing As A Service, especially those subject to GDPR and, increasingly, the EU Data Act. This post consolidates our answers on encryption, data hosting, incident response, sub-processors, and data subject rights in one place.
A quick note on who we are: Kitameraki Limited (trading as TeamsWork) is a Hong Kong-based company. We don't have a separate EU legal entity. Our compliance with EU data protection law is built on where and how we host data (Microsoft Azure regions inside the EU), and on the contractual safeguards described below, not on having an EU-registered office.
1. Encryption
All Ticketing As A Service data is encrypted:
In transit, using TLS 1.2 or higher for all connections.
At rest, using AES-256 encryption for databases, backed by Microsoft Azure's standard storage encryption.
2. Where your data is hosted
For EU/EMEA customers, all data for Ticketing As A Service is hosted in the Microsoft Azure Germany datacenter, with geo-redundant backups within that same region pair.
Full detail on data categories, retention periods, DPIA support, and Record of Processing information is in our Privacy Policy and our Data Processing Agreement. We don't repeat it here to avoid the two documents drifting out of sync.
3. Incident Response & Breach Notification
We maintain a documented security incident response process, with continuous logging, monitoring, and alerting across our infrastructure. Breach notification commitments to customers and, where applicable, supervisory authorities are set out in our DPA (Section 5.7). In short, we notify affected customers within 48 hours of becoming aware of a breach, and meet the 72-hour regulatory notification window under GDPR where required.
On audits and penetration testing: as part of the Microsoft 365 App Certification process, Ticketing As A Service underwent an independent penetration test / vulnerability assessment. We don't currently run this on an ongoing annual third-party cadence. Per our DPA (Section 8), we don't offer customer-initiated audits or penetration tests of our infrastructure. This is standard practice for SaaS vendors of our size, and our assurance instead comes from the Microsoft 365 Certification and from Azure's own independent certifications (see below). We're happy to share relevant compliance documentation on request.
Privacy / DPO contact: contact@teamswork.app
4. Sub-processors
TeamsWork uses Microsoft Azure exclusively as its sub-processor for infrastructure and data hosting (an earlier legacy payment processor is no longer in active use). Terms governing sub-processors, including advance notice of any future additions, are set out in our DPA (Section 5.4).
Because Azure is our sole sub-processor, its certifications are directly relevant to your risk assessment: Microsoft Azure holds ISO 27001, SOC 2, and PCI DSS certifications. These are Azure's certifications, inherited through our hosting choice. Kitameraki Limited does not separately hold ISO 27001 or SOC 2 certification as a company.
5. Data Processing Agreement (DPA)
Our standard DPA (Art. 28 GDPR-compliant) is available at teamswork.app/dpa. It's a self-service agreement. By accepting our Terms & Conditions, you're automatically bound by it; no separate signature is required. It covers processing scope, security measures, sub-processor terms, breach notification, and international transfer safeguards (including reliance on Standard Contractual Clauses where applicable, consistent with Schrems II requirements).
6. Data Subject Rights
We maintain a documented process for handling Subject Access Requests (SARs) and other data subject rights requests (rectification, erasure, restriction, portability, objection). As part of this process, we're able to identify all locations where a given data subject's data is stored, including backups, so we can respond effectively and completely to a request.
These requests are currently handled manually rather than through a self-service API or dashboard. Contact contact@teamswork.app and we'll assist directly, or assist your administrator. Full detail is in our Privacy Policy and DPA (Section 5.5).
7. EU Data Act
Data access & portability ("Access by Design"): Ticket data can be exported in structured, commonly-used formats (Excel/CSV) directly from the product, and via the Ticketing API for automated extraction.
Cloud switching: Data export via the API and Excel/CSV export can support a customer-led migration to another provider. A dedicated cloud-switching policy is not yet available.
Protection against unlawful third-country government access: We rely on Microsoft Azure's technical and organizational safeguards at the infrastructure level, combined with the contractual transfer safeguards (SCCs) in our DPA.
Questions?
If anything here doesn't fully answer your question, or you need supporting documentation (DPA copy, information to support your own DPIA, etc.), reach out to us using the button below.
TeamsWork is a Microsoft Partner Network member, and their expertise lies in developing Productivity Apps that harness the power of the Microsoft Teams platform and its dynamic ecosystem. Their SaaS products, including CRM as a Service, Ticketing as a Service and Checklist as a Service, are highly acclaimed by users. Users love the user-friendly interface, seamless integration with Microsoft Teams, and affordable pricing plans. They take pride in developing innovative software solutions that enhance company productivity while being affordable for any budget.



Comments