GDPR Compliance

We take the protection of your and your customer's personal data very seriously and treat personal data verify confidentially and in accordance with the statutory data protection regulations and this data protection declaration


Future Online Legacy is committed to protecting the privacy of our users and their customers. We stay apprised of developments in data protection laws to ensure that you can be confident in your safety while using our platform.

In our commitment to privacy, we also recognize the unique considerations introduced by our use of artificial intelligence (AI) technologies in processing personal data. We are dedicated to ensuring these technologies are implemented responsibly and in full compliance with GDPR.

This page is intended to explain what the rules are, how they apply to your use of the Future Online Legacy platform and the steps we have taken to comply.

You should review this document in conjunction with our Privacy Policy and contact a specialist legal professional if you require more information or advice.

General Data Protection Regulation (GDPR)

Regulation (EU) 2016/679, more commonly known at the General Data Protection Regulation (GDPR) is an EU regulation aimed at harmonizing data protection and privacy laws across the EU. The provisions of the GDPR apply wherever personal data of an EU data subject is involved.

The GDPR is focused on giving individuals more control over how their data is used by companies, and making the collection and processing of data more transparent.

As we employ AI to enhance our services, we are mindful of GDPR's emphasis on data subject rights and transparency in the use of personal data. Our AI systems are designed to uphold these principles, ensuring data is processed ethically and transparently.

The GDPR was incorporated directly into UK law following the end of the Brexit transition period, meaning that UK businesses still have to comply with its provisions through the ‘UK GDPR’.

Basic GDPR concepts

Controller and processor

The GDPR imposes various obligations on a person depending on whether they are a controller or a processor of personal data.

A controller is an entity which decides to process personal data, and makes decisions regarding the basis of processing and the methods which will be used. Controllers have certain obligations regarding personal data, which you should familiarize yourself with before collecting personal data from your customers.

A processor is an entity which processes data for and on behalf of a controller. They make no independent decisions regarding the data or its processing, as they only process it on behalf of the controller and must comply with all instructions given by the controller.

While Future Online Legacy serves as a data processor, our AI systems operate under strict guidelines to act in this capacity responsibly, processing data strictly according to your directives as the data controller.

When you use the Future Online Legacy service, you are a controller. You are in control of the data you upload to the Future Online Legacy system, what you do with that data, and why. As a result, you are responsible for ensuring that you have a legal basis on which to process the data, and that you do not retain the data for any longer than is necessary.

You should ensure that you understand your obligations as a controller, and update your own systems and policies to allow the lawful transfer of personal data to Future Online Legacy.

Future Online Legacy is a data processor. We, through the Future Online Legacy platform, store and manage the data you have collected under your instructions. We will never use any personal data which you have uploaded to the Future Online Legacy system for our own purposes or without your instruction.

Legal basis for processing

Personal data may only be collected and processed if there is a legal basis for doing so. The allowable legal bases are set out in the GDPR.

When employing AI technologies, it's crucial that the legal basis for processing personal data, as identified by you, the controller, encompasses the use of such technologies. We advise reviewing the compatibility of AI processing activities with your selected legal basis.

As a processor, Future Online Legacy relies on our customers to select the correct basis under which they will be collecting and processing personal data, and to put the appropriate notices and consents in place. Before you use the Future Online Legacy service, you should take time to identify which legal bases may be available to you, and only collect and retain personal data to the extent necessary to carry out that basis. You should not change the basis under which you have collected personal data without very good reason, so it is important to understand the requirements of the different bases and make sure you select the right one at the start.

Data subject access rights

The GDPR grants data subjects (i.e. your customers) certain rights relating to their personal data, including the right to access, correct and/or delete any data relating to them.

Our platform facilitates the management of data subject requests, including those that may involve AI-processed data. We ensure mechanisms are in place for the easy extraction, correction, or deletion of personal data processed by AI, in alignment with data subjects' rights under GDPR.

Future Online Legacy has put in place easy systems for you to inform us if you receive such a request from a data subject, and for us to inform you if we receive such a request. We will ensure that, following your instructions, these requests are promptly complied with. You should familiarize yourself with the obligations which will be imposed on you, including relating to any personal data you hold on your own systems, or services other than Future Online Legacy.

Transfers of data to the USA

Personal data may not be transferred outside the EEA other than under specific circumstances. We utilize the Standard Contractual Clauses as part of our Data Processing Agreement which we sign with all of our customers.

In the context of AI, data transfers, including those to the USA, are governed by Standard Contractual Clauses, ensuring protection levels that are consistent with EU data protection laws.

Data Security

We have put in place strong security safeguards and measures to ensure that any personal data we hold is stored securely. We regularly test our products for bugs and vulnerabilities.

Our security measures extend to the protection of data processed by AI, with robust safeguards against unauthorized AI access or misuse. We continuously evaluate these measures to address the evolving risks associated with AI technologies.

We ensure that we have regular backup systems in place, and ensure that we have data recovery and data integrity systems and processes to minimize risk of corruption to or loss of personal data.

Steps we have taken to ensure GDPR compliance

We take our duties as a processor very seriously. We have put in place a number of procedures and taken a number of steps in order to ensure that we remain compliant with the GDPR and that you are able to lawfully send personal data collected by you to us, for example:

Our data processing agreement utilizes the Standard Contractual Clauses to ensure that you are able to lawfully send personal data to us in the USA.

We are able to detect personal breaches and to inform our customers as soon as possible.

We are able to deal with subject access requests and rights of erasure requests, and ensure that we inform you when a data subject has made such a request to us.

We have assessed and documented the personal data processed by us on your behalf.

We have assessed our security and upgraded this where necessary to ensure that it is appropriate for the level of risk we face in relation to a data breach.Bullet list

Our GDPR compliance efforts explicitly address the integration of AI technologies. This includes:

  • Conducting AI-specific data protection impact assessments to understand and mitigate risks.

  • Ensuring our AI systems are transparent in their data processing activities and that data subjects are informed about the use of AI in processing their personal data.

  • Implementing enhanced security protocols for AI systems to protect against data breaches.

  • Establishing procedures for responding to data subjects' requests that involve AI-processed data.

We are committed to ethical AI use, ensuring our AI technologies adhere to GDPR principles and respect data subject rights. This includes ongoing monitoring and evaluation of AI impacts on privacy and data protection.