Security and compliance
Your client data is sensitive. We treat it that way. This page describes the concrete measures we use to protect it.
Data hosting & residency
Encryption
Access control & authentication
Backups & availability
GDPR & privacy
Subprocessors
We use a limited number of third-party subprocessors for infrastructure and service delivery. All subprocessors are contractually bound to appropriate data protection obligations. A current list of subprocessors is available on request—contact us at hello@glimzer.com.
Built for regulated firms
Features designed specifically for FCA-regulated advice firms.
See how Glimzer works for your firm
Learn more about the platform and how it supports regulated advice firms.
Frequently asked questions
Where is my data stored?
All data is stored in UK-based data centres with appropriate security certifications. We do not transfer data outside the UK unless explicitly required and agreed.
Can I export my data?
Yes. You can export all your data at any time in standard formats (CSV, JSON). This supports both GDPR requirements and ensures you always have access to your own data.
How do you handle data breaches?
We have documented incident response procedures. In the unlikely event of a breach, we would notify affected customers within 72 hours as required by GDPR, and provide full details of the impact and remediation steps.
How often do you back up data?
Automated backups run daily with 30-day retention. We also maintain point-in-time recovery capabilities for database restoration.
Can I get a detailed security overview?
Yes. Contact us to request a detailed overview of our security practices, architecture, and data handling procedures. We are happy to discuss specifics with prospective and existing customers.
Questions about security?
We're happy to discuss our security practices in detail.