Data Protection & GDPR Compliance
GDPR & Data Localization Guidelines
OBCRM operates as a data processor on behalf of global education agencies. We maintain compliance under the General Data Protection Regulation (GDPR), protecting student candidates and referral partners worldwide.
Localized Hosting
Each tenant's data is logically isolated within our hosting environment. Regional/multi-region data residency options are available on request for enterprise agreements — contact us to discuss your jurisdiction's requirements.
General GDPR Principles
Our CRM is architected to support fundamental candidate privacy rights:
- Right to Deletion: Upon subscription termination, we work with you to remove your organization's data from active systems on request — contact our security desk to initiate a deletion request.
- Access Controls: Candidates can request copies of all recorded documents, easily compiled through standard export filters.
- Data Minimization: We capture only values necessary to execute admission matches and subclass checking processes.
Data Processing Addendum (DPA)
We offer standard Data Processing Addendums (DPA) containing Standard Contractual Clauses (SCC) for agencies recruiting students from European locations. You can request a signed DPA copy through our governance desk: dpo@obcrm.net.