GDPR · EU & UK
GDPR compliance for your practice
The General Data Protection Regulation sets a high bar for handling personal data across the EU and UK. Quzek gives you the consent, security and data-rights tools to meet it.
What GDPR means
The GDPR (and the UK GDPR) governs how organisations collect, store and use the personal data of people in the EU and UK. It requires a lawful basis for processing, clear consent where consent is the basis, strong security, and respect for data-subject rights — access, correction, erasure and portability. As the practice, you are the data controller; Quzek acts as your data processor.
How Quzek helps you meet it
Quzek records each client's consent to your privacy policy, data processing and marketing — with a timestamped, versioned audit trail you can produce on demand. You can export a client's data or delete it on request, data is encrypted in transit and at rest, and every practice is isolated in its own database. We also provide a Data Processing Agreement covering our role as your processor.
The features that support GDPR
-
✅
Consent management
Record and audit each client's consent to your privacy policy, data processing and direct marketing — with a full, timestamped history of every grant and withdrawal.
-
🔐
Two-factor authentication
Optional app-based 2FA for every team member, with encrypted secrets and one-time recovery codes.
-
🗄
Per-practice data isolation
Every practice runs in its own separate database — client data is never mixed between practices.
Learn more → -
🔒
Encryption in transit & at rest
Strong, industry-standard encryption protects data as it travels and while it is stored.
Learn more → -
👤
Role-based access control
You decide exactly what each person can see and do, so people only access what they need.
Learn more → -
📤
Data export & deletion
Export your practice data whenever you like, and have it deleted on request when you leave.
A note on honesty. Quzek gives you the tools and safeguards to meet your obligations — it does not, on its own, make your practice compliant, and we do not claim certifications we do not hold. Where a regime needs a signed agreement (such as a Data Processing Agreement or a Business Associate Agreement) we can provide one on request. Compliance is a shared responsibility between the platform and how your practice uses it.
Frequently asked
Is Quzek GDPR compliant?
Can I get a Data Processing Agreement?
How do I handle a data-subject access or deletion request?
Does Quzek support the UK GDPR too?
Explore all the regulations we support on our Compliance hub, or read about our security practices and privacy policy.
Meet the GDPR without the spreadsheet
Start a free 14-day trial and see the privacy and security tools built in.
Start your free trial