Articles on: ⚖️ Compliance & Data
This article is also available in:

Who is responsible for what?

The GDPR distinguishes two clear roles in the processing of personal data. You are the data controller, Hodi is your data processor. This split isn't a legal technicality: it defines who decides what, and who is accountable for what.


You, the data controller


You determine why and how personal data is processed. In practical terms, that means you:

  • define the purposes (what the data is used for) and the legal basis;
  • decide which data is collected;
  • inform your users and manage their rights (access, rectification, erasure, etc.);
  • remain responsible for the compliance of your processing.

The data controller is the one steering. The GDPR places primary responsibility on them.


Hodi, the data processor


Hodi processes data on your behalf, following your instructions.
We never use your data for our own purposes. In practical terms, we:

  • host and process data according to your instructions;
  • put security measures in place (Tier III, backups, DRP, access control);
  • help you respond in the event of an incident, including data breach notification;
  • support you, on the technical side, in responding to your users' requests.


Compliance, a shared responsibility


Let's be clear: we do not guarantee your compliance, no one can do that in your place. As the data controller, it's yours to own. What we bring is a solid, GDPR-aligned foundation to strengthen it: secure hosting, data localized according to your choice, and a point of contact who knows the subject. For your specific situation, the best approach is still to talk to your DPO or legal counsel: every processing activity has its own specifics.

Updated on: 17/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!