Maseke and GDPR
CertReports found no public GDPR evidence for Maseke as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 18 Oct 2016
- Expires or valid through
- 23 Aug 2027
- Scope
- WHY the data is processed Solely to deliver the HR and payroll technology services the client has engaged us to perform, to the client's own specifications: 1. Data conversion and migration — extracting, mapping, transforming, validating, and loading data from a client's legacy system into the client's new system. 2. Integration and interface services — transmitting data between systems inside the client's own IT environment, for example HR to payroll, time and labor management to payroll, or payroll results back to the HR system. 3. Implementation, configuration, testing, and post-go-live support — including validation and parallel testing performed on client-supplied data. Maseke does not use personal data for any purpose of its own. We do not use it for marketing, profiling, analytics, product development, or the training of AI or machine learning models. WHERE the data resides All client solutions and client data are hosted exclusively in a cloud environment commissioned for that client — on AWS (our preferred platform) or Microsoft Azure, according to the client's requirement. A separate, dedicated tenant environment is commissioned for each client, so client data is logically segregated and is never commingled between clients. No client data is downloaded to, copied into, or stored in Maseke's own lab, development, or internal test environments, and none is retained on Maseke end-user devices or local infrastructure. Processing takes place only within the client-designated cloud environment. WHO accesses the data Personal data is accessed only by Maseke's own employees assigned to the client's project. All development and delivery work is performed in-house. Maseke does not engage sub-contractors, and no personal data is disclosed to any sub-contractor or other third party. Maseke's delivery model includes an onshore U.S. team and our own back-office delivery team in India. The onshore and offshore composition of the project team, and each resource's role, is documented in the Statement of Work agreed with the client, and access for India-based personnel is expressly approved by the client. Access is provisioned by the client through the client's own identity infrastructure: Maseke project personnel are issued a client-domain account and reach the client environment exclusively through the client's single sign-on, subject to the client's own authentication, authorization, and access-monitoring controls. Access is limited to the individuals named for the engagement, on a need-to-know basis, under confidentiality obligations, and is revoked on role change or project completion. WHO the data is shared with No third parties. Personal data is returned to the client or delivered to the destination systems within the client's own IT environment in the format and template the client specifies. Maseke does not sell, rent, license, or otherwise disclose personal data to any third party for that party's own purposes. Data is retained only for the duration of the engagement and is returned or deleted on client instruction.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Maseke, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 b46aed7312 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Maseke GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.