Compliance
Last updated: July 2026
Mabstack takes compliance seriously. While we are a small, focused team and do not hold enterprise-level certifications like SOC 2 or ISO 27001, we follow practical, proportionate practices to meet the regulatory and contractual obligations of every engagement.
Data Protection
We handle personal data responsibly and in line with applicable data protection laws. We will sign a Data Processing Agreement (DPA) with clients who need one, and we only collect and process data that is necessary for the services we provide.
Client Confidentiality
All client information, project data, and business details are treated as confidential. We do not share client data with third parties without explicit consent, and team access is limited on a need-to-know basis.
Regulatory Alignment
We adapt to the regulatory requirements of each engagement. Whether your business requires compliance with Bangladesh's Data Protection Act, GDPR for EU-facing projects, or industry-specific rules, we work with you to meet those obligations.
Contractual Transparency
Every engagement starts with a clear scope, timeline, and pricing. Data handling terms, ownership of deliverables, and confidentiality obligations are documented in writing before work begins.
Working With Regulated Industries
If your business operates in a regulated industry — finance, healthcare, or government — we will review your specific compliance requirements before starting work and agree on a plan to meet them. This may include additional security measures, documentation, or audit cooperation as part of the project scope.
Questions?
For compliance questions or to discuss your specific requirements, contact us at compliance@mabstack.com.
