Compliance & Governance
FW Delta LLC is a company incorporated under US law. Services are provided remotely for clients in the DACH region, while EU data protection standards apply to data processing.
This page outlines our approach to regulatory compliance, the certification of our hosting provider's data centres, ethical business practices, and transparent governance structures.
01. Compliance Overview
FW Delta LLC operates under a comprehensive compliance framework that balances global operational agility with strict adherence to regional data protection and regulatory requirements.
US Legal Entity
Registered in Wyoming, USA. Governed by US commercial law, Wyoming LLC Act, and federal regulations. Provides flexibility, IP protection, and international scalability.
Data Residency in Germany
Client project data is processed exclusively on infrastructure located in Germany. Audience measurement on fwdelta.com runs on a self-hosted, cookieless analytics service on our own infrastructure. Details are set out in our privacy policy.
Hybrid Compliance Model
This structure allows us to combine the operational advantages of US incorporation (flexible contracts, lower overhead, international banking) with the data protection standards our European clients expect and require.
02. Corporate Governance Structure
FW Delta LLC maintains a lean, efficient governance structure appropriate for a location-independent professional services firm.
Management Structure
Managing Member: Fabian Weiss
Responsible for strategic direction, operations, and compliance oversight. Also the contact for questions on GDPR, sanctions requirements, and ethical standards, as well as for data subject rights and supervisory authorities.
Operational Model
- Remote-First: No physical offices. Global talent recruitment based on merit.
- Agile Decision-Making: Flat hierarchy enables rapid response to market changes.
- Client-Centric: Direct communication between decision-makers and clients.
03. Data Sovereignty & Infrastructure
Data Residency
We maintain a strict separation between legal entity jurisdiction and data processing location. Client project data is processed exclusively on infrastructure located in Germany. Audience measurement on fwdelta.com runs on a self-hosted, cookieless analytics service on our own infrastructure (stats.fwdelta.com); no data is passed on to third parties for this purpose. Details are set out in our privacy policy.
Technical Implementation:
Primary Infrastructure
Provider: Hetzner Online GmbH (Germany)
Locations: Falkenstein, Nuremberg (Germany)
Certifications: ISO/IEC 27001:2022 certified data centres, GDPR-compliant DPA
We utilize bare-metal dedicated servers and private networking. No shared cloud infrastructure. Full control over data processing environment.
Security Architecture
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Encrypted backups of the production systems at regular intervals
- Dedicated firewall with strict ingress/egress rules
- Automated monitoring with alerting. Response by FW Delta within the agreed service hours.
04. GDPR Compliance Framework
Despite being a US-registered entity, we voluntarily comply with the EU General Data Protection Regulation for all personal data processing activities.
Data Processing Principles
- Lawfulness, fairness, transparency
- Purpose limitation
- Data minimization
- Accuracy and up-to-date
- Storage limitation
- Integrity and confidentiality
Data Subject Rights
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent
05. Security Standards & Certifications
We implement comprehensive technical and organizational measures in accordance with Art. 32 GDPR and industry best practices.
We process personal data in accordance with the requirements of the GDPR. Payment card data is processed exclusively by certified payment service providers. FW Delta does not store card data.
Hetzner: ISO/IEC 27001:2022 certified data centres
Infrastructure ProviderInformation Security Management System of Hetzner Online GmbH. The certification is held by the data centre operator.
Data Processing Agreement under Art. 28 GDPR
ConcludedA data processing agreement is in place with the data centre operator. Processing takes place in Germany.
06. Tax & Fiscal Compliance
FW Delta LLC is a US tax resident and maintains full transparency with tax authorities in all operating jurisdictions.
US Tax Compliance
As a Wyoming LLC, we meet our US tax obligations and keep proper accounting records.
- Registered Agent in Wyoming for legal correspondence
- Annual Report filed with Wyoming Secretary of State
International B2B Invoicing (Reverse Charge)
For B2B clients in the European Union, we apply the Reverse Charge Mechanism in accordance with Art. 196 EU VAT Directive.
How it works: Services are invoiced net (without VAT). The tax liability shifts to the recipient (your company). You report and pay VAT in your country.
Requirements: Valid VAT ID required for all EU B2B clients. We check the validity of the VAT ID before invoicing.
Benefits: No VAT pre-financing needed. Simplified cross-border transactions. Improved cash flow.
Note: Swiss clients (non-EU) receive invoices according to Swiss VAT regulations. For B2C transactions, applicable consumer VAT may apply. We do not accept cash payments or cryptocurrencies.
07. Export Control & Trade Compliance
Sanctions Lists
We do not work with individuals or companies listed on relevant sanctions lists.
08. Code of Ethics & Business Conduct
We uphold the highest standards of ethical conduct in all business operations.
Anti-Bribery & Corruption
Strict adherence to the US Foreign Corrupt Practices Act (FCPA) and UK Bribery Act principles. Zero tolerance for bribery, kickbacks, or improper payments.
Diversity & Inclusion
Remote-first model enables global talent acquisition based on merit. No discrimination based on nationality, religion, gender, or background.
Environmental Responsibility
No physical offices reduce carbon footprint. EU infrastructure powered by renewable energy sources through Hetzner's green data centers.
Conflicts of Interest
Full disclosure of potential conflicts. We do not accept engagements that compromise our independence or client confidentiality.
09. Subprocessor Management
We maintain a limited list of carefully vetted subprocessors. All subprocessors are bound by GDPR-compliant Data Processing Agreements. The public website does not use any third-party analytics or marketing tools.
Hetzner Online GmbH
Infrastructure & Hosting
Server hosting, data storage, backup services
Safeguards: ISO/IEC 27001:2022 certified Infrastructure, GDPR DPA
Change Notification: We will notify clients of any new subprocessors or changes to existing ones with at least 30 days' notice, allowing you to object if you have legitimate concerns.
10. Security Incident Response
We maintain documented procedures for identifying, responding to, and reporting security incidents and personal data breaches.
Incident Response Timeline
Detection and initial assessment. Containment measures activated.
Investigation and impact analysis. Affected systems isolated.
Client notification (if affected). Supervisory authority notification (if required by GDPR). Remediation implementation.
Breach Notification Obligations
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours (as required by Art. 33 GDPR) and affected data subjects without undue delay if high risk to rights and freedoms exists (Art. 34 GDPR).
11. Audits & Compliance Verification
We disclose our security and data protection measures to our clients.
Internal Monitoring
- Logging and review of access and security-relevant events
Client Audit Rights
Enterprise clients may request information about our technical and organizational measures upon reasonable notice. We provide this documentation as an annex to the data processing agreement.
12. Compliance Contact & Reporting
For compliance inquiries, concerns, or to report potential violations:
Compliance Framework Summary
GDPR (EU)
Personal data of EU/EEA residents
Swiss FADP
Personal data of Swiss residents
Compliance Questions?
We are happy to discuss our governance framework, the certification of our hosting provider's data centres, or specific compliance requirements.
Contact us