Our Commitment
We are committed to processing personal data lawfully, fairly, and transparently. We apply the GDPR principles of data minimization, purpose limitation, accuracy, storage limitation, integrity, and accountability across the Service.
Data Controller and Processor Roles
For your account data, Sadakom acts as a data controller. For the end-customer data you upload and process through the Service, you are the controller and Sadakom acts as your processor, handling that data only on your documented instructions.
Lawful Basis for Processing
We process personal data on lawful bases including consent, performance of a contract, compliance with legal obligations, and legitimate interests. You are responsible for ensuring a lawful basis for any end-customer data you process through the Service.
Your Rights Under GDPR
Data subjects have the right to access, rectify, erase, restrict, and port their personal data, to object to processing, and to withdraw consent at any time. We help our customers respond to these requests for data held in the Service.
Data Processing Agreements
Where we act as a processor, we make a Data Processing Agreement (DPA) available that sets out our obligations, the categories of data processed, and the security measures we apply. Contact us to request a copy.
International Data Transfers
When personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses to ensure an adequate level of protection.
Data Breach Notification
We maintain procedures to detect, investigate, and report personal-data breaches. Where required, we will notify the relevant supervisory authority and affected customers without undue delay.
Exercising Your Rights
To exercise your GDPR rights or ask about our data-protection practices, contact us using the details below. We will respond within the timeframes required by applicable law.
Questions about this document? We're happy to help — contact our team.