Roles

The customer is the controller of the personal data it provides, and SAO Labs Inc. is the processor. Our DPA is designed to meet the requirements of Article 28 of the GDPR and UK GDPR, and to serve as a service-provider or processor contract under US state privacy laws.

The DPA forms part of the customer agreement. If the two conflict on data protection matters, the DPA takes priority.

Processing on instructions

We process customer personal data only on the customer's documented instructions, which are set out in the agreement and project specifications. We do not use it for our own purposes, and we do not sell or share it.

If we believe an instruction breaks data protection law, we will tell the customer.

Confidentiality

Everyone who works on customer data, including our employees and experts, is bound by written confidentiality obligations. Access is limited to people who need it for the project.

Security measures

We maintain technical and organisational measures designed to protect customer personal data, appropriate to the risk. These are described in an annex to the full DPA.

  • Access control based on least privilege, with access removed when no longer needed.
  • Encryption of data in transit and at rest.
  • Segregation of project data between customers.
  • Logging and monitoring of access to systems that hold customer data.
  • Security and confidentiality training for staff and experts.
  • Incident response and business continuity procedures.

Subprocessors

The customer gives general authorisation for us to use subprocessors. We impose data protection terms on each subprocessor that are no less protective than those in the DPA, and we remain responsible for their performance.

We list our subprocessors at /legal/subprocessors and give customers notice before adding or replacing one, so they have the opportunity to object on reasonable data protection grounds.

Helping customers meet their obligations

Taking into account the nature of the processing, we assist customers in responding to data-subject requests, such as requests for access or deletion. If we receive a request directly, we pass it to the customer.

We also provide reasonable assistance with data protection impact assessments (DPIAs) and prior consultations with supervisory authorities where they relate to our processing.

Personal data breaches

If we become aware of a personal data breach affecting customer data, we will notify the customer without undue delay. We will share the information reasonably available to us to help the customer meet its own notification obligations.

We will take reasonable steps to contain the breach, reduce its effects and prevent it from happening again.

Deletion or return at the end

When the services end, we will delete or return customer personal data, at the customer's choice, unless the law requires us to keep it. Data held in backups is deleted as backups expire in the normal course.

Audits and information

We make available the information reasonably necessary to demonstrate compliance with the DPA. We also allow for and contribute to audits, including inspections, by the customer or an auditor it appoints, subject to reasonable notice, confidentiality and scope terms set out in the DPA.

International transfers

Where customer personal data is transferred out of the EEA, UK or Switzerland to a country without an adequacy decision, we use the European Commission's standard contractual clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum. These are incorporated into the full DPA where required.

Contact

To request the full DPA or ask about our processor commitments, email info@saolabs.ai. For privacy questions, email privacy@saolabs.ai.