Last Updated: March 31, 2026
1. Overview
Samodrei is committed to complying with the General Data Protection Regulation (GDPR) for all personal data processed within the European Economic Area.
This document outlines our approach to data protection and user rights.
2. Roles and Responsibilities
Samodrei acts as a Data Controller for account and platform usage data.
For customer-uploaded data, Samodrei acts as a Data Processor on behalf of the customer.
3. Lawful Basis for Processing
Personal data is processed based on contractual necessity, legitimate interests, legal obligations, or user consent.
Each processing activity is evaluated to ensure a valid lawful basis.
4. Data Subject Rights
Users have the right to access, rectify, erase, restrict processing, and request data portability.
Users may also object to certain types of processing.
Requests will be handled within statutory timelines.
5. Data Processing and Purpose Limitation
Data is processed only for specified, explicit, and legitimate purposes.
Samodrei does not process data in a manner incompatible with these purposes.
6. Subprocessors
Samodrei engages trusted subprocessors for infrastructure and service delivery.
All subprocessors are subject to contractual obligations ensuring GDPR compliance.
7. International Transfers
Data transfers outside the EEA are conducted using appropriate safeguards such as Standard Contractual Clauses.
These measures ensure adequate levels of protection.
8. Security Measures
Samodrei implements technical and organizational measures including encryption, access controls, and monitoring.
Regular assessments are conducted to maintain security effectiveness.
9. Breach Notification
In the event of a personal data breach, Samodrei will notify relevant authorities within 72 hours where required.
Affected users will be informed without undue delay when necessary.
10. Data Minimization and Retention
Only data necessary for service delivery is collected and processed.
Data is retained in accordance with legal and contractual requirements.
11. AI Transparency
Samodrei provides explainable and traceable AI outputs where applicable.
Users are informed when outputs are generated by AI systems.