SOPMASTER
// COMPLIANCE

GDPR Compliant

Platform compliance — Version 1.0

Overview

SOPMaster is designed to comply with the EU General Data Protection Regulation (GDPR) and the UK GDPR (as retained in UK law). This page describes how the Platform supports your obligations as a data controller when using SOPMaster as a data processor.

Roles

Under GDPR, the parties are categorised as follows:

  • Data Controller: You (the workspace owner and your organisation). You determine the purposes and means of processing personal data.
  • Data Processor: SOPMaster. We process personal data only on your instructions and for the purposes of providing the Platform.

SOPMaster does not access, use or process personal data for any purpose other than delivering the services you request. We do not sell, share or monetise personal data.

Lawful Basis for Processing

We rely on the following lawful bases under Article 6 of the GDPR:

  • Contract (Art. 6(1)(b)): Processing necessary for the performance of our contract with you (providing the Platform).
  • Legitimate Interest (Art. 6(1)(f)): Processing necessary for our legitimate interest in improving platform security, performance and reliability.
  • Consent (Art. 6(1)(a)): Where you opt in to non-essential features such as analytics telemetry.

Data We Process

Account Data
Name, email, company name, hashed PIN. Required for authentication and workspace provisioning.
Document Content
SOPs, checklists, department packages. Stored in your encrypted, tenant-isolated workspace.
Payment Data
Stripe customer ID, transaction references. Card details held by Stripe, never by SOPMaster.
Usage Telemetry
Anonymised feature interactions and error logs. Used for platform improvement.
Visitor Location
Country-level geolocation from IP for the homepage globe display. Not linked to individual accounts.

Data Processing Agreement

When you create a workspace, our Data Processing Agreement (DPA) is incorporated into these terms by reference. The DPA covers:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Types of personal data and categories of data subjects
  • Obligations and rights of the controller
  • Sub-processor obligations

Sub-Processors

We use the following sub-processors, each operating under their own GDPR-compliant data processing terms:

  • Stripe, Inc. — Payment processing (USA, EU SCCs in place)
  • Turso (ChiselStrike) — Database hosting (EU/US, Standard Contractual Clauses)
  • Vercel, Inc. — Application hosting (USA, EU SCCs in place)

We will notify you at least 30 days before adding or replacing a sub-processor.

International Transfers

Where personal data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Addendum, as applicable. You may request a copy of the relevant transfer mechanism at any time.

Your Rights Under GDPR

As a data subject, you have the following rights:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data (subject to legal retention obligations).
  • Right to Restrict Processing (Art. 18): Request limitation of processing in certain circumstances.
  • Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing is based on consent.

To exercise any right, contact: dpo@sopmaster.tech

Data Protection Impact

SOPMaster has been designed with data protection by design and by default (Art. 25). Key measures include:

  • Tenant-isolated workspaces with cryptographic separation
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Minimal data collection — we only collect what is necessary
  • No profiling, no automated decision-making with legal effects
  • Immutable audit logging of all data access events
  • Data minimisation in all interfaces

Data Breach Notification

In the unlikely event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 33 & 34).

Data Retention

We retain personal data only for as long as necessary to provide the Platform. Account data is retained while your workspace is active and deleted within 30 days of closure. Anonymised usage telemetry may be retained indefinitely. We do not retain payment card details.

Supervisory Authority

If you are dissatisfied with our handling of your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or the relevant supervisory authority in your EU member state.

Contact

Data Protection Officer: dpo@sopmaster.tech

← Back to SOPMaster