GDPR Compliant
Platform compliance — Version 1.0
Overview
SOPMaster is designed to comply with the EU General Data Protection Regulation (GDPR) and the UK GDPR (as retained in UK law). This page describes how the Platform supports your obligations as a data controller when using SOPMaster as a data processor.
Roles
Under GDPR, the parties are categorised as follows:
- Data Controller: You (the workspace owner and your organisation). You determine the purposes and means of processing personal data.
- Data Processor: SOPMaster. We process personal data only on your instructions and for the purposes of providing the Platform.
SOPMaster does not access, use or process personal data for any purpose other than delivering the services you request. We do not sell, share or monetise personal data.
Lawful Basis for Processing
We rely on the following lawful bases under Article 6 of the GDPR:
- Contract (Art. 6(1)(b)): Processing necessary for the performance of our contract with you (providing the Platform).
- Legitimate Interest (Art. 6(1)(f)): Processing necessary for our legitimate interest in improving platform security, performance and reliability.
- Consent (Art. 6(1)(a)): Where you opt in to non-essential features such as analytics telemetry.
Data We Process
Data Processing Agreement
When you create a workspace, our Data Processing Agreement (DPA) is incorporated into these terms by reference. The DPA covers:
- Subject matter and duration of processing
- Nature and purpose of processing
- Types of personal data and categories of data subjects
- Obligations and rights of the controller
- Sub-processor obligations
Sub-Processors
We use the following sub-processors, each operating under their own GDPR-compliant data processing terms:
- Stripe, Inc. — Payment processing (USA, EU SCCs in place)
- Turso (ChiselStrike) — Database hosting (EU/US, Standard Contractual Clauses)
- Vercel, Inc. — Application hosting (USA, EU SCCs in place)
We will notify you at least 30 days before adding or replacing a sub-processor.
International Transfers
Where personal data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Addendum, as applicable. You may request a copy of the relevant transfer mechanism at any time.
Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data (subject to legal retention obligations).
- Right to Restrict Processing (Art. 18): Request limitation of processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing is based on consent.
To exercise any right, contact: dpo@sopmaster.tech
Data Protection Impact
SOPMaster has been designed with data protection by design and by default (Art. 25). Key measures include:
- Tenant-isolated workspaces with cryptographic separation
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Minimal data collection — we only collect what is necessary
- No profiling, no automated decision-making with legal effects
- Immutable audit logging of all data access events
- Data minimisation in all interfaces
Data Breach Notification
In the unlikely event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 33 & 34).
Data Retention
We retain personal data only for as long as necessary to provide the Platform. Account data is retained while your workspace is active and deleted within 30 days of closure. Anonymised usage telemetry may be retained indefinitely. We do not retain payment card details.
Supervisory Authority
If you are dissatisfied with our handling of your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or the relevant supervisory authority in your EU member state.
Contact
Data Protection Officer: dpo@sopmaster.tech