We believe data protection is a fundamental right. SAAS.PROJECT is built with privacy by design and is fully compliant with the General Data Protection Regulation (GDPR).
Under the GDPR, you have the following rights. We make it easy to exercise any of them.
Request a complete copy of all personal data we hold about you, in a readable format.
Correct any inaccurate or incomplete personal data we have on file about you.
Request the deletion of your personal data. We erase it within 30 days of your request.
Export your data in a structured, machine-readable format (JSON) to take it elsewhere.
Limit how we process your data while a dispute or request is being resolved.
Object to certain types of data processing, including profiling and direct marketing.
Withdraw your consent at any time for processing based on consent. No penalties, ever.
Every piece of data we process has a clear legal basis under the GDPR. We never collect data we do not need.
We process data necessary to provide you with the SAAS.PROJECT service. This includes your account information, integration configurations, and agent processing data. Without this processing, we cannot deliver the service you signed up for.
We process anonymized usage analytics to improve the service, monitor for security threats, prevent fraud, and maintain system performance. We balance our interests against your rights and only process what is necessary.
We only send you marketing emails if you opt in. We use cookies for analytics and preferences only with your explicit consent. You can withdraw consent at any time through your account settings or by contacting us.
A complete overview of the personal data we collect, why we collect it, and how long we keep it.
| Data Type | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Account data | Provide the service (name, email, password hash) | Contract | While active + 30 days |
| Usage analytics | Improve the service, monitor performance | Legitimate interest | 90 days (anonymized) |
| Integration data | AI agent processing (connected platform data) | Contract | Until disconnected |
| Payment data | Billing and invoicing (processed by Stripe) | Contract | As required by law |
| Cookies | Preferences and analytics | Consent | See cookie policy |
We carefully vet every sub-processor. All operate under Standard Contractual Clauses (SCCs) to ensure your data is protected regardless of location.
When your data is transferred outside the European Economic Area (EEA), we ensure adequate protection through:
In the unlikely event of a data breach, we follow a strict response protocol:
Exercising your GDPR rights is simple and free.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
Our Data Protection Officer is here to help with any privacy or GDPR-related questions.