Legal
Privacy Policy
This Privacy Policy explains how Samudaia (“we”, “us”, “our”) collects, uses, stores, shares, and protects personal data when you use our website, apps, and collaboration workspaces in the European Economic Area (EEA), the United Kingdom, and elsewhere. It is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and related European data-protection law.
1. Data controller
Samudaia is the data controller for personal data processed to operate accounts, authentication, workspaces, platform security, and support. Where a customer organisation (for example an employer) configures a workspace and decides how members collaborate inside it, that organisation may also act as an independent controller for certain workspace content.
Privacy and data-subject requests can be submitted through the Contact page on this website. We aim to respond within one month of receipt, as required by Article 12 GDPR (extendable by two further months for complex requests, with notice).
2. Personal data we process
- Identity & account: name, email address, authentication identifiers (including via Clerk), profile image, and account preferences.
- Workspace & membership: workspace memberships, roles (e.g. owner/admin/member), invite links, allowed domains, tags, settings, and map / workspace configuration.
- Collaboration activity: presence, zone activity, calls, mute / moderation events, raised hands, direct and zone messages, whiteboard activity, and related timestamps.
- Technical & security: IP address, browser / device information, logs, diagnostics, connection quality signals, and similar telemetry needed to keep the service secure and reliable.
- Support: information you voluntarily send via the contact form or email.
We do not intentionally collect special-category data (Article 9 GDPR). Please do not submit sensitive health, political, or similar data through the platform unless strictly necessary and lawful.
3. Purposes and legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)): creating accounts, providing workspaces, enabling collaboration features, and delivering support you request.
- Legitimate interests (Art. 6(1)(f)): securing the platform, preventing abuse, improving reliability, and understanding product usage in a privacy-aware way, balanced against your rights and freedoms.
- Consent (Art. 6(1)(a)): optional notifications, non-essential cookies / similar technologies where required, and other processing we clearly ask you to opt into. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): compliance with applicable law, regulatory requests, and accounting / tax duties where they apply.
4. How we use data
- Operate accounts, sessions, and authentication.
- Run collaboration features (presence, messaging, calling, moderation, whiteboards, hand raises).
- Enforce permissions, investigate incidents, and maintain security.
- Send transactional notices (e.g. invites, security alerts) and respond to support requests.
- Monitor availability, fix bugs, and improve the product.
- Comply with law and protect Samudaia, users, and third parties.
5. Cookies and similar technologies
We use strictly necessary cookies and similar technologies to keep you signed in, protect sessions, and remember essential preferences. Where non-essential analytics or marketing technologies are used in your region, we will obtain consent where required by the ePrivacy rules and GDPR, and you can withdraw that consent later through your browser settings or any consent tool we provide.
6. Sharing and processors
We share personal data with carefully selected processors that help deliver authentication, hosting, communications, storage, analytics, and support, and only under written contracts that meet Article 28 GDPR. We do not sell personal data.
We may disclose data when required by law, to respond to lawful requests, or to protect rights, security, or the integrity of the service.
7. International transfers
If personal data is transferred outside the EEA / UK, we rely on a lawful mechanism such as an adequacy decision, Standard Contractual Clauses (SCCs), or another safeguard recognised under Chapter V GDPR, together with any supplementary measures that are reasonably required.
8. Retention
We keep personal data only as long as needed for the purposes described above, including account administration, workspace operation, security, support, and legal compliance. When data is no longer required, we delete or anonymise it, unless a longer period is mandated by law.
9. Your GDPR rights
- Right to be informed (Arts. 13–14)
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (“right to be forgotten”, Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Rights related to automated decision-making and profiling (Art. 22)
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. To exercise rights, use the Contact page on this website. We may need to verify your identity before fulfilling a request.
10. Complaints to a supervisory authority
If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection authority. A list of EEA authorities is published by the European Data Protection Board. UK residents may contact the Information Commissioner’s Office (ICO). We would appreciate the chance to address your concerns first through the Contact page on this website.
11. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including access controls, encryption in transit where applicable, and least-necessary access. No system is perfectly secure; please use a strong unique password and protect your devices.
12. Children’s privacy
Samudaia is aimed at adults and professional teams. We do not knowingly offer the service to children under 16 (or a higher age if required by local Member State law under Art. 8 GDPR) without appropriate authorisation. Contact us if you believe a child has provided data unlawfully so we can review and delete it where required.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted here with a revised effective date. Where required by law, we will provide additional notice.