Security & Trust
Sariio is built for enterprise BPO and contact centre operations. This page summarises the controls, certifications, and compliance posture that procurement and security teams need when evaluating the platform.
Data Hosting and Residency
All Sariio platform data is hosted in Frankfurt, Germany (EU) on Render.com infrastructure running on Amazon Web Services eu-central-1. Data never leaves the European Economic Area as part of the core platform.
| Hosting provider | Render.com Inc. |
|---|---|
| Cloud region | AWS eu-central-1 (Frankfurt, Germany) |
| Data residency | European Economic Area (EEA) |
Certifications and Compliance
Infrastructure certifications held by our providers:
| Provider | Certification |
|---|---|
| Render.com | SOC 2 Type II Attestation of Compliance (security, availability, and confidentiality) |
| AWS eu-central-1 | ISO 27001, SOC 1 / SOC 2 / SOC 3, PCI DSS |
Sariio Limited is registered in England and Wales (Company No. 15760535) and operates as a UK-based data controller under UK GDPR.
Encryption
| Data in transit | TLS 1.2 or higher on all connections |
|---|---|
| Data at rest | AES-256 encryption (AWS and Render managed) |
| Database | Encrypted at rest and in transit; access restricted to application layer |
Access Controls
Sariio enforces organisation-level data isolation. No user can access data belonging to another organisation.
- Role-based permissions: employee, manager, coach, org admin, and super admin roles with least-privilege defaults
- Authentication: Passwordless magic link sign-in; no passwords stored by Sariio
- Session management: Short-lived tokens; forced re-authentication on expiry
- Admin access: Production database access restricted to named individuals on a need-to-know basis
GDPR Compliance
Primary platform infrastructure is hosted within the EEA (Frankfurt, Germany). Core platform data for EU and UK clients does not transfer to third countries.
One sub-processor is US-based and operates under Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office:
- Anthropic (AI processing) — SCC Article 46(2)(c)
Sariio does not sell personal data. No data is used for advertising. AI model training by our providers is contractually prohibited on client data.
POPIA Compliance
The Protection of Personal Information Act (South Africa) requires that personal data transferred outside South Africa be subject to equivalent protections. EU hosting satisfies POPIA's adequacy requirement: the European Union is recognised as providing equivalent data protection under POPIA Section 72.
South African BPO clients can rely on EU Frankfurt hosting as a lawful transfer mechanism without additional safeguards.
Employee Monitoring and Agent Data
Sariio's use of agent performance data for coaching purposes is designed with compliance in mind:
- MAPS assessments are transparent, opt-in preference surveys. Agents are informed of the purpose before completing the survey.
- Preference data is used to inform coaching conversations, not to score or rank agents.
- Lawful basis: Use of preference data for individual coaching constitutes legitimate interest under GDPR Article 6(1)(f), balanced against the agent's right to receive personalised development support. Equivalent lawful basis applies under POPIA.
- Transparency: BPO clients are responsible for informing agents that preference data is used for coaching purposes, as is standard practice in contact centre operations.
Sub-processor List
Sariio uses the following third-party sub-processors:
| Processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Render.com / AWS eu-central-1 | Infrastructure and hosting | Frankfurt, Germany (EU) | EEA — no transfer |
| Anthropic | AI narrative summary generation | United States | SCCs (ICO-approved) |
| Resend | Transactional email delivery | United States | SCCs |
| Stripe | Payment processing | United States / Ireland | SCCs / EU entity |
This list is kept up to date. Material changes to sub-processors will be reflected in the Privacy Policy.
Data Retention and Deletion
Data is retained only as long as necessary to provide the service. Full retention periods are documented in the Privacy Policy.
- Account and assessment data: retained while the account is active
- Payment records: retained per applicable tax and accounting regulations
Data deletion requests can be submitted to hello@sariio.com.
Incident Response
Sariio maintains an incident response process aligned with GDPR Article 33 requirements:
- Security incidents affecting personal data are assessed within 24 hours of discovery
- Affected clients are notified within 72 hours where required under GDPR Article 33
- Regulatory notifications (to the ICO) are made where required by law
To report a security concern: hello@sariio.com
For security questionnaires, DPA requests, or procurement enquiries, contact hello@sariio.com. We aim to respond within two business days.