Sariio sariio.
← Back to Sariio

Security & Trust

Last updated: June 2026

Sariio is built for enterprise BPO and contact centre operations. This page summarises the controls, certifications, and compliance posture that procurement and security teams need when evaluating the platform.

Data Hosting and Residency

All Sariio platform data is hosted in Frankfurt, Germany (EU) on Render.com infrastructure running on Amazon Web Services eu-central-1. Data never leaves the European Economic Area as part of the core platform.

Hosting providerRender.com Inc.
Cloud regionAWS eu-central-1 (Frankfurt, Germany)
Data residencyEuropean Economic Area (EEA)

Certifications and Compliance

Infrastructure certifications held by our providers:

ProviderCertification
Render.comSOC 2 Type II Attestation of Compliance (security, availability, and confidentiality)
AWS eu-central-1ISO 27001, SOC 1 / SOC 2 / SOC 3, PCI DSS

Sariio Limited is registered in England and Wales (Company No. 15760535) and operates as a UK-based data controller under UK GDPR.

Encryption

Data in transitTLS 1.2 or higher on all connections
Data at restAES-256 encryption (AWS and Render managed)
DatabaseEncrypted at rest and in transit; access restricted to application layer

Access Controls

Sariio enforces organisation-level data isolation. No user can access data belonging to another organisation.

  • Role-based permissions: employee, manager, coach, org admin, and super admin roles with least-privilege defaults
  • Authentication: Passwordless magic link sign-in; no passwords stored by Sariio
  • Session management: Short-lived tokens; forced re-authentication on expiry
  • Admin access: Production database access restricted to named individuals on a need-to-know basis

GDPR Compliance

Primary platform infrastructure is hosted within the EEA (Frankfurt, Germany). Core platform data for EU and UK clients does not transfer to third countries.

One sub-processor is US-based and operates under Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office:

  • Anthropic (AI processing) — SCC Article 46(2)(c)

Sariio does not sell personal data. No data is used for advertising. AI model training by our providers is contractually prohibited on client data.

POPIA Compliance

The Protection of Personal Information Act (South Africa) requires that personal data transferred outside South Africa be subject to equivalent protections. EU hosting satisfies POPIA's adequacy requirement: the European Union is recognised as providing equivalent data protection under POPIA Section 72.

South African BPO clients can rely on EU Frankfurt hosting as a lawful transfer mechanism without additional safeguards.

Employee Monitoring and Agent Data

Sariio's use of agent performance data for coaching purposes is designed with compliance in mind:

  • MAPS assessments are transparent, opt-in preference surveys. Agents are informed of the purpose before completing the survey.
  • Preference data is used to inform coaching conversations, not to score or rank agents.
  • Lawful basis: Use of preference data for individual coaching constitutes legitimate interest under GDPR Article 6(1)(f), balanced against the agent's right to receive personalised development support. Equivalent lawful basis applies under POPIA.
  • Transparency: BPO clients are responsible for informing agents that preference data is used for coaching purposes, as is standard practice in contact centre operations.

Sub-processor List

Sariio uses the following third-party sub-processors:

Processor Purpose Location Transfer basis
Render.com / AWS eu-central-1 Infrastructure and hosting Frankfurt, Germany (EU) EEA — no transfer
Anthropic AI narrative summary generation United States SCCs (ICO-approved)
Resend Transactional email delivery United States SCCs
Stripe Payment processing United States / Ireland SCCs / EU entity

This list is kept up to date. Material changes to sub-processors will be reflected in the Privacy Policy.

Data Retention and Deletion

Data is retained only as long as necessary to provide the service. Full retention periods are documented in the Privacy Policy.

  • Account and assessment data: retained while the account is active
  • Payment records: retained per applicable tax and accounting regulations

Data deletion requests can be submitted to hello@sariio.com.

Incident Response

Sariio maintains an incident response process aligned with GDPR Article 33 requirements:

  • Security incidents affecting personal data are assessed within 24 hours of discovery
  • Affected clients are notified within 72 hours where required under GDPR Article 33
  • Regulatory notifications (to the ICO) are made where required by law

To report a security concern: hello@sariio.com

For security questionnaires, DPA requests, or procurement enquiries, contact hello@sariio.com. We aim to respond within two business days.

About Terms Privacy Security Modern Slavery
Copyright 2024-2026 Sariio Limited. All rights reserved.

Are you sure?