Trust & AI governance

The declaration

This page exists so that a data protection officer, security reviewer or procurement team can assess Sariio from a single document. This document is deliberately formal; every claim on this page is checkable, and requests for evidence are welcome.

Last reviewed: October 2026 · Applies to the Sariio platform (app.sariio.ai) and this marketing site · Canonical legal documents: Privacy Policy (opens in new tab), Terms (opens in new tab), Security & Trust (opens in new tab)

1. Controller and registration

The data controller is Sariio Limited, registered in England and Wales, company number 15760535, of Suite 5, 5th Floor, City Reach, 5 Greenwich View Place, London E14 9NN. Sariio Limited operates as a UK-based data controller under UK GDPR. Contact for security questionnaires, DPA requests and procurement enquiries: hello@sariio.com (response within two business days).

2. Hosting and data residency

Hosting providerRender.com Inc., running on Amazon Web Services
Cloud regionAWS eu-central-1 - Frankfurt, Germany (EU)
Data residencyAll core platform data remains within the European Economic Area. Core platform data for EU and UK clients does not transfer to third countries.
Certifications (providers)Render.com: SOC 2 Type II Attestation of Compliance. AWS eu-central-1: ISO 27001, SOC 1/2/3, PCI DSS.

3. Encryption and infrastructure security

In transitTLS 1.2 or higher on all connections
At restAES-256 server-side encryption, keys managed by AWS KMS; database and backups included
NetworkWeb Application Firewall, load balancing, private networking for internal services, rate limiting on authentication and API endpoints
DatabaseManaged PostgreSQL; no public database port; SSL/TLS connections; multi-tenant isolation enforced at both database and application layers
ResilienceAutomated daily backups, point-in-time recovery, application-level exports, automated failover; the application server is stateless - its complete loss results in zero data loss

4. Access control

Sariio enforces organisation-level data isolation: no user can access another organisation's data. Role-based permissions run on least-privilege defaults across employee, manager, coach, organisation-admin and super-admin roles. Authentication is passwordless (magic link), so Sariio stores no passwords; sessions use short-lived tokens with forced re-authentication on expiry. Production database access is restricted to named individuals on a need-to-know basis, and access to personal data is logged and auditable.

5. The AI, and how it is constrained

Narrative commentary on Sariio maps is generated by large language models provided by Anthropic. The following constraints apply by design and by contract:

Gated outputWhere the survey numbers give no support for naming a leading preference, the commentary names none. The model works only from what the survey recorded.
AuditabilityAll AI output is logged with timestamps and version numbers, traceable to the model, prompt and data that produced each report.
No automated decisionsNo automated decision is made about any individual (GDPR Article 22). A human being always decides. This commitment is contractual, not only architectural.
No model trainingClient data is not used to train AI models. Sariio requires the same commitment from its AI providers, and Anthropic processes data under a data processing addendum that prohibits training on it.
No biometric identificationSariio does not identify anybody from their voice, face or image. Where a call transcript separates the agent from the customer, the two are labelled by their role in that single call: no voiceprint or biometric template is created, nothing is stored that could recognise a speaker, and no speaker is matched across calls. The platform performs no analysis of tone, pitch, timbre, accent or inflection.
Call audio is transcribed, then deletedWhere a client submits call audio to Sariio one2one, Sariio produces a text transcript and deletes the audio file on a fixed schedule once the transcript exists. Deletion is logged. Coaching is derived from the words spoken, the shape of the conversation, and the client's own quality framework.
Conversation shape, not emotional stateSariio measures how a conversation was structured in time: who spoke, for how long, the balance of talking to listening, periods where neither party spoke, and points where both spoke at once. These are timings, taken from the timestamps on the transcript, and they describe the conversation rather than the person. Sariio infers no emotion, sentiment, mood or attitude, produces no sentiment score, and makes no claim to know how anybody felt. Because Article 5(1)(f) of the EU AI Act prohibits inferring emotions from biometric data in the workplace, and Sariio does neither of those things, the platform sits outside that prohibition by design.
No acoustic analysisSariio does not measure tone, pitch, volume, timbre, accent, inflection or any other acoustic property of a voice, and draws no conclusion from how a voice sounded. A long silence is recorded as a long silence, never as hesitation, discomfort or a state of mind. What it meant is for the team leader who knows the person to judge.
Only selected calls are transcribedTranscription happens only for calls a client has chosen for coaching, never across all recorded traffic. Submitting a call to the platform does not by itself cause it to be transcribed.
Coaching notes are endorsed by a humanA draft coaching note is prepared by Sariio and reviewed, edited where the reviewer wishes, and endorsed by the agent's own team leader before the agent sees it. Nothing generated reaches an agent unendorsed, and no coaching output is a decision about a person.
Matching informs, humans decideWhere a successMAP benchmark is used, the app shows how closely a candidate's preferences sit against it - deterministic positions, dimension by dimension and cell by cell, computed from the person's own answers, always shown alongside the picture they summarise. It is a calculation, not an AI judgement: the AI never produces a score, rank or recommendation - its commentary describes alignment and difference in words only. A match is not a merit ranking - sitting close to the benchmark means similar preferences to the benchmark group, not a better candidate, and a recruiter may deliberately look for difference. The app applies no threshold, rejects nobody and shortlists nobody on its own. Because a benchmark drawn from a homogeneous group can reproduce whatever that group has in common - a risk under the Equality Act 2010 - the material warns against selecting for sameness: the match informs, the client decides.

Safety boundaries built into the code

Sariio uses a defence-in-depth architecture to ensure AI remains an exploratory tool, not a decision-maker. Sariio's system prompts and output validators forbid the AI from making or recommending decisions about hiring, dismissal or suitability. The AI is structurally constrained so it cannot invent data, guess traits, or grade and rank human preferences. It can only add context to the verified survey data it is given.

  • Conversational tools like Ask Sariio and Coach include explicit distress and safeguarding tripwires, designed to halt the AI and hand off to human support channels or verified crisis resources when appropriate.

6. Lawful basis and workforce data

Sariio surveys are transparent, opt-in preference surveys; the purpose is explained before each survey begins, and consent is captured with an audit trail. Preference data informs coaching and development conversations; use for individual coaching rests on legitimate interest (GDPR Article 6(1)(f)), balanced against the individual's right to personalised development support, with equivalent basis under POPIA. Clients are responsible for informing their people that preference data supports coaching. The data belongs to the person who took the survey.

7. International positions

UK / EU (GDPR, UK GDPR)EEA hosting; no third-country transfer of core platform data. Full data-subject rights honoured within one month; complaints may be raised with the ICO.
South Africa (POPIA)POPIA Section 72 requires equivalent protection for cross-border transfers. The EU is recognised as providing equivalent protection, so South African BPO clients can rely on EU Frankfurt hosting as a lawful transfer mechanism without additional safeguards.
United States (sub-processing)US-based sub-processors operate under Standard Contractual Clauses approved by the UK Information Commissioner's Office (Article 46(2)(c)).

8. Sub-processors

ProcessorPurposeLocationTransfer basis
Render.com / AWS eu-central-1Infrastructure and hostingFrankfurt, Germany (EU)EEA - no transfer
AnthropicAI narrative generationUnited StatesSCCs (ICO-approved)
ResendTransactional emailUnited StatesSCCs
StripePayment processingUnited States / IrelandSCCs / EU entity
Speech-to-text provider (Sariio one2one audio ingest only)Transcription of calls selected for coachingNamed in the client's DPA before any audio is submittedSCCs where the provider sits outside the EEA
Plausible AnalyticsCookieless web analytics (this marketing site only)European UnionEEA - no transfer
NutshellCRM visitor tracking and enquiry follow-up for this marketing siteUnited StatesUK/US transfer safeguards

This marketing site measures aggregate traffic with Plausible, a cookieless, EU-hosted analytics service, and uses Nutshell visitor tracking to connect site visits with enquiries and follow-up. Fonts are self-hosted, so no visitor request leaves this site for third-party typography services. Sariio does not sell personal data, and no data is used for advertising. Material changes to sub-processors are reflected in the Privacy Policy.

9. Retention and deletion

Data is retained only as long as necessary to provide the service. Survey data is retained as part of a person's MAPS history, to enable longitudinal preference tracking, and deleted sooner if the individual asks. Payment records are retained as required by tax and accounting regulations. Deletion requests: hello@sariio.com, honoured subject to legal obligations.

For Sariio one2one, call transcripts and coaching notes are retained for the period set in the client contract. Call audio is retained only for as long as transcription requires, and is then deleted.

10. Incident response

Sariio maintains an incident response process aligned with GDPR Article 33. Security incidents affecting personal data are assessed within 24 hours of discovery; affected clients are notified within 72 hours where required; regulatory notifications to the ICO are made where required by law. To report a security concern: hello@sariio.com.

11. Verification

Within Sariio, one person holds super-administrator access to customer data - the founder - which is a smaller access surface than a support team sharing a login, and that claim is checkable on request. Security questionnaires and evidence requests are answered within two business days. If your diligence process needs something this page does not cover, ask: talk to David.