The declaration
This page exists so that a data protection officer, security reviewer or procurement team can assess Sariio from a single document. This document is deliberately formal; every claim on this page is checkable, and requests for evidence are welcome.
1. Controller and registration
The data controller is Sariio Limited, registered in England and Wales, company number 15760535, of Suite 5, 5th Floor, City Reach, 5 Greenwich View Place, London E14 9NN. Sariio Limited operates as a UK-based data controller under UK GDPR. Contact for security questionnaires, DPA requests and procurement enquiries: hello@sariio.com (response within two business days).
2. Hosting and data residency
| Hosting provider | Render.com Inc., running on Amazon Web Services |
|---|---|
| Cloud region | AWS eu-central-1 - Frankfurt, Germany (EU) |
| Data residency | All core platform data remains within the European Economic Area. Core platform data for EU and UK clients does not transfer to third countries. |
| Certifications (providers) | Render.com: SOC 2 Type II Attestation of Compliance. AWS eu-central-1: ISO 27001, SOC 1/2/3, PCI DSS. |
3. Encryption and infrastructure security
| In transit | TLS 1.2 or higher on all connections |
|---|---|
| At rest | AES-256 server-side encryption, keys managed by AWS KMS; database and backups included |
| Network | Web Application Firewall, load balancing, private networking for internal services, rate limiting on authentication and API endpoints |
| Database | Managed PostgreSQL; no public database port; SSL/TLS connections; multi-tenant isolation enforced at both database and application layers |
| Resilience | Automated daily backups, point-in-time recovery, application-level exports, automated failover; the application server is stateless - its complete loss results in zero data loss |
4. Access control
Sariio enforces organisation-level data isolation: no user can access another organisation's data. Role-based permissions run on least-privilege defaults across employee, manager, coach, organisation-admin and super-admin roles. Authentication is passwordless (magic link), so Sariio stores no passwords; sessions use short-lived tokens with forced re-authentication on expiry. Production database access is restricted to named individuals on a need-to-know basis, and access to personal data is logged and auditable.
5. The AI, and how it is constrained
Narrative commentary on Sariio maps is generated by large language models provided by Anthropic. The following constraints apply by design and by contract:
| Gated output | Where the survey numbers give no support for naming a leading preference, the commentary names none. The model works only from what the survey recorded. |
|---|---|
| Auditability | All AI output is logged with timestamps and version numbers, traceable to the model, prompt and data that produced each report. |
| No automated decisions | No automated decision is made about any individual (GDPR Article 22). A human being always decides. This commitment is contractual, not only architectural. |
| No model training | Client data is not used to train AI models. Sariio requires the same commitment from its AI providers, and Anthropic processes data under a data processing addendum that prohibits training on it. |
| No biometrics | Sariio takes no biometric input and performs no analysis of voice, face or video. The platform therefore sits outside the EU AI Act's Article 5 prohibition on emotion recognition in the workplace by design. |
| Matching informs, humans decide | Where a successMAP benchmark is used, the app shows how closely a candidate's preferences sit against it - deterministic positions, dimension by dimension and cell by cell, computed from the person's own answers, always shown alongside the picture they summarise. It is a calculation, not an AI judgement: the AI never produces a score, rank or recommendation - its commentary describes alignment and difference in words only. A match is not a merit ranking - sitting close to the benchmark means similar preferences to the benchmark group, not a better candidate, and a recruiter may deliberately look for difference. The app applies no threshold, rejects nobody and shortlists nobody on its own. Because a benchmark drawn from a homogeneous group can reproduce whatever that group has in common - a risk under the Equality Act 2010 - the material warns against selecting for sameness: the match informs, the client decides. |
6. Lawful basis and workforce data
Sariio surveys are transparent, opt-in preference surveys; the purpose is explained before each survey begins, and consent is captured with an audit trail. Preference data informs coaching and development conversations; use for individual coaching rests on legitimate interest (GDPR Article 6(1)(f)), balanced against the individual's right to personalised development support, with equivalent basis under POPIA. Clients are responsible for informing their people that preference data supports coaching. The data belongs to the person who took the survey.
7. International positions
| UK / EU (GDPR, UK GDPR) | EEA hosting; no third-country transfer of core platform data. Full data-subject rights honoured within one month; complaints may be raised with the ICO. |
|---|---|
| South Africa (POPIA) | POPIA Section 72 requires equivalent protection for cross-border transfers. The EU is recognised as providing equivalent protection, so South African BPO clients can rely on EU Frankfurt hosting as a lawful transfer mechanism without additional safeguards. |
| United States (sub-processing) | US-based sub-processors operate under Standard Contractual Clauses approved by the UK Information Commissioner's Office (Article 46(2)(c)). |
8. Sub-processors
| Processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Render.com / AWS eu-central-1 | Infrastructure and hosting | Frankfurt, Germany (EU) | EEA - no transfer |
| Anthropic | AI narrative generation | United States | SCCs (ICO-approved) |
| Resend | Transactional email | United States | SCCs |
| Stripe | Payment processing | United States / Ireland | SCCs / EU entity |
| Plausible Analytics | Cookieless web analytics (this marketing site only) | European Union | EEA - no transfer |
This marketing site measures traffic with Plausible, a cookieless, EU-hosted analytics service: no cookies are set, no personal data is collected, and no consent banner is required. Fonts are self-hosted, so no visitor request leaves this site for third-party typography services. Sariio does not sell personal data, and no data is used for advertising. Material changes to sub-processors are reflected in the Privacy Policy.
9. Retention and deletion
Data is retained only as long as necessary to provide the service. Survey data is retained as part of a person's MAPS history, to enable longitudinal preference tracking, and deleted sooner if the individual asks. Payment records are retained as required by tax and accounting regulations. Deletion requests: hello@sariio.com, honoured subject to legal obligations.
10. Incident response
Sariio maintains an incident response process aligned with GDPR Article 33. Security incidents affecting personal data are assessed within 24 hours of discovery; affected clients are notified within 72 hours where required; regulatory notifications to the ICO are made where required by law. To report a security concern: hello@sariio.com.
11. Verification
Within Sariio, one person holds super-administrator access to customer data - the founder - which is a smaller access surface than a support team sharing a login, and that claim is checkable on request. Security questionnaires and evidence requests are answered within two business days. If your diligence process needs something this page does not cover, ask: talk to David.