Sauce AI
  • Welcome to Sauce AI Docs
  • What is Sauce AI?
  • Getting started
  • Fundamentals
    • Understanding highlights
    • Understanding trends
    • What do all the counts mean?
  • Importing feedback
    • Overview
    • Slack integration
    • Discord integration
    • Gong integration
    • Intercom integration
    • Zendesk integration
    • Salesforce integration
    • Hubspot integration
    • Zapier integration
    • Uploading a CSV file
  • Tools
    • Find similar feedback
    • Top-down trends
    • Spaces
    • Saved views
    • Clusters
    • Digests
    • Feedback rules
  • Security
    • Security at Sauce
    • Security Trust Center
    • GDPR Commitment
    • Data Processing Addendum (DPA)
Powered by GitBook
On this page
  • Introduction
  • GDPR compliance
  • Our security
  • Data portability and right to be forgotten
  • Privacy and consent
  • The Australian Privacy Act and the GDPR
  • Additional resources
  • Contact us

Was this helpful?

  1. Security

GDPR Commitment

Last updated: 27 November 2023

PreviousSecurity at SauceNextData Processing Addendum (DPA)

Last updated 7 months ago

Was this helpful?

Introduction

This article is designed to help Sauce customers and users understand, and where applicable, comply with the General Data Protection Regulation (“GDPR”). The GDPR is the most significant change to European data privacy legislation in the last 20 years and went into effect on May 15, 2018.

GDPR is designed to give European Union (“EU”) citizens more control over their data and seeks to unify a number of existing privacy and security laws under one comprehensive law.

Sauce has made information security and data privacy foundational principles of everything we do, and we recognise the importance of adhering to regulations to advance information security and data privacy for citizens of the EU.

GDPR compliance

We appreciate that our customers have requirements under the GDPR that are directly impacted by their use of our Services. Below are several GDPR initiatives that have been implemented across our Services:

  • Investment in security – We’ve increased our investment in security. This includes implementing dependency vulnerability detection, improved auditing and logging across all services, new internal security policies, staff security training, improved password and secret management, 2FA enforcement, stronger password policies, and more.

  • Employee training – We ensure our team are trained in handling customer data and personal information, and that they maintain the confidentiality and security of that data.

  • Updated terms – We have updated the structure and language used in all of our terms and policies to more clearly communicate what information we collect, what we use it for, who we share it with, what your rights are, and more.

  • Data Sub-Processors – We list all of our third party data sub-processors and share information on what we use them for and where they are located. You can view that .

  • Data portability – We’ve improved our data export features so customers may request an export of customer data and personal information in a machine-readable format.

  • EU data storage – You can choose to host certain data you upload to your Sauce workspace in our data center located in the EU (coming in Q1 2023).

Our security

We appreciate that we are entrusted with valuable and sometimes sensitive user research data, which is why we have built security into every layer of our architecture, pursuing a ‘privacy by design’ approach to the design and development of our Services.

Our application is built on world-class, modern cloud infrastructure designed to ensure the safety of your data. We have carefully chosen proven third party cloud providers that have a great security track record, and we employ best practices including regular backups, data encryption, sanitized logging, and common attack prevention.

Data portability and right to be forgotten

We help you honor your customers’ requests to export their data. Sauce provides data portability and data management tools for exporting product and user data.

We also help customers meet obligations under the GDPR ‘right to be forgotten’ (or ‘right to erasure’) clause by making it easy to request the deletion of personal data from Sauce.

Privacy and consent

The Australian Privacy Act and the GDPR

As an Australian-based business, our information security and data privacy practices and policies are already guided by Australian law, namely the Australian Privacy Act.

The GDPR and the Privacy Act include some similar requirements. Both laws foster transparent information handling practices and business accountability, to give individuals confidence that their privacy is being protected. Both laws require businesses to implement measures that ensure compliance with a set of privacy principles, and both take a ‘privacy by design’ approach to compliance.

Additional resources

The following resources might prove useful:

Contact us

Your privacy is important to us, and so is being transparent about how we collect, use, and share your information. In our , we share what information we collect, how we use and store that data, and how you can access and control your information.

If you have any questions, please email us at

here
Privacy Policy
The EU’s definition of personal data
Full text of the GDPR
security@sauce.app