1. Roles
Where you determine the purposes and means of processing, you are the controller and Sterdam is the processor. Sterdam processes personal data only on your documented instructions.
2. Scope of processing
Subject matter, duration, nature, and purpose of processing are defined by the engagement. Data subjects typically include your users, staff, and contacts.
3. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations and access is granted on a least-privilege basis.
4. Security measures
- Encryption in transit and at rest where supported.
- Role-based access control and audit logging.
- Environment separation and least-privilege service accounts.
- Regular review of access and dependencies.
5. Sub-processors
We use a limited set of sub-processors, including hosting and database infrastructure, payment processing, and email delivery. We remain responsible for their performance and will give notice of material changes.
6. International transfers
Transfers outside your region rely on Standard Contractual Clauses or equivalent safeguards under GDPR, UK GDPR, and POPIA.
7. Assistance and breach notification
We assist with data subject requests, impact assessments, and regulator queries, and notify you without undue delay after becoming aware of a personal data breach.
8. Deletion and return
On termination we delete or return personal data, except where retention is required by law.
9. Audit
We make available the information reasonably needed to demonstrate compliance and support audits scoped to the processing under the engagement.
