GDPR Compliance
Our commitment to EU data protection
Our GDPR Commitment
Supersei Technologies Pvt. Ltd. ("Supersei", "we", "our", or "us") is committed to protecting the personal data of individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland. We fully embrace the principles of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and its UK equivalent as a foundational standard for all of our data processing activities — not merely a compliance obligation.
This page supplements our Privacy Policy and provides detailed information about how we meet our obligations under the GDPR. Where our general Privacy Policy describes what data we collect and why, this page addresses the specific GDPR framework that governs how we handle personal data belonging to individuals in GDPR-covered jurisdictions.
Our approach is rooted in six core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality. We also uphold the principle of accountability — meaning we take active responsibility for demonstrating compliance, not just claiming it.
Roles: Data Controller and Data Processor
Under the GDPR, the distinction between a Data Controller and a Data Processor determines the nature of our obligations. Supersei Technologies Pvt. Ltd. can act in either capacity depending on the context of the processing activity.
When Supersei Acts as a Data Controller
We act as a Data Controller when we independently determine the purposes and means of processing personal data. This applies to:
- Personal data collected directly from visitors to our website and marketing channels (name, email address, company name, inquiry details)
- Account registration and profile data for users of the Supersei platform
- Billing and payment information for subscription management
- Data collected for our own internal analytics, product improvement, and security monitoring
- Personal data processed for recruitment, employment, and HR purposes
- Data collected through our support and customer success communications
As a Controller, we bear full responsibility for establishing a lawful basis for processing, honouring data subject rights, and ensuring that any processors we engage are bound by appropriate contractual safeguards.
When Supersei Acts as a Data Processor
We act as a Data Processor when we process personal data on behalf of our enterprise and business customers ("Clients") who use the Supersei platform to process data belonging to their own end users or employees. In this capacity:
- The Client is the Data Controller and determines the purpose and means of processing
- Supersei processes data only on documented instructions from the Client
- We do not use Client data for our own commercial purposes
- We maintain a Data Processing Agreement (DPA) with each qualifying Client (see Section 6 below)
- We assist Controllers in fulfilling their own GDPR obligations, including responding to data subject requests
In some instances, Supersei may act as both Controller and Processor simultaneously — for example, when we process metadata about platform usage (Controller) while also processing end-user content on behalf of a Client (Processor). We maintain clear internal demarcation between these activities.
Lawful Basis for Processing
The GDPR requires that every processing activity rests on one of six lawful bases. Supersei relies on the following bases, depending on the specific activity:
Consent (Article 6(1)(a))
Where we process personal data based on your consent, we will have obtained that consent through a clear, affirmative action — such as ticking an opt-in box or confirming a preference in our cookie consent manager. We rely on consent for:
- Sending marketing communications, newsletters, and promotional content
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special categories of personal data where explicitly volunteered
You have the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, use the unsubscribe link in any marketing email, update your cookie preferences via our Cookie Settings page, or contact us at privacy@supersei.ai.
Contract (Article 6(1)(b))
We process personal data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:
- Creating and managing your Supersei account
- Delivering the services described in our Terms of Service
- Processing payments and managing billing
- Providing customer support and onboarding assistance
- Communicating service-critical information such as downtime notices and security alerts
Legitimate Interests (Article 6(1)(f))
We process personal data where we have a legitimate interest in doing so and that interest is not overridden by your rights and interests. Before relying on this basis, we conduct a Legitimate Interests Assessment (LIA) to ensure balance. We rely on legitimate interests for:
- Fraud prevention, abuse detection, and platform security
- Business-to-business direct marketing to existing customers and prospects in a B2B context
- Internal analytics and product usage analytics that improve the platform experience
- Network and information security monitoring and incident response
- Sharing personal data within the Supersei corporate group for administrative purposes
You have the right to object to processing based on legitimate interests at any time (see Section 4 below).
Legal Obligation (Article 6(1)(c))
We process personal data where necessary to comply with a legal obligation to which we are subject. This includes:
- Retaining financial and transactional records in compliance with applicable tax and accounting laws
- Responding to lawful requests from courts, regulators, and law enforcement authorities
- Fulfilling anti-money laundering (AML) and know-your-customer (KYC) obligations where applicable
- Notifying supervisory authorities of personal data breaches as required by Article 33 GDPR
Data Subject Rights
If you are located in the EEA, the UK, or Switzerland, the GDPR grants you a number of rights with respect to your personal data. Supersei is committed to facilitating the exercise of these rights promptly and without undue barrier.
Right of Access (Article 15)
You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data along with information about the purposes of processing, the categories of data involved, recipients, retention periods, and your other rights. We will provide this information within one calendar month of receipt of a valid request.
Right to Rectification (Article 16)
If the personal data we hold about you is inaccurate or incomplete, you have the right to request correction. You may update much of your account information directly through your Supersei account settings. For other corrections, please contact us using the details below.
Right to Erasure ("Right to be Forgotten") (Article 17)
You have the right to request that we delete your personal data where one of the following grounds applies: the data is no longer necessary for the purposes for which it was collected; you withdraw consent and there is no other lawful basis; you object to processing and there are no overriding legitimate grounds; the data has been unlawfully processed; or erasure is required to comply with a legal obligation. We will comply unless an exemption applies — for example, where retention is required to comply with a legal obligation or to establish, exercise, or defend legal claims.
Right to Data Portability (Article 20)
Where we process your personal data based on consent or contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV), and to transmit that data to another controller. You may request a data export from your account settings or by contacting our DPO.
Right to Restriction of Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in the following circumstances: you contest the accuracy of the data (for a period enabling us to verify accuracy); the processing is unlawful but you oppose erasure; we no longer need the data but you require it for legal claims; or you have objected to processing pending verification of whether our legitimate grounds override yours. During restriction, we will continue to store your data but will not otherwise process it without your consent or for limited purposes.
Right to Object (Article 21)
You have the right to object at any time to processing of your personal data based on our legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object to other legitimate-interest processing, we will cease unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.
Rights Related to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to a decision based solely on automated processing — including profiling — where that decision produces legal or similarly significant effects concerning you. If we carry out any such automated decision-making, we will inform you, provide you with the opportunity to request human review, express your point of view, and contest the decision. Currently, Supersei does not make solely automated decisions with legal or similarly significant effects in respect of individual natural persons.
How to Exercise Your Rights
To exercise any of the rights described above, please submit a request to our Data Protection Officer using one of the following methods:
- Email: dpo@supersei.ai
- Email (general privacy): privacy@supersei.ai
To help us process your request efficiently and verify your identity, please include your full name, email address associated with your account, a clear description of your request, and — if you are acting on behalf of another individual — proof of authorisation. We will respond within one calendar month. In complex cases we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it within the initial one-month period. There is no charge for exercising your rights, though we may charge a reasonable fee where requests are manifestly unfounded or excessive.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority. In the EU, you can find your national supervisory authority at edpb.europa.eu. In the UK, the relevant authority is the Information Commissioner's Office (ICO) at ico.org.uk.
Data Protection Officer
Supersei Technologies Pvt. Ltd. has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and ensuring compliance with GDPR obligations. The DPO operates independently and serves as the primary point of contact for all GDPR-related matters, including data subject requests, regulatory enquiries, and internal data protection governance.
You can contact our Data Protection Officer directly at:
- Email: dpo@supersei.ai
- Organisation: Supersei Technologies Pvt. Ltd., Data Protection Officer
All communications with the DPO are treated as confidential. The DPO reports directly to senior leadership and has the authority to escalate data protection concerns without interference. If you are a supervisory authority wishing to contact our DPO, please use the email address above and mark your correspondence accordingly.
Data Processing Agreements
Where Supersei processes personal data on behalf of enterprise customers acting as Data Controllers, we are required under Article 28 GDPR to enter into a written Data Processing Agreement (DPA) that governs the terms of such processing.
Our standard DPA covers:
- The subject matter, duration, nature, and purpose of the processing
- The type of personal data and categories of data subjects involved
- Obligations and rights of the Controller
- Confidentiality obligations on all authorised processors
- Technical and organisational security measures in place
- Sub-processor engagement procedures and approval mechanisms
- Data subject rights assistance obligations
- Data breach notification procedures
- Return or deletion of data at the end of the contract
- Audit rights and contribution to compliance demonstrations
Our standard DPA is available for review and execution by enterprise customers. You can download our DPA template and initiate the execution process at supersei.ai/dpa. If your organisation requires a bespoke DPA or has specific contractual requirements, please contact dpo@supersei.ai to discuss your needs. We are committed to accommodating reasonable customer-specific requirements and will work with your legal team to reach a mutually acceptable agreement.
International Transfers
Supersei Technologies Pvt. Ltd. is headquartered in India, which — as of the date of this policy — is not the subject of an EU Commission adequacy decision under Article 45 GDPR with respect to all data transfer scenarios. Accordingly, where we transfer personal data from the EEA, the UK, or Switzerland to India or any other third country not deemed adequate, we implement appropriate safeguards as required by Chapter V of the GDPR.
Standard Contractual Clauses (SCCs)
Our primary transfer mechanism is the use of Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR. We use the SCCs adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021. For transfers from the UK, we use the International Data Transfer Addendum (IDTA) issued by the UK ICO. These clauses are incorporated into our Data Processing Agreements and, where applicable, our vendor contracts. The SCCs impose legally binding obligations on the data importer to maintain protections equivalent to those afforded by the GDPR.
Transfer Impact Assessments
In addition to executing SCCs, we conduct Transfer Impact Assessments (TIAs) to evaluate whether the legal and practical circumstances in the destination country may impair the effectiveness of the SCCs. Where a TIA identifies risk, we implement supplementary technical or contractual measures — such as encryption, pseudonymisation, or contractual commitments to challenge unlawful government access requests — to bring the level of protection to the GDPR standard.
Adequacy Decisions
Where the European Commission has issued an adequacy decision in respect of a particular country to which we transfer data, we rely on that decision as our transfer mechanism. We monitor adequacy decisions actively and will update our transfer mechanisms promptly in the event that any decision is suspended, amended, or revoked.
Binding Corporate Rules
As our business scales, we are evaluating the adoption of Binding Corporate Rules (BCRs) to govern intra-group international transfers. We will update this page upon approval of any BCRs by the relevant supervisory authority.
For a current list of the third countries to which Supersei transfers personal data and the transfer mechanisms in place for each, or to obtain a copy of our executed SCCs, please contact dpo@supersei.ai.
Data Breach Notification
Supersei Technologies Pvt. Ltd. maintains a comprehensive Incident Response Policy governing the detection, containment, investigation, and notification of personal data breaches, in accordance with Articles 33 and 34 GDPR.
Notification to Supervisory Authority
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where notification cannot be made within 72 hours, we will provide the notification accompanied by reasons for the delay. Our notification to the supervisory authority will include:
- A description of the nature of the breach, including categories and approximate number of data subjects and records affected
- The name and contact details of our Data Protection Officer
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including mitigation measures
Where information is not yet available at the time of initial notification, we will provide it in phases as it becomes available, without undue further delay.
Notification to Data Subjects
Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will notify those data subjects without undue delay. Our notification will describe the nature of the breach in plain language, provide the contact details of our DPO, describe the likely consequences of the breach, and set out the steps we have taken or are taking to address the breach and to mitigate its possible adverse effects. We will also advise data subjects of any steps they should take to protect themselves.
Notification to data subjects may be omitted or replaced by a public communication where direct notification would involve a disproportionate effort, subject to applicable regulatory guidance. In such cases, we will document our reasoning.
Internal Breach Register
We maintain a written record of all personal data breaches, including those that do not meet the threshold for supervisory authority notification, as required by Article 33(5) GDPR. This register includes the facts relating to the breach, its effects, and the remedial action taken. The register is available for inspection by supervisory authorities upon request.
Processor Obligations
Where Supersei acts as a Data Processor, we will notify the relevant Controller of any personal data breach without undue delay upon becoming aware of it, providing sufficient information to allow the Controller to fulfil its own notification obligations under Articles 33 and 34 GDPR.
Privacy by Design and Default
Supersei embeds data protection into the design and architecture of our systems and processes from the outset — not as an afterthought. This approach, known as Privacy by Design and Privacy by Default (Article 25 GDPR), is a core engineering and product principle at Supersei.
Data Minimisation
We collect only personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Before any new product feature or processing activity is introduced, our engineering and privacy teams conduct a data flow mapping exercise to identify and eliminate unnecessary data collection. Fields that are optional are clearly marked as such. We do not collect data "just in case" it becomes useful in the future.
Purpose Limitation
Personal data collected for a specified purpose is not used for a new, incompatible purpose without fresh legal basis or your consent. We maintain an internal Record of Processing Activities (RoPA) under Article 30 GDPR that documents the purpose of each processing activity. Any proposed new use of existing data is reviewed by our DPO against the original collection purpose before implementation.
Storage Limitation
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Our data retention schedules define maximum retention periods for each category of personal data. At the end of the applicable retention period, data is securely deleted or anonymised. Anonymised data, which can no longer be attributed to an identifiable individual, falls outside the scope of the GDPR and may be retained for longer-term analytical purposes.
Privacy by Default
By default, Supersei applies the most privacy-protective settings available for any given feature. This means that users are not required to take additional steps to protect their privacy — the default configuration is already the most privacy-protective. Privacy-enhancing features such as end-to-end encryption, granular access controls, and session timeout settings are enabled or offered by default. Features that share or expose personal data require affirmative action by the user to activate.
Privacy Impact Assessments
For high-risk processing activities — including large-scale profiling, systematic monitoring, or processing of special category data — we conduct Data Protection Impact Assessments (DPIAs) under Article 35 GDPR before processing commences. Where a DPIA identifies residual high risk that cannot be mitigated, we consult with the competent supervisory authority prior to processing.
Sub-processors
As an AI SaaS platform, Supersei engages a number of third-party sub-processors to provide components of our infrastructure and service delivery. We engage sub-processors only where necessary and ensure that each sub-processor is bound by a written contract that imposes data protection obligations equivalent to those set out in our DPAs with Customers, in accordance with Article 28(4) GDPR.
We maintain and publish a current list of sub-processors, which enterprise customers may access upon request or as provided in their DPA. We give Customers advance notice of any intended changes to our sub-processor list (additions or replacements), providing an opportunity to object before the change takes effect.
Our sub-processors fall into the following categories:
- Cloud Infrastructure Providers: We use third-party cloud infrastructure providers for compute, storage, database, and content delivery services. These providers host the Supersei platform and the data processed on it.
- Analytics and Observability: We use analytics and monitoring sub-processors to understand platform usage, diagnose performance issues, and improve the product. These providers process usage metadata and log data. Where possible, data is pseudonymised or anonymised before transmission.
- Payment Processing: We use third-party payment processors to handle subscription billing and payment card processing. These providers are PCI-DSS compliant. Supersei does not store raw payment card data.
- Communication and Messaging: We use sub-processors to deliver transactional emails (account confirmations, password resets, service alerts), in-product notifications, and customer support communications.
- Customer Support Platforms: We use ticketing and CRM platforms to manage customer support interactions. These processors may handle the personal data contained in support tickets.
- Security and Fraud Prevention: We use sub-processors to detect and prevent abuse, fraud, and security threats on the platform.
To request the current sub-processor list, or to exercise your right to object to a new sub-processor, please contact dpo@supersei.ai.
Cookie Consent
We use cookies and similar tracking technologies on our website and platform. Under the GDPR (read alongside the ePrivacy Directive), we are required to obtain your prior consent before placing non-essential cookies on your device. Essential cookies necessary for the basic functioning of the website may be placed without consent.
Our cookies fall into the following categories:
- Strictly Necessary Cookies: Required for the website and platform to function. These cannot be disabled without impairing core features such as authentication, session management, and security.
- Analytics and Performance Cookies: Used to understand how visitors interact with our website and platform — for example, which pages are most visited and where errors occur. These cookies require your consent.
- Functional Cookies: Used to remember your preferences and personalise your experience. These cookies require your consent.
- Marketing and Targeting Cookies: Used to deliver relevant advertising and measure the effectiveness of marketing campaigns. These cookies require your consent and may involve sharing data with third-party advertising platforms.
When you first visit our website, you will be presented with our cookie consent banner, which allows you to accept or decline non-essential cookies by category. You can change your cookie preferences at any time by visiting our Cookie Settings page. We record your consent choices and the timestamp of consent as part of our accountability records. Consent records are available for inspection upon request by supervisory authorities.
For full details about the specific cookies we use, their providers, and their retention periods, please see our Cookie Policy.
Children's Data
The Supersei platform and our associated websites are not directed at children and are not intended for use by individuals under the age of 16 years. We do not knowingly collect personal data from children under 16. The age of 16 is set as our threshold in accordance with Article 8 GDPR, which permits Member States to lower this threshold to no less than 13; we apply 16 as a consistent standard across all GDPR-covered jurisdictions.
If you believe that we have inadvertently collected personal data from a child under 16 without appropriate parental or guardian consent, please contact us immediately at privacy@supersei.ai or dpo@supersei.ai. Upon receiving such a report, we will promptly investigate and, if confirmed, delete the relevant personal data without undue delay.
Our registration process includes a declaration of age, and we take reasonable steps to verify that users meet the minimum age requirement. Enterprise customers who use the Supersei platform in any context that may involve children are responsible for ensuring that they obtain appropriate consents and comply with applicable laws protecting children's personal data, including the GDPR, the UK GDPR, and where applicable, the US COPPA.
Contact Us
If you have questions, concerns, or requests relating to this GDPR Compliance page, our data processing practices, or the exercise of your data subject rights, please contact us using the details below.
Data Protection Officer
For all formal GDPR-related requests, data subject rights exercises, DPA enquiries, and regulatory matters, please contact our DPO directly:
- Email: dpo@supersei.ai
General Privacy Enquiries
For general privacy questions, consent management, marketing opt-outs, and informal data enquiries:
- Email: privacy@supersei.ai
Organisation
- Legal entity: Supersei Technologies Pvt. Ltd.
We aim to acknowledge all incoming GDPR-related correspondence within 5 business days and to resolve matters within the statutory timeframes. Where a matter involves a supervisory authority, we will coordinate our response with the relevant authority as appropriate.
This page was last reviewed and updated on June 2026. We will update it as our practices evolve or as regulatory guidance changes.