# Privacy & Data Protection



> How GoSmarter handles personal data under GDPR - data processing practices, subject rights, and our sub-processors' DPAs.
> 
> **URL:** https://www.gosmarter.ai/docs/privacy/

**Date:** 0001-01-01



## Privacy and data protection

GoSmarter processes data on behalf of our customers. This page describes our data protection practices and how we support your GDPR obligations.

This page provides a high-level overview. Detailed privacy control documentation is available on request under NDA.

### Our role under GDPR

- **You** (the customer) are the **data controller**: you decide what data is uploaded and processed
- **GoSmarter** acts as a **data processor**: we process data according to your instructions via the platform
- **Microsoft Azure** acts as a **sub-processor**: they host the infrastructure and provide AI services
- **Clerk** acts as a **sub-processor**: they provide user authentication and identity/session management, under [Clerk's DPA](https://clerk.com/legal/dpa), which is automatically incorporated into their standard terms of service
- **Stripe** acts as a **sub-processor**: they provide subscription billing and payment processing — GoSmarter does not store payment card details — under [Stripe's DPA](https://stripe.com/legal/dpa), which is automatically part of their standard services agreement

### What personal data does GoSmarter process?

GoSmarter is a B2B platform. The personal data we process is limited to what is required for account access, platform authorisation, and business-document workflows. This includes identity data processed by Clerk on our behalf (name, email address, authentication/session metadata) and billing contact/subscription data processed by Stripe on our behalf.

GoSmarter does not collect or process sensitive personal data (health, biometric, financial) as part of its core functionality. Payment card data is collected and stored directly by Stripe, not by GoSmarter.

### Data Processing Agreement

We provide a Data Processing Agreement (DPA) that covers:

- The scope and purpose of data processing
- Technical and organisational security measures
- Sub-processor obligations (Microsoft Azure, Clerk, Stripe)
- Data subject rights support
- Breach notification commitments
- Data deletion on contract termination

Data Processing Agreement available on request via [support@gosmarter.ai](mailto:support@gosmarter.ai)

### Sub-processors' data processing commitments

As our infrastructure and platform providers, each sub-processor's own processing commitments apply:

- [Microsoft Products and Services DPA](https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA)
- [Microsoft Trust Center](https://www.microsoft.com/en-gb/trust-center/privacy/gdpr-overview)
- AI services: Your data is not used to train Microsoft AI models ([Azure AI data privacy](https://learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy))
- [Clerk's Data Processing Agreement](https://clerk.com/legal/dpa) and [privacy policy](https://clerk.com/legal/privacy)
- [Stripe's Data Processing Agreement](https://stripe.com/legal/dpa) and [privacy policy](https://stripe.com/privacy)

### Data subject rights

If your users or data subjects exercise their rights (access, rectification, erasure, portability), we support you as follows:

- **User account data (name associated with a login)**: on a verified erasure request, we remove the individual's identifying details from their account record, including historical versions held for audit purposes. A pseudonymous internal identifier is retained where needed to preserve the integrity of audit trails (see below) — this identifier alone does not identify the individual.
- **Business contact records** (e.g. a named contact on a supplier or customer organisation): where this data is processed as part of an active or recently active commercial relationship, we retain it for the period required to support contractual, accounting, and legal-claims obligations (typically up to 6 years, in line with UK limitation periods for contracts), consistent with UK GDPR Article 17(3). We erase or anonymise this data once that period lapses and no ongoing legal basis for retention applies.
- **Audit trail preservation**: because our platform maintains full change-history records (a requirement for manufacturing traceability and quality audits, including EN 10204 mill certification records), erasure of an individual's identifying details does not remove the underlying transaction, order, or certification history — only the personal identifiers within it. This lets your organisation retain evidential and audit continuity while individuals' personal data is removed.
- Data can be accessed and exported in standard formats through the platform or by contacting us directly.

Data Processing Agreement available on request via [support@gosmarter.ai](mailto:support@gosmarter.ai) — it sets out erasure timelines and process in full.

### Data retention

- **Active data**: Retained for the duration of your subscription
- **Uploaded documents**: Stored in Azure Blob Storage for the duration of your subscription
- **Audit logs**: Retained in line with our operational and compliance requirements
- **On contract termination**: We retain Customer Data — including mill certificate, order, and audit-trail records — for 6 years following termination, consistent with common manufacturing quality/traceability record-keeping practice and UK statutory limitation periods. You can export your data at any time during that period. We delete data earlier than this only at your explicit request, subject to any legal or regulatory requirement to retain it for longer.

### International transfers

Core persistent data hosted directly by GoSmarter is in UK regions. Where supporting processing uses EU regions, it remains within UK/EU operating boundaries.

Two sub-processors are the exception: Clerk (identity/authentication) and Stripe (billing) both process and store data in the **United States**. Neither offers UK/EU data residency. International transfer relies on Standard Contractual Clauses and self-certification under the EU-US, UK-US, and Swiss-US Data Privacy Framework — see [Data Residency](../data-residency/)'s "Third-party sub-processor regions" section for detail.

### Key points for your security team

- **Data processor role**: GoSmarter processes data under your instructions as controller
- **Limited personal data**: Primarily user accounts and names on business documents, plus identity/session data (Clerk) and billing/subscription data (Stripe) processed on our behalf
- **DPA available**: Covers processing scope, security measures, breach notification, and deletion
- **Sub-processors**: Microsoft Azure (covered by Microsoft's Products and Services DPA), Clerk (covered by [Clerk's DPA](https://clerk.com/legal/dpa)), and Stripe (covered by [Stripe's DPA](https://stripe.com/legal/dpa)) — all applied automatically under each provider's standard terms, no separate execution required
- **No AI model training**: Contractual commitment from Microsoft
- **UK/EU only (GoSmarter-hosted infrastructure)**: No international transfers outside UK GDPR adequacy framework for our own Azure deployment. Clerk and Stripe are the exception — both transfer to the US under DPF/SCCs; see [Data Residency](../data-residency/)

### Detailed information under NDA

Additional privacy and data protection evidence can be shared under mutual NDA, including:

- Data flow and processing context documentation
- Retention and deletion process details
- Sub-processor and transfer assurance information
- Operational control evidence relevant to due diligence

### Request evidence

[Email us](mailto:support@gosmarter.ai), [contact us online](https://gosmarter.ai/contact), or [book a compliance call](https://calendly.com/gosmarter-demo) to request the NDA pack.

