Privacy Policy

1. Scope

This Privacy Policy explains how Saaporo processes personal data when people visit the Saaporo website, communicate with the company, request information, create accounts, or use the Saaporo client operations platform.

Additional terms may apply to specific products, enterprise agreements, events, recruitment activities, or integrations. Customer organizations may also provide their own privacy notices for data they control inside a Saaporo workspace.

2. Saaporo's roles

Saaporo acts as a data controller for website, account, billing, sales, recruitment, security, and customer-support data collected for its own purposes. When customers use Saaporo to process information about their clients, employees, contractors, or other contacts, the customer is generally the controller and Saaporo acts as a processor under the applicable data-processing agreement.

3. Personal data collected

  • Account data: Name, email address, organization, role, authentication details, workspace membership, and settings
  • Service data: Projects, messages, files, forms, approvals, tasks, reports, contacts, and other information submitted to a workspace
  • Usage data: Device, browser, IP address, language, pages, feature activity, logs, and diagnostic events
  • Commercial data: Subscription, billing, transaction, proposal, renewal, and account-management information
  • Communication data: Emails, calls, support requests, feedback, survey responses, event registrations, and meeting notes
  • Recruitment data: Application materials, professional history, interview notes, references, and availability information

4. Sources of personal data

Saaporo receives data directly from individuals, from customer administrators, from connected integrations, from service providers, and through use of the website and platform. Customers determine which information they upload, connect, or make available inside their workspaces.

5. How personal data is used

Saaporo uses personal data to:

  • Provide, administer, support, and secure the service
  • Create and manage accounts, permissions, and subscriptions
  • Process payments and maintain commercial records
  • Respond to questions, support requests, and product feedback
  • Monitor reliability, prevent abuse, and investigate security events
  • Improve product usability, performance, accessibility, and features
  • Send operational notices, account communications, and requested marketing information
  • Recruit and evaluate candidates
  • Meet legal, tax, regulatory, and contractual obligations

6. Legal bases

Where the General Data Protection Regulation or similar law applies, processing may be based on performance of a contract, steps requested before entering a contract, legitimate interests, consent, protection of legal rights, and compliance with legal obligations. The applicable basis depends on the activity and context.

7. Service providers and subprocessors

Saaporo uses vetted providers for hosting, infrastructure, communications, analytics, payments, customer support, security, and business administration. These providers process information under contractual restrictions and according to the services they provide.

Customers may also connect third-party integrations. Information shared through an integration is governed by the customer's configuration and the third party's terms and privacy practices.

8. International transfers

Where personal data is transferred outside the European Economic Area, United Kingdom, or another protected jurisdiction, Saaporo uses appropriate safeguards such as adequacy decisions, standard contractual clauses, contractual commitments, or other lawful transfer mechanisms.

9. Data retention

Saaporo retains personal data for as long as needed to provide the service, maintain security and business records, meet contractual and legal obligations, resolve disputes, and enforce agreements. Retention periods depend on the type of information and the reason it is processed.

Workspace data is exported, returned, retained, or deleted according to customer instructions, product settings, subscription terms, and applicable legal requirements.

10. Security

Saaporo uses organizational and technical measures designed to protect personal data. Measures may include access controls, encryption, secure development practices, monitoring, backups, incident-response procedures, vendor review, and employee confidentiality obligations.

No system can guarantee absolute security. Customers remain responsible for account access, authorized users, workspace permissions, and lawful configuration of connected systems.

11. Individual rights

Depending on location, individuals may have rights to access, correct, delete, restrict, object to processing, withdraw consent, or request portability of personal data. Requests relating to data controlled by a Saaporo customer should normally be directed to that customer.

Saaporo may need to verify identity and may retain limited information where required by law or necessary to protect legal rights.

12. Marketing communications

Recipients may unsubscribe from optional marketing communications using the link provided in the message or by contacting Saaporo. Operational, security, billing, and account communications may still be sent where necessary to provide the service.

13. Cookies

The public website uses cookies and similar technologies as described in the Saaporo Cookie Policy. Consent choices can be managed through the website's cookie controls where available.

14. Children's data

Saaporo is intended for business use and is not directed to children. The company does not knowingly offer accounts directly to children or intentionally collect children's data for consumer services.

15. Complaints and contact

Privacy questions and requests may be sent to privacy@saaporo.com. Individuals may also have the right to contact a local data-protection authority.

16. Changes to this policy

Saaporo may update this policy to reflect changes in products, practices, providers, or legal requirements. Material changes will be communicated where required, and the Last Updated date identifies the current version.