Sodtrack Data Processing Terms

Sodtrack as data processor

Last updated: September 2, 2026.

1. Scope

These Terms govern the processing of personal data carried out by Sodtrack in its capacity as data processor with respect to data hosted by Sodtrack's customers (the "Customer") on the platform.

2. Roles of the Parties

The Customer acts as the data controller and determines the purposes and means of the processing of personal data.

Sodtrack acts exclusively as a data processor and processes personal data solely in accordance with the Customer's documented instructions.

3. Purpose

Sodtrack will process personal data exclusively to:

  • Provide the contracted services.
  • Maintain and operate the platform.
  • Provide technical support.
  • Resolve incidents.
  • Comply with the Customer's instructions.

Sodtrack will not use personal data for its own purposes, marketing, advertising, or to train artificial intelligence models.

4. Confidentiality

Sodtrack will ensure that personnel authorized to access personal data are subject to appropriate confidentiality obligations.

5. Security

Sodtrack will implement reasonable security measures, including:

  • Encryption in transit.
  • Encryption at rest.
  • Audit logs.
  • Backup management.
  • Environment segregation.
  • Incident response procedures.

6. Access for Support Purposes

Authorized Sodtrack personnel may access personal data hosted by the Customer when reasonably necessary to:

  • Provide technical support.
  • Resolve incidents.
  • Maintain operational continuity.
  • Comply with the Customer's instructions.

7. Subprocessors

The Customer authorizes Sodtrack to use subprocessors for the provision of the services.

Sodtrack currently uses, among others:

  • Amazon Web Services (AWS).
  • Auth0.
  • Zendesk.
  • Amazon SES.
  • Datadog.

Sodtrack maintains agreements with these providers under which they commit to maintaining appropriate levels of security and confidentiality.

8. Data Subject Requests

Sodtrack does not receive or handle requests from the Customer's users.

9. Security Incidents

Sodtrack will notify the Customer, within a reasonable time after becoming aware of it, of any security incident affecting personal data processed on the Customer's behalf.

10. Retention and Deletion

For the duration of the contractual relationship, Sodtrack will retain the personal data necessary to provide the services.

Upon termination of the services, the data will be deleted or returned to the Customer, as applicable, unless there is a legal obligation to retain it.

Backup copies may be retained for limited periods in accordance with Sodtrack's internal backup policies.

11. International Transfers

Data may be stored and processed using infrastructure located in the United States and other countries necessary for the operation of the services.