Data Protection Policy
Last updated: June 2026
1. Our Commitment
SadiGroup is committed to protecting the personal data of clients, contributors, vendors, and website visitors. This policy sets out our approach to data protection across all aspects of our AI data services operations.
2. Data Protection Principles
We adhere to the following data protection principles in all our operations:
- Lawfulness, fairness, and transparency: Data is processed lawfully, fairly, and transparently.
- Purpose limitation: Data is collected for specified, explicit, and legitimate purposes only.
- Data minimisation: We collect only the data that is necessary for the stated purpose.
- Accuracy: We take reasonable steps to ensure data is accurate and kept up to date.
- Storage limitation: Data is retained only for as long as necessary.
- Integrity and confidentiality: Data is processed securely to protect against unauthorised access or loss.
3. Client Data
Client project data is handled under strict confidentiality. All client engagements are protected by a mutual NDA. Client datasets are:
- Accessed only by authorised project team members
- Stored in secure, access-controlled environments
- Never shared with third parties without explicit written consent
- Deleted or returned to the client at project close unless otherwise agreed
4. Contributor Data
Contributor personal data collected during vendor registration and project participation is:
- Used only for project matching, payment, and communication purposes
- Anonymised where possible in project reporting
- Never sold or shared with third parties for commercial purposes
- Retained only for the duration of the contributor relationship
5. Technical Safeguards
We implement the following technical measures to protect data:
- Encryption of data in transit (TLS) and at rest
- Role-based access controls limiting data access to authorised personnel
- Audit logging of data access and modifications
- Secure file transfer protocols for data delivery
- Regular security reviews of our systems and processes
6. Data Breach Response
In the event of a data breach that poses a risk to individuals, SadiGroup will notify affected parties and relevant authorities in accordance with applicable law, including within 72 hours where required under GDPR.
7. Contact
For data protection enquiries, contact us at [email protected].
