GDPR Compliance

Last updated: January 2026

Overview

Stiamond Agents is fully compliant with the General Data Protection Regulation (GDPR, Regulation EU 2016/679). As a French company hosting data in the European Union, we process personal data in accordance with GDPR principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and accountability.

EU Data Hosting

  • All customer data is hosted in the European Union (France / Frankfurt).
  • No data is stored in the US or other non-adequate jurisdictions.
  • Database encryption at rest (AES-256).
  • TLS 1.3 encryption in transit.
  • Daily encrypted backups retained in EU data centers.

Tenant Isolation

Each customer's data is logically isolated at the application level. Every database query is scoped to the tenant ID. Cross-tenant data access is prevented at the ORM layer (TypeORM tenant scoping). API keys are tenant-scoped and hashed with bcrypt.

Data Processing Agreement (DPA)

Stiamond Agents acts as both data controller (for account data) and data processor (for end-user conversation data) under GDPR. A Data Processing Agreement is available for Enterprise customers and can be requested at privacy@stiamond.com. The DPA covers:

  • Subject matter and duration of processing.
  • Nature and purpose of processing.
  • Type of personal data and categories of data subjects.
  • Technical and organizational security measures (TOMs).
  • Sub-processor list and notification of changes.

Data Subject Rights

We facilitate the exercise of data subject rights as defined in GDPR Articles 15-22:

  • Right of access (Art. 15): full data export available in the dashboard.
  • Right to rectification (Art. 16): profile editing in the dashboard.
  • Right to erasure (Art. 17): account deletion removes all associated data within 30 days.
  • Right to data portability (Art. 20): JSON export of all conversations, leads, and analytics.
  • Right to object (Art. 21): opt-out of marketing communications at any time.

Sub-Processors

ProcessorPurposeLocation
StripePayment processingEU + US (SCCs)
SendGridTransactional emailEU + US (SCCs)
TwilioSMS delivery (optional)EU + US (SCCs)
Cloud hostingApplication & database hostingEU (Frankfurt)

Breach Notification

In the event of a personal data breach, Stiamond Agents will notify affected customers within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Notifications will include the nature of the breach, likely consequences, and measures taken.

Supervisory Authority

Stiamond Agents SAS is subject to the jurisdiction of the CNIL (Commission Nationale de l'Informatique et des Libertés), the French data protection authority. Complaints can be filed with the CNIL at www.cnil.fr.

Contact

For GDPR inquiries, DPA requests, or data subject rights: privacy@stiamond.com