Explainer
Personal data and GDPR
STRIA is the controller for data about your users in the workspace, such as accounts, sign-in, communication and invoicing, under the Privacy Notice. When STRIA processes personal data in your systems on your behalf, you are the controller and STRIA the processor, and the Data Processing Agreement applies. Data subjects have rights including access, rectification and erasure.
Two roles
Both, in different situations. For accounts, sign-in, the customer relationship, security, communication and invoicing, STRIA decides the purposes and means and is the controller. The Privacy Notice then applies. When STRIA works in your systems and processes personal data on your behalf, you are the controller and STRIA the processor. The Data Processing Agreement then applies.
Data processed
Depending on how you use STRIA: name, work email and contact details, organisation, role and permissions, account and sign-in data, data about sessions, IP address, device and security events, messages to and from STRIA, data about requests, proposals, deliveries, access mandates and Care that can be linked to a person, invoicing and administration data, and data documenting agreements and approvals.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account, portal and customer relationship | Legitimate interest, and in some cases performance of a contract |
| Sign-in and security | Legitimate interest in information and account security |
| Requests, proposals, projects and support | Legitimate interest |
| Invoicing and accounting | Legal obligation, and legitimate interest for debt collection |
| Evidence of agreements and approvals | Legitimate interest |
| Information about STRIA's business services | Legitimate interest. You can object at any time. |
Retention
Data is kept only as long as it is needed. Account data is kept while the account or customer relationship is active and then for the time reasonably needed for wind-down, security and evidence of agreements. Accounting records are kept under bookkeeping law, normally seven years after the end of the calendar year in which the financial year ended. After that the data is deleted or anonymised.
Recipients and transfers
STRIA may share data with suppliers that process it on STRIA's behalf, for example for hosting, communication, security and invoicing, and with authorities when the law requires it. If data is made available outside the EU/EEA, a mechanism permitted under the GDPR is used, for example the European Commission's standard contractual clauses. Information about the mechanism is available on request.
This article is guidance. The General Terms and your agreement take precedence over it. General Terms