Legal
GDPR compliance
ASoc is built to help you meet your obligations under the GDPR, whether you're a controller or a processor.
Last updated June 1, 2026
Lawful basis
We process personal data to perform our contract with you and on the basis of legitimate interests in running and improving the service.
Data processing agreement
We offer a DPA to all customers. It's available on request at privacy@asoc.io and forms part of our terms for business accounts.
Sub-processors
We maintain a current list of sub-processors and notify customers before adding a new one, so you have time to object.
Data subject requests
We help you respond to access, correction, and deletion requests within the timelines the regulation requires.
Transfers
Where data leaves the EEA, we rely on standard contractual clauses and appropriate safeguards.