Legal Policy

GDPR Compliance

GDPR Compliance Statement

Effective Date: July 2026

SOVEVO is fully committed to compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws. This statement outlines our approach to data protection, privacy rights, and regulatory compliance.

1. Our Commitment to Data Protection

SOVEVO is an EU Hub operator, with data processing governed by GDPR and carried out through reputable third-party infrastructure providers under appropriate data protection safeguards. We have designed our platform from the ground up with data protection as a structural principle, not an afterthought. Every layer of the platform, from authentication to storage to communication, is designed for GDPR compliance.

Key Commitment: Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses or other safeguards recognized by the European Commission. We do not sell, license, or share personal data with third parties for commercial purposes. We do not engage in mass surveillance or behavioral tracking.

2. Legal Basis for Processing

We process personal data only when we have a lawful basis under GDPR Article 6, specifically:

  • Performance of a Contract (Article 6(1)(b)): Processing necessary to provide you with SOVEVO services, including account creation, transaction processing, and service delivery.
  • Legal Obligation (Article 6(1)(c)): Processing required by law, including tax reporting, financial services compliance (if applicable), and law enforcement requests.
  • Legitimate Interests (Article 6(1)(f)): Processing for fraud prevention, security monitoring, platform improvement, and communication about service updates, only when your interests do not override ours.
  • Consent (Article 6(1)(a)): Processing (such as marketing communications) only with your explicit, freely given, specific, and informed consent, which you may withdraw at any time.

We balance data minimization with necessity: we collect only the personal data required to deliver our services and fulfill your requests.

3. Your Rights Under GDPR

You have the following rights, which SOVEVO fully respects and supports:

3.1 Right of Access (Article 15)

You have the right to request a copy of all personal data we hold about you, including the sources of that data, the purposes of processing, and the recipients. We will provide this information within 30 days in a clear, structured format.

3.2 Right of Rectification (Article 16)

If personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it. We will make corrections within 30 days and inform relevant recipients if necessary.

3.3 Right to Erasure / "Right to Be Forgotten" (Article 17)

You have the right to request that we delete your personal data, except where processing is required by law (tax, financial, or law enforcement purposes). Upon deletion, we will purge all copies within 30 days and inform sub-processors. Tax and compliance records are retained for the period required by law, then securely destroyed.

3.4 Right to Restrict Processing (Article 18)

You can request that we suspend or limit processing of your data while we verify accuracy or pending your decision on deletion. During restriction, we will store your data but not actively process it, except to maintain security or fulfill legal obligations.

3.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON) and to transmit that data to another service provider without hindrance from us. We will provide this within 30 days upon request.

3.6 Right to Object (Article 21)

You have the right to object to processing for legitimate interests (including direct marketing and profiling). We will cease processing within 30 days, except where we have compelling reasons to continue that override your interests. You can object at any time.

3.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to fully automated decision-making that produces legal or similarly significant effects. SOVEVO does not engage in algorithmic profiling or automated decisions about access to our services; all access decisions are reviewed by a real person.

4. Processing Activities and Transparency

We process personal data for the following purposes:

Data CategoryPurposeLawful BasisRetention
Name, email, contact infoAccount creation, service delivery, communicationContract performanceDuration of service + 30 days
Authentication data (passwords, 2FA)Account security, access controlContract, legitimate interestDuration of account
Usage logs and IP addressesSecurity, fraud detection, platform improvementLegitimate interest90 days (aggregated indefinitely)
Financial data (for invoicing)Billing, tax compliance, accountingContract, legal obligation7 years (tax retention requirement)
Voluntary profile informationCommunity interaction, personalizationConsent, contractUntil deletion or account closure
Communication recordsSupport, service updates, complianceContract, legal obligation3 years (compliance retention)

5. Data Security and Protection Measures

SOVEVO implements comprehensive technical and organizational safeguards:

Technical Measures

  • End-to-end encryption for sensitive data in transit (TLS 1.2 or higher)
  • AES-256 encryption for data at rest in secure, isolated databases
  • Regular security patching and vulnerability assessments
  • Intrusion detection and prevention systems
  • DDoS protection and rate-limiting
  • Database access logging and audit trails

Organizational Measures

  • Role-based access control (RBAC) with principle of least privilege
  • Employee data protection training and confidentiality agreements
  • Vendor and sub-processor agreements imposing equivalent data protection obligations
  • Incident response procedures and breach notification protocols
  • Regular third-party security audits and penetration testing
  • ISO 27001 certification and compliance verification

6. Data Breach Notification

In the event of a personal data breach, SOVEVO will notify you and affected individuals without undue delay, and in any case within 72 hours of discovery. Notification will include:

  • Nature and scope of the breach
  • Categories and approximate number of affected individuals
  • Likely consequences and steps taken to mitigate
  • Contact information for our Data Protection Officer

You can report suspected breaches to our DPO at dpo@sovevo.eu at any time.

7. Sub-Processors and Third-Party Services

SOVEVO uses only essential third-party services and holds all sub-processors to the same GDPR standards as ourselves:

Current Sub-Processors

  • Cloud Infrastructure (Amazon Web Services): Compute, storage, and networking services, processed under appropriate data protection safeguards in compliance with GDPR.
  • Database Services (AWS RDS/Aurora): Managed relational database services with encryption at rest and multi-AZ redundancy.
  • Email Delivery (Postmark/SendGrid): Transactional email only, processed under appropriate data protection safeguards; no marketing email sharing.
  • Analytics (Plausible): Privacy-focused, cookieless analytics without personal data sharing.
  • CDN/DDoS Protection (AWS CloudFront): Global content delivery network; cache only, no personal data storage.

A complete, updated list is maintained at https://sovevo.eu/sub-processors. We notify you of changes 30 days in advance and provide an opportunity to object.

8. Data Location and International Transfers

SOVEVO is headquartered in Rovinj, Croatia, within the European Union. Where personal data is processed by infrastructure providers located outside the EEA, we implement Standard Contractual Clauses (SCCs) or other appropriate safeguards. We never rely on Privacy Shield or other mechanisms that have been invalidated by regulators.

9. Children's Data (GDPR Article 8)

SOVEVO does not knowingly collect or process personal data from children under 16 years of age. If we become aware that a child's data has been collected without proper parental consent, we will delete it immediately. Our services are not directed to children.

10. Exercising Your Rights

To exercise any GDPR rights, submit a written request to:

Data Protection Officer
SOVEVO
Rovinj, Croatia
Email: dpo@sovevo.eu

We will acknowledge your request within 5 business days and respond fully within 30 days (extendable by 60 days for complex requests). Requests are fulfilled free of charge, unless manifestly unfounded or excessive, in which case we will inform you of our reasoning.

11. Data Protection Impact Assessments (DPIA)

For high-risk processing activities, SOVEVO conducts and maintains Data Protection Impact Assessments. We are happy to provide relevant excerpts from our DPIAs to help you comply with your own GDPR obligations.

12. Privacy by Design and Default

SOVEVO has embedded data protection principles into its infrastructure and organizational processes:

  • Minimal data collection: we collect only what is necessary
  • Automated pseudonymization: where possible, we separate personal data from identifiers
  • Data retention limits: we delete data once it is no longer needed
  • No profiling or behavioral tracking: we do not build consumer profiles or track behavior across services
  • No cross-border transfers without appropriate safeguards in place

13. Regulatory Compliance and Oversight

SOVEVO is subject to oversight by European data protection authorities, including:

  • Croatian Data Protection Authority (AZOP): Primary regulator of SOVEVO's compliance
  • EU Data Protection Board (EDPB): For guidance on GDPR interpretation and enforcement
  • National Data Protection Authorities of Member States: For complaints from individuals in their jurisdictions

14. Your Right to Lodge Complaints

If you believe SOVEVO has violated your GDPR rights, you have the right to lodge a complaint with your local data protection authority. You do not need to contact us first; however, we welcome the opportunity to resolve concerns directly.

Croatian Data Protection Authority (AZOP):
Selska cesta 130, 10000 Zagreb
Email: info@azop.hr
Phone: +385 1 5205 800

15. Changes to This Policy

SOVEVO may update this GDPR Compliance Statement to reflect changes in law, regulation, or our practices. We will notify you of material changes and provide a 30-day notice period before implementation. Continued use of SOVEVO constitutes acceptance of updated terms.

16. Contact Information

  • Data Protection Officer: dpo@sovevo.eu
  • Legal Inquiries: legal@sovevo.eu
  • General Contact: hello@sovevo.eu
  • Address: SOVEVO, Rovinj, Croatia

This GDPR Compliance Statement reflects SOVEVO's commitment to the highest standards of data protection. We recognize that trust is built on transparency and accountability. If you have questions or concerns, please do not hesitate to contact our Data Protection Officer.