GDPR & Data Rights Commitment
Updated: July 29, 2026. Learn how AuthSetu guarantees data privacy, processing transparency, and full compliance with the European Union General Data Protection Regulation (GDPR).
1. Data Controller vs. Data Processor Role
Under GDPR terminology:
- AuthSetu as Data Processor: For identity verification, end-user authentication, and custom tenant data, our enterprise customers act as Data Controllers while AuthSetu acts strictly as a Data Processor under a binding Data Processing Addendum (DPA).
- AuthSetu as Data Controller: For account registration, billing data, and developer developer dashboard management, AuthSetu acts as the Data Controller.
2. End-User Data Subject Rights (DSR)
AuthSetu provides self-service APIs and administrative tools to fulfill data subject rights guaranteed under GDPR Articles 15 through 22:
Right to Access & Export
Request complete json/csv data archives of stored identity credentials and audit logs via our Admin Export API.
Right to Erasure
Execute hard-delete calls to purge end-user PII and authorization records permanently across all databases.
Right to Rectification
Instantly modify email, profile attributes, and verification metadata through our Management SDK.
3. International Data Transfers & EU Standard Contractual Clauses (SCCs)
All cross-border data transfers are executed under European Commission Standard Contractual Clauses (SCCs) and robust encryption mechanisms ensuring equal levels of data protection regardless of physical server residency.
4. Data Processing Addendum (DPA) & DPO Contact
Enterprise customers can sign our Standard DPA or request custom compliance documentation. For DPO requests or formal GDPR inquiries, contact:
Data Protection Officer: dpo@authsetu.com
GDPR Desk: authsetu.com/contact