Regulatory Compliance

GDPR & Data Rights Commitment

Updated: July 29, 2026. Learn how AuthSetu guarantees data privacy, processing transparency, and full compliance with the European Union General Data Protection Regulation (GDPR).

1. Data Controller vs. Data Processor Role

Under GDPR terminology:

  • AuthSetu as Data Processor: For identity verification, end-user authentication, and custom tenant data, our enterprise customers act as Data Controllers while AuthSetu acts strictly as a Data Processor under a binding Data Processing Addendum (DPA).
  • AuthSetu as Data Controller: For account registration, billing data, and developer developer dashboard management, AuthSetu acts as the Data Controller.

2. End-User Data Subject Rights (DSR)

AuthSetu provides self-service APIs and administrative tools to fulfill data subject rights guaranteed under GDPR Articles 15 through 22:

Right to Access & Export

Request complete json/csv data archives of stored identity credentials and audit logs via our Admin Export API.

Right to Erasure

Execute hard-delete calls to purge end-user PII and authorization records permanently across all databases.

Right to Rectification

Instantly modify email, profile attributes, and verification metadata through our Management SDK.

3. International Data Transfers & EU Standard Contractual Clauses (SCCs)

All cross-border data transfers are executed under European Commission Standard Contractual Clauses (SCCs) and robust encryption mechanisms ensuring equal levels of data protection regardless of physical server residency.

4. Data Processing Addendum (DPA) & DPO Contact

Enterprise customers can sign our Standard DPA or request custom compliance documentation. For DPO requests or formal GDPR inquiries, contact:

Data Protection Officer: dpo@authsetu.com

GDPR Desk: authsetu.com/contact