---
title: "Security at Sageo"
description: "Sageo is built so structured, auditable performance management is possible without exposing your people to unnecessary risk. Here is how we protect their data."
url: "https://sageo.ai/security"
source: "Sageo (sageo.ai)"
---


# Performance data, handled with care

_Sageo is built so structured, auditable performance management is possible without exposing your people to unnecessary risk. Here is how we protect their data._

## How Sageo protects your data

### Your data stays yours

For the employee and performance data in the platform, you are the data controller and Sageo is your processor under a Data Processing Agreement. We process it only on your documented instructions, and you can export or delete it.

### The AI never sees names

Identifying details are stripped before anything is sent to the AI. Framework generation uses only organisation-level inputs, your values, functions and levels, and development plans are written about the employee, never a named person.

### Encrypted and isolated

Data is encrypted in transit, and the platform runs on vetted cloud hosting and managed database infrastructure with tenant isolation between customers.

### Role-scoped access and an audit trail

Access is scoped by role, so people see only what their role allows. Sensitive actions, calibration changes, plan approvals and releasing results, are written to an audit trail that is not editable after the fact.

### EU-first, with safeguards for transfers

Sageo is built with the GDPR as its primary framework. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses together with additional measures.

### A small set of vetted sub-processors

We use a small, vetted set of sub-processors under appropriate data-protection terms: cloud hosting and database infrastructure, our AI provider for framework and plan generation, and an email delivery provider. A current list is available on request.

### Retention and deletion on your terms

Customer content is retained according to your instructions and is deleted or returned after your subscription ends, subject to short, documented backup cycles.

### Built for the GDPR and the EU AI Act

Privacy is part of the product design, not an afterthought. Sageo is designed around the GDPR and aligned to the EU AI Act, and is operated by Sageo SIA (Rīga, Latvia).

## Policies and documents

Read how we handle data, or request the documents your team needs for review.

- [Privacy Policy](https://sageo.ai/privacy)
- [Terms of Service](https://sageo.ai/terms)
- [Request a DPA or sub-processor list](mailto:privacy@sageo.ai?subject=DPA%20and%20sub-processor%20list)

## Report a security concern

Found a vulnerability, or have a question about how your data is handled? Email us and a person will get back to you quickly. We appreciate responsible disclosure.

Email: [privacy@sageo.ai](mailto:privacy@sageo.ai?subject=Security%20report)

_No system is perfectly secure. We work to protect your data in line with recognised industry practice, and we are honest about where we are as we grow._
