Data Processing
This page explains, in plain English, how Saedi Group LLC (“Saedi Tech”, “we”, “us”) handles personal data that we process on behalf of our business clients — for example, when we build, host, or maintain your website or app and it collects data from your customers. For how we handle your own information as a visitor or client, see our Privacy Policy.
1. Controller vs. processor
When your website or app collects data from your customers (their names, emails, orders, messages, and so on), you are the “controller” of that data — it’s yours, and you decide how it’s used. When we handle it to deliver our Services to you, we act as your “processor.” We only process that data on your documented instructions.
2. What we process and why
The categories of data depend on your project, but typically include contact details, form submissions, account information, and usage data collected by the site or app we build for you. We process it only to provide, run, maintain, secure, and support the Services you’ve engaged us for.
3. Confidentiality
We keep your data confidential. Anyone on our side with access is bound by confidentiality obligations and only accesses what they need to do their job.
4. Security
We apply reasonable technical and organizational measures appropriate to the data — such as access controls, encryption in transit, sensible credential handling, and regular backups where applicable. No system is perfectly secure, but we take protecting your data seriously and improve our practices over time.
5. Sub-processors
To deliver the Services we rely on trusted infrastructure providers (for example, hosting, database, email, and analytics vendors). We choose reputable providers, and we remain responsible to you for the parts of the work they support. We can share the current list of key providers for your project on request.
6. Data location & transfers
Your data may be stored and processed in the United States or other countries where our providers operate. Where required, we use appropriate safeguards for international transfers.
7. Your customers’ rights
If one of your customers asks to access, correct, or delete their data, that’s a request to you as the controller. We’ll assist you — within the scope of our engagement — in responding to such requests and to any regulator inquiries.
8. Data breaches
If we become aware of a security incident affecting your data, we’ll notify you without undue delay and share the information you reasonably need to meet your own obligations.
9. Retention & deletion
We keep your data only as long as needed to provide the Services or as you instruct. On the end of our engagement, we’ll return or delete the data on your request, except where we’re legally required to keep it.
10. A formal agreement
If your business needs a signed Data Processing Agreement (DPA) — for example, to meet GDPR, CCPA, or your own compliance requirements — we’re happy to enter one. This page is a summary; the signed DPA is the binding document. Request one at support@saeditech.com.

