Our commitment to GDPR and data protection regulations
Last updated: July 8, 2026
Last Updated: July 8, 2026
Effective Date: January 15, 2026
This document outlines how SnowCoder complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and related data protection laws. It is intended for customers, particularly those in the European Union (EU), European Economic Area (EEA), and United Kingdom (UK).
SnowCoder is committed to:
This guide covers:
SnowCoder is the Data Controller for:
Legal Bases for Controller Processing:
| Purpose | Legal Basis |
|---|---|
| Account management | Contractual necessity |
| Billing and payments | Contractual necessity |
| Service communications | Legitimate interest |
| Security and fraud prevention | Legitimate interest |
| Marketing | Consent |
| Legal compliance | Legal obligation |
SnowCoder is the Data Processor when processing:
When acting as Processor, we process data only according to customer instructions as documented in our Data Processing Agreement.
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Name, username | Account management |
| Contact Data | Email address | Communications |
| Technical Data | IP address, browser info | Security, analytics |
| Usage Data | Feature usage, logs | Service improvement |
| Financial Data | Payment info (via Stripe) | Billing |
| Content Data | Code, conversations | Service delivery |
We do not intentionally collect special category data (sensitive personal data). If you submit such data, you do so at your own risk and should ensure you have a lawful basis.
We process data necessary to:
We process data based on legitimate interests for:
Balancing Test: We have conducted legitimate interest assessments ensuring our interests do not override your fundamental rights and freedoms.
We obtain consent for:
We process data to comply with:
You have the right to:
How to Exercise:
You have the right to:
How to Exercise:
You have the right to request deletion when:
Exceptions: We may retain data where required by law or for legal claims.
How to Exercise:
You have the right to restrict processing when:
You have the right to:
Scope: Applies to data you provided, processed by automated means, based on consent or contract.
Format: JSON or CSV export available.
You have the right to object to:
How to Exercise:
You have the right to:
Our Practice: We do not make significant automated decisions affecting your legal rights without human oversight.
Where processing is based on consent, you may withdraw at any time:
Email: privacy@snowcoder.ai
Required Information:
To protect your data, we may need to verify your identity:
| Request Type | Initial Response | Maximum Time |
|---|---|---|
| Standard requests | 30 days | 30 days |
| Complex requests | 30 days | 90 days (with notice) |
| Manifestly unfounded | May refuse | With explanation |
We do not charge for reasonable requests. We may charge a reasonable fee for:
If unsatisfied with our response, you may:
We transfer data outside the EEA using:
| Recipient | Country | Transfer Mechanism |
|---|---|---|
| AWS | UK (London, eu-west-2) | UK data residency; EEA→UK transfers covered by the EU adequacy decision for the UK |
| Anthropic (LLM inference, standard tier) | US | SCCs + Supplementary Measures |
| OpenAI (embeddings, standard tier) | US | SCCs |
| Google (transactional email) | US / global | SCCs |
| AWS Bedrock (in-region AI – Enterprise+ dedicated, provisioned per engagement) | Customer-nominated region (e.g. EU) | In-region processing (no cross-border transfer) |
| Stripe | US | SCCs |
| Cloudflare | Global | SCCs |
| Xero (billing) | Australia / New Zealand | SCCs / adequacy (New Zealand) |
| Telegram (operational error alerts) | Global | SCCs |
| UptimeRobot (uptime monitoring) | US | SCCs |
Note: For Enterprise+ dedicated deployments we can provision in-region AI via AWS Bedrock as part of the engagement, so AI prompts/responses are processed in the customer-nominated region rather than crossing borders. This is delivered per engagement and is not the standard-tier configuration – the standard (shared) tier processes AI via Anthropic in the US under SCCs.
We implement supplementary measures including:
Following the Schrems II decision, we have:
In-region AI option (Enterprise+): For Enterprise+ dedicated deployments we can provision AI inference in-region via AWS Bedrock as part of the engagement, avoiding cross-border AI transfers for that deployment. This is delivered per engagement; the standard (shared) tier processes AI via Anthropic in the US under SCCs.
See our Security Assurance Pack for detailed security documentation.
| Data Type | Retention Period | Basis |
|---|---|---|
| Account data | Account lifetime + 30 days | Contractual |
| Billing records | 7 years | Legal obligation |
| Access logs | 90 days | Legitimate interest |
| Conversations | Until user deletion, or within 30 days of account termination | Contractual |
| Marketing preferences | Until withdrawal | Consent |
When data is deleted:
We implement GDPR Article 25 through:
We conduct Data Protection Impact Assessments (DPIAs) for:
We maintain a current list of sub-processors on our Sub-processors page and in the Sub-processors section of our Data Processing Agreement.
All sub-processors must:
Email: dpo@snowcoder.ai
The DPO is available to:
Email: privacy@snowcoder.ai
Response Time: 10 business days
If you are in the EU/EEA, you may contact your local Data Protection Authority. A list is available at: https://edpb.europa.eu/about-edpb/board/members_en
As a UK-established data processor, our supervisory authority is the UK Information Commissioner’s Office (ICO):
We update this guide to reflect:
Material updates will be communicated via email.
Document Status: Production Ready Classification: Customer-Facing Review Cycle: Annual