🌱 Responsible Growth

Security & Governance Statement

Persooa Enterprise Security & Governance Statement - data protection, GDPR compliance, access management, security awareness, vendor governance and incident management.

Last updated: 2026-06-19

Persooa Enterprise Security & Governance Statement 2026 Version 2026.1


Context and role

Persooa acts as an implementation and managed-services partner in the Synerise ecosystem. In the relationship with the customer, we usually act as a processor, operating on the documented instructions of the data controller (the customer). End-customer data is generally stored and processed in the customer's infrastructure or on the Synerise platform, in accordance with the project architecture.


FieldValue
Full namePersooa Sp. z o.o.
Registered officeul. Rondo ONZ 1, 00-124 Warsaw, Poland
KRS0000338740 (District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register)
NIP7010202996
Share capitalPLN 30,000.00, fully paid up
Operating modelremote-first; global delivery, without maintaining dedicated office space for project teams

Persooa has a formal registered office in Warsaw and delivers its services in a remote-first model. We confirm the full scope of registration details as part of due diligence and in contracts.


Data protection

  • Encryption of data using the data-protection mechanisms provided by the Synerise platform and cloud providers (in transit and at rest).
  • Environment segregation - separation of development, test and production environments.
  • Minimization - we process only the data necessary to deliver the service; we prefer pseudonymization and aggregation.
  • Retention - data is stored only for the period necessary and agreed with the customer.

GDPR compliance and DPA readiness

  • As a rule, we act as a processor on the customer's documented instructions. With respect to our own operational data (B2B contact data, HR data, our own logs) we are a controller. We establish our role with respect to the platform and further entities in the DPA for a given deployment.
  • Sub-processors - we maintain an up-to-date list made available as part of the DPA. We inform of significant changes in advance, allowing a reasoned objection to be raised. We impose on every sub-processor obligations no less stringent than our own; we are liable for confidentiality maintained by further subcontractors as for our own actions (flow-down).
  • DSAR - we support the customer in fulfilling the rights of data subjects, in accordance with Article 28(3)(e) of the GDPR; we handle requests within an agreed SLA (as a rule 5-10 business days) so that the customer meets the statutory one-month deadline.
  • Return / deletion of data - after the engagement ends, at the customer's choice, we return the data in a machine-readable format or delete it (together with copies), and on request we issue a written confirmation of deletion (Article 28(3)(g) of the GDPR).
  • Register and audit - we maintain a record of categories of processing activities (Article 30(2) of the GDPR) and, on the terms of the DPA, we enable the customer to audit or inspect (Article 28(3)(h) of the GDPR).
  • Transfers - by default we prefer processing in the EU/EEA; for transfers outside the EEA we apply standard contractual clauses (SCC), a transfer impact assessment (TIA) and - if necessary - supplementary measures.

Access management

  • Least privilege principle - access only to the extent necessary for the role.
  • Need-to-know - only people involved in a specific customer's project have access to that customer's data.
  • Multi-factor authentication (MFA) for access to critical systems.
  • Access reviews and the immediate revocation of access upon the end of the engagement (offboarding).
  • Use of the customer's systems takes place on the accounts and terms defined by the customer.

Security awareness

  • The team is required to observe security and data-protection rules.
  • We run activities that build awareness of threats (phishing, social engineering, password hygiene, device security).
  • In the remote-first model, we apply secure remote-work rules: secured devices, password managers, disk encryption.

Vendor governance

  • We select subcontractors and tools taking into account their security and data-protection practices, preferring providers with recognized certifications.
  • We base delivery on the Synerise platform and on recognized cloud providers; we keep the supplier chain as short and transparent for the customer as possible.
  • Confidentiality chain (flow-down) - every subcontractor commits to confidentiality before the collaboration begins, and this obligation continues after it ends. We are liable for confidentiality maintained by further contractors and subcontractors as for our own actions.
  • Counterparty integrity - in higher-risk processes we apply integrity checks in accordance with our Anti-Corruption and Anti-Fraud Policy (including the Transparency International index, PEP links, verification of final convictions of people in the counterparty's bodies for economic or fiscal-criminal offences).
  • Conflict of interest - supplier selection is assessed for conflicts of interest; we exclude situations in which the choice would bring an undue benefit to a decision-maker, and we keep relationships transparent for the customer.

Security of the Synerise platform

Persooa deploys and runs solutions on the Synerise platform, which the end-customer data usually concerns. According to Synerise's official statement (synerise.com/security), the platform provides enterprise-grade security together with SOC 2, GDPR and CCPA compliance, and describes its security architecture, data protection and deployment options.

  • This means that the security and compliance foundation of the data-processing layer is provided and independently audited at the platform level (SOC 2).
  • Persooa is responsible for the secure configuration and operation of this platform within the customer's project - in accordance with the principles described in this statement.
  • We confirm the current, detailed scope of Synerise's certifications and deployment options directly on the vendor's website and in the documentation for the customer.

Division of roles: Synerise is responsible for platform certification; Persooa, as the partner, for the security of the deployment, access and operations; the customer for the role of data controller.


Protection of confidential information and trade secrets

Independently of the security of the Synerise platform, Persooa maintains a formalized Trade Secret Protection System (SOT), based on the internal Confidential Information Protection Policy (compliant with the Act on Combating Unfair Competition, UZNK):

  • Four SOT principles - confidentiality, access minimization, proportionality of measures, and accountability for violations.
  • Information classification - the "Basic" category (all confidential information) and "Restricted" (information of strategic significance), with proportionately selected technical and organizational measures.
  • Responsible person - appointed by the Management Board, conducts periodic audits of the application of the policy and keeps an incident log.
  • Scope of protection - we protect not only the personal data of end customers but also the confidential information and trade secrets of the customer itself (terms of cooperation, know-how, commercial data, plans). Information is protected at every stage of development, transmission and storage; uncontrolled copying and unnecessary printing are prohibited.
  • Persooa's own measures - disk encryption of team devices, secure document-exchange channels, password managers and MFA, adequate and proportionate to the information category.
  • Durability of the obligation - the confidentiality obligation binds employees and contractors during the collaboration and for the period agreed contractually after it ends.

Incident management

We base our incident-response process for confidential-information incidents on the internal Confidential Information Protection Policy, which defines a formalized Trade Secret Protection System (SOT):

  • A designated Responsible person (appointed by the Management Board), together with management, verifies the report, its nature and its scale.
  • Risk-level classification according to a matrix: the information category (Basic / Restricted) against the scale of the leak (small / medium / large) yields a low / medium / high level.
  • Actions proportionate to the risk level - from securing the consequences and changing technical/organizational measures, through an order to cease the violation and additional training, to legal action.
  • An incident-response report and an incident log provide an audit trail, root-cause analysis and preventive recommendations.
  • In the event of an incident concerning customer data, we inform the customer without undue delay (as a rule within 24-48 hours of confirming the incident), providing the scope, nature and preliminary risk assessment, so that the customer, as controller, can meet their own notification deadlines (including the 72h under Article 33 of the GDPR). The binding deadline and notification format are set out in the DPA/SLA.

Business continuity

  • The remote-first and cloud-first model increases operational resilience (no single point of physical office failure).
  • Artifacts and documentation are versioned and copied in secure cloud environments.
  • We rely on the high-availability and backup mechanisms provided by the cloud platforms and Synerise.

Readiness for security questionnaires

Persooa is prepared to support supplier assessment and a security review on the customer's side:

  • completing security questionnaires (e.g. SIG, CAIQ, the customer's own questionnaires),
  • signing a DPA, NDA and relevant security clauses,
  • participating in supplier due diligence.

Document owner: Persooa Management Board / person responsible for security. Review: annual. Version: 2026.1. This document describes operational practices; specific and binding commitments are governed by the agreements with customers (including the DPA and SLA).

Get started

Grow in a way that makes sense.

Book a free call - we will show how to build growth responsibly: on first-party data, with privacy in mind and outcomes proven, not promised.