GDPR Compliance

Effective: June 1, 2026 · Last updated: June 16, 2026

SayHiGlobal is committed to the principles of the General Data Protection Regulation (GDPR). This page explains how MINGHAO is designed for GDPR compliance — not through policy alone, but through architecture.

1. Architectural GDPR Compliance

MINGHAO\'s BYOG (Bring Your Own GPU) architecture means that personal data (voice recordings, conversations) is processed entirely on your local machine. This has profound GDPR implications:

No Data Transfer: Under GDPR Article 44-49, transferring personal data outside the EU requires specific safeguards. Since MINGHAO never receives your audio data, there is no cross-border transfer of personal data by SayHiGlobal.

Data Minimization (Art. 5): We only collect minimal account data. Your voice data is not among it.

Privacy by Design (Art. 25): Local processing is built into the architecture, not added as an afterthought.

2. Data Processing Agreement (DPA)

For enterprise customers who require a formal DPA:

• Since MINGHAO does not process your personal data on our servers, our role as a data processor is limited to account management data.
• A standard DPA is available upon request for Business plan subscribers. Contact [email protected].
• If you use third-party GPU cloud services with MINGHAO, you become the data controller for that processing.

3. Your GDPR Rights

As an EU/EEA resident, you have the right to: Access, Rectification, Erasure, Restriction, Portability, and Objection regarding your account data. Email [email protected] to exercise these rights. Response within 30 days.

4. Lawful Basis for Processing

We process your account data under: Contractual Necessity (Art. 6(1)(b)) for service provision; Legitimate Interest (Art. 6(1)(f)) for anonymous analytics; Consent (Art. 6(1)(a)) for optional communications.

5. Sub-Processors

We use: Stripe (USA) for payment processing — certified under EU-US Data Privacy Framework; Hosting Provider for website and account data. No sub-processors have access to your audio/translation content because we never receive it.

6. Data Breach Notification

In the event of a data breach affecting your account data, we will notify you and the relevant supervisory authority within 72 hours, per GDPR Art. 33-34. Since we do not store your audio/translation data, a breach cannot expose your conversation content.

7. Data Protection Officer

Contact our DPO: [email protected] with subject "ATTN: Data Protection Officer". You also have the right to lodge a complaint with your local data protection authority.

8. International Data Transfers

Account data is stored on servers in the EEA or countries with an EU adequacy decision. For transfers to other countries, we implement Standard Contractual Clauses (SCCs) as required by the Schrems II ruling.