Legal

Data Processing Agreement

This Data Processing Agreement forms part of the SvereSystems Terms & Conditions or another applicable service agreement. It applies only where SvereSystems processes personal data on a customer's behalf as a processor under the EU General Data Protection Regulation.

Last updated: 29 June 2026 SvereSystems · Sveresa Tmi · Finland Article 28 GDPR · Processor terms where applicable

1. Parties and scope

This DPA is between:

  • the customer that has entered into the SvereSystems Terms & Conditions, order, or other relevant service agreement (“Controller” or “Customer”); and
  • Sveresa Tmi, Business ID / Y-tunnus 3592316-3, Finland, operating under the brand SvereSystems (“Processor” where this DPA applies).

This DPA forms part of the applicable Terms & Conditions, order, or service agreement (the “Main Agreement”). If there is a conflict between this DPA and the Main Agreement regarding the processing of personal data on behalf of the Customer, this DPA will prevail to the extent of that conflict.

Whether SvereSystems acts as a processor depends on the actual processing. SvereSystems acts as an independent controller for its own website, Fit Check submissions, sales enquiries, checkout and payment records, email subscriptions, service administration, direct client communication, accounting, and legal compliance. Those activities are outside this DPA and are described in the SvereSystems Privacy Notice.

Important scope note: this DPA applies only where a customer asks SvereSystems to handle personal data as part of the agreed service on that customer's behalf. It does not apply merely because someone submits an enquiry, completes a Fit Check, makes a purchase, or joins a SvereSystems email list.

2. Subject matter and duration

This DPA covers personal data that SvereSystems processes on the Customer's behalf where needed to prepare, deliver, or support an agreed written review service. This may include service intake processing, review of submitted material, internal draft preparation, and delivery of the agreed written service.

Fit Check submissions, general enquiries, checkout activity, payment administration, and direct sales communication are handled by SvereSystems as controller and are not processor activities under this DPA.

This DPA applies for as long as SvereSystems processes Customer Personal Data on the Customer's behalf and continues to apply to the post-service obligations described here.

3. Nature and purpose of processing

SvereSystems processes Customer Personal Data only to provide, maintain, secure, document, and support the agreed service, and to follow the Customer's documented instructions for the processing covered by this DPA. Processing may include:

  • receiving and organising service intake material;
  • reviewing customer-provided business, outreach, follow-up, reply-handling, or client-acquisition material;
  • preparing internal working notes or AI-assisted internal drafts;
  • creating and delivering written review documents or related service responses;
  • communicating with the Customer about the agreed service; and
  • maintaining security, access controls, logs, and limited operational records related to the processor activity.

The service does not include lead sourcing, done-for-you outreach, campaign sending, campaign management, CRM setup, technical implementation, ads management, SEO work, or full funnel buildout unless separately and explicitly agreed in writing.

4. Categories of data and data subjects

The personal data processed on behalf of the Customer may include, depending on what the Customer submits:

  • business contact information, such as names, business email addresses, roles, company names, websites, or business pages;
  • business context and client-acquisition information submitted through forms or email;
  • outreach messages, follow-up examples, reply-handling examples, communication snippets, and related notes;
  • First Contact Fix-specific material, such as one current first outreach message, one follow-up message, target-buyer context, qualification criteria, reply examples, constraints, and supporting links;
  • limited information about the Customer's prospects, leads, clients, or target-client roles where included in submitted material;
  • service-processing metadata, such as submission timestamps, internal status notes, and delivery records; and
  • technical and security metadata necessary to operate the client-service workflow.

The categories of data subjects may include:

  • the Customer's owners, staff, contractors, or representatives;
  • the Customer's prospects, leads, customers, or business contacts where their information is included in submitted material;
  • other individuals whose personal data is provided by or on behalf of the Customer for the agreed service.

The service is not intended for processing special categories of personal data under Article 9 GDPR, data relating to criminal convictions, passwords, access credentials, private login details, confidential credentials, or unnecessary sensitive information. The Customer must not intentionally submit such data.

5. Customer obligations

The Customer is responsible for:

  • ensuring that it has a valid legal basis for any personal data submitted to SvereSystems;
  • providing required privacy notices to relevant data subjects where necessary;
  • ensuring that all instructions to SvereSystems are lawful and consistent with the Main Agreement and this DPA;
  • submitting only information necessary for the requested service;
  • removing or anonymising unnecessary personal data before submission where practical;
  • not submitting passwords, access credentials, special-category data, criminal offence data, or other unnecessary sensitive information;
  • using SvereSystems' service outputs in a lawful and privacy-compliant manner.

6. Processor obligations

SvereSystems shall:

  • process personal data only on documented instructions from the Customer, unless required by EU or Member State law;
  • maintain confidentiality and ensure that persons authorised to process personal data are subject to confidentiality obligations;
  • use appropriate technical and organisational measures to protect personal data, taking into account the nature and risk of the processing;
  • assist the Customer, insofar as reasonably possible, with data subject requests and GDPR Articles 32 to 36 obligations, taking into account the nature of the service;
  • inform the Customer if, in SvereSystems' opinion, an instruction infringes applicable data protection law;
  • keep required records of processing activities where required by law;
  • avoid unnecessary data handling and use data minimisation in internal workflows where practical.

7. AI-assisted processing

Where needed for the agreed service, SvereSystems may use AI-assisted drafting tools to organise Customer Personal Data and prepare internal working drafts. AI-assisted outputs are internal working material only and are not sent directly to the Customer without SvereSystems review.

SvereSystems applies data minimisation when using AI-assisted tools. Where practical, unnecessary personal data such as email addresses, personal names, payment context, or unrelated identifying details are not included in AI prompts. The Customer should not submit sensitive information or credentials in any service intake.

Final client-facing responses and written review documents are checked, edited, and approved by SvereSystems before delivery. The service does not rely on solely automated decision-making that produces legal or similarly significant effects for the Customer.

8. Sub-processors

The Customer gives SvereSystems a general written authorisation to use sub-processors where reasonably necessary for the processor activity covered by this DPA. Relevant sub-processors may provide:

  • website and form infrastructure used for service intake;
  • workflow automation;
  • cloud storage, spreadsheets, and internal records;
  • email and communication infrastructure used for the agreed service; and
  • AI-assisted drafting and analysis tools.

Depending on the active client-service workflow, current provider categories may include ClickSites, Make.com, Google Workspace services, Private Email, and OpenAI API. Payhip, Stripe, and MailerLite are not listed here because they are used for SvereSystems' own checkout, payment, or email-list activities as controller, rather than as sub-processors of Customer Personal Data under this DPA.

SvereSystems shall:

  • use sub-processors only where reasonably necessary for the service;
  • take reasonable steps to ensure sub-processors are subject to appropriate data protection obligations;
  • remain responsible for sub-processor performance to the extent required by applicable law and the Main Agreement; and
  • make information about relevant sub-processor categories reasonably available upon request.

Before adding or replacing a material sub-processor expected to process Customer Personal Data under this DPA, SvereSystems will give active Customers reasonable prior notice by email or other written electronic notice. The Customer may object in writing on reasonable data-protection grounds. The parties will work in good faith to find a practical solution. If no practical solution is available and the sub-processor is necessary, either party may end the affected processing before the change takes effect, subject to the Main Agreement.

9. International transfers

Some sub-processors may process personal data outside the European Economic Area (“EEA”) or use infrastructure that involves international transfers.

Where personal data is transferred to a country that does not benefit from an adequacy decision, SvereSystems will aim to rely on appropriate transfer safeguards where required, such as Standard Contractual Clauses, an applicable adequacy framework, or another lawful transfer mechanism available under Chapter V GDPR.

Details may depend on the relevant provider, account configuration, and service used at the time of processing.

10. Security measures

SvereSystems shall implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the nature, scope, context, purpose, and risk of the processing.

Such measures may include, as appropriate:

  • encrypted connections for data in transit where supported by the relevant provider;
  • limited access to workflow automation, spreadsheet, email, storage, and AI-provider accounts used in client-service workflows;
  • strong passwords and multi-factor authentication where available;
  • least-privilege access and avoidance of public sharing links for client records;
  • separation of test and live data where practical;
  • retention and deletion practices for test submissions, internal drafts, and completed service files;
  • incident review and corrective action where a security issue is identified.

The Customer remains responsible for the security of its own systems, accounts, submitted materials, and use of any service outputs.

11. Data subject requests

If SvereSystems receives a data subject request relating to personal data processed on behalf of the Customer, SvereSystems will, where reasonably possible and appropriate:

  • advise the requester to contact the Customer directly; and/or
  • notify the Customer and provide reasonable assistance for the Customer's response.

The Customer is responsible for handling and responding to data subject requests where the Customer is the controller, including rights of access, rectification, erasure, restriction, portability, and objection.

12. Personal data breaches

If SvereSystems becomes aware of a personal data breach affecting personal data processed on behalf of the Customer, SvereSystems shall notify the Customer without undue delay and provide information reasonably available to SvereSystems that the Customer may need to assess and meet its legal obligations.

SvereSystems will take reasonable steps to mitigate the effects of the breach and support required notifications, taking into account the nature of the processing, the information available, and the relevant sub-processor involvement.

13. Compliance information

Upon reasonable written request and subject to confidentiality, SvereSystems shall make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. This may include:

  • this DPA and related privacy documentation;
  • summaries of relevant security and organisational measures;
  • information about provider categories and relevant data flows;
  • responses to reasonable privacy or security questions proportionate to the service.

On-site audits are not normally appropriate for a small asynchronous written service. If legally required and not satisfied by available documentation, any audit must be limited, proportionate, subject to confidentiality, at the Customer's cost, and arranged to avoid unreasonable disruption or exposure of other customers' information.

14. Return and deletion of personal data

After completion or termination of the relevant service, SvereSystems will, at the Customer's choice and upon reasonable written request, return or delete Customer Personal Data processed under this DPA and delete existing processor copies, unless Union or Member State law requires storage.

This does not prevent SvereSystems from keeping separate records that it holds as an independent controller, such as its own contract, invoice, payment, correspondence, accounting, or legal-compliance records. Those records are governed by the Privacy Notice, not by this DPA.

Unless otherwise agreed, limited copies may remain temporarily in backups or provider logs until overwritten through normal technical retention cycles.

Practical rule: SvereSystems aims to avoid indefinite retention of unnecessary processor data, internal draft material, spreadsheet rows, and completed working files.

15. Liability and hierarchy

The limitations of liability, exclusions, and remedies in the Main Agreement apply to this DPA, subject to any mandatory provisions of applicable law.

If documents conflict, the following order applies for data protection matters:

  • this DPA;
  • the Main Agreement or Terms & Conditions;
  • other related service documents, unless expressly agreed otherwise in writing.

16. Governing law and contact

This DPA is governed by the laws of Finland, without regard to conflict-of-laws rules. Disputes relating to this DPA shall be handled according to the dispute-resolution provisions in the Main Agreement, unless mandatory law requires otherwise.

For DPA, privacy, or data-protection questions, please contact SvereSystems using the contact details shown in the footer of this page.

SvereSystems – Privacy & Legal
Operated by Sveresa Tmi
Business ID / Y-tunnus: 3592316-3
Finland

Appendix 1 — Processing details

Subject matter: Processing of Customer-provided personal data where needed for an agreed Client Acquisition Review, First Contact Fix, or another agreed written review service, including service-intake processing, internal working-draft preparation, written delivery, and related support.

Duration: For the period needed to provide the service and then for any limited processor retention required by Union or Member State law, or until return or deletion under Section 14.

Nature and purpose: Receipt, organisation, review, storage, internal analysis, AI-assisted internal draft preparation, manual editing, delivery, communication, security, and limited processor record-keeping.

Types of personal data: Business contact data supplied by the Customer as part of the service, business context, websites or business pages, submitted service-intake answers, outreach/follow-up examples, reply-handling examples, First Contact Fix message material, prospect/client references included by the Customer, communication metadata, internal working notes, AI-assisted draft material, and final written delivery files.

Categories of data subjects: Customer representatives; Customer staff or contractors; Customer prospects, leads, clients, or business contacts included in submitted material; other individuals included by the Customer in the service material.

Special categories: Not intended. The Customer must not intentionally submit special-category data, criminal offence data, passwords, access credentials, or unnecessary sensitive information.

Appendix 2 — Security measures

SvereSystems maintains proportionate technical and organisational measures for a small asynchronous B2B written service. These may include:

  • use of reputable service providers for hosting, automation, storage, email, payment, and AI-assisted internal drafting;
  • HTTPS/TLS in transit where supported by the relevant platform;
  • restricted access to workflow automation, spreadsheets, email, storage, and AI-provider accounts used for client-service work;
  • multi-factor authentication where available;
  • data minimisation in AI prompts and internal working materials;
  • avoidance of unnecessary passwords, credentials, and sensitive data in forms;
  • private spreadsheet/storage settings and avoidance of public sharing links;
  • manual review before any client-facing delivery;
  • periodic cleanup of test data, abandoned submissions, internal draft emails, and outdated working files where practical;
  • incident response and corrective action if a data-security issue is identified.
Security measures may evolve over time. SvereSystems will aim to keep measures appropriate to the nature and risk of the processing and aligned with GDPR Article 32.