1. Parties, definitions and scope
Processor where this DPA applies:
Sveresa Tmi, trading as SvereSystems
Business ID: 3592316-3
VAT ID: FI35923163
Address:
Suopurontie 1
02920 Espoo
Finland
Email: info@sveresystems.com
The “Customer” is the business client that determines the purposes and essential means of the covered processing and acts as controller for Customer Personal Data. “Customer Personal Data” means personal data that SvereSystems processes on the Customer’s behalf under documented instructions.
The “Main Agreement” means the applicable SvereSystems Terms & Conditions together with the relevant order, service page, proposal, email confirmation or other written service agreement.
This DPA becomes part of the Main Agreement only to the extent the actual service activity requires SvereSystems to act as a processor. It does not turn SvereSystems into a processor for activities in which SvereSystems determines its own purposes and means.
2. When this DPA applies — and when it does not
SvereSystems normally acts as an independent controller for its own website, free tools, fit checks, enquiries, client contact details, contract administration, payment and invoicing, accounting, service records, direct communications, security and marketing. Those activities are governed by the SvereSystems Privacy Notice rather than this DPA.
For the avoidance of doubt, the following are SvereSystems controller activities and are outside this DPA:
- the SvereSystems Free Clarity Check;
- SvereSystems’ own Website + Presenter fit-check and private paid-client intake;
- HubSpot CRM and client administration used for SvereSystems’ own business relationship;
- payment administration and accounting;
- requested Clarity Check result delivery; and
- security and anti-abuse controls used to protect SvereSystems’ own services.
Providers used for those controller activities are described in the Privacy Notice and do not become sub-processors under this DPA merely because SvereSystems also uses them elsewhere.
This DPA applies only to the extent a business client provides personal data about its own customers, prospects, staff, contractors or other individuals and SvereSystems processes that data solely on the client’s behalf for the agreed service.
Examples may include, depending on the agreed project:
- conversation excerpts supplied for a Client Conversation Clarity service;
- client-supplied photographs, testimonials, names or other personal data used in a Website + Presenter project;
- personal data processed while configuring or supporting a client-controlled contact form or another agreed website function; or
- other client-controlled personal data that SvereSystems must handle solely to perform documented project instructions.
If no Customer Personal Data is processed on the client’s behalf, this DPA has no practical processing subject matter even though it remains available as part of the SvereSystems legal framework.
3. Documented instructions, subject matter and duration
SvereSystems shall process Customer Personal Data only on documented instructions from the Customer, unless processing is required by Union or Member State law.
The documented instructions consist of the Main Agreement, this DPA, the submitted project material, approved project decisions and later written instructions that remain within the agreed lawful scope.
If applicable law requires SvereSystems to process Customer Personal Data outside those instructions, SvereSystems will inform the Customer of that legal requirement before processing unless the law prohibits such information on important grounds of public interest.
The subject matter, nature, purpose and expected duration of the covered processing are described in Appendix 1 and may be further specified in the relevant written project scope.
If SvereSystems considers an instruction to infringe the GDPR or other applicable Union or Member State data-protection law, SvereSystems will inform the Customer without undue delay and may pause the affected processing while the issue is resolved.
4. Categories of personal data and data subjects
Depending on what the Customer provides and the service actually requires, Customer Personal Data may include:
- names, business contact details, roles and organisation details;
- communications, conversation excerpts, enquiries, replies and related notes;
- photographs, recordings, testimonials, quotations or other client-supplied media containing identifiable people;
- website-enquiry details or other contact-form data where SvereSystems is involved in processing that data for the Customer;
- project-specific context linked to identifiable customers, prospects, staff or contractors; and
- limited technical or operational metadata created in the covered processing.
Data subjects may include the Customer’s customers, prospects, staff, contractors, representatives, testimonial providers, website visitors or other individuals whose data the Customer lawfully provides for the agreed service.
The standard services are not designed for Article 9 special-category data, criminal-conviction or offence data, passwords, account credentials, payment-card data or other unnecessary sensitive information. Such data must not be intentionally supplied unless the parties first agree in writing that the processing is necessary and appropriate safeguards are in place.
5. Customer obligations
The Customer is responsible for:
- having an appropriate lawful basis for the Customer Personal Data and the processing instructions;
- providing required notices and obtaining any required permissions or consents;
- ensuring that instructions are lawful and within the agreed service;
- providing only personal data that is reasonably necessary for the purpose;
- removing unnecessary personal data before it is supplied to SvereSystems;
- not intentionally supplying prohibited or unnecessary sensitive information; and
- deciding how the final client-facing output will be used after handover.
6. SvereSystems processor obligations
For Customer Personal Data covered by this DPA, SvereSystems shall:
- process the data only on documented instructions from the Customer, subject to applicable law;
- ensure that persons authorised to process the data are subject to an appropriate duty of confidentiality;
- implement technical and organisational measures appropriate to the risk in accordance with Article 32 GDPR;
- comply with the Article 28 conditions for engaging sub-processors;
- assist the Customer, taking into account the nature of processing, with appropriate technical and organisational measures for responding to data-subject rights requests where reasonably possible;
- assist the Customer, taking into account the nature of processing and information available to SvereSystems, with obligations under Articles 32 to 36 GDPR;
- return or delete Customer Personal Data at the end of the covered services in accordance with Section 15;
- make available information necessary to demonstrate compliance with the processor obligations in this DPA and Article 28 GDPR; and
- not use Customer Personal Data for SvereSystems’ own unrelated purposes while acting as processor.
7. AI-assisted workflow and OpenAI boundaries
SvereSystems may use AI-assisted tools in its wider production and business workflow, but an AI provider may process Customer Personal Data covered by this DPA only if that provider has first been authorised for the relevant processor activity and the required contractual, security and international-transfer safeguards are in place.
Personal ChatGPT Plus workspace
SvereSystems’ current personal ChatGPT Plus workspace is not an approved sub-processor for Customer Personal Data. SvereSystems therefore must not knowingly enter Customer Personal Data into that workspace.
Before project material is used in the personal ChatGPT workspace, SvereSystems applies an internal sanitisation step. Direct and indirect identifiers must be removed to the extent necessary so that no natural person is reasonably identifiable from the material entered into ChatGPT.
Pseudonymisation is not enough by itself. Replacing a person’s name or email with “CLIENT_A” can reduce risk, but the material remains personal data if SvereSystems or another person can still reasonably link it back to an identifiable natural person using the remaining context or additional information. If sufficient anonymisation cannot be achieved without losing the information needed for the task, that material must not be entered into the personal ChatGPT workflow.
OpenAI API
SvereSystems currently uses the OpenAI API for the Free Clarity Check in SvereSystems’ capacity as controller. That controller-side use is governed by the SvereSystems Privacy Notice and is outside the scope of this DPA.
The OpenAI API is not currently authorised to process Customer Personal Data under this DPA. If SvereSystems later intends to use the OpenAI API for a covered processor activity, SvereSystems will first treat OpenAI as a proposed sub-processor for that activity, ensure that the required processor and transfer safeguards are in place, and provide the Customer with the sub-processor change notice described in Section 8 before Customer Personal Data is routed through that service.
The Customer may still be asked to minimise personal data before submission, but SvereSystems remains responsible for applying its own internal processing boundaries before using AI-assisted tools.
8. Sub-processors
The Customer gives SvereSystems general written authorisation to engage sub-processors where reasonably necessary for Customer Personal Data covered by this DPA.
Only providers that actually receive or otherwise process Customer Personal Data for a covered processor activity are sub-processors under this DPA. The categories below are therefore an authorisation framework rather than a statement that every listed provider receives Customer Personal Data in every project.
Providers used solely for SvereSystems’ own controller activities are not sub-processors under this DPA. In particular, the current Free Clarity Check workflow — including Cloudflare Turnstile, Make.com, the OpenAI API and MailerLite — is a SvereSystems controller activity. Likewise, Web3Forms and HubSpot are not sub-processors under this DPA when they are used only for SvereSystems’ own fit-check, intake, CRM or client-administration purposes.
Provider categories that may be relevant to covered processor activities
- Google Workspace services — business email, documents or storage where covered project material is processed there.
- Make.com — workflow automation only where a configured processor-side workflow actually carries Customer Personal Data.
- Namecheap / Private Email infrastructure — business-email infrastructure where covered Customer Personal Data is transmitted or stored through the service.
- Web3Forms or another form backend — only where it is used for a client-controlled website function and SvereSystems is acting as processor for the Customer in that activity.
- Website, hosting or media providers — only where a provider must process Customer Personal Data as part of an agreed client website or media-delivery function.
OpenAI is deliberately excluded from the current authorised sub-processor framework for Customer Personal Data. SvereSystems’ personal ChatGPT Plus workspace must not receive Customer Personal Data, and the OpenAI API is currently used only for SvereSystems’ controller-side Free Clarity Check. If SvereSystems later intends to route Customer Personal Data through the OpenAI API or another AI service for a covered processor activity, that provider must first be added to the relevant sub-processor framework and the Customer must receive the change notice described below.
SvereSystems shall impose data-protection obligations on each sub-processor that are appropriate to the delegated processing and consistent in substance with Article 28 GDPR. SvereSystems remains responsible to the Customer for the performance of a sub-processor’s processor obligations to the extent required by applicable law.
SvereSystems will give active Customers reasonable prior written electronic notice before adding or replacing a material sub-processor expected to process Customer Personal Data under this DPA. Unless urgency makes advance notice impracticable, SvereSystems will aim to give at least 14 days for a reasonable data-protection objection. If an urgent replacement is required for security or service continuity, notice will be given as soon as reasonably practicable.
If the Customer objects on reasonable data-protection grounds, the parties will try in good faith to identify a practical alternative. If no reasonable alternative is available and the provider is necessary for the affected processing, either party may end the affected processing or service component in accordance with the Main Agreement.
9. International transfers
SvereSystems will transfer Customer Personal Data outside the European Economic Area only where the transfer is consistent with the Customer’s documented instructions and Chapter V GDPR.
Where an applicable European Commission adequacy decision covers the destination or transfer framework, the transfer may rely on that decision. Otherwise SvereSystems will use an available lawful transfer mechanism, such as applicable Standard Contractual Clauses or another mechanism permitted by Chapter V, together with supplementary measures where required by the circumstances.
On reasonable request, SvereSystems will provide information about the transfer mechanism relevant to the covered processing and how the Customer may obtain or review the relevant safeguards where available.
10. Technical and organisational security measures
SvereSystems shall maintain measures appropriate to the nature, scope, context and purpose of the covered processing and the risks to individuals. The current baseline is described in Appendix 2.
Measures may be updated as systems and providers change, provided that the overall level of protection for Customer Personal Data is not materially reduced without a lawful and documented reason.
The Customer remains responsible for security of its own systems, accounts, permissions, credentials and source material.
11. Data-subject requests
If SvereSystems receives a request from a data subject concerning Customer Personal Data processed only on the Customer’s behalf, SvereSystems will not respond substantively on the Customer’s behalf unless authorised or required by law.
SvereSystems will, where appropriate, refer the requester to the Customer and notify the Customer. Taking into account the nature of the processing, SvereSystems will provide reasonable assistance through appropriate technical and organisational measures insofar as this is possible.
The Customer remains responsible for deciding and documenting the response where it is the controller.
12. Personal-data breaches
If SvereSystems becomes aware of a personal-data breach affecting Customer Personal Data covered by this DPA, SvereSystems will notify the Customer without undue delay.
The notification will include information reasonably available to SvereSystems that the Customer may need for its own assessment and notification obligations, such as the nature of the incident, affected categories of data or individuals, likely consequences and measures taken or proposed.
Information may be supplied in phases where it is not reasonably available at the same time. SvereSystems will take reasonable steps to contain and mitigate the breach and preserve relevant information for the Customer’s assessment.
13. DPIAs and prior consultation
Taking into account the nature of the processing and the information available to SvereSystems, SvereSystems will provide reasonable assistance where the Customer needs information for a data-protection impact assessment or prior consultation under Articles 35 or 36 GDPR relating to the covered processing.
SvereSystems does not decide for the Customer whether a DPIA or prior consultation is legally required.
14. Compliance information and audits
On reasonable written request and subject to appropriate confidentiality protections, SvereSystems will make available information necessary to demonstrate compliance with the processor obligations in this DPA and Article 28 GDPR.
The Customer may conduct an audit itself or appoint an independent auditor. SvereSystems shall allow for and contribute to audits of the processing covered by this DPA, including inspections where reasonably necessary.
Where written evidence, provider documentation, answers or remote review can reasonably satisfy the purpose of the audit, the parties may use those methods first. This does not remove the Customer’s statutory audit rights.
Audits should, where practicable, be conducted on reasonable notice, during normal business hours, subject to confidentiality and in a way that avoids unnecessary disruption or disclosure concerning other customers. These practical arrangements do not prevent urgent steps required by law, a supervisory authority or credible evidence of material non-compliance.
15. Return and deletion
At the Customer’s choice, communicated in writing by or at the end of the covered services, SvereSystems shall return or delete Customer Personal Data and delete existing processor copies unless Union or Member State law requires continued storage.
If the Customer does not request return and there is no lawful need for continued processor retention, SvereSystems may delete covered processor data as part of normal project closure and retention management.
Limited residual copies may remain temporarily in provider backups or security logs until overwritten or deleted through the provider’s normal retention cycle. During that period they remain protected and are not intentionally used for another purpose except legitimate restoration, security or legal compliance.
This section does not require deletion of separate records that SvereSystems holds as controller, such as its own contracts, invoices, accounting records, payment records, direct correspondence or legal-compliance records. Those records are governed by the Privacy Notice.
16. Liability and document hierarchy
The liability provisions of the Main Agreement apply to this DPA subject to mandatory provisions of applicable law and without limiting responsibilities that cannot lawfully be excluded.
If the documents conflict specifically on processor obligations for Customer Personal Data, this DPA prevails to the extent of that conflict. The Main Agreement continues to govern commercial scope, fees, delivery and other matters not specifically displaced by this DPA.
17. Governing law and contact
This DPA is governed by the laws of Finland. Disputes are handled under the dispute-resolution provisions of the Main Agreement unless mandatory law requires otherwise.
Questions concerning this DPA can be sent to info@sveresystems.com.
SvereSystems
Operated by Sveresa Tmi
Business ID: 3592316-3
VAT ID: FI35923163
Suopurontie 1
02920 Espoo
Finland
18. Appendix 1 — Processing details
Subject matter: Limited processing of Customer Personal Data that a business client provides to SvereSystems and instructs SvereSystems to handle solely to perform an agreed Website + Presenter, Client Conversation Clarity or other expressly agreed SvereSystems service.
Duration: For the period reasonably necessary to perform the covered processor activity, followed by return or deletion in accordance with Section 15, subject to any legally required retention.
Nature of processing: Receipt, access, organisation, review, temporary storage, editing, transformation, publication or integration where instructed, delivery, support, deletion and other operations reasonably necessary for the agreed processor activity.
Purpose: To perform the client’s documented instructions within the agreed SvereSystems service and not for SvereSystems’ own unrelated purposes.
Types of personal data: Business contact information; communications; conversation excerpts; customer, prospect, staff or contractor details; photographs, recordings, testimonials or quotations; website-enquiry data; and limited project or technical metadata, but only where actually needed for the covered service.
Categories of data subjects: The Customer’s customers, prospects, employees, contractors, representatives, testimonial providers, website visitors and other individuals whose personal data the Customer lawfully supplies for the agreed processor activity.
Excluded by default: Article 9 special-category data, criminal-conviction or offence data, passwords, access credentials, payment-card details and other unnecessary sensitive information.
Customer rights and obligations: The Customer determines the lawful purpose and legal basis, provides lawful instructions, handles transparency and data-subject rights as controller, and decides whether covered processor data should be returned or deleted at the end of processing.
19. Appendix 2 — Baseline technical and organisational measures
SvereSystems applies proportionate measures appropriate to its small-business service workflows and the risk of the covered processing. Measures include, as applicable:
- HTTPS/TLS for data in transit where supported by the relevant provider;
- restricted access to business email, storage, workflow and website systems used for covered processing;
- strong account credentials and multi-factor authentication where available and appropriate;
- least-privilege access and avoidance of unnecessary public sharing links;
- data minimisation in forms, working materials and service workflows;
- an internal rule prohibiting Customer Personal Data from being entered into the current personal ChatGPT Plus workspace;
- an internal routing rule prohibiting Customer Personal Data from being sent to the OpenAI API or another AI service for a covered processor activity unless that provider has first been authorised under Section 8 and the required processor and transfer safeguards are in place;
- anonymisation of material before personal ChatGPT use where the task can be performed without personal data, with the task withheld from that workflow if sufficient anonymisation cannot be achieved;
- avoidance of passwords, credentials, special-category data, criminal-offence data and other unnecessary sensitive information in normal forms and working materials;
- separation or clear identification of test material and live client material where practical;
- reasonable deletion and retention controls for working material and completed processor files;
- incident assessment and corrective action where an issue affecting covered processing is identified; and
- use of service providers with security measures appropriate to their role in the workflow.
The exact implementation varies by provider and project. SvereSystems will maintain an overall level of protection appropriate to the risks as required by Article 32 GDPR.