Privacy · Personal data

Privacy Notice

This notice explains how SvereSystems handles personal data in enquiries, projects, invoicing, newsletter subscriptions, website use, business prospecting, direct marketing, AI-assisted production and consent-controlled website analytics.

Last updated: 6 October 2026SvereSystems · Sveresa · Finland
Data minimisation: do not send passwords, card details or unnecessary sensitive personal data through ordinary project forms. SvereSystems does not request WordPress, Wix, Squarespace, other CMS, hosting, cPanel, FTP/SFTP, DNS or server credentials for website projects.

1. Controller

SvereSystems / Sveresa
Business ID 3592316-3 · VAT ID FI35923163
Suopurontie 1 D 27, 02920 Espoo, Finland
info@sveresystems.com

Sveresa is the controller where it determines the purposes and means of processing, including website use, enquiries, project administration, invoicing, accounting, business prospecting, direct marketing and its own business communications.

If SvereSystems processes personal data controlled by a business client only on that client's documented instructions, SvereSystems may act as a processor for that processing. Where applicable, the Data Processing Agreement applies.

2. Data we may process

  • name, email, phone, company, professional role and communication history;
  • for business prospecting, limited professional and business-contact data such as company, work contact details, verified role, public source, relevant business context, the factual reason or evidence for a possible contact, and contact status;
  • suppression information needed to honour objections or avoid repeated unwanted contact, such as do-not-contact, decline or hard-bounce status and the relevant date;
  • newsletter subscription data, such as the email address and subscription status;
  • company/registration/VAT information, country, billing details and invoice/payment records;
  • project requests, private intake answers, confirmed offer, delivery route and scope, current or planned website URL, service and audience information, CTA or public-contact destinations, website or content elements the customer asks to preserve, and other project instructions;
  • logos, images, documents, testimonials and other material supplied for a project;
  • where Analytics consent is given, website-usage and online-identifier data such as page URL, referrer or campaign information, interactions, browser/device information, IP address and IP-derived technical information, analytics cookies and related identifiers;
  • technical data such as IP address, browser/device data, security logs, consent choices and source/UTM information.

3. Sources of data

Data comes mainly from you, your organisation, website forms, newsletter sign-up forms, project email, invoices and project files.

For business prospecting, we may use limited publicly available business and professional information from sources such as company websites, official company registers, Google Business Profile and other identifiable public professional or business pages. Public availability does not by itself mean that personal data may be used for every purpose.

Where personal data is obtained indirectly, SvereSystems records the source or source category needed for transparency and contact management.

4. Purposes and legal bases

  • Pre-contract steps and contract: assessing a project request, preparing a Project Confirmation, deciding the appropriate delivery route, carrying out the agreed project, preparing the agreed copy, structure, CTA and change notes for an existing website or producing the agreed new HTML/CSS/JavaScript/media files, carrying out a bounded final public-page review where that review is included in the confirmed existing-site scope, and communicating with the client.
  • Legal obligations: invoicing, accounting, tax and statutory records.
  • Legitimate interests: security, fraud/abuse prevention, service administration, documentation of business decisions, protecting legal rights, relevant and proportionate B2B prospecting and direct-marketing data management, and maintaining minimal suppression records where these interests are not overridden by the rights and interests of the individual.
  • Consent: newsletter subscriptions and other optional communications, and non-essential browser technologies such as Google Analytics 4 where consent is required.

Fields marked as required in a project or intake form are needed to assess, start or carry out the agreed work. If information that is necessary for the project is not provided, SvereSystems may be unable to start or complete the work as agreed. Optional fields may be left blank.

The GDPR legal basis for processing personal data and the separate rules governing whether a particular electronic direct-marketing message may be sent are assessed separately where required.

5. Service providers and recipients

Depending on the process, limited data may be processed by providers used for website delivery, forms, email, CRM, invoicing/accounting, banking, video hosting, security, analytics and AI-assisted production. Current service providers may include ClickSites, Web3Forms, Namecheap Private Email, MailerLite for opt-in newsletter subscriptions, HubSpot, NoCFO, SvereSystems’ bank, Bunny.net, jsDelivr for delivery of the consent-manager library, Google Ireland Limited for consented Google Analytics 4 measurement on selected main pages, and selected AI/media tools used for the agreed task.

If a client asks SvereSystems to send project material or final files to the client's chosen web developer, IT support or hosting provider, SvereSystems may share only the project information reasonably necessary for that handover. Those recipients are selected by the client, not by SvereSystems. SvereSystems does not require access to the client's CMS, hosting, DNS, server or other technical accounts for website projects. Clients are asked not to include unnecessary personal data in project material.

Personal data is not sold to advertisers. A provider may act under its own legal obligations for its platform or payment/banking functions.

6. Business prospecting and direct marketing

SvereSystems may use limited publicly available business and professional information to identify potentially relevant business customers and decide whether a one-to-one business contact is appropriate. Prospecting is deliberately low-volume and evidence-based: the company, service relevance and a factual reason for contact are checked before a message is sent. SvereSystems does not use sensitive personal data or private lifestyle information for prospecting.

Where a suitable general company address is available, SvereSystems may prefer that route. If a named person's work contact details are considered, the person's professional role and its material relevance to the service being offered are assessed before contact. A work address that identifies a natural person is not treated as automatically available for unrestricted marketing merely because it is public.

Where personal data has not been obtained directly from the individual, SvereSystems provides the information required by Article 14 of the GDPR within the applicable time limit—normally within one month and, where the data is used to contact the person, no later than the first communication—unless a legal exception applies. The source or source category of the data is recorded and can be provided to the individual.

Whether an electronic direct-marketing message may be sent is assessed separately under the Finnish Act on Electronic Communications Services and other applicable law. Electronic direct marketing to a natural person generally requires prior consent, subject to statutory exceptions such as the existing-customer rule. Direct marketing to a legal person may be sent unless the organisation has prohibited it. Where a named work address identifies a natural person, SvereSystems does not treat public availability alone as permission to send. The applicable sending rule is assessed before contact; if permission is unclear, SvereSystems uses a suitable general company address where practical or does not send.

Every direct-marketing message must be identifiable as marketing, identify SvereSystems as the sender and provide a simple, free way to object or request that further marketing stop. A reply requesting no further contact is sufficient. If an individual or organisation objects, SvereSystems stops direct marketing to that recipient and records only the minimum suppression information reasonably needed to respect the request.

SvereSystems does not use tracking pixels in its one-to-one cold outbound email. Website analytics, where used, are handled separately under the consent-controlled analytics described in this notice and the Cookie Notice.

7. Google Analytics 4

SvereSystems uses Google Analytics 4 on selected main pages to understand traffic sources and general website use. Google Analytics is non-essential analytics, and the external Google Analytics script is not loaded until the visitor gives Analytics consent through the consent manager.

After consent, Google Analytics may process information such as the page URL, referrer or campaign information, interactions, browser/device information, IP-derived technical information, analytics cookies and related online identifiers. SvereSystems does not intentionally send project-form free text or client-provided business details to Google Analytics as analytics-event parameters.

This setup is used for website analytics only and only after Analytics consent. Meta Pixel and other advertising pixels are not currently enabled on SvereSystems pages.

The applicable Google Analytics service provider is Google Ireland Limited. Google group companies may process data internationally in accordance with Google's applicable terms and transfer safeguards. See how Google uses information from sites and apps that use its services. Consent can be changed or withdrawn through the site's privacy settings.

8. AI-assisted processing

SvereSystems uses AI-assisted tools for parts of analysis, business research, drafting, website production and presenter/media creation. Data minimisation is used: unnecessary personal data should not be included in prompts or production inputs. Client-facing work and outbound decisions are human-reviewed.

SvereSystems does not use solely automated decision-making that produces legal or similarly significant effects for individuals.

9. International transfers

Some providers operate internationally. Where personal data is transferred outside the EU/EEA and a transfer mechanism is required, SvereSystems relies on an applicable lawful transfer mechanism and appropriate safeguards, such as an adequacy decision or Standard Contractual Clauses where relevant.

10. Retention

Data is kept only as long as reasonably necessary for enquiries, contracts, project delivery, agreed final reviews, invoicing, accounting, tax, security and legal claims. Project intake answers and client-supplied project material are not kept longer than needed for the project, client relationship, agreed follow-up work and justified legal or accounting needs.

As an internal retention rule, prospecting records that do not become an active conversation or customer relationship are normally reviewed and removed within 12 months of the last relevant verification or contact. This may include the recorded source and factual contact rationale used for outbound qualification. Minimal suppression records may be retained longer where reasonably necessary to honour an objection, prevent repeated unwanted contact or document compliance.

Newsletter subscription records are retained as needed to manage the subscription, honour unsubscribe requests and demonstrate consent where required. Accounting and tax records are retained for the periods required by Finnish law. Working project material is removed from active systems when it is no longer needed, subject to backups and provider retention cycles.

11. Your rights

Depending on the legal basis and circumstances, you may have rights to access, correct, erase or restrict your personal data, object to certain processing, receive portable data, withdraw consent and lodge a complaint with a supervisory authority.

Direct marketing: you may object at any time to the processing of your personal data for direct-marketing purposes. If you object, SvereSystems will no longer process your personal data for that purpose. You can exercise this right simply by replying to a marketing email or by writing to info@sveresystems.com. No reason or fee is required. A minimal suppression record may be retained solely to ensure that the objection is respected.

12. Supervisory authority

Sveresa is established in Finland. The Finnish supervisory authority is the Office of the Data Protection Ombudsman. An EU/EEA data subject may also have the right to contact the competent authority in their own Member State.

13. Cookies and browser technologies

See the Cookie Notice for essential storage, embedded media, newsletter forms and any consent-managed browser technologies currently in use.

14. Changes and contact

This notice may be updated when SvereSystems services, providers, marketing practices or legal requirements change. Questions can be sent to info@sveresystems.com.