Legal · Personal data

Privacy Notice

This notice explains how SvereSystems handles personal data when you use the website, contact us, submit a fit check or project intake, receive a free digital resource, join optional email updates, or buy and receive a SvereSystems business service.

Last updated: 15 August 2026 SvereSystems · operated by Sveresa Tmi · Finland

Data-minimisation rule: Do not send passwords, login credentials, payment-card details, unnecessary health or other special-category personal data, or third-party personal data that is not genuinely needed for the requested service.

1. Controller

Brand: SvereSystems

Controller: Sveresa Tmi

Business ID: 3592316-3

VAT ID: FI35923163

Business address:
Suopurontie 1
02920 Espoo
Finland

Website: www.sveresystems.com

Email: info@sveresystems.com

Sveresa Tmi, trading under the SvereSystems brand, is the controller where SvereSystems determines the purposes and means of processing for its own website, enquiries, client administration, contracts, billing, marketing, security and business records.

2. Personal data we may use

The categories depend on how you interact with SvereSystems and may include:

  • Identity and contact data: name, work email, company, role, business address, telephone number where supplied, and contact history.
  • Business and project data: legal business name, public brand name, Business ID or registration information, country, website or domain, hosting situation, service area, service descriptions, target audience, approved facts, exclusions, customer questions, requested visitor action and other project instructions.
  • Website + Presenter intake data: visual preferences, logo status, image approach, presenter direction and preferences, launch information, approvals and project communications.
  • Client-supplied media and source material: logos, photographs, documents, recordings, testimonials or other files supplied for use in a project. These may contain personal data where people are identifiable.
  • Conversation-review material: outreach messages, follow-ups, replies, offer descriptions, target-client information and other business context submitted for analysis.
  • Payment and billing data: transaction references, billing details, VAT-related information, service purchased, price and payment status. SvereSystems does not receive or store full payment-card numbers from Stripe.
  • Email and free-resource data: email address, requested product or resource, delivery/download record, marketing-consent status and unsubscribe status.
  • Technical and security data: IP address, browser/device information, timestamps, referral or request information, consent records and provider-generated logs where these are created by the website or services used to operate it.

3. Where personal data comes from

Most personal data is provided directly by you through a website form, project intake, checkout, email or other business communication.

We may also receive data from the organisation you represent, from a payment or checkout provider used for your order, or from service providers that generate necessary security, delivery or transaction records.

If a business client supplies personal data about another person as part of source material, SvereSystems will use that material only as necessary for the agreed service and in accordance with the applicable controller or processor role described below.

4. Enquiries and fit checks

We use information submitted through an enquiry or fit check to understand the request, determine whether the relevant SvereSystems service appears suitable, respond to the sender and maintain an appropriate business record.

Legal basis: Article 6(1)(b) GDPR where the processing is necessary to take requested steps before a contract with you as an individual or sole trader; otherwise Article 6(1)(f) GDPR, based on our legitimate interest in handling requested B2B enquiries, assessing fit, preventing abuse and maintaining relevant business correspondence.

A fit-check submission does not by itself create a paid-service contract.

5. Website + Presenter projects

For Website + Presenter, SvereSystems uses the information needed to assess the project, confirm fit, administer payment, receive the private project intake, develop approved content and visual direction, create or coordinate agreed media, build the website, prepare the agreed contact route, perform quality checks, manage launch or handover where included, and retain an appropriate service record.

Website + Presenter forms are currently submitted through Web3Forms. Web3Forms states that form submissions are processed and forwarded to the configured email or endpoint rather than stored as submission records by Web3Forms; it also states that server logs may contain personal information and are deleted periodically.

Legal basis: Article 6(1)(b) GDPR where processing is necessary for a contract with you as an individual or sole trader; for representatives of business customers, Article 6(1)(f) GDPR based on our legitimate interest in administering and performing the B2B service relationship; Article 6(1)(c) GDPR for applicable accounting, tax and other legal duties.

We do not require passwords or hosting credentials in the standard public intake form. If technical access is later required for an agreed launch, it should be provided only through an appropriate method requested for that purpose.

6. Client Conversation Clarity services

For services such as First Contact Fix and Client Acquisition Conversation Review, we use submitted business context and conversation material to assess the request, produce the agreed written analysis or rewrite, deliver the work and maintain relevant service records.

Some existing conversation-service workflows may use Make.com for operational automation. Where Make is used, it processes the information needed for the configured workflow under the applicable data-processing terms.

Legal basis: the same contract, pre-contract, legitimate-interest and legal-obligation bases described above, depending on whether the individual is personally the contracting party or acts for a business customer.

7. Payments, invoices and legal records

SvereSystems uses Stripe for certain paid-service payment links. Stripe processes payment and transaction information needed to operate the checkout, authenticate or secure transactions, prevent fraud and comply with its own legal obligations. SvereSystems receives transaction and payment-status information needed to administer the order but does not receive the full payment-card number.

We retain invoices, transaction references and accounting information for the periods required by applicable Finnish accounting and tax law. Records needed for legal claims or dispute handling may be retained for an appropriate limitation period where justified.

Legal basis: Article 6(1)(b) GDPR for contract administration where applicable, Article 6(1)(c) GDPR for accounting and tax obligations, and Article 6(1)(f) GDPR for fraud prevention, payment reconciliation and the establishment, exercise or defence of legal claims.

8. Free resources and optional email updates

SvereSystems may make free digital resources or digital products available through Payhip. Payhip may provide SvereSystems with order or download information associated with the requested resource.

Where you separately opt in to SvereSystems marketing emails, your subscriber information may be stored and processed in MailerLite for mailing-list management and email delivery.

Receiving a free resource or buying a service does not automatically subscribe you to marketing. Where consent is used, it can be withdrawn at any time, including through the unsubscribe link in a marketing email.

Legal basis: Article 6(1)(f) GDPR for delivering and administering a free resource you requested, subject to the circumstances of that flow; Article 6(1)(a) GDPR for optional marketing where consent is the chosen basis; and Article 6(1)(c) GDPR where transaction records must be retained by law.

9. AI-assisted work and human review

SvereSystems may use AI-assisted tools for limited parts of drafting, analysis, organisation, coding, image generation, presenter production and quality-control workflows.

For the current internal ChatGPT workflow, SvereSystems applies a data-minimisation and anonymisation step before project material is entered into ChatGPT. Direct identifiers such as a contact person’s name, individually identifying email address and telephone number are removed, together with indirect or contextual details where necessary. Sole-trader names, identifiers and third-party details receive particular care because business information can also identify a natural person.

The material entered into the current personal ChatGPT workspace must be reduced so that no natural person is reasonably identifiable from the information provided to ChatGPT. Simply replacing a name or email address with a placeholder is not treated as sufficient if the remaining context can still reasonably be linked to that person. If sufficient anonymisation cannot be achieved without losing information needed for the task, that material is not entered into the current ChatGPT Plus workflow.

SvereSystems does not intentionally use its personal ChatGPT workspace as a processor for client personal data. The ChatGPT account is also configured so that new conversations are not used to improve OpenAI’s models. That setting is an additional privacy control and does not replace the anonymisation rule above.

Passwords, credentials, payment-card details, unnecessary sensitive personal data and unrelated third-party personal data must not be submitted to AI tools.

AI-assisted outputs are working material. Client-facing deliverables within the agreed service scope are subject to human review before final delivery.

SvereSystems does not use solely automated decision-making that produces legal effects or similarly significant effects for a person.

10. Providers and categories of recipients

We do not sell personal data. Depending on the interaction and service, personal data may be disclosed to or processed through providers in the following categories:

  • Website and infrastructure providers, including ClickSites AI and domain/email infrastructure providers used to operate SvereSystems.
  • Form-processing providers, including Web3Forms for Website + Presenter fit-check and paid project-intake submissions.
  • Email, document and business-tool providers, including Google services where used for business email, files, spreadsheets or cloud storage.
  • Workflow automation providers, including Make.com where used in a configured operational flow.
  • AI and production-tool providers. Under the current workflow, OpenAI’s personal ChatGPT Plus workspace is intended to receive only material anonymised as described in section 9, rather than client personal data. Other production tools are assessed according to the data they actually receive and the applicable contractual role.
  • Video and media infrastructure, including Bunny.net / Bunny Stream where video hosting or streaming is used.
  • Payment and checkout providers, including Stripe and Payhip.
  • Email-marketing providers, including MailerLite for contacts who have opted in.
  • Professional advisers and public authorities where disclosure is reasonably necessary for accounting, legal advice, compliance, tax, fraud prevention or a binding legal requirement.

Some providers process data on our documented instructions as processors or subprocessors. Others, particularly payment, checkout or platform providers, may also act as independent controllers for parts of their own security, fraud-prevention, regulatory or platform processing. The exact role depends on the processing activity and the provider’s applicable terms.

11. When SvereSystems acts as controller or processor

For SvereSystems own enquiries, fit checks, client administration, payment records, service communications, marketing, security and legal records, Sveresa Tmi normally acts as controller.

A business client may sometimes provide personal data about its own customers, prospects, employees or other individuals solely so that SvereSystems can perform an agreed service on the client’s documented instructions. To the extent SvereSystems processes that personal data on behalf of the client rather than for SvereSystems own purposes, the client may be the controller and SvereSystems the processor.

Where Article 28 GDPR applies to such processing, the SvereSystems Data Processing Agreement applies as required. The DPA does not convert SvereSystems own controller activities, such as billing or business administration, into processor activities.

12. International transfers

Some service providers or their subprocessors may process personal data outside the European Economic Area.

Where GDPR Chapter V requires a transfer mechanism, the relevant transfer must rely on an applicable adequacy decision or appropriate safeguard, such as the European Commission’s Standard Contractual Clauses, together with any additional measures required in the circumstances. Some providers may also participate in an applicable adequacy framework where available.

You may contact info@sveresystems.com for information about safeguards relevant to a particular SvereSystems processing activity.

13. Retention

We keep personal data only for as long as reasonably necessary for the stated purpose, unless a longer period is required by law or justified for the establishment, exercise or defence of legal claims.

  • General enquiries and unsuccessful fit checks: normally up to 12 months after the last meaningful contact, unless a shorter or longer period is justified by the circumstances.
  • Website + Presenter and conversation-service project records: normally for the active engagement and up to 24 months after completion for support, quality control and ordinary dispute handling, after which unnecessary working material should be deleted or minimised.
  • Client-supplied media and production working files: kept only for as long as needed for production, handover, reasonable support or an agreed archive purpose, unless the client requests earlier deletion and no overriding obligation requires retention.
  • Marketing subscribers: until consent is withdrawn, the contact unsubscribes, or the list is no longer used for the stated purpose, subject to a minimal suppression record where needed to respect an unsubscribe request.
  • Web3Forms technical logs: Web3Forms states that server logs that may include personally identifiable information are deleted periodically, currently every two months.
  • Invoices and accounting/tax records: retained for the period required under applicable Finnish accounting and tax rules. Different accounting records may have different statutory retention periods.

Provider-side backup, security and statutory records may remain for the provider’s applicable retention period even after SvereSystems deletes an operational copy, where the provider is entitled or required to retain them.

14. Your data-protection rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • obtain information about and access to personal data concerning you;
  • have inaccurate personal data corrected;
  • request erasure in circumstances where the right applies;
  • request restriction of processing in circumstances where the right applies;
  • receive portable data where Article 20 GDPR applies;
  • object to processing based on legitimate interests, including an unconditional right to object to direct marketing;
  • withdraw consent at any time where consent is the legal basis, without affecting processing carried out lawfully before withdrawal; and
  • lodge a complaint with a competent supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman. You may also have the right to complain to another competent supervisory authority where GDPR allows.

To exercise a right concerning processing controlled by SvereSystems, email info@sveresystems.com. We may request information reasonably necessary to verify identity and locate the relevant records.

If the relevant personal data is processed by SvereSystems only as a processor for a business client, we may need to refer the request to that client as controller.

15. Security and automated decisions

SvereSystems uses reasonable technical and organisational measures appropriate to the nature and scale of the processing, including limiting access to business systems, using established service providers, reducing unnecessary data collection and keeping credentials out of ordinary intake forms.

No internet or cloud service can be guaranteed completely secure. If a personal-data breach occurs, SvereSystems will assess and handle it in accordance with applicable GDPR notification and documentation duties.

SvereSystems does not use solely automated decision-making, including profiling, that produces legal effects or similarly significant effects for individuals.

16. Cookies, embedded media and external services

Information about cookies, consent storage, the Bunny Stream embed, Stripe payment pages and Payhip’s separate store environment is provided in the Cookie Notice.

External websites and platforms have their own privacy notices and may act independently for their own processing. Following an external link does not make SvereSystems responsible for all processing performed by that third party.

17. Changes and contact

We may update this Privacy Notice when SvereSystems services, workflows, providers or legal obligations change. The current version will be published on this page with its revision date.

Questions about this notice or SvereSystems handling of personal data can be sent to info@sveresystems.com.

SvereSystems
Operated by Sveresa Tmi
Business ID: 3592316-3
VAT ID: FI35923163
Suopurontie 1
02920 Espoo
Finland