1. Parties and scope
This DPA is between the business customer that is the controller of Customer Personal Data and Sveresa Tmi, Business ID 3592316-3, Finland, operating as SvereSystems, where SvereSystems processes that data on the customer’s behalf as processor.
This DPA forms part of the relevant Project Confirmation or other written service agreement. It does not apply to SvereSystems’ own controller-side records such as project enquiries, contracts, invoices, bank-payment records, ordinary client correspondence, accounting or legal-compliance records.
2. Subject matter and duration
The processing covers personal data that the customer instructs SvereSystems to handle for an agreed website, content or presenter project. Processing lasts for the project and any limited period reasonably needed for completion, correction, secure deletion, backup cycles or mandatory retention.
3. Nature and purpose
Processing may include receiving, viewing, organising, minimising, drafting, transforming, storing, transmitting and deleting Customer Personal Data to prepare or deliver the agreed project.
4. Data and data subjects
Depending on the project, data may concern the customer’s staff, customers, reviewers, reference contacts or other people appearing in customer-supplied material. Data may include names, work contact details, public professional information, approved testimonials, images and other ordinary project content.
Passwords, payment-card data, special-category data, criminal-offence data and other unnecessary sensitive information must not be submitted unless separately agreed and legally justified.
5. Customer obligations
- provide lawful documented instructions;
- have a valid legal basis for Customer Personal Data;
- provide required privacy information to data subjects;
- submit only data reasonably necessary for the project;
- remove or anonymise unnecessary personal data where practical;
- ensure rights to supplied images, testimonials and other material.
6. Processor obligations
- process Customer Personal Data only on documented instructions unless law requires otherwise;
- maintain confidentiality;
- apply appropriate technical and organisational measures proportionate to the service;
- assist reasonably with data-subject and GDPR compliance requests;
- inform the customer if an instruction appears to infringe applicable data-protection law;
- apply data minimisation where practical.
7. AI-assisted processing
Where reasonably necessary for the agreed project, SvereSystems may use AI-assisted tools for drafting, organisation, translation, visual/media preparation or other production tasks. SvereSystems applies data minimisation and avoids including unnecessary identifying details in prompts or production inputs.
AI-assisted outputs are working material and are human-reviewed before client-facing delivery. The service does not use solely automated decision-making that produces legal or similarly significant effects for data subjects.
8. Sub-processors
The customer gives general written authorisation for SvereSystems to use sub-processors reasonably necessary for the agreed processing. Categories may include website/hosting infrastructure, forms, cloud/email, CRM, video/media hosting and AI/media production tools.
SvereSystems remains responsible for selecting providers proportionately and for ensuring that processor obligations are addressed where required by Article 28 GDPR.
9. International transfers
Where a sub-processor processes Customer Personal Data outside the EU/EEA and a transfer mechanism is required, SvereSystems will rely on an applicable lawful mechanism and safeguards, such as an adequacy decision or Standard Contractual Clauses where relevant.
10. Security measures
- need-based access to business systems;
- use of established service providers and account-security controls;
- data minimisation and separation of project records where practical;
- keeping credentials and payment-card data out of ordinary intake forms;
- reasonable deletion of unnecessary working data;
- secure transport provided by the relevant platforms.
11. Data-subject requests
If SvereSystems receives a request relating to Customer Personal Data for which the customer is controller, SvereSystems will notify or refer the request to the customer where appropriate and provide reasonable assistance, taking into account the nature of the processing.
12. Personal-data breach
SvereSystems will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed under this DPA and will provide reasonably available information needed for the customer’s assessment and notification duties.
13. Compliance information
On reasonable written request and subject to confidentiality, SvereSystems will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR. On-site audits are not normally appropriate for this small written-first service; where legally required and not satisfied by documentation, any audit must be proportionate and arranged to minimise disruption and exposure of other clients’ information.
14. Return and deletion
After the relevant processing ends, SvereSystems will return or delete Customer Personal Data on reasonable written request unless EU or Member State law requires storage. Limited copies may remain temporarily in backups or provider logs until overwritten through normal retention cycles.
This does not require deletion of separate controller-side records such as SvereSystems’ own contract, invoice, payment, accounting or legal-compliance records.
15. Liability, hierarchy and law
For data-protection matters, this DPA prevails over conflicting general terms to the extent of the conflict. The liability and dispute provisions of the Main Agreement otherwise apply subject to mandatory law.
This DPA is governed by Finnish law. Questions: info@sveresystems.com.