Data Processing Agreement
For customers who need a formal processing agreement, this covers how Serravee handles data on your behalf.
Version 1.0 · 22 August 2026Roles
You are the controller of the personal data in the accounts you connect. Serravee Inc. is the processor: we process that data only to provide the service, and only on your documented instructions — which include your use of the product and the approvals you give inside it.
This agreement forms part of the Terms of Service. Need it signed on your paper? Mail privacy@serravee.com.
What we process
- Subject matter and duration: running growth experiments for you, for as long as your account is open plus the retention window in the Privacy Policy.
- Categories of data subject: your customers and subscribers, and your own team members who use Serravee.
- Categories of personal data: contact and engagement data from the tools you connect — email addresses, order and campaign history, segment membership. Serravee works from aggregates wherever the job allows it.
- Special category data: none is requested, and none should be sent to us.
Our obligations
- Process personal data only on your instructions, and tell you if we believe an instruction breaks the law.
- Keep everyone with access under a duty of confidentiality.
- Apply the security measures below, and not weaken them during the term.
- Help you respond to data-subject requests and to regulators, at no extra charge.
- Delete or return personal data at the end of the agreement, on the schedule in the Privacy Policy.
- Make available the information you need to audit our compliance.
Security measures
- Encryption in transit (TLS) and at rest.
- Least-privilege access, reviewed regularly; connections start read-only.
- Credentials held encrypted and revocable by you in one click.
- Logging of what the system did, why, and on whose approval.
- Separation of customer data between accounts.
- SOC 2 Type II is in progress. We will state the certification the day it is issued, and not before.
Sub-processors
You give general authorisation for us to engage sub-processors. Each is bound by terms no less protective than these. We currently use vendors for cloud hosting and storage, database hosting, email delivery, customer relationship management, error monitoring, and large language model inference.
For the current named list, and to be told before we add one, mail privacy@serravee.com. You may object to a new sub-processor on reasonable data-protection grounds; if we cannot resolve it, you may terminate the affected service.
Breach notification
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 72 hours, with what we know: what happened, which data was affected, the likely consequences, and what we are doing about it. We will keep you updated as we learn more.
International transfers
Where personal data moves outside its region of origin, we rely on the appropriate safeguards for that transfer, including the European Commission’s standard contractual clauses and the UK addendum, which are incorporated here by reference.
Questions about any of this?
Mail privacy@serravee.com and a person will answer. Security reviews go to security@serravee.com.