01Roles
You are the controller of the personal data in the accounts you connect. Serravee Inc. is the processor: we process that data only to provide the service, and only on your documented instructions, which include your use of the product and the approvals you give inside it.
Your instructions also authorise us to create and use aggregated and de-identified information, from which no individual, and no brand, can be identified, to operate, secure and improve Serravee. We will not attempt to re-identify it, and we will not disclose it in any form that identifies you or your customers.
This agreement forms part of the Terms of Service, and using the service means you accept it. Where this agreement and those terms disagree about personal data, this agreement wins. Need it signed on your paper? Mail privacy@serravee.com.
02What we process
- Subject matter and duration: running growth experiments for you, for as long as your account is open plus the retention window in the Privacy Policy.
- Categories of data subject: your customers and subscribers, and your own team members who use Serravee.
- Categories of personal data: contact and engagement data from the tools you connect: email addresses, names, order history, campaign engagement and segment membership. Shopify access includes individual customer records; that is what makes an audience definition possible. The reporting shown to the operator is aggregate.
- Special category data: none is requested. You agree not to submit special category data, and not to configure a connected account so that it reaches us. If it does reach us anyway, we process it under this agreement on the same terms as everything else, and neither of us treats that as consent to process it going forward, tell us and we will remove it.
03Our obligations
- Process personal data only on your instructions, and tell you if we believe an instruction breaks the law.
- Keep everyone with access under a duty of confidentiality.
- Apply the security measures below, and not weaken them during the term.
- Help you respond to data-subject requests and to regulators, taking into account the nature of our processing and the information available to us, and at no extra charge for requests of ordinary volume and complexity.
- Delete or return personal data at the end of the agreement, on the schedule below.
- Make available the information you reasonably need to demonstrate our compliance with this agreement. You may audit us once in any 12-month period, on 30 days’ written notice, during business hours, in a way that does not disrupt the service, at your cost and subject to confidentiality. We will also answer reasonable security questionnaires and provide relevant documentation. Additional audits are permitted if a regulator directs one, or following a confirmed breach of your data.
04Security measures
- Encryption in transit (TLS) and at rest.
- Least-privilege access, reviewed regularly. Shopify is read-only. Klaviyo requires write access to create the drafts Serravee builds, and a runtime guard plus a test prevent any send path existing.
- Credentials held encrypted and revocable by you in one click.
- Logging of what the system did, why, and on whose approval.
- Separation of customer data between accounts.
05Sub-processors
You give general authorisation for us to engage sub-processors. The current list, with each vendor’s purpose, the data it reaches and where it runs, is published at serravee.com/subprocessors and is dated.
Before we add or replace a sub-processor we will update that page and notify you by email at least 30 days beforehand. You do not need to ask to be notified. You may object on reasonable data-protection grounds within those 30 days; we will work with you to resolve it, and if we cannot you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.
Every sub-processor is required to be bound by written terms no less protective than those in this agreement, and we remain fully liable to you for each sub-processor’s performance of its data protection obligations. Where that paperwork is still in progress for a particular vendor we will tell you so on request rather than imply otherwise.
We send content to a large language model provider (currently Anthropic PBC, United States) to generate and analyse copy. Under our commercial agreement with them, that content is not used to train their models.
06Breach notification
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 72 hours of confirming it, with what we know: what happened, which data was affected, the likely consequences, and what we are doing about it. We will keep you updated as we learn more.
Unsuccessful attempts that do not compromise data, such as blocked logins, port scans, failed authentication and the like, are not breaches, and we will not notify you about each one. We will summarise anything material on request.
07Deletion and return
On termination, or on your written instruction, we delete the personal data we process for you within 30 days, other than what we are legally required to retain. Encrypted backups age out on their own cycle within 90 days and are not restored except to recover the service. We will confirm deletion in writing if you ask.
If a request from one of your customers reaches us directly, we route it to you rather than action it ourselves, and tell the person we have done so.
08California
Where you are a “business” and we are a “service provider” as those terms are used in the California Consumer Privacy Act as amended: we will not sell or share the personal information you disclose to us; we will not retain, use or disclose it for any purpose other than performing the services in this agreement, or as otherwise permitted by that Act; we will not retain, use or disclose it outside our direct business relationship with you; and we will not combine it with personal information we receive from any other source, except as that Act permits. We understand these restrictions and will comply with them, and we will tell you if we determine we can no longer meet them.
09International transfers
Serravee processes personal data in the United States. Where personal data moves outside its region of origin, we will enter into the European Commission’s standard contractual clauses and the UK International Data Transfer Addendum with you, with the module, annexes and options completed for your transfer. Mail privacy@serravee.com and we will execute them.
We say “will enter into” rather than “are incorporated by reference” on purpose. Clauses without completed annexes are not a transfer mechanism, and we would rather hand you a real signed set than point at a sentence.
10Liability and governing law
The limitation of liability in the Terms of Service applies to this agreement, and the two together are a single cap rather than one each. This agreement is governed by the same law as those terms.
Questions about any of this?
Mail privacy@serravee.com and a person will answer. Security reviews go to security@serravee.com.