Data processing terms

The processor obligations that apply when you use this service as a business customer. Reviewed 18 August 2026.

Last updated · Written and reviewed by Jonatan Tensetti · Tensetti Tools

1. Parties and role

These terms form a data processing agreement under Article 28 GDPR between you (the controller) and Jonatan Tensetti, Swedish sole trader, organisation number 19910516-5253 (the processor). They apply automatically to every paid account — no signature is required. A countersigned copy is available on request from jonatan@tensetti.se.

2. Subject matter and duration

The processor hosts readiness assessments, entitlements and account records for the duration of your account, and for the statutory retention periods set out in the privacy policy thereafter.

3. Nature and purpose

Storing account identities, granting and verifying access to purchased deliverables, and retaining structured assessment answers so a result can be reopened. The technical writing checker performs its analysis in your browser; document content is not processed by the processor at all.

4. Categories of data and data subjects

Data subjects: your employees and named contacts who use the service. Categories: business contact data (email, name), authentication identifiers, structured assessment answers and purchase records. Special categories of data and criminal-offence data must not be submitted. Do not enter live incident detail, credentials or personal data of third parties.

5. Instructions

The processor processes personal data only on your documented instructions, which include these terms and your use of the service. If an instruction appears to infringe the GDPR, the processor will tell you before acting.

6. Confidentiality

Access is limited to the sole trader named above and to sub-processors under written confidentiality obligations.

7. Security measures

  • TLS in transit and encryption at rest for the managed database.
  • Row-level security so a signed-in user can read only their own records.
  • Access to purchased deliverables granted only after the payment provider confirms payment.
  • No collection of free-text evidence, no file uploads and no answer values in logs.
  • Least-privilege service credentials, rotated when personnel or providers change.
  • Automated daily backups of the managed database, retained by the provider.

8. Sub-processors

You give general authorisation for the sub-processors below. You will be told about any intended addition or replacement through the corrections page at least 30 days in advance, and may object on reasonable data protection grounds.

CategoryPurposeLocation
Application hosting and edge deliveryServing the site and server functionsEU / global edge
Managed database and authenticationAccounts, entitlements and purchase recordsEU (Ireland)
Payment providerCard processing, invoicing, tax and fraud preventionEU / US (SCCs)
Transactional email providerReceipts, access links and support repliesEU

9. International transfers

Data is stored in the EU. Any transfer outside the EEA relies on the European Commission's standard contractual clauses together with the relevant provider's supplementary technical measures.

10. Assistance to the controller

The processor assists you with data subject requests, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available. Requests are answered within two working days.

11. Personal data breach

The processor notifies you without undue delay and at the latest within 48 hours of becoming aware of a personal data breach affecting your data, with the information needed for your own Article 33 notification.

12. Deletion and return

On termination, account and assessment data is deleted within 30 days, except records the processor must keep to satisfy Swedish accounting law. You can export your purchased deliverables at any time before deletion.

13. Audit

The processor makes available the information needed to demonstrate compliance and allows for audits, including inspections, conducted by you or an auditor you mandate, with reasonable notice and no more than once a year unless a breach has occurred.

14. Liability and precedence

These terms supplement the terms of service. Where they conflict on data protection matters, these terms prevail.