Data processing terms
The processor obligations that apply when you use this service as a business customer. Reviewed 18 August 2026.
Last updated · Written and reviewed by Jonatan Tensetti · Tensetti Tools
1. Parties and role
These terms form a data processing agreement under Article 28 GDPR between you (the controller) and Jonatan Tensetti, Swedish sole trader, organisation number 19910516-5253 (the processor). They apply automatically to every paid account — no signature is required. A countersigned copy is available on request from jonatan@tensetti.se.
2. Subject matter and duration
The processor hosts readiness assessments, entitlements and account records for the duration of your account, and for the statutory retention periods set out in the privacy policy thereafter.
3. Nature and purpose
Storing account identities, granting and verifying access to purchased deliverables, and retaining structured assessment answers so a result can be reopened. The technical writing checker performs its analysis in your browser; document content is not processed by the processor at all.
4. Categories of data and data subjects
Data subjects: your employees and named contacts who use the service. Categories: business contact data (email, name), authentication identifiers, structured assessment answers and purchase records. Special categories of data and criminal-offence data must not be submitted. Do not enter live incident detail, credentials or personal data of third parties.
5. Instructions
The processor processes personal data only on your documented instructions, which include these terms and your use of the service. If an instruction appears to infringe the GDPR, the processor will tell you before acting.
6. Confidentiality
Access is limited to the sole trader named above and to sub-processors under written confidentiality obligations.
7. Security measures
- TLS in transit and encryption at rest for the managed database.
- Row-level security so a signed-in user can read only their own records.
- Access to purchased deliverables granted only after the payment provider confirms payment.
- No collection of free-text evidence, no file uploads and no answer values in logs.
- Least-privilege service credentials, rotated when personnel or providers change.
- Automated daily backups of the managed database, retained by the provider.
8. Sub-processors
You give general authorisation for the sub-processors below. You will be told about any intended addition or replacement through the corrections page at least 30 days in advance, and may object on reasonable data protection grounds.
| Category | Purpose | Location |
|---|---|---|
| Application hosting and edge delivery | Serving the site and server functions | EU / global edge |
| Managed database and authentication | Accounts, entitlements and purchase records | EU (Ireland) |
| Payment provider | Card processing, invoicing, tax and fraud prevention | EU / US (SCCs) |
| Transactional email provider | Receipts, access links and support replies | EU |
9. International transfers
Data is stored in the EU. Any transfer outside the EEA relies on the European Commission's standard contractual clauses together with the relevant provider's supplementary technical measures.
10. Assistance to the controller
The processor assists you with data subject requests, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available. Requests are answered within two working days.
11. Personal data breach
The processor notifies you without undue delay and at the latest within 48 hours of becoming aware of a personal data breach affecting your data, with the information needed for your own Article 33 notification.
12. Deletion and return
On termination, account and assessment data is deleted within 30 days, except records the processor must keep to satisfy Swedish accounting law. You can export your purchased deliverables at any time before deletion.
13. Audit
The processor makes available the information needed to demonstrate compliance and allows for audits, including inspections, conducted by you or an auditor you mandate, with reasonable notice and no more than once a year unless a breach has occurred.
14. Liability and precedence
These terms supplement the terms of service. Where they conflict on data protection matters, these terms prevail.