1. Parties & roles
The Customer (the entity that registered the Sovvento account) is the data controller for the personal data of its staff, contractors and named representatives processed through the platform. Sovvento is the data processor for that data and a joint or independent controller for the limited account-administration and security-monitoring data described in the Privacy notice.
2. Subject matter, duration, nature & purpose
Sovvento processes Customer Personal Data for the duration of the subscription, plus any retention periods imposed by accounting or AML law. The nature of processing is hosting, indexing, scoring, drafting, and audit-logging. The purpose is to deliver the matching and application-drafting service contracted under the Terms of Service.
3. Categories of data & data subjects
- Account identifiers — work email and login metadata of named seats.
- Company profile — legal name, registration number, VAT, NACE, headcount, turnover, founded year, addresses, website.
- Project and team data — text the customer enters about projects, team CVs, value proposition and prior funding history.
- Funder-portal correspondence — references the customer chooses to upload (e.g. award letters).
- Operational logs — IP addresses, user-agent strings and request metadata necessary for security and abuse monitoring.
Data subjects: the Customer’s authorised users and any individuals named in materials the Customer uploads (typically founders, team members and points of contact).
4. Sub-processors
The Customer authorises the following sub-processors, each bound by a written contract that imposes data-protection obligations equivalent to this DPA:
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Auth + Postgres hosting | EU (Frankfurt) |
| Google Cloud Run | API and worker compute | EU (europe-west3) |
| Google Cloud Run (us-central1) | Cold rollback only: sovvento-api and sovvento-worker-svc, min instances 0 | USA (Iowa) |
| Artifact Registry | Container images for Cloud Run | us-central1 |
| Cloud Scheduler | Job control plane. Live jobs are in us-central1 and europe-west1; europe-west3 currently has 0 jobs until they are recreated in Frankfurt. | us-central1 + europe-west1 |
| Vercel | Web frontend hosting | EU edge regions |
| Stripe | Subscription billing & invoicing | Ireland (Stripe Payments Europe) |
| Resend | Transactional email | EU |
| OpenAI | Programme and profile embeddings | USA, transferred under SCCs |
| OpenRouter | Optional LLM routing when the Customer supplies their own key | EU-routed where possible; SCCs otherwise |
| Anthropic | Underlying LLM model when selected via the Customer’s key | USA, transferred under SCCs |
We will give the Customer at least 30 days’ notice (via the dashboard and email) before adding or replacing a sub-processor. If the Customer reasonably objects on data-protection grounds, the Customer may terminate the subscription with pro-rated refund of unused prepayments.
5. International transfers
Customer Personal Data is stored at rest in the European Economic Area (Supabase Postgres in Frankfurt). Primary API and worker compute run on Google Cloud Run in europe-west3 (Frankfurt). A cold us-central1 Cloud Run pair (sovvento-api / sovvento-worker-svc, min instances 0) is retained only as rollback. Container images live in Artifact Registry us-central1. Cloud Scheduler’s control plane is us-central1 and europe-west1; no beat jobs currently run in europe-west3. Model providers may still see prompt or embedding payloads outside the EEA: OpenAI embeddings always do; drafting via a Customer-supplied OpenRouter or Anthropic key may do so depending on the model they choose. Those transfers rely on the European Commission’s 2021 Standard Contractual Clauses, together with the supplementary measures recommended by the EDPB (encryption in transit, limited data minimisation in prompt payloads, no use of customer data for model training).
6. Security measures
- TLS 1.2+ for all data in transit.
- Postgres encryption at rest via Supabase.
- Row-level security with SECURITY DEFINER helpers; per-org isolation enforced at the database tier, not just the application tier.
- Principle-of-least-privilege service accounts; service-role credentials are never exposed to browsers.
- Audit logging of all state-changing API calls; logs retained for 90 days.
- Quarterly access review of internal staff with admin or service-account credentials.
- Documented incident-response runbook; security incidents that meet the GDPR notification threshold are reported to the Customer without undue delay and in any event within 72 hours of confirmation.
7. Data-subject requests
We will assist the Customer in responding to access, rectification, erasure, restriction and portability requests within the timeframes required by Articles 15-22 GDPR. Authorised users can self-serve access and erasure from the dashboard privacy page. For requests outside that scope, contact privacy@sovvento.eu.
8. Audit rights
The Customer may, at most once per twelve-month period and at its own cost, request a written security questionnaire and a copy of our most recent third-party security report. On-site audits are available to Agency Plus customers under a separate confidentiality agreement and with reasonable notice.
9. Return & deletion
On termination of the subscription, the Customer may export its data from the dashboard for 30 days. After that window we delete Customer Personal Data within 90 days, except for records required by accounting or AML law which are retained for the minimum legally required period.
10. Contact
Data protection enquiries: privacy@sovvento.eu. Sovvento is registered with the relevant supervisory authority of its place of establishment; details are available on request.