Data processing
How we hold data on your behalf.
When your team records results in Ateliva, you decide what is measured and we hold it for you. These are the terms for that, and the list of everyone else involved.
In one line. You are the controller, we are the processor, four subprocessors are listed below, and the CRMs you connect yourself are not among them.
What this is
These data processing terms apply whenever Swepth Oy holds personal data on behalf of a customer, which is what happens with everything inside a workspace. They form part of the terms and are Article 28 terms under the GDPR.
If your organisation needs a signed copy on your own paper, write to hello@ateliva.com and we will sign one. This page is the standard position; it is not legal advice, and if the stakes are high, have your own adviser read it.
Who is what
The organisation that owns the workspace is the controller. It decides what is measured, about whom, and for how long.
Swepth Oy is the processor. We hold that data and act on the controller's instructions.
For our own account, billing and business records we are a controller in our own right, and the privacy policy covers that instead.
What is processed
| Subject matter | Providing the Ateliva service to the controller |
| Duration | While the workspace exists, and until deletion is asked for |
| Nature and purpose | Recording, storing, organising, calculating and displaying measured work |
| Categories of data | Names, work email addresses, roles and team membership; results, targets, rankings, competitions and work sessions; notes a person writes on a result; the identifiers of records in a connected CRM |
| Data subjects | The controller's own people: employees, contractors, and anyone else whose work the controller measures |
Ateliva does not ask for and has no place to put special category data. Do not put any in it.
Instructions
We process the data only on the controller's documented instructions. Using the product is an instruction, and so is a written request to us. If we think an instruction breaks data protection law, we will say so rather than carry it out quietly.
Confidentiality
Everyone at Swepth Oy who can reach customer data is bound to keep it confidential. Access is limited to the people who need it to run and support the service.
Security measures
The measures in place under Article 32:
- tenant isolation enforced in the database itself, so one workspace cannot read another's rows even if the application asks it to
- encryption in transit, and encryption at rest for the database
- passwords and API keys stored only as hashes; CRM tokens held in a vault no browser role can read
- an audit history of who changed what, which cannot be edited
- rate limits on sign-in, on email and on the public API
- least privilege for staff access, and secrets held outside the codebase
We hold no security certification and do not claim one.
Subprocessors
The controller authorises these subprocessors:
| Who | What they do | Where |
|---|---|---|
| Supabase | The database, sign-in and file storage | Ireland (EU) |
| Vercel | Running and delivering the application | Stockholm (EU) for server code; a global network for static files |
| Stripe | Subscriptions, invoices and payment | Ireland, with group companies in the United States |
| Resend | Transactional email: verification, password reset, invitations, the trial reminder | United States |
Before adding or replacing one, we will update this page and email workspace owners at least 30 days beforehand. A controller who objects on reasonable data protection grounds may cancel without penalty for the remainder of the period.
What is not a subprocessor
HubSpot, Pipedrive and Zapier are not our subprocessors. A customer connects their own account with one of those vendors, under their own agreement with them. Ateliva reads from it because the customer asked it to; we do not engage those vendors, we do not send them the workspace's data, and their handling of the customer's data is between the customer and them.
Calling them subprocessors would be tidier and would be wrong.
Helping with requests from people
If somebody asks us directly about data inside a workspace, we tell them to ask the controller and let the controller know. We will help the controller answer — access, correction, deletion, portability, restriction — using the product where it can and by hand where it cannot, and we do not charge for reasonable help.
If something goes wrong
If we become aware of a personal data breach affecting a customer's data, we will tell the controller without undue delay and in any case within 48 hours of becoming aware, with what we know, what we are doing, and what we advise. We will not wait until we have the whole picture before saying anything.
Return and deletion
A workspace's data stays for as long as the workspace does, including after a subscription is cancelled: performance history is not deleted for non-payment.
The controller can export results and history to CSV at any time. When the controller asks for deletion, we confirm the scope, give a chance to export first, and then delete, aiming to finish within 30 days. Backups roll off on their own schedule and are not restored to recover deleted data.
Information and audits
We will give the controller the information reasonably needed to show that these terms are being met. For an audit, we would rather answer questions and share what we have than host an inspection, and we will agree something workable if that is not enough.
Transfers
The application and the database run inside the EU. Transactional email goes through a provider in the United States, and Stripe contracts through Ireland with group companies in the United States. Those transfers rely on the European Commission's standard contractual clauses.
Who to write to
hello@ateliva.com, marked for the attention of data protection. There is no separate data protection officer: Ateliva is small enough that the same people answer.
Last updated 9 September 2026
Ateliva is operated by Swepth Oy, Business ID 3619574-3, Finland. Questions about this page go to hello@ateliva.com.