Data Processing Agreement
Last updated: 22 June 2026
1. Parties & scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller", "you") and Selda Oy, business ID 3546628-1, Viipurinkatu 12 L 122, 00510 Helsinki, Finland ("Processor", "Selda"). It applies where Selda processes personal data on your behalf in connection with the service (your "campaign data": leads, messages, replies, results). It governs processing under the EU General Data Protection Regulation (GDPR) and Finnish data protection law. If you require a separately signed DPA, contact [email protected].
For Selda's own business contact database, Selda acts as an independent controller as described in the Privacy Policy; that processing is outside this DPA.
2. Subject matter, duration, nature & purpose
Selda processes personal data to provide the service: discovering and enriching business contacts, generating and sending outreach, handling replies, scheduling meetings, and related analytics. Processing lasts for the term of your subscription and the deletion period below. The nature of processing includes collection, storage, organization, use, transmission, and deletion by automated means.
3. Categories of data & data subjects
- Data subjects: your prospects and contacts, recipients of your outreach, and your own users.
- Personal data: business contact details (name, job title, work email, company), message content, engagement and reply data, and meeting details. No special categories of data are intended to be processed.
4. Roles & instructions
You are the controller and Selda is the processor for campaign data. Selda processes such personal data only on your documented instructions, which include the instructions given through your use of the product, unless required to act otherwise by EU or Finnish law (in which case Selda will inform you unless legally prohibited). You are responsible for ensuring you have a lawful basis for the processing and that your instructions comply with applicable law.
5. Confidentiality
Selda ensures that persons authorized to process personal data are bound by confidentiality obligations and process the data only as needed to provide the service.
6. Security
Selda implements appropriate technical and organizational measures under GDPR Article 32, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, access logging, and EU-based primary storage. Measures are reviewed and adapted as risks evolve.
7. Sub-processors
You authorize Selda to engage sub-processors to provide the service. Current categories include cloud infrastructure (Convex, Vercel), authentication (Clerk), email delivery (Mailgun), payments (Stripe), AI model providers, lead discovery/enrichment providers, and social-channel connection partners, as listed in the Privacy Policy. Sub-processors are bound by data-protection obligations no less protective than this DPA. Selda will reflect material changes to its sub-processors in the Privacy Policy; if you reasonably object to a new sub-processor on data-protection grounds, contact [email protected].
8. International transfers
Primary storage is in the EU. Where personal data is transferred outside the EEA (e.g. to certain AI or authentication providers), Selda relies on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework as the transfer mechanism.
9. Data subject requests
Taking into account the nature of the processing, Selda will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR concerning your campaign data. If a data subject contacts Selda directly regarding your campaign data, Selda will refer them to you where appropriate.
10. Breach notification
Selda will notify you without undue delay after becoming aware of a personal data breach affecting your campaign data, and will provide information reasonably available to assist you in meeting your own notification obligations under GDPR Articles 33-34.
11. Assistance & audits
Selda will assist you, taking into account the nature of processing and information available to Selda, with your obligations under GDPR Articles 32-36 (security, breach notification, and data protection impact assessments). Selda will make available information necessary to demonstrate compliance with this DPA and, on reasonable prior written request and subject to confidentiality, will respond to reasonable audit inquiries no more than once per year.
12. Return & deletion
On termination of your account, Selda will delete your campaign data within 30 days, except where retention is required by law. You can export or request your data before deletion.
13. Liability & precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails. This DPA is governed by the laws of Finland.
Contact
Selda Oy, Viipurinkatu 12 L 122, 00510 Helsinki, Finland · [email protected] · [email protected].