Data Processing Addendum

Version 1.1 · Effective 9 September 2026

This Data Processing Addendum ("Addendum") forms part of the Terms of Use between you ("Customer") and Viimos Oy, a limited liability company incorporated in Finland (Business ID 3612414-4, registered office Espoo), trading as Valuepoint Labs ("we", "us", "our"). It applies where we process personal data contained in the content you submit to the Service, and it takes effect when you accept the Terms — no signature is required. Where this Addendum conflicts with the Terms, this Addendum governs for that processing.

Terms used here have the meaning given in the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"). "Customer Content" means the material you submit to the Service: the business cases you create, and the documents, text and web addresses you upload, paste or give us to read.

1. Roles of the parties

For personal data contained in Customer Content, you are the controller and we are your processor. That is what this Addendum governs.

We are an independent controller, not your processor, for the data described in Sections 1 and 2 of the Privacy Policy: your account data, the names and business email addresses you enter in order to share a business case, the record of who opened a shared case, and the usage and technical data the Service generates. The Privacy Policy governs those, and this Addendum does not apply to them.

2. Subject matter, duration, nature and purpose

Subject matter. Processing of personal data contained in Customer Content.

Duration. For as long as your account is active, followed by the retention periods set out in Section 4 of the Privacy Policy.

Nature and purpose. Hosting, storage, display and AI-assisted analysis of Customer Content in order to produce business cases and the documents derived from them; and transmission of Customer Content to the sub-processors in Annex I for those purposes and no others.

3. Types of personal data and categories of data subject

Types of personal data. Business contact details — name, business email address, job title and employer — and any other personal data you choose to include in Customer Content, subject to the prohibition in Section 5.1 of the Terms.

Categories of data subject. Your personnel; personnel of your customers and prospects named in a business case; and the people you invite to read, comment on or co-edit a case.

Special categories. None. Section 5.1 of the Terms prohibits submitting special categories of personal data and the other high-risk categories listed there, and the Service is not designed to process them.

4. Processing on your instructions

We process personal data contained in Customer Content only on your documented instructions, which comprise the Terms, this Addendum, and your use of the features of the Service, including any instruction to transfer data to a third country. We will tell you if we believe an instruction infringes the GDPR or other applicable data protection law.

We do not sell personal data, do not use Customer Content for advertising, and do not use Customer Content to train AI models. Our AI sub-processor is contractually barred from training its models on it.

5. Confidentiality

Access to Customer Content is limited to those personnel who need it to operate, support and secure the Service, and every person with access is bound by a duty of confidentiality that survives the end of their engagement.

6. Security

We implement the technical and organisational measures set out in Annex II, which are appropriate to the risk within the meaning of Article 32 GDPR. We keep them under review and may update them, provided the level of protection is not reduced.

7. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex I. We impose data protection obligations on each of them by contract that are no less protective than those in this Addendum, and we remain fully liable to you for their performance.

We will publish an updated Annex I on this page at least 30 days before a new or replacement sub-processor begins processing Customer Content, and will notify you at the email address on your account. You may object on reasonable data protection grounds within those 30 days. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of any fees paid for the unused remainder of your term.

8. Assisting with data subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in responding to requests from data subjects. The Service lets you read, correct, export and delete Customer Content directly. Where a request needs our help, write to [email protected] and we will respond within 30 days.

If a data subject contacts us directly about Customer Content, we will not respond substantively; we will pass the request to you.

9. Personal data breaches, impact assessments

We will notify you of a personal data breach affecting Customer Content without undue delay and, where feasible, within 48 hours of becoming aware of it, with the information then available to us and further information as it emerges. Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with a supervisory authority.

10. Deletion or return

On termination of your account, and at your choice, we will delete Customer Content or return it to you within 30 days, unless applicable law requires us to retain it. Encrypted backup copies expire on the schedule stated in Section 4 of the Privacy Policy. The consent record and the enforcement record described in that Section survive, because they are the evidence that what we did was permitted; neither contains Customer Content.

11. Audit

We will make available to you the information necessary to demonstrate compliance with Article 28 GDPR. In practice, we will answer a reasonable written questionnaire once in any twelve-month period. We will additionally allow for and contribute to an audit or inspection conducted by you or an auditor you mandate where a supervisory authority requires it, or following a personal data breach affecting your Customer Content. Audits are at your expense, on reasonable prior notice, during business hours, and subject to confidentiality.

12. International transfers

Some sub-processors listed in Annex I process data outside the European Economic Area. For those transfers we rely on the European Commission's Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), which are incorporated into this Addendum by reference. Annex I and Annex II of this Addendum populate the corresponding annexes of those Clauses; the optional docking clause applies; the governing law is the law of Finland and the competent supervisory authority is the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu). For transfers of UK data we rely on the UK International Data Transfer Addendum to those Clauses.

13. Liability and order of precedence

The limitations and exclusions of liability in the Terms apply to claims under this Addendum. In the event of a conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the rest of the Terms.

Annex I — Sub-processors

The sub-processors we engage to process Customer Content, current as of the effective date above:

Sub-processor Purpose Location Transfer mechanism
Anthropic, PBC AI generation and analysis of submitted content United States Standard Contractual Clauses
Railway Corp. Application hosting and database United States Standard Contractual Clauses
Stripe, Inc. and Stripe Payments Europe, Ltd. Payments, billing and tax European Union and United States Standard Contractual Clauses
Postmark (ActiveCampaign, LLC) Transactional email United States Standard Contractual Clauses
Cloudflare, Inc. (R2) Off-site database backups, encrypted by us before upload European Union Not applicable — stored in the EU
Functional Software, Inc. (Sentry) Error monitoring European Union Not applicable — stored in the EU

Google and LinkedIn act as independent controllers when you choose to sign in with them, and Google Fonts and jsDelivr deliver typefaces and icons to your browser. None of them receives Customer Content, so none is a sub-processor under this Addendum. Section 6 of the Privacy Policy describes each.

Annex II — Technical and organisational measures

The measures we apply under Section 6, as at the effective date above:

Area Measure
Encryption in transit HTTPS on every connection, with HTTP Strict Transport Security enforced in production. Traffic between the Service and its sub-processors is encrypted in transit.
Encryption at rest Passwords are stored as bcrypt hashes at cost factor 12. Password reset and email verification tokens are stored hashed. Off-site backups are encrypted by us with AES-256-GCM before they are uploaded, so the storage provider holds only ciphertext.
Access control Every request for a business case, a shared resource or an organisation record is authorised at a single choke point against the requester's role. Sharing grants are read-only or comment-only; editing requires an explicit co-editor grant and a single-writer lock. Administrative access is limited to named accounts.
Authentication Session cookies are HTTP-only, secure in production and same-site. Optional time-based one-time-password two-factor authentication. A password change ends every other session and notifies both addresses involved. Sign-in is rate limited per address and per account, and account creation is rate limited per network address and per email domain.
Segregation Every record is scoped to an owning account and organisation, and cross-account access is possible only through an explicit grant made by the owner.
Availability and resilience Daily encrypted database snapshots to off-site storage in the European Union, with a 60-day expiry.
Logging and monitoring Application errors are monitored in the European Union. Administrative acts that restrict a workspace are recorded in an append-only ledger with the actor, the time and the reason. Usage records are retained for 180 days and then deleted.
Data minimisation Section 5.1 of the Terms prohibits submitting special categories and other high-risk personal data. Records of activity on a shared business case are erased on the schedule in Section 4 of the Privacy Policy.
Personnel Access is limited to personnel who need it to operate, support and secure the Service, each under a duty of confidentiality.

Contact

Questions about this Addendum, and requests under Sections 8, 10 and 11, go to [email protected]. It reaches Viimos Oy, the party identified at the top of this page.