Security
Security
FEIM Sales is built so your data and your customers' data stay protected — not bolted on afterwards, but from the ground up.
Where data is stored
All FEIM Sales data is stored in Supabase's data centre in Helsinki, within the EU. Data does not leave the EU/EEA area in normal use.
Encryption
All traffic between the browser and the server is encrypted (TLS/HTTPS). Data is also encrypted at rest in the database.
User isolation
Each account's data is isolated at the database level (Row Level Security). One customer can never see another customer's leads or data — the rule is enforced in the database, not just in application code.
Backups
Automatic daily backups are taken of the database.
Access control
Sign-in happens through an encrypted authentication service. We never see or store your password in plain text.
Subcontractors
We use a limited set of trusted subcontractors to deliver the service. Full list: Subcontractors.
Security reports
If you find a security vulnerability, report it to riku@feim.fi. We respond within 48 hours.
Questions? riku@feim.fi
Who is responsible for what (GDPR roles)
When you use FEIM Sales, two different roles apply side by side:
You (our customer) are the data controller for the data you enter into FEIM Sales — for example leads, contacts, and notes. You decide what data you collect and why. FEIM acts as the processor: we store and process data on your behalf; we do not use it for our own purposes.
FEIM is the data controller for our own customer relationship data — your account details, billing, and sign-in information. We describe this in more detail in our privacy policy.
In practice: if a data subject (for example someone on your lead list) exercises their GDPR rights, contact riku@feim.fi — we will help you fulfil the request in our role as processor.
Subcontractors
FEIM Sales uses the following subcontractors to deliver the service. We do not add or change subcontractors without updating this page.
| Subcontractor | Purpose | Location | Data processed |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Helsinki, Finland (EU) | Leads, contacts, account data |
| Vercel | Application hosting and CDN | Global edge network (no personal data stored permanently) | No personal data stored permanently |
| Paddle | Payment processing (Merchant of Record) | UK / global | Name, email, payment data (tokenised) |
| Supabase Auth | Email notifications and invites | EU | Email address, message content |
We do not sell or rent user data to third parties for marketing purposes.
Data Processing Agreement (DPA)
If you need a Data Processing Agreement as a FEIM Sales customer, you can request one below. We will send you a signed copy by email.
DPA template (draft)
This Data Processing Agreement ("Agreement") supplements the FEIM Sales service agreement/terms of use and governs the processing of personal data under the EU General Data Protection Regulation (GDPR).
Data controller: Customer (FEIM Sales subscriber). Processor: Feim, Business ID 3585947-2, riku@feim.fi
- Purpose: This agreement sets the terms under which the Processor processes personal data on behalf of the Controller in connection with use of FEIM Sales.
- Processing: The Processor processes personal data only to deliver FEIM Sales features — lead and contact storage, pipeline management, calendar and reminders, and optional AI agent integration if the Controller has enabled it.
- Data categories: name, contact details, company, notes, and other data entered by the user. Data subjects: the Controller's leads, contacts, and customers.
- Processor obligations: process data only per documented instructions; ensure confidentiality; implement appropriate security measures; assist with data subject rights and breach notification; delete or return data when the agreement ends.
- Sub-processors: listed at feimsales.com/security. New sub-processors are announced in advance; the Controller may object on reasonable grounds.
- International transfers: data is processed mainly in the EU/EEA. Any transfer outside the EU/EEA relies on appropriate safeguards (e.g. EU Standard Contractual Clauses).
- Security: GDPR Article 32 measures — encryption in transit and at rest, per-user data isolation (Row Level Security), access control, and regular backups.
- Breach notification: the Processor notifies the Controller without undue delay, within 72 hours of becoming aware of a breach.
- Audit rights: the Controller may request information on compliance at reasonable intervals. On-site audits are agreed separately.
- Data return and deletion: when the agreement ends, the Processor deletes or returns all personal data within 30 days at the Controller's choice, unless law requires longer retention.
- Term: in force for as long as the FEIM Sales service agreement is in force.
Date and signatures: _______________________
