Privacy Policy
1. The controller
Blackhole Enterprise FZ-LLC (registered office: FOB 51646, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates; free zone licence number 47010494) — "Svada", "we".
Data protection contact: marton@blackholemedia.eu. We are not required to appoint a data protection officer under Article 37 GDPR; data protection enquiries are handled at the address above.
This notice is provided under Regulation (EU) 2016/679 (GDPR). We offer our service to customers established in the European Union, and our activity is therefore subject to the GDPR pursuant to Article 3(2).
2. Our dual role: when we are controller and when we are processor
We are the CONTROLLER for user accounts and the data needed to operate the service: email address, name, role, language, time zone, last activity, billing and contact details, enquiries submitted through website forms, in-app feedback, and usage and cost records.
We are a PROCESSOR for all personal data the Customer (your employer, the subscribing organisation) enters or generates in the system: call transcripts, notes, deals, prospect contacts, uploaded documents, and the analyses generated from them. For that data the Customer is the controller and we act on its instructions. Data subject requests concerning such data are best addressed to the Customer; we assist in fulfilling them.
The processing terms are set out in clause 10 of the Terms of Service, which constitutes the parties' data processing agreement under Article 28 GDPR.
3. What data we process
Account and organisation data: email address, optional name, role (rep/administrator), language, time zone, last-activity timestamp, the organisation's name and plan. We store no passwords — sign-in uses a single-use link sent by email.
Business data entered by the Customer: seller profile (what the organisation sells, and to whom), deals, prospect companies and contacts (name, title, role, notes), meetings and their call transcripts, and the outputs the system generates from them: briefs, debriefs, skill scores, coaching plans, deal strategy, draft emails and daily summaries.
Decision-maker profile: the system may produce a "suggested approach" for a contact (decision style, communication preference). It always appears as an inference, together with the quote or finding it derives from — never as a diagnosis or a statement of fact.
Research dossier: cited information about a prospect company and decision-maker, compiled from public web sources and licensed business databases. We do not use gated or login-required sources (such as LinkedIn) — the system blocks this structurally. We do not research private individuals (consumer deals).
Practice data: the text of roleplay sessions run against a simulated buyer, and the feedback on them. This is the user's own development data.
Transient data: an uploaded audio recording exists only for the duration of transcription; an uploaded document only for the duration of text extraction. Both are deleted immediately afterwards — only the transcript, or the extracted text, remains. In spoken practice, audio is not stored in either direction.
Inbound transcripts (optional): if the organisation enables it, call transcripts may arrive by email or by webhook from the organisation's own call-recording tool. They are matched to deals or wait in an Inbox for a human decision; discarding erases the content.
Operational data: error logs (technical identifiers, no content), rate-limit counters, per-organisation AI usage and cost records. Research cache: public, non-personal web responses, for at most 7 days.
4. Purposes and legal bases
Providing the service and performing the contract (creating and maintaining the account, operating the features, support): performance of a contract (Article 6(1)(b) GDPR), or — where the data subject is not the contracting party but, for example, an employee of the Customer — our legitimate interest (Article 6(1)(f)).
Handling quote and contact form submissions: steps prior to entering into a contract, at the data subject's request (Article 6(1)(b)).
Invoicing and accounting retention: compliance with a legal obligation (Article 6(1)(c)) and legitimate interest.
Security of the service, abuse and fraud prevention, troubleshooting, and measuring and improving service quality: legitimate interest (Article 6(1)(f)). We have carried out a balancing test; a summary is available on request.
Establishing, exercising or defending legal claims: legitimate interest (Article 6(1)(f)).
The legal basis for personal data contained in content uploaded by the Customer is determined by the Customer as controller — in that case we act as processor on its instructions.
5. Where data is stored and processed
The database runs on Neon, physically located in the AWS eu-central-1 (Frankfurt, Germany) region. The application runs on Vercel, pinned to the Frankfurt (fra1) region. Customer data therefore remains within the European Union both at rest and during processing.
Static assets (code, fonts, images) are served by Vercel's global content delivery network. These contain no customer data.
Transient file storage (audio, documents) uses Vercel Blob, for the duration of processing.
The exceptions — which specific sub-tasks leave the European Union — are listed in full in sections 6 and 7.
6. Processors we engage
Neon Inc. (USA; storage in the EU, Frankfurt) — database service. Required.
Vercel Inc. (USA; execution in the EU, Frankfurt) — application hosting, transient file storage, content delivery. Required.
Anthropic PBC (USA) — AI processing. To produce a brief, debrief or other output, the relevant context is sent to the Claude API and the output is written back to our EU database. The context may include transcript text, notes and the organisation's seller profile. Required: AI is the core function of the service. Under Anthropic's commercial terms, data sent through the API is not used to train models.
Resend, Inc. (a US company, with a European sending region) — delivery of sign-in links and notification emails. What it receives: the recipient's email address and the message. Required.
Tavily (USA) — web search. Optional: only where the organisation enables web research. What it receives: search terms and company identifiers. Never transcripts or customer data.
People Data Labs, Inc. (USA) — business contact enrichment. Optional: only where the organisation enables enrichment. What it receives: a company domain, or a name and company. Never transcripts. Not used for private individuals.
AssemblyAI (European endpoint) — transcription of audio recordings with speaker detection. Optional: only where a recording is uploaded. The recording is processed in the EU and deleted immediately once transcription completes or fails.
ElevenLabs (USA) — speech recognition and synthesis, solely for spoken practice. Optional. Practice content leaves the system; real customer data does not, unless the user speaks it. We store no audio in either direction.
Sentry (EU-region project) — technical error reports: error messages, stack traces, organisation and user identifiers. Cookies and request headers are stripped; transcripts, prompts and business content are never sent.
We update this list when it changes and notify contracted Customers at least 30 days in advance, in accordance with clause 10 of the Terms of Service.
7. Transfers to third countries
The primary place of storage and processing is the European Union. In addition, the US-established processors listed above (Anthropic, Resend, Tavily, People Data Labs, ElevenLabs), and the US parent companies of Neon and Vercel, may access data to the extent necessary to provide the service.
These transfers rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 or, where the provider is a certified participant in the EU–US Data Privacy Framework, on the Commission's adequacy decision. We have data processing agreements in place with these providers.
The operator of Svada is a company incorporated in the United Arab Emirates. Administrative access (operations, troubleshooting, support) may therefore take place from outside the European Union. Such access is restricted to the narrowest possible group, logged, and carried out solely for the purpose of providing the service.
The European Commission has not adopted an adequacy decision in respect of the United Arab Emirates. We apply the same safeguards as above to such access, and the provisions of the data processing agreement with contracted Customers govern. Documentation of the transfer mechanism is available on request.
8. How long we keep data
The Customer's content is retained until the Customer deletes it or the contract ends. Deleting a deal permanently removes its meetings and transcripts, briefs, debriefs, skill assessments, research dossier and deal strategy — and also the prospect's company and contact records, including the decision-maker profile and enrichment data, where no other deal references them.
Deactivating a user: sign-in is blocked immediately and existing sessions are terminated. Their historical contributions (assessments) remain with the organisation.
After the contract ends we retain data for 30 days for export purposes, then delete it permanently, unless retention is required by law.
Audio recording: deleted immediately once transcription completes or fails. Uploaded document file: deleted immediately after text extraction. Research cache: at most 7 days. Rate-limit counters: until the relevant window expires. Error reports: per Sentry's retention period (currently 90 days).
Invoicing and accounting records: for the retention period required by applicable accounting law.
9. Automated assessment and profiling
The service produces automated analysis of call transcripts, including scoring a salesperson's skills, and may produce a suggested approach for a prospect's decision-maker. This constitutes profiling within the meaning of the GDPR.
The system does not take decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect them. The assessment is decision-support information: every resulting decision — including employment decisions — is taken by a human at the Customer.
The logic of the assessment: the system analyses the uploaded transcript against a sales methodology framework and ties its observations to verbatim quotes from the text. Where there is no evidence, the system flags an open question rather than an inference. A separate verification step checks the generated text against the source material.
Data subject rights in relation to the assessment of salespeople — including the right to information and to object — are provided by the Customer as employer and controller; we assist in this.
10. Security
All data transmission uses an encrypted channel (TLS), with mandatory HTTPS redirection and HSTS. The database is encrypted at rest.
Because sign-in is passwordless, we store no passwords. Sessions are database-backed and re-checked on every request, so revoking access takes effect immediately.
Every query is scoped to the organisation, and this is enforced automatically at the code level. A salesperson sees only their own deals; an administrator sees their own organisation — never another organisation's data. There is no self-service organisation creation.
Abuse protections: rate limiting on costly operations and on sign-in links; sign-in responses that are identical regardless of account status; server-side request forgery (SSRF) protection on the research fetcher; strict security response headers (CSP, HSTS, framing denied); and prompt-injection defence, which presents transcripts, web pages and documents to the AI as data rather than as instructions.
We also state openly what we have not done: there is currently no independent penetration test and no formal certification (such as ISO 27001 or SOC 2). Our security methodology and its limits are published in a separate public document.
In the event of a personal data breach we follow a documented procedure: we notify controller Customers without undue delay and, where we are the controller, meet the notification and communication obligations under Articles 33–34 GDPR.
11. Cookies
We use only strictly necessary cookies: a session cookie (keeps you signed in), a cross-site request forgery protection cookie, and a language preference cookie.
We use no analytics, advertising, social media or other tracking cookies, and run no third-party tracking code. We therefore display no cookie consent banner: under the applicable electronic communications rules, strictly necessary cookies do not require consent.
12. Your rights
You have the right to: be informed about processing concerning you and obtain a copy of your data; have inaccurate data corrected; have your data erased; have processing restricted; object to processing based on legitimate interest; and receive the data you provided in a portable format.
Requests may be submitted to marton@blackholemedia.eu. We fulfil requests within one month at the latest; for complex or numerous requests this may be extended by two months, of which we will inform you. Fulfilling a request is free of charge.
Where a request concerns data for which we are a processor (content uploaded by the Customer), we forward it to the controller Customer and assist in fulfilling it. In that case responding is the Customer's responsibility.
You may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. In Hungary: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11, postal address: 1363 Budapest, Pf. 9, ugyfelszolgalat@naih.hu, +36 1 391 1400. You may also apply to the courts.
13. Children's data
The service is aimed at business users and is not directed at persons under 18. We do not knowingly collect data concerning children. If we become aware that such data has entered the system, we delete it.
14. Changes to this notice
We update this notice as needed. We notify contracted Customers of material changes by email at least 30 days before they take effect; the version in force is always available on this page, with its effective date.