Privacy Policy
1. Introduction
This privacy policy describes how personal data is processed in relation to the DamnGoodSales cloud service ("Service") in accordance with the EU General Data Protection Regulation (GDPR). The Service is intended for business and professional use (SaaS).
2. Data Controller
The controller is Riku Miettinen. For privacy and data subject requests, contact hello@feim.fi.
3. Categories of Personal Data
The Service may process, for example, the following data:
- Service users: name, email, account identifiers, logs, and settings.
- Customer and sales data stored by the user in the Service (e.g., leads, contact information, notes, call data), depending on what the user enters.
- Payment-related information: data processed by the payment provider (Paddle) according to their terms.
4. Purposes and Legal Bases
Personal data is processed for the following purposes:
- Contract — providing the Service, managing user accounts, and customer relationship management.
- Legitimate Interest — service development, security, abuse prevention, and troubleshooting.
- Legal Obligation — for example accounting and tax obligations where applicable.
- Consent — when consent is required by law (e.g., certain marketing communications, if separately requested).
5. Data Sharing and Processors
Data may be transferred to trusted subcontractors enabling the technical operation of the Service (e.g., cloud infrastructure). Any transfers outside the EU/EEA are carried out with GDPR-compliant safeguards (e.g., standard contractual clauses), unless an adequacy decision applies.
Payments are processed through Paddle.com Market Limited; Paddle acts as the Merchant of Record under its own terms and processes billing and payment data.
A full list of subprocessors is available on our security page.
5b. Who is responsible for what (GDPR roles)
When you use DamnGoodSales, two different roles apply side by side:
You (our customer) are the data controller for the data you enter into DamnGoodSales — for example leads, contacts, and notes. You decide what data you collect and why. DamnGoodSales acts as the processor: we store and process data on your behalf; we do not use it for our own purposes.
DamnGoodSales is the data controller for our own customer relationship data — your account details, billing, and sign-in information. We describe this in sections 2–3 of this policy.
In practice: if a data subject (for example someone on your lead list) exercises their GDPR rights, contact riku@feim.fi — we will help you fulfil the request in our role as processor.
6. Retention Periods
Personal data is retained only as long as necessary for the purposes described in this policy, unless otherwise required by law. Users may request deletion of their account and data where applicable; some data may need to be retained to meet legal obligations.
7. Data Subject Rights (GDPR)
You have the right to request:
- access to your data,
- rectification or erasure,
- restriction of processing,
- to object to processing based on legitimate interests,
- data portability where applicable,
- to withdraw consent where processing is based on consent.
You can submit requests to hello@feim.fi. You also have the right to lodge a complaint with a supervisory authority (in Finland, the Data Protection Ombudsman).
8. Security
We use technical and organizational measures to protect personal data, such as encrypted traffic and access control. However, no system is entirely risk-free.
9. Changes
We may update this policy. Significant changes will be communicated through the Service or by email where applicable.
