Legal & Trust Center | SalesBond

Legal & Trust Center

Find the terms, privacy information, data-processing terms and trust documentation governing SalesBond.

Legal

{{ d.title }} {{ d.desc }} {{ d.dateLine }} View document →

Trust & Compliance

{{ d.title }} {{ d.desc }} {{ d.dateLine }} View document →

Commercial terms

Frequently referenced sections of the Terms of Service.

{{ docTitle }}

{{ docDateLine }}

SalesBond is a product and trading name operated by Rifeberry OÜ.

Legal nameRifeberry OÜ
Product / trading nameSalesBond
Registry code16488400
Trade registerEstonian Commercial Register
Registered addressTornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia
Table of contents
1. About These Terms 2. Acceptance and Electronic Contracting 3. Definitions 4. Business-Only Eligibility 5. Organization Accounts and Authorized Users 6. CRM and Marketplace Integrations 7. Subscriptions, Plans and Usage Limits 8. Trials, Free Services and Beta Features 9. Billing, Fees, Payment and Taxes 10. Automatic Renewal 11. Cancellation 12. No Refunds 13. License and Permitted Use 14. Customer Responsibilities 15. Acceptable Use and Prohibited Conduct 16. Customer Data 17. Data Protection 18. AI-Powered Features 19. Sales-Team and Worker-Related Use 20. Service Usage Data and De-Identified Information 21. Third-Party Services 22. Security 23. Confidentiality 24. Service Operation, Support, Service Indicators and Changes 25. Intellectual Property 26. Suspension 27. Term and Termination 28. Effect of Termination; Export and Deletion 29. Limited Service Warranty 30. Disclaimers 31. Customer Indemnification 32. Limitation of Liability 33. Force Majeure 34. Export Controls and Sanctions 35. Changes to the Service and These Terms 36. Governing Law and Jurisdiction 37. Notices 38. Assignment 39. General Provisions 40. Legal Notice and Company Information

Provider: Rifeberry OÜ, registry code 16488400, Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia

Contact: support@salesbond.app

IMPORTANT: THESE TERMS GOVERN A BUSINESS-TO-BUSINESS SERVICE ONLY. THE SERVICE IS NOT OFFERED TO CONSUMERS OR TO PERSONS UNDER 18 YEARS OF AGE. BY ACCEPTING THESE TERMS, YOU REPRESENT THAT YOU ARE ACTING FOR BUSINESS OR PROFESSIONAL PURPOSES AND HAVE AUTHORITY TO BIND THE CUSTOMER.

1. About These Terms

These Terms of Service (the “Terms”) form a legally binding agreement between Rifeberry OÜ, an Estonian private limited company with registry code 16488400 and registered address at Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia (“Company”, “Rifeberry”, “SalesBond”, “we”, “us” or “our”), and the business or other professional entity that accesses or uses the Service (“Customer”, “you” or “your”).

These Terms govern access to and use of the SalesBond websites, applications, CRM integrations, dashboards, analytics, artificial-intelligence-enabled functions, reports, recommendations, APIs and related services made available by Company (collectively, the “Service”).

The individual who accepts these Terms, installs or authorizes an integration, creates an Organization account, purchases a Subscription, or otherwise activates the Service for Customer represents and warrants that the individual is at least 18 years old and has full legal authority to bind Customer. If that individual lacks such authority, the individual must not accept these Terms or use the Service.

2. Acceptance and Electronic Contracting

Customer accepts these Terms and the DPA incorporated into them by selecting an unchecked acceptance box, clicking an acceptance or activation control, completing checkout, installing or activating the Service through a CRM marketplace where these Terms and DPA are clearly presented as governing the installation, or continuing from a first-launch acceptance screen. Acceptance by electronic means has the same effect as a handwritten signature to the maximum extent permitted by applicable law.

Company may present the following or a substantially equivalent checkbox: “I agree to the Terms of Service and Data Processing Addendum and acknowledge the Privacy Notice.” For clarity, acknowledgment of the Privacy Notice confirms that it was made available and does not constitute consent where Applicable Data Protection Law requires a separate consent.

Where a CRM marketplace or other third-party platform does not provide Company with an adequate acceptance mechanism, Customer must accept these Terms within the Service before substantive access, synchronization or processing is enabled. An Organization Administrator may accept these Terms on behalf of Customer. Company may retain evidence of acceptance, including the accepted version, date, time, account identifier, Organization identifier, marketplace installation identifier and technical logs.

Customer’s procurement terms, purchase order terms, portal terms or other additional or conflicting terms do not apply unless Company expressly agrees to them in a document signed by an authorized representative of Company.

3. Definitions

“Authorized User” means an individual whom Customer authorizes to access the Service under Customer’s Organization account. “Customer Data” means data, content and information submitted to, synchronized with, accessed by, generated from or otherwise processed through the Service on Customer’s behalf, including CRM records, deal data, contact data, activity data, notes, communications, pipeline information and Authorized User data. Customer Data does not include Service Usage Data.

“Documentation” means Company’s then-current user instructions and technical documentation for the Service. “Organization” means the Customer workspace or tenant within the Service. “Organization Administrator” means an Authorized User designated to manage the Organization, integrations, permissions, users, settings and Subscription. “Subscription” means paid access to the Service for the subscription period, plan, usage limits and price displayed at checkout or in the Service.

“Service Usage Data” means technical, operational, diagnostic, performance and usage information concerning operation and use of the Service that does not identify Customer’s clients or disclose Customer’s Confidential Information in identifiable form. “Third-Party Service” means a product, platform, model, marketplace, API, data source or service provided by a party other than Company.

4. Business-Only Eligibility

The Service is intended solely for companies, organizations, sole traders and other persons acting exclusively in the course of trade, business, craft or profession. The Service is not intended or offered for personal, family or household purposes and is not a consumer service.

Customer represents and warrants throughout the Term that it is acquiring and using the Service solely for business or professional purposes. No person under 18 years of age may create an account, become an Authorized User, accept these Terms or use the Service.

If a person uses the Service in breach of this Section, Company may refuse registration, suspend access or terminate the account. Nothing in these Terms excludes a mandatory right that applicable law does not permit the parties to exclude, but no person may misrepresent consumer status, age, identity or authority to obtain rights or access not offered by Company.

5. Organization Accounts and Authorized Users

Customer must provide accurate, complete and current registration, billing and Organization information. Customer is responsible for keeping that information current and for ensuring that each Authorized User uses an individual account. Shared accounts and credential sharing are prohibited unless expressly supported by the Service.

Customer is responsible for all acts and omissions occurring through its Organization and Authorized User accounts, including configuration choices, integration permissions, automation instructions, data exports and use of AI outputs. Customer must promptly disable access for persons who are no longer authorized and notify Company of suspected unauthorized access.

Organization Administrators may add and remove Authorized Users, connect CRM systems, grant permissions, configure automation, access Organization data and take other actions on Customer’s behalf. Customer is solely responsible for appointing appropriate Organization Administrators and for their instructions to Company.

Customer must maintain reasonable security for its accounts, email systems, devices, credentials, authentication links and connected systems. Company is not liable for loss arising from compromised credentials, insecure endpoints, Customer’s failure to remove access, or actions taken in reasonable reliance on instructions received through Customer’s accounts.

6. CRM and Marketplace Integrations

The Service may be installed through or connected to CRM platforms, including third-party marketplaces. Customer authorizes Company to access, retrieve, synchronize, analyze, create, update and, where expressly enabled by Customer, modify Customer Data in connected systems to provide the selected functions.

Customer must review requested permissions before authorizing an integration and must grant only permissions that Customer is legally entitled to grant. Customer represents that it has all rights, notices, lawful bases, permissions and authorizations necessary for Company and its subprocessors to process data from each connected system.

Third-party marketplaces and CRM providers are independent from Company. Their terms, privacy notices, availability, API limits, certification requirements and technical restrictions apply separately. Company does not control and is not responsible for a Third-Party Service, changes to its API, data quality, suspension of Customer’s third-party account, or loss of functionality caused by that third party.

Disconnecting or uninstalling an integration may stop future synchronization but may not automatically delete data already processed or stored by the Service. Customer must follow the Service’s account and data-deletion procedures if deletion is required.

7. Subscriptions, Plans and Usage Limits

Features, Authorized User limits, usage allowances, integration limits, support levels, billing frequency and prices are determined by the Subscription selected at checkout or shown in the Service. Unless expressly stated otherwise, a Subscription is non-transferable and limited to one Customer Organization.

Customer must not exceed applicable plan limits. Company may restrict additional usage, require an upgrade, charge applicable overage fees disclosed before the charge, or suspend the affected functionality until Customer brings usage within the applicable limits.

Company may introduce, change or discontinue plans prospectively. A plan or price change affecting an existing paid Subscription will take effect at the next renewal after reasonable prior notice, unless the change is required sooner by law, tax, security, a Third-Party Service or Customer’s requested change.

8. Trials, Free Services and Beta Features

Company may offer trials, free plans, previews, early-access functions or beta features. Their duration, limits and conversion terms will be disclosed in the Service. Customer must cancel before the stated conversion date if the offer expressly provides that it will convert into a paid Subscription.

Trials, free services and beta features may be modified, limited, suspended or withdrawn at any time. They are provided without service-level commitments, warranties, support obligations or liability to the maximum extent permitted by law. Customer must not rely on a beta feature for production-critical operations.

Company may use reasonable eligibility controls to prevent repeated or abusive trial registrations and may refuse or terminate a trial or free account at its discretion.

9. Billing, Fees, Payment and Taxes

Customer must pay all fees in the currency, amount and billing frequency displayed at checkout or in the Service. Except as expressly stated in these Terms, fees are fixed for the applicable billing period, non-cancellable and non-refundable.

Customer authorizes Company and its payment providers to charge the selected payment method for initial fees, renewals, applicable taxes and authorized usage charges. Customer must keep a valid payment method and accurate billing information on file. Payment-provider terms may apply separately.

Payment Methods Used on Behalf of Customer. Customer may use a payment method issued to an Authorized User, employee, director, owner or other third party only if Customer and the cardholder are authorized to use that payment method for the Subscription. The business entity identified in the Organization and billing information remains the Customer and contracting party, regardless of the name appearing on the payment method. Use of a personal or non-business payment method does not convert the transaction into a consumer transaction, confer contractual rights on the cardholder, or change the business and professional nature of the Service. Customer remains responsible for all fees, chargebacks, payment disputes and unauthorized use of the payment method. Any permitted refund will be returned only to the original payment method unless Company determines otherwise.

Fees are exclusive of VAT, sales, use, withholding and similar taxes unless expressly stated otherwise. Customer is responsible for all taxes associated with its purchase, except taxes based on Company’s net income. Customer must provide a valid VAT or tax identification number and any documentation reasonably required to determine the correct tax treatment. If Customer must withhold tax, Customer will gross up the payment so that Company receives the amount it would have received without the withholding, except where applicable law prohibits gross-up.

Overdue amounts may accrue statutory or commercially reasonable interest up to the maximum permitted by law. Customer must reimburse reasonable collection costs and any statutory recovery compensation available for late B2B payments. Company may suspend access for overdue amounts after reasonable notice, except where a charge is disputed in good faith and Customer cooperates promptly to resolve the dispute.

Customer must contact support before initiating a chargeback or payment reversal. An unjustified chargeback or reversal constitutes a material breach, and Company may suspend the account and recover related fees and reasonable costs.

Unless checkout or another written ordering document states otherwise, fees are charged in advance when the Subscription begins and on each renewal date and are due immediately. Company may issue invoices and receipts electronically to Customer’s billing contact. Customer must raise any good-faith billing question or dispute promptly and no later than 30 days after the relevant invoice or charge, without limiting rights that cannot lawfully be waived. A billing dispute does not relieve Customer from paying undisputed amounts when due.

10. Automatic Renewal

Each paid Subscription automatically renews for successive periods equal to the expiring subscription period, unless Customer cancels before the renewal date or the Service expressly states a different renewal period. Company will charge the then-current renewal price and applicable taxes using Customer’s payment method.

Customer is responsible for tracking its renewal date. Company may provide renewal reminders where required by law or as a courtesy, but failure to receive a courtesy reminder does not cancel a renewal or create a refund right. Company will provide notice of a material price increase before it applies to a renewal.

Cancellation stops future renewal; it does not retroactively cancel the current paid period.

11. Cancellation

Customer may cancel a Subscription through the billing or account settings made available in the Service or by any other method Company expressly identifies. A cancellation is effective at the end of the then-current paid subscription period.

Following cancellation, Customer retains access to paid functionality through the end of the current paid period, unless the account is suspended or terminated earlier for breach, security, legal or sanctions reasons. Customer remains responsible for all charges incurred before the cancellation becomes effective.

Deleting an application, removing a browser extension, uninstalling a CRM integration, ceasing use, removing a payment method or requesting that a third-party marketplace disable an integration does not necessarily cancel the Subscription. Customer must complete the designated cancellation process and retain confirmation.

12. No Refunds

ALL PAYMENTS ARE FINAL, NON-CANCELLABLE AND NON-REFUNDABLE TO THE MAXIMUM EXTENT PERMITTED BY LAW. COMPANY DOES NOT PROVIDE REFUNDS OR CREDITS FOR PARTIALLY USED PERIODS, UNUSED FEATURES, UNUSED AUTHORIZED USER SEATS, FAILURE TO USE THE SERVICE, DOWNGRADES, CUSTOMER CONFIGURATION, THIRD-PARTY SERVICE FAILURES, MARKETPLACE REMOVAL, OR CANCELLATION AFTER A CHARGE OR RENEWAL HAS OCCURRED.

The no-refund rule does not apply where a refund is expressly required by non-waivable applicable law. Company may, in its sole discretion and without creating an obligation or precedent, issue a refund, credit or extension in an exceptional case.

If Company terminates a paid Subscription solely for Company’s convenience, and not because of Customer’s breach, non-payment, security risk, legal requirement, sanctions restriction, Third-Party Service change, force majeure event or discontinuation made necessary by circumstances outside Company’s reasonable control, Company will refund prepaid fees allocable to the unused remainder of the terminated paid period. That prorated refund is Customer’s sole and exclusive remedy for such termination.

13. License and Permitted Use

Subject to Customer’s compliance with these Terms and payment of all fees, Company grants Customer a limited, non-exclusive, non-transferable, non-sublicensable and revocable right during the Term to permit its Authorized Users to access and use the Service for Customer’s internal business operations in accordance with the Documentation and applicable plan limits.

No rights are granted by implication. Customer may not resell, lease, sublicense, distribute, white-label, make available on a service-bureau basis or otherwise commercialize the Service for a third party unless Company expressly authorizes that activity in writing.

Customer may use reports and outputs generated for Customer’s internal business purposes, subject to these Terms and third-party rights. Outputs may not be unique, and Company does not warrant that the same or similar output will not be generated for another customer.

14. Customer Responsibilities

Customer is responsible for its sales processes, CRM configuration, pipeline structure, data quality, legal compliance, management decisions, communications, offers, contracts and commercial outcomes. The Service supports Customer’s work but does not replace Customer’s judgment, supervision or professional advice.

Customer must verify the accuracy and appropriateness of recommendations, calculations, alerts, generated text, proposed CRM changes and other outputs before relying on them or using them externally. Customer must maintain appropriate backups and change controls before enabling any function that can update or delete data in a connected system.

Customer is responsible for providing all notices and obtaining all consents, lawful bases, employee consultations, permissions and approvals required for Customer Data and Customer’s use of the Service, including in relation to employees, contractors, prospects, clients and other individuals.

Customer must not provide data that Company has not agreed to process, including passwords, authentication secrets, payment-card data subject to PCI DSS, government identification numbers, protected health information, children’s data, biometric data or special-category/sensitive personal data, unless Company has expressly agreed in writing and appropriate safeguards are in place.

15. Acceptable Use and Prohibited Conduct

Customer and Authorized Users must use the Service lawfully and in good faith. They must not use the Service to violate law or third-party rights; send unlawful, deceptive or unsolicited communications; discriminate unlawfully; harass, exploit or surveil individuals unlawfully; process data without required authority; or facilitate fraud, malware, credential theft or other harmful activity.

Customer must not probe, scan or test vulnerabilities without written authorization; bypass security, usage or access controls; interfere with the Service; introduce malicious code; access another customer’s data; scrape the Service except through authorized interfaces; reverse engineer or attempt to derive source code except to the limited extent a prohibition is unenforceable under applicable law; benchmark for a competing product without consent; or use the Service or its outputs to develop or train a competing model or service.

Customer must not use the Service for autonomous or solely automated decisions that produce legal or similarly significant effects concerning an individual, including hiring, dismissal, compensation, promotion, discipline, credit, insurance, housing or access to essential services, unless Company has expressly approved that use and Customer independently establishes full legal compliance.

Company may investigate suspected violations, preserve relevant records, remove or restrict content, block activity and cooperate with competent authorities where legally required.

16. Customer Data

As between the parties, Customer retains all rights in Customer Data. Customer grants Company and its subprocessors a worldwide, non-exclusive right during the Term, and for any limited post-termination period permitted by these Terms or the Data Processing Addendum, to host, copy, transmit, access, transform, analyze, display, generate outputs from and otherwise process Customer Data solely to provide, secure, support and maintain the Service, comply with law and perform Customer’s documented instructions.

Customer represents and warrants that Customer Data, Customer’s instructions and Company’s permitted processing do not violate law, contract, confidentiality, intellectual-property, privacy, employment or other rights. Customer is responsible for the legality, accuracy, quality and integrity of Customer Data.

Company is not responsible for loss, corruption, alteration or disclosure caused by Customer, an Authorized User, a connected Third-Party Service, Customer’s configuration, credentials or instructions. Company may rely on Customer’s Organization Administrators as authorized to issue instructions concerning Customer Data.

17. Data Protection

For personal data that Company processes on Customer’s behalf as a processor, the SalesBond Data Processing Addendum (“DPA”), available at https://salesbond.app/dpa, forms part of and is incorporated into these Terms. Customer accepts the DPA through the same electronic acceptance mechanism used for these Terms. The DPA controls over conflicting provisions solely concerning Company’s processor or subprocessor obligations for personal data.

For personal data that Company processes as an independent controller, including account administration, billing, security, support and direct business communications, Company’s Privacy Notice, available at https://salesbond.app/privacy, applies. The Privacy Notice is provided for transparency and is not incorporated as a contractual promise except where these Terms expressly state otherwise. Company’s list of subprocessors will identify material service providers involved in processing Customer Data.

Customer is the controller or otherwise determines the lawful instructions for Customer Data. Customer must respond to individuals and regulators concerning Customer’s processing and must not instruct Company to process personal data unlawfully. Company may refuse or suspend an instruction that it reasonably believes violates applicable data-protection law.

If Customer’s use requires a data-protection impact assessment, legitimate-interest assessment, employee consultation or authorization from a regulator or works council, Customer is responsible for completing it. Company will provide reasonable information and assistance required by applicable law, subject to confidentiality, security and reasonable cost limitations.

18. AI-Powered Features

The Service may use machine learning, statistical models and generative artificial intelligence supplied by Company or Third-Party Services (“AI Features”) to analyze Customer Data and produce risk signals, summaries, recommendations, forecasts, scores, proposed actions, generated text or other outputs.

AI outputs are probabilistic and may be incomplete, inaccurate, outdated, biased, unsuitable or similar to outputs produced for others. Company does not warrant the factual accuracy, completeness, uniqueness, legality or fitness of an AI output. Customer must apply meaningful human review before acting on an output, sending it to another person, changing CRM data, or using it in a consequential decision.

AI Features are not legal, financial, employment, tax or other regulated professional advice and do not guarantee sales, revenue, conversion, retention, quota attainment or any other result. Historical correlations, predictions and recommendations are not assurances of future performance.

Customer authorizes Company to send the minimum Customer Data reasonably required for an enabled AI Feature to disclosed AI subprocessors. Company will not knowingly authorize a third-party general-purpose model provider to train its public or generally available models on Customer Data unless Customer expressly opts in or separately agrees, but Customer acknowledges that technical retention for security, abuse prevention or legal compliance may occur as described in the DPA, Privacy Notice, AI notice or subprocessor documentation.

Company may apply input and output filters, usage limits, safety controls and model substitutions. Company may disable an AI Feature where necessary for safety, law, third-party model terms, quality or security.

19. Sales-Team and Worker-Related Use

The Service may display deal activity, process adherence, task completion, pipeline contribution, goals, rankings, coaching indicators and other performance-related information associated with Authorized Users. These functions are intended to support sales operations and human management, not to make autonomous employment decisions.

Customer is solely responsible for determining whether and how such functions may lawfully be used in its workplace. Customer must provide transparent notice to affected workers, establish an appropriate lawful basis, comply with employment, privacy, collective-labor and works-council requirements, enable appropriate access or correction rights, and avoid covert or disproportionate monitoring.

Customer must not use an AI output, score, ranking or alert as the sole basis for hiring, dismissal, discipline, compensation, promotion, demotion or another decision that has legal or similarly significant effects on a person. A qualified human must review relevant source data, limitations and context and retain independent decision-making authority.

Customer is responsible for addressing questions, objections and challenges from its workers and for documenting the basis of its decisions. Company does not become an employer, co-employer, employment agency or decision-maker by providing the Service.

20. Service Usage Data and De-Identified Information

Company may collect and use Service Usage Data to operate, secure, support, analyze and improve the Service, allocate resources, prevent abuse and develop features. Company may create aggregated or de-identified information from Customer Data and Service Usage Data, provided that the resulting information does not reasonably identify Customer, an Authorized User, Customer’s clients or other individuals.

Company may use and disclose aggregated or de-identified information for lawful business purposes, including benchmarking and product improvement, and will not intentionally attempt to re-identify it. Company will not publicly disclose a benchmark that reasonably identifies Customer without Customer’s permission.

21. Third-Party Services

Customer may choose to enable Third-Party Services. Customer’s relationship with each Third-Party Service is governed by the third party’s terms, and Customer is responsible for obtaining and maintaining necessary accounts, licenses, permissions and payments.

Company does not warrant a Third-Party Service and is not responsible for its acts, omissions, data handling, security, accuracy, availability, changes or termination. Interoperability may cease without notice if a third party changes or restricts its service. Company may replace, modify or discontinue an integration where reasonably necessary.

Customer instructs Company to exchange Customer Data with enabled Third-Party Services. Once data is transmitted to a third party as directed by Customer, that third party’s processing is outside Company’s control except to the extent it acts as Company’s contracted subprocessor.

22. Security

Company will maintain commercially reasonable technical and organizational measures designed to protect Customer Data against unauthorized access, alteration, loss and disclosure, taking account of the nature of the Service and applicable risks. Additional measures may be described in the DPA or security documentation.

No system is completely secure. Company does not guarantee that the Service will be uninterrupted, invulnerable or free from every harmful component or unauthorized access. Customer must use the Service in accordance with reasonable security practices and promptly report suspected incidents to support@salesbond.app.

Customer must not conduct penetration testing, load testing, vulnerability scanning or security research against the Service without Company’s prior written authorization and agreed rules of engagement.

23. Confidentiality

“Confidential Information” means non-public information disclosed by one party to the other that is identified as confidential or should reasonably be understood to be confidential, including Customer Data, product plans, security information, pricing not publicly available, technology and business information. Confidential Information excludes information that the recipient can document was lawfully known without restriction, becomes public without breach, is received lawfully from a third party without duty, or is independently developed without use of the discloser’s Confidential Information.

The recipient will use Confidential Information only to perform or exercise rights under these Terms, protect it with at least reasonable care, and disclose it only to personnel, professional advisers and contractors who need to know it and are bound by appropriate confidentiality obligations.

The recipient may disclose Confidential Information where legally compelled, provided it gives prior notice where legally permitted and reasonable assistance at the discloser’s expense. Each party may seek injunctive or other equitable relief for actual or threatened misuse of Confidential Information.

24. Service Operation, Support, Service Indicators and Changes

Company will use commercially reasonable efforts to operate and support the paid Service. Support is available at support@salesbond.app and through any in-product support channel that Company makes available.

Support Hours. Standard support hours are 09:00–18:00, Monday through Friday, Europe/Tallinn time (EET/EEST, UTC+2 or UTC+3 depending on daylight-saving time), excluding public holidays observed in Estonia (“Support Hours”). A “Support Day” is a day on which Support Hours apply.

Initial Response Targets. For a valid Critical Incident reported to support@salesbond.app with “CRITICAL” in the email subject, Company targets an initial human response within one hour during Support Hours. For all other valid support requests, Company targets an initial human response within 24 hours. A request received outside Support Hours is treated as received at the start of the next Support Day for measuring these targets. Company may monitor Critical Incident reports outside Support Hours on a commercially reasonable basis, but 24/7 human coverage is not included unless expressly agreed in a separate written service-level agreement.

A “Critical Incident” means a reproducible production incident in which the paid Service is materially unavailable for substantially all of Customer’s Authorized Users, or there is a credible and immediate risk of unauthorized access to Customer Data, and no reasonable workaround is available. Company may reasonably reclassify a report based on actual impact, scope, reproducibility and available workarounds.

An initial response means acknowledgment and commencement of triage; it is not a commitment to resolve, restore or provide a workaround within the response target. Resolution time depends on the nature of the issue, Customer cooperation and Third-Party Services. Customer must provide its Organization identifier, affected users and functions, timestamps, steps to reproduce, relevant screenshots or logs, and a contact who can assist with diagnosis. The response clock is paused while Company reasonably awaits information, access, confirmation or action from Customer.

The response targets do not apply to free or trial access, beta or preview features, unsupported configurations, incomplete or duplicate reports, general questions, feature requests, planned maintenance, or incidents caused by Customer, a CRM or other Third-Party Service, misuse, internet or telecommunications failures, force majeure, or circumstances outside Company’s reasonable control. These targets are service objectives only, not warranties or a service-level agreement, and do not create service credits, refunds, termination rights or damages.

Service Level Indicators. Company may measure operational indicators such as monthly availability, successful-request rate, latency, error rate, incident detection and restoration time, and initial support response time (“SLIs”). SLIs are measurement methods, not contractual commitments. Any binding service-level objective, availability commitment, support coverage, service credit or remedy must be expressly stated in a separate written service-level agreement or ordering document signed or accepted by Company.

Company may perform scheduled or emergency maintenance and may modify the Service to improve functionality, security, legal compliance, performance or usability. Company will use commercially reasonable efforts to give advance notice of scheduled maintenance that is expected to cause material unavailability. Emergency maintenance may be performed without advance notice. Company may discontinue a feature, but will use reasonable efforts not to materially reduce the core functionality of a paid Subscription during its current period unless necessary because of law, security, a Third-Party Service, technical infeasibility or circumstances outside Company’s reasonable control.

Documentation, forecasts, roadmaps, “coming soon” statements and descriptions of planned features are informational and are not binding commitments. Customer purchases the Service based on functionality available at the time of purchase, not future features.

25. Intellectual Property

Company and its licensors retain all rights, title and interest in and to the Service, software, models, algorithms, interfaces, design, Documentation, trademarks, know-how, improvements and derivative works, excluding Customer Data. These Terms do not transfer ownership of the Service or Company intellectual property to Customer.

Customer must not remove proprietary notices or use the SalesBond name, logo or marks without permission. Company will not use Customer’s name or logo in public marketing without Customer’s consent.

If Customer provides feedback, suggestions, requests or ideas concerning the Service, Customer grants Company a perpetual, irrevocable, worldwide, royalty-free, transferable and sublicensable right to use and incorporate them without restriction, attribution or compensation, provided Company does not identify Customer as the source without permission.

26. Suspension

Company may immediately suspend all or part of the Service where Company reasonably believes that Customer has breached these Terms; payment is overdue; use presents a security, legal, sanctions, fraud or operational risk; Customer Data or instructions may be unlawful; suspension is requested by a competent authority; or a Third-Party Service necessary to provide the affected functionality has suspended access.

Where reasonably practicable and lawful, Company will notify Customer and limit the suspension to the affected functionality. Company may require remediation, verification or payment before restoring access.

Fees continue to accrue during a suspension caused by Customer, its Authorized Users, its systems or its breach, and no refund or credit is due. Suspension does not limit Company’s right to terminate or pursue other remedies.

27. Term and Termination

These Terms begin when Customer first accepts them and continue while Customer has an account, an active Subscription or access to the Service (the “Term”).

Customer may terminate these Terms by cancelling all Subscriptions, disconnecting integrations, ceasing use and closing the Organization account. A paid Subscription remains effective through the end of its paid period unless terminated earlier under these Terms.

Company may terminate for material breach if Customer fails to cure a curable breach within ten days after notice. Company may terminate immediately for non-payment, unlawful use, material security risk, sanctions or export restriction, fraud, misrepresentation of authority or eligibility, infringement, repeated breach, insolvency, or conduct reasonably likely to harm Company, the Service, another customer or a third party.

Company may terminate a free account or free service at any time. Company may terminate a paid Subscription for convenience on at least thirty days’ notice, subject to the limited prorated refund described in Section 12.

28. Effect of Termination; Export and Deletion

Upon expiration or termination, Customer’s license ends and Authorized Users must stop using the affected Service, except for any limited export period Company provides. Accrued payment obligations, remedies and provisions that by nature should survive will survive, including provisions on fees, confidentiality, intellectual property, disclaimers, indemnification, liability and disputes.

Customer is responsible for exporting Customer Data before the end of access. Subject to account status, technical capability, the DPA and applicable law, Company will make standard export functionality available during the Subscription and for up to thirty days after expiration or termination. Company may charge reasonable fees for non-standard assistance requested by Customer.

After the applicable export period, Company may delete Customer Data from active systems without liability. Deletion from backups may occur through ordinary backup cycles. Company may retain data where required by law, necessary to establish or defend legal claims, or maintained in securely isolated backups, and may retain aggregated or de-identified information.

Where mandatory law, including applicable data-portability or switching rules, grants Customer additional rights, Company will comply with those non-waivable requirements.

29. Limited Service Warranty

Company warrants that, during a paid Subscription, the Service will perform in all material respects in accordance with the then-current Documentation when used as authorized. This warranty does not apply to free or beta features, Third-Party Services, Customer Data, unsupported configurations, misuse, unauthorized modifications or issues caused by Customer or a third party.

Customer must notify Company with reasonable detail promptly after discovering a material non-conformity. Company’s first obligation and Customer’s primary remedy is for Company to use commercially reasonable efforts to correct or work around the non-conformity. If Company cannot do so within a reasonable period and the non-conformity materially prevents use of the paid Service, Company may terminate the affected Subscription and refund prepaid fees for its unused remainder. This is Customer’s exclusive remedy for breach of the limited warranty, except where applicable law requires otherwise.

30. Disclaimers

EXCEPT FOR THE EXPRESS LIMITED WARRANTY IN SECTION 29 AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE, DOCUMENTATION, OUTPUTS, AI FEATURES, FREE SERVICES AND BETA FEATURES ARE PROVIDED “AS IS” AND “AS AVAILABLE”. COMPANY DISCLAIMS ALL EXPRESS, IMPLIED, STATUTORY AND OTHER WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, QUIET ENJOYMENT AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

COMPANY DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, COMPATIBLE WITH EVERY SYSTEM, OR THAT DEFECTS WILL BE CORRECTED; THAT DATA OR OUTPUTS WILL BE ACCURATE, COMPLETE OR PRESERVED; OR THAT CUSTOMER WILL ACHIEVE ANY SALES, REVENUE, PERFORMANCE, COMPLIANCE OR OTHER RESULT.

CUSTOMER ACKNOWLEDGES THAT INTERNET, CLOUD, CRM, MARKETPLACE AND AI SERVICES INVOLVE RISKS AND DEPENDENCIES OUTSIDE COMPANY’S CONTROL. CUSTOMER USES OUTPUTS AND ENABLES AUTOMATION AT ITS OWN RISK AND REMAINS RESPONSIBLE FOR HUMAN REVIEW, BACKUPS AND BUSINESS DECISIONS.

31. Customer Indemnification

Customer will defend, indemnify and hold harmless Company, its affiliates and their directors, officers, employees, contractors and licensors from third-party claims, proceedings, losses, liabilities, damages, penalties, judgments and reasonable legal fees arising out of or relating to Customer Data; Customer’s or an Authorized User’s use of the Service; Customer’s instructions, communications or business practices; violation of law or third-party rights; employment or worker-related decisions; or breach of these Terms.

Company will give Customer prompt notice of an indemnified claim and reasonable cooperation at Customer’s expense. Customer may control the defense and settlement, but may not admit fault by Company, impose an obligation on Company or settle a claim affecting Company’s rights without Company’s prior written consent. Company may participate with counsel at its own expense.

32. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER COMPANY NOR ITS AFFILIATES, LICENSORS OR SUPPLIERS WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE OR CONSEQUENTIAL DAMAGES; LOSS OF PROFITS, REVENUE, SALES, SAVINGS, GOODWILL, BUSINESS OPPORTUNITY OR ANTICIPATED BENEFIT; BUSINESS INTERRUPTION; OR LOSS, CORRUPTION OR RECONSTRUCTION OF DATA, EVEN IF ADVISED OF THE POSSIBILITY.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF COMPANY AND ITS AFFILIATES, LICENSORS AND SUPPLIERS ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE FEES ACTUALLY PAID OR PAYABLE BY CUSTOMER TO COMPANY FOR THE SERVICE DURING THE TWELVE MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY. FOR A FREE SERVICE OR WHERE NO FEES WERE PAID, THE CAP IS EUR 100.

The exclusions and cap apply collectively to all claims and theories of liability, including contract, tort, negligence, strict liability, statutory duty, misrepresentation, restitution and indemnity, and apply even if a remedy fails of its essential purpose.

Nothing in these Terms limits liability to the extent it cannot lawfully be limited or excluded. Customer’s payment obligations, infringement or misuse of Company intellectual property, breach of use restrictions and indemnification obligations are not limited by this Section.

33. Force Majeure

Company is not liable for delay, interruption or failure caused by events beyond its reasonable control, including natural disaster, war, terrorism, civil disorder, epidemic, labor dispute, governmental action, sanctions, power or telecommunications failure, internet disruption, cyberattack despite reasonable precautions, cloud or data-center failure, CRM or marketplace outage, AI-model provider failure, change in third-party API or service, or shortage of necessary resources.

Company will use commercially reasonable efforts to mitigate the effect of a force majeure event. The event does not excuse Customer’s obligation to pay amounts accrued before or during the event for access that remains available.

34. Export Controls and Sanctions

Customer must comply with applicable export-control, trade-control and sanctions laws. Customer represents that neither Customer nor any Authorized User is prohibited from receiving the Service, located in a comprehensively sanctioned territory where provision is prohibited, or owned or controlled by a prohibited person.

Customer must not use, export, re-export or provide the Service in violation of applicable restrictions or for prohibited end uses. Company may screen accounts, request verification, restrict access or terminate immediately where reasonably necessary for compliance, without refund except where mandatory law requires otherwise.

35. Changes to the Service and These Terms

Company may update these Terms from time to time. Company will post the updated version and revise the effective or last-updated date. For a material change that adversely affects an existing paid Customer, Company will provide reasonable prior notice by email, in-product notice or another reasonable electronic method.

A change may take effect immediately where required by law, security, a regulator, a Third-Party Service or to prevent abuse. Otherwise, a material contractual change will normally apply to an existing paid Subscription at its next renewal. Continued use after the effective date constitutes acceptance of the updated Terms. If Customer does not agree, Customer must cancel before the change or renewal becomes effective.

Company may make non-material corrections, clarifications and formatting changes without advance notice.

36. Governing Law and Jurisdiction

These Terms and any non-contractual obligations arising out of or relating to them are governed by the laws of the Republic of Estonia, without regard to conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

The courts of the Republic of Estonia, with Harju County Court as the court of first instance where legally permitted, have exclusive jurisdiction over any dispute arising out of or relating to the Service or these Terms. Each party irrevocably submits to that jurisdiction and waives objections based on venue or inconvenient forum, to the maximum extent permitted by law.

Before filing a claim, the parties will attempt in good faith for at least thirty days to resolve the dispute through written notice and business discussions, except where urgent injunctive relief, preservation of rights or collection of undisputed overdue fees is necessary.

37. Notices

Company may send operational, legal and account notices to the email address associated with Customer’s Organization, through the Service or through a connected marketplace. Customer must keep its contact details current. Electronic notices are deemed received when sent or made available, unless the sender receives a failure notice.

Formal legal notices to Company must be sent to support@salesbond.app with the subject line “Legal Notice” and by a delivery method that provides evidence of receipt where applicable law requires it. This Section does not govern service of court proceedings where mandatory procedural law requires another method.

38. Assignment

Customer may not assign, transfer or delegate these Terms, an account or a Subscription without Company’s prior written consent. Any attempted transfer in violation of this Section is void.

Company may assign or transfer these Terms, in whole or in part, to an affiliate or in connection with a merger, reorganization, financing, sale of shares, sale of business or assets, or similar transaction. Subject to the foregoing, these Terms bind and benefit the parties and their permitted successors and assigns.

39. General Provisions

These Terms, together with the DPA and any policies expressly incorporated by reference, constitute the entire agreement concerning the Service and supersede prior or contemporaneous proposals, communications and understandings on that subject. In a conflict, the DPA controls solely for processor obligations concerning personal data; otherwise these Terms control unless Company expressly states a different order of precedence.

If a provision is held invalid or unenforceable, it will be enforced to the maximum extent permitted and the remaining provisions remain effective. Failure to enforce a provision is not a waiver. A waiver must be in writing and applies only to the specific instance.

The parties are independent contractors. These Terms do not create employment, agency, fiduciary, partnership, franchise or joint-venture relationships. Neither party may bind the other except as expressly stated.

Headings are for convenience only. “Including” means “including without limitation”. References to writing include permitted electronic communications. The English version controls to the maximum extent permitted by law. No person other than the parties and permitted successors has rights under these Terms, except indemnified parties may enforce applicable protections.

Sections that by their nature should survive expiration or termination survive, including payment, Customer Data representations, confidentiality, intellectual property, disclaimers, indemnification, liability, governing law and general provisions.

40. Legal Notice and Company Information

Rifeberry OÜ

Registry code: 16488400

Registered address: Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia

Email: support@salesbond.app

SalesBond is a product and trading name operated by Rifeberry OÜ.

Trade register: Estonian Commercial Register

Legal notices must be sent in accordance with Section 37.

1. Scope

This AI Transparency and Use Notice explains how AI-assisted functionality is used in SalesBond and the responsibilities of business customers and professional users. It supplements the SalesBond Terms of Service, Privacy Notice, Data Processing Addendum, Acceptable Use Policy and Subprocessor List.

SalesBond is provided by Rifeberry OÜ (Rifeberry, SalesBond, we, us or our) only for business and professional use by persons aged 18 or over.

This Notice is intended to provide practical transparency. It does not classify every SalesBond feature or Customer use under a particular law. Legal roles and obligations depend on the feature, configuration, purpose, data, jurisdiction and Customer’s use.

2. What SalesBond AI does

Depending on enabled features and available data, SalesBond may use rules, statistical analysis, machine learning and generative AI to:

  • summarize CRM records, activities, communications and deal history;
  • classify information and identify missing or inconsistent CRM data;
  • detect patterns, anomalies, stalled activity and pipeline risk signals;
  • generate forecasts, scores, priorities and suggested next actions;
  • draft text, explanations, checklists, coaching suggestions and reports;
  • support search, question answering and analysis across authorized CRM information; and
  • improve the usability, security and operation of requested workflows.

Specific outputs depend on the Customer’s CRM data, configuration, prompts, selected features and model availability.

3. AI providers and model routing

SalesBond may use commercial AI APIs supplied by OpenAI, Anthropic, Mistral AI and Google, as identified in the current Subprocessor List. SalesBond may select or substitute a provider or model based on feature requirements, quality, availability, latency, cost, region, security, provider restrictions and Customer configuration.

A named provider is not necessarily used for every request. SalesBond may disable, replace or limit a model or AI feature where reasonably necessary for security, safety, law, quality, availability or compliance with provider terms.

4. Data sent to AI providers

For an enabled AI workflow, SalesBond may send the selected prompt, system instructions, relevant CRM context, identifiers needed to complete the request, and generated input/output metadata to one or more disclosed AI providers.

Depending on the Customer’s use, this context may include business contact details, organizations, deals, pipelines, activities, tasks, notes, email or communication content, user-entered prompts and other CRM fields. Attachments are not intentionally sent unless SalesBond later introduces and discloses an attachment-processing feature.

SalesBond is designed to send only data reasonably necessary for the requested workflow. Customer remains responsible for limiting connected CRM data, permissions and prompts and must not submit unnecessary sensitive or prohibited data.

5. Model training and provider retention

SalesBond does not use identifiable Customer Content to train its own or a third party’s general-purpose AI models. SalesBond will not knowingly opt Customer Content into optional model-improvement, feedback-training, public-sharing or similar programs without Customer’s express written opt-in and an appropriate lawful basis.

Commercial AI providers may retain limited inputs, outputs or technical logs for abuse prevention, security, debugging, legal compliance or provider features selected by SalesBond. Retention and access depend on the provider, endpoint, product tier, configuration and applicable agreement. Where commercially and technically available, SalesBond will use no-training configurations, minimize submitted data, disable unnecessary storage and evaluate zero-data-retention or equivalent controls.

6. Outputs are probabilistic

AI outputs are generated probabilistically and may be inaccurate, incomplete, inconsistent, biased, outdated, misleading, non-unique or unsuitable for a particular purpose. An output may omit relevant context or confidently state incorrect information.

SalesBond does not warrant that an AI output is factually correct, complete, lawful, unique or fit for a specific decision. Scores, forecasts, recommendations and risk indicators describe patterns or estimates; they do not guarantee sales, revenue, conversion, retention, quota attainment or any other result.

7. Human oversight

AI features are intended to support — not replace — professional judgment. Customer must ensure that a qualified person:

  • reviews material outputs before reliance or external use;
  • checks source data, assumptions and relevant context;
  • can disregard, correct or override an output;
  • does not automate an action where human review is legally or operationally required; and
  • documents review where the use may materially affect a person.

Customer should train Authorized Users on appropriate AI use, limitations, confidentiality, prompt hygiene and escalation.

8. Legally or similarly significant decisions

SalesBond is not intended to make autonomous decisions producing legal or similarly significant effects. Customer must not use a SalesBond output as the sole or determinative basis for hiring, termination, promotion, discipline, compensation, credit, insurance, housing, education, medical, legal, eligibility, law-enforcement or similar high-impact decisions.

If Customer configures or combines SalesBond with other systems in a way that may create a regulated or high-risk AI use, Customer is responsible for determining the applicable classification and implementing required risk management, documentation, notices, impact assessments, human oversight, logging, consultation and rights mechanisms. Customer must notify SalesBond before any proposed use requiring capabilities or contractual commitments not included in the standard Services.

9. Sales-team and worker-related analytics

SalesBond may display activity, process adherence, task completion, pipeline contribution, rankings, coaching indicators and other performance-related information associated with Authorized Users.

These features are intended to support sales operations and human management, not to autonomously evaluate workers or make employment decisions. Customer must comply with employment, labor, works-council, collective-bargaining, privacy, surveillance and anti-discrimination requirements and must provide meaningful context and an opportunity for appropriate human review or correction.

Customer must not infer protected or highly sensitive characteristics or use SalesBond to conduct prohibited emotion recognition, biometric categorization or discriminatory profiling.

10. Transparency to affected persons

Customer is responsible for providing employees, contractors, prospects, customers and other affected persons with disclosures required for Customer’s use of SalesBond and AI-assisted processing.

Where required, Customer must clearly inform a person that they are interacting with an AI system or receiving materially AI-generated or manipulated content. Customer must retain any machine-readable provenance or disclosure mechanism implemented by SalesBond and must not present an unreviewed AI communication as a personal statement by a real individual.

If Customer uses AI-generated content in a public-interest publication, deep fake or other regulated context, Customer must assess and comply with applicable labeling and disclosure requirements. SalesBond is not designed as a deep-fake generation service.

11. Prohibited AI uses

The Acceptable Use Policy applies to all AI features. Without limitation, Customer must not use SalesBond AI to:

  • deceive, impersonate, defraud or fabricate evidence, endorsements, identities or credentials;
  • exploit vulnerabilities or materially manipulate persons through subliminal or deceptive techniques;
  • unlawfully discriminate or make decisions based on protected or highly sensitive traits;
  • create or distribute unlawful, abusive or rights-infringing content;
  • bypass safeguards, extract system prompts, expose secrets or access another tenant’s data;
  • make autonomous high-impact decisions; or
  • process data or perform activities prohibited by the Agreement or applicable AI-provider terms.

12. Data quality, fairness and contestability

Customer controls the quality, completeness and lawfulness of CRM data. Incomplete, historically biased or incorrectly configured data may produce misleading outputs. Customer should regularly assess data quality, compare outputs with real-world evidence and monitor for disproportionate or discriminatory effects.

Authorized Users should have a practical way to flag incorrect CRM data or questionable outputs to the Customer administrator. SalesBond may provide explanation, source references or correction controls where supported, but not every model output can be fully explained.

13. Security and prompt-related risks

Customer must treat AI inputs and outputs as potentially sensitive and must not include passwords, API keys, payment credentials or unnecessary confidential information in prompts.

Content imported from a CRM or received from a third party may contain malicious or misleading instructions. Customer must not assume that model safeguards will detect every prompt-injection, data-exfiltration or manipulated-content attempt. High-risk actions must require independent authorization and appropriate technical controls.

14. AI governance and literacy

Customer is responsible for ensuring that personnel using or overseeing AI features have a level of AI literacy appropriate to their role, experience, context and potential impact. This should include training on limitations, human review, data protection, security, bias, prohibited uses and reporting.

Customer should maintain internal rules identifying permitted purposes, authorized users, approval thresholds, escalation paths and prohibited data. Where required, Customer should conduct a data protection, legitimate-interest, algorithmic or fundamental-rights impact assessment before deployment.

15. Questions, rights and concerns

Privacy rights and requests are addressed in the SalesBond Privacy Notice and DPA. Concerns about an AI output, suspected misuse or a material adverse effect may be sent to support@salesbond.app with sufficient context for review.

If the relevant data was submitted by a SalesBond Customer, that Customer is normally responsible for responding as controller. SalesBond will assist as required by applicable law and the DPA.

16. Changes and contact

SalesBond may update this Notice when features, providers, models, safeguards or law change. The current version will show its latest update date, and material changes will be notified where required.

Rifeberry OÜ

Registry code: 16488400

Tornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia

Email: support@salesbond.app

Table of contents
ControllerRifeberry OÜ Effective date20 July 2026 Version1.0 Privacy contactsupport@salesbond.app

Rifeberry OÜ

Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia

Registry code 16488400

Privacy at a glance

TopicSummary Who this is forBusiness customers and their authorized professional users aged 18 or over; website visitors, business contacts, partners, and referrers. Our rolesRifeberry OÜ is a controller for its own website, account, billing, support, security, and marketing data. For CRM data submitted by a customer, the customer is normally the controller and Rifeberry OÜ is its processor. CRM dataUsers, companies, contacts, deals, stages, custom fields, tasks, calls, meetings, notes, email/message content, change history, goals, KPIs, rankings, and performance data. SalesBond does not intentionally import CRM file attachments. AISelected data may be sent to commercial APIs of OpenAI, Anthropic, Mistral, and Google to generate analysis and recommendations. We do not permit Customer Content to be used to train general-purpose models unless a customer separately and expressly opts in under a written arrangement. Storage and transfersPrimary service data is intended to be hosted in the EEA. Some processing may occur in the United States or other countries through AI, analytics, security, and infrastructure providers, subject to applicable transfer safeguards. After subscriptionOrdinary service access ends when the paid subscription ends. Personal Customer Data is then returned, deleted, or irreversibly anonymized under the DPA and the retention schedule below. Backups may age out within 180 days. Your rightsDepending on where you live, you may have rights to access, correct, delete, restrict, object, or port personal data, and to withdraw consent. Contact support@salesbond.app.

1. Scope

This Privacy Notice explains how Rifeberry OÜ (“Rifeberry”, “SalesBond”, “we”, “us”, or “our”) processes personal data in connection with the SalesBond website, SaaS platform, CRM integrations, AI-assisted analytics, support, billing, business communications, partner program, and referral program (together, the “Services”).

The Services are offered only to organizations and individuals acting in a business or professional capacity. This Notice applies to personal data even where the contractual customer is a legal entity.

This Notice does not replace a customer’s own privacy notice to its employees, contractors, sales representatives, prospects, customers, or other individuals whose data the customer places in SalesBond. Our Data Processing Addendum (“DPA”) governs processing of Customer Data on the customer’s instructions. If there is a conflict regarding that processing, the DPA controls.

2. Who we are and our data protection roles

Rifeberry OÜ is an Estonian private limited company with registry code 16488400 and registered address Tornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia.

2.1 When Rifeberry OÜ is a controller

We act as a controller when we determine why and how personal data is processed for our own business purposes, including website operation, account and contract administration, billing, support, service security, fraud prevention, business development, partner and referral administration, marketing, and legal compliance.

2.2 When Rifeberry OÜ is a processor

A business customer normally determines the purposes and means of processing information imported from its CRM or otherwise submitted as Customer Data. For that data, the customer is the controller (or a processor for another controller), and Rifeberry OÜ acts as its processor or subprocessor. We process that data only to provide, secure, support, and improve the contracted Services, as permitted by the DPA and documented customer instructions.

If your request concerns information placed in SalesBond by your employer, client, or another SalesBond customer, that organization is normally the appropriate controller. We will direct the request to it or assist it as required by law and the DPA.

3. Where personal data comes from

We obtain personal data from the following sources:

  • directly from account administrators, users, prospects, partners, referrers, and support correspondents;
  • from CRMs and marketplaces connected or authorized by a customer, including through APIs, OAuth, webhooks, and marketplace installations;
  • from customer administrators and other authorized users who configure workflows or add data;
  • automatically from browsers, devices, application sessions, logs, cookies, and similar technologies;
  • from payment, identity, analytics, security, communications, and infrastructure providers;
  • from public business sources, where lawful, such as company websites and professional profiles; and
  • from derived analysis, including metrics, classifications, rankings, summaries, forecasts, and AI-generated recommendations based on other data.

4. Personal data we process

CategoryExamples Website and device dataIP address; browser and device type; operating system; language; approximate location derived from IP; referral URL; pages and features viewed; timestamps; cookie and similar identifiers; consent choices; diagnostic and security events. Business account dataName; work email; business contact details; organization; job title; role and permissions; account status; authentication and session data; workspace membership; administrator choices; marketplace installation identifiers. Contract and billing dataCustomer legal name; registered and billing address; registry and VAT/tax numbers; plan; subscription dates; invoices; amounts; currency; payment status; refunds or disputes; limited card metadata such as brand and last four digits. Stripe, not SalesBond, normally receives full payment-card details. CRM user and workforce dataName; work email; team and role; assigned records; activities; usage and performance metrics; goals; KPIs; rankings; seller results; change history. Companies, contacts, and leadsNames; employers; business contact details; job titles; account relationships; lead source; communications preferences; CRM identifiers; custom fields. Deals and pipeline dataDeal names; values; currencies; stages; probabilities; expected and actual close dates; products; owners; loss reasons; custom fields; record history. Activities and communicationsTasks; calls; meetings; calendar events; notes; email correspondence; message content; timestamps; participants; engagement data; outcomes; activity history. AI inputs and outputsPrompts; workflow instructions; selected CRM context; summaries; classifications; suggestions; forecasts; scores; risk indicators; recommendations; generated text; provider and model metadata. Support and business communicationsEmail correspondence; request details; troubleshooting information; feedback; meeting notes; business development and sales communications. Partner and referral dataApplicant and representative identity; business contact information; organization; referral links and codes; referred account attribution; commission eligibility; payout and tax information; program communications; compliance and fraud checks. Derived and aggregate dataUsage statistics; feature adoption; conversion and retention metrics; service performance; aggregated benchmarks; de-identified statistical insights.

File attachments. SalesBond does not intentionally import or process file attachments from connected CRMs. This does not prevent a user from placing personal data in notes, message bodies, custom fields, prompts, or other supported fields.

Sensitive and regulated data. The Services are not designed for special-category data under the GDPR, protected health information, payment-card numbers, government identifiers, precise geolocation, criminal-offence data, children’s data, or other highly sensitive data. Customers must not submit such data unless SalesBond has expressly agreed in writing and all required safeguards and legal bases are in place.

5. Why we process data and our legal bases

Where the GDPR or a similar law requires a legal basis, we rely on the bases below. More than one basis may apply depending on the data and context. When we act as processor, the customer is responsible for identifying its legal basis and issuing lawful instructions.

PurposeData typically involvedLegal basis when we are controller Provide and administer the ServicesAccount, contract, billing, configuration, usage, supportPerformance of a contract; legitimate interests in serving and administering business customers. Integrate CRMs and operate customer workflowsCRM identifiers, connected records, activities, configurationPrimarily processing on customer instructions under the DPA; for our own account administration, contract and legitimate interests. Generate AI analysis and recommendationsSelected Customer Data, prompts, outputs, model metadataPrimarily processing on customer instructions; otherwise contract and legitimate interests in providing requested functionality, subject to safeguards. Secure, troubleshoot, and prevent abuseLogs, IP, session, diagnostic, support, fraud signalsLegitimate interests in protecting users, systems, data, and legal rights; legal obligations where applicable. Bill and keep recordsCustomer, invoice, transaction and limited payment dataContract; legal obligations, including accounting and tax; legitimate interests in collecting amounts due and resolving disputes. Improve performance and usabilityProduct telemetry, support trends, de-identified or aggregate statisticsLegitimate interests in improving the Services. Identifiable Customer Content is not used for unrelated product development or general-purpose model training without a separate lawful basis and customer authorization. Analytics and non-essential cookiesCookie IDs, device and website interaction dataConsent where required; otherwise legitimate interests where local law permits. Business marketingBusiness contact details, engagement, preferencesConsent where required; otherwise legitimate interests in relevant B2B marketing, with a right to object or unsubscribe. Partner and referral programsIdentity, business, attribution, commission and payout dataContract; pre-contract steps; legitimate interests in operating and protecting the programs; legal obligations. Legal compliance and claimsAny data relevant to a legal duty, audit, dispute or requestLegal obligation; legitimate interests in establishing, exercising, or defending legal claims.

If we rely on legitimate interests, we consider the nature of the data, reasonable expectations, benefits, necessity, and impact on individuals, and apply safeguards. You may request information about a relevant balancing assessment.

6. CRM data, employee monitoring, and customer responsibilities

SalesBond can analyze sales activity, communications, goals, KPIs, rankings, and individual or team performance. Depending on how a customer configures and uses the Services, this may constitute employee or worker monitoring, profiling, or performance evaluation.

The customer is solely responsible for its decision to connect data and use SalesBond in its workplace or sales operations. Before doing so, the customer must:

  • provide clear and timely privacy notices to employees, contractors, sales representatives, prospects, customers, and other affected individuals;
  • identify a valid legal basis for collection, integration, monitoring, analysis, disclosure, and retention;
  • complete any required legitimate-interest assessment, data protection impact assessment, algorithmic impact assessment, or consultation;
  • comply with employment, labor, works council, collective bargaining, electronic communications, recording, and surveillance laws;
  • obtain consents where consent is legally required, without relying on invalid consent in an employment relationship;
  • configure access, data scope, AI workflows, and retention in a proportionate and least-intrusive manner; and
  • ensure that a qualified person reviews important recommendations and decisions.

SalesBond does not determine whether a customer may lawfully monitor a particular person, conversation, or activity. We may provide compliance controls and information, but they do not replace the customer’s legal assessment.

7. AI processing and model training

7.1 How AI is used

SalesBond uses AI to summarize and classify CRM information, detect patterns, assess deal or pipeline signals, prepare suggestions and forecasts, generate text, and assist professional users. To perform a requested workflow, we may transmit prompts, instructions, and the minimum relevant Customer Data to one or more commercial AI APIs operated by OpenAI, Anthropic, Mistral, and Google.

The provider and model used may vary based on feature, availability, quality, cost, region, security, and customer configuration. AI providers act as our subprocessors for Customer Data where the applicable contract and law support that role.

7.2 Training commitment

SalesBond does not use identifiable Customer Content to train its own or a third party’s general-purpose AI models. We do not opt Customer Content into optional model-improvement, feedback-training, public sharing, or similar programs. A different arrangement would require an express written customer opt-in, appropriate transparency, a lawful basis, and any other legally required safeguards.

7.3 Provider retention

Commercial API providers generally state that they do not use API inputs and outputs for model training by default, but they may keep limited logs or application state for abuse prevention, security, debugging, legal compliance, or features selected by us. Retention varies by provider, endpoint, configuration, and contractual control and may, in some cases, extend when content is flagged for policy or legal reasons. Where available and appropriate, we use no-training configurations, minimize submitted data, disable unnecessary storage, and evaluate zero-data-retention or equivalent controls.

Users should not place information in prompts that is unnecessary for the professional task. AI outputs may be inaccurate, incomplete, or biased and must be reviewed by a qualified person before reliance.

8. Cookies and analytics

We use cookies, local storage, pixels, SDKs, and similar technologies to operate the website and application, remember choices, secure sessions, measure performance, and understand use.

TypePurposeChoice Strictly necessaryAuthentication, security, network management, load balancing, consent storage, core functionality.Required for the requested service; generally cannot be disabled through our consent tool. PreferencesRemember language, interface, and similar choices.Consent where required; otherwise controllable through browser or product settings. AnalyticsMeasure website traffic, feature use, errors, and performance. Google Analytics may be used for this purpose only under the configuration and consent rules described below.Activated only after consent where EEA/UK/Swiss or other law requires it; consent can be withdrawn.

Where Google Analytics is enabled, it is loaded only after consent where required. We use a 14-month analytics data-retention setting and keep advertising personalization and Google Signals disabled unless separately disclosed and lawfully consented to.

Our separate Cookie Notice will identify the technologies in production, their providers, purposes, and lifetimes. Browser controls may not remove data already collected. Where legally required, we honor applicable opt-out preference signals such as Global Privacy Control for covered processing.

9. How we disclose personal data and our providers

We disclose personal data only as reasonably necessary for the purposes described in this Notice, under contractual, confidentiality, security, and data protection obligations where required. Recipients may include:

Recipient/categoryPurpose and dataTypical location/status Contabo GmbH — cloud server, database, and backup infrastructureApplication hosting, database, storage, and backup dumps; may contain all Customer Data and service metadata.European Economic Area; the application server, primary database, and backup copies are hosted on Contabo infrastructure in the EEA. StripeSubscription billing, payment processing, fraud prevention, invoices, limited transaction and account data. Stripe normally receives full card details directly.EEA and United States; contractual transfer safeguards as applicable. OpenAICommercial AI API processing of prompts, selected CRM context, outputs, and technical metadata.United States and other disclosed processing locations; safeguards as applicable. AnthropicCommercial AI API processing of prompts, selected CRM context, outputs, and technical metadata.United States and other disclosed processing locations; safeguards as applicable. Mistral AICommercial AI API processing of prompts, selected CRM context, outputs, and technical metadata.EEA and other disclosed processing locations; safeguards as applicable. GooglePaid Gemini API processing and Google Analytics; prompts, selected context, outputs, website/device analytics and technical metadata as applicable.EEA, United States, and other disclosed processing locations; safeguards as applicable. Sentry (Functional Software, Inc.), if enabledError monitoring and diagnostics; technical events, device/session data, and limited content included in error traces.United States or European Union depending on the selected account region; limited account and service metadata may be processed in other disclosed locations. Customer Content is minimized or redacted from diagnostic payloads where feasible. Cloudflare (Cloudflare, Inc.), if enabledDNS, CDN, network security, bot and attack mitigation; IP, headers, traffic and security logs.Global network, subject to selected region and safeguards. Business email provider supporting support@salesbond.appSupport and business email; sender/recipient details, message content, and attachments voluntarily emailed to us.EEA, United States, and other provider locations; contractual transfer safeguards as applicable. Customer-selected CRM and marketplaceImport, synchronization, installation, authentication, and requested data exchange.Determined by the customer and relevant provider. Professional advisers and corporate service providersLegal, accounting, audit, insurance, financing, transaction, and compliance support on a need-to-know basis.EEA or other locations with safeguards where required. Authorities, courts, and protected partiesCompliance with law, legal process, enforcement, security, fraud prevention, and protection of rights, safety, and property.As legally required. Corporate transaction recipientsDue diligence and completion of a merger, financing, reorganization, acquisition, sale, or similar transaction, subject to safeguards.As relevant to the transaction.

We do not sell Customer Content. We do not disclose Customer Content for third-party cross-context behavioral advertising. Our current subprocessor list and change-notification process will be maintained at salesbond.app/legal/subprocessors.

10. International transfers

We are established in Estonia and host the primary Service infrastructure, database, and backups in the European Economic Area using Contabo. Because we operate a global service and use providers such as AI, payment, analytics, security, and infrastructure companies, personal data may also be accessed from or processed in the United States and other countries whose laws may not provide the same level of protection as your home jurisdiction.

Where Chapter V of the GDPR or similar transfer rules apply, we use an available lawful transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, approved contractual terms, and supplementary technical and organizational measures. Where a recipient relies on an adequacy framework such as the EU–U.S. Data Privacy Framework, that mechanism applies only to the extent the recipient is validly certified and the transfer is covered.

You may contact us for information about the relevant transfer safeguards. Commercial terms, provider locations, and certifications can change, so the current subprocessor list and provider documentation should be consulted together with this Notice.

11. Retention and deletion

We retain personal data only for as long as reasonably necessary for the stated purpose, customer instructions, security and continuity, legal compliance, or legal claims. We consider the amount, nature, sensitivity, risk, purpose, relationship, contractual commitments, and applicable limitation and retention periods.

Data/categoryDefault retention approach Customer Data during subscriptionAvailable while the paid subscription remains active, subject to plan, account status, customer configuration, and the agreement. Customer Data after subscriptionOrdinary product access ends when the paid subscription ends. Subject to the DPA, customer instructions, mandatory retrieval rights, security needs, and legal holds, active-system Customer Data is returned, deleted, or irreversibly anonymized within up to 90 days after termination. A customer may be offered an export-only channel where law requires data retrieval; this does not restore general service access. BackupsEncrypted or access-restricted backup copies may persist until overwritten through the backup cycle, up to 180 days after active-system deletion. Backups are not used for ordinary analytics or operations and, if restored for disaster recovery, remain subject to the applicable deletion status. Anonymized statisticsMay be retained indefinitely only if irreversibly anonymized so no individual is reasonably identifiable. Pseudonymized data, hashed identifiers, and free-text records that can be linked back to a person remain personal data and are not treated as anonymous. Account, customer, and contract administrationFor the relationship and generally up to 24 months afterward, or longer where necessary for unresolved obligations, fraud prevention, or legal claims. Invoices, transactions, and accounting recordsSeven years from the end of the financial year in which the relevant transaction was recorded, or longer if another law or legal hold requires. Support correspondenceGenerally up to 24 months after the request is closed, unless needed longer for security, contract administration, or claims. Security, access, and diagnostic logsGenerally up to 12 months, unless a shorter configuration applies or longer retention is necessary to investigate an incident, abuse, or legal claim. Website analyticsUp to 14 months under the intended analytics configuration, subject to consent choices and final production settings. Marketing dataUntil you unsubscribe, object, or consent expires; afterward, minimal suppression data may be retained as needed to honor the opt-out. Partner and referral program recordsFor the program relationship and afterward as required for commissions, tax/accounting, fraud prevention, audits, disputes, and applicable limitation periods. Legal holds and disputesFor as long as reasonably necessary to comply with law or establish, exercise, or defend legal claims.

11.1 Why identifiable CRM data cannot be kept indefinitely for analytics

GDPR storage-limitation and processor obligations generally do not permit indefinite retention of identifiable CRM records merely because they may be useful for future analysis. After the applicable operational and legal retention period, we delete the personal data or transform it into genuinely anonymous aggregate statistics. Removing names alone is not sufficient if the remaining data can still single out, link to, or permit inferences about a person.

The 90-day active-system and 180-day backup periods are outer default limits, not guaranteed minimums. A valid deletion instruction, legal obligation, security incident, dispute, or mandatory switching/retrieval rule may require a different sequence.

12. Security

We use technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures may include access controls and least privilege, authentication and session controls, encryption in transit, encryption or equivalent protections at rest where supported, tenant separation, logging and monitoring, vulnerability and dependency management, backups, incident response, staff confidentiality, vendor review, and contractual safeguards.

Customers are responsible for selecting authorized users, protecting credentials and connected CRM tokens, configuring permissions, limiting data scope, training users, reviewing integrations, and promptly notifying us of suspected compromise. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

If a personal data breach affects Customer Data for which we act as processor, we will notify and assist the customer as required by the DPA and applicable law. Controller-side notifications to individuals or authorities will be made where legally required.

13. EEA, UK, and Swiss privacy rights

Subject to conditions and exceptions in applicable law, you may have the right to:

  • receive information about processing and obtain access to your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • restrict processing;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller;
  • withdraw consent at any time, without affecting processing already carried out;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where the relevant law applies; and
  • complain to a competent supervisory authority.

To submit a request, email support@salesbond.app and describe the data and relationship involved. We may request information reasonably necessary to verify identity, authority, and scope. We will respond within the period required by law, usually one month under the GDPR, subject to permitted extensions.

If SalesBond processes the data solely on behalf of a customer, please contact that customer first. We may forward the request to the customer and will assist it. A request may be refused or limited where permitted by law, including to protect the rights of others, confidentiality, security, legal privilege, or legal obligations.

14. United States privacy rights

Residents of certain U.S. states may have rights, subject to legal thresholds, exemptions, and verification requirements, to know or access, correct, delete, and obtain a portable copy of personal information; to opt out of certain sales, targeted advertising, sharing, or profiling; to limit certain uses of sensitive personal information; and to appeal a denied request.

SalesBond is a business-to-business service. Some U.S. state privacy laws exempt or limit coverage of business-contact, employee, or processor data. Where a right applies, you may exercise it at support@salesbond.app. You may use an authorized agent where permitted; we may verify the agent’s authority and your identity. We will not discriminate against you for exercising an applicable privacy right.

We do not sell personal information for money and do not use Customer Content for targeted advertising. We configure analytics and cookies so they are not used for cross-context behavioral advertising. We do not enable advertising personalization or Google Signals unless separately disclosed and subject to any required consent or opt-out. If our practices change, we will update this Notice and provide any legally required opt-out mechanism.

15. Marketing communications

We may send relevant B2B product, event, partner, or service communications where permitted by law. Marketing emails include an unsubscribe method. You may also object or withdraw consent by emailing support@salesbond.app. Transactional, security, billing, legal, and service-administration messages are not marketing and may continue while relevant.

An unsubscribe request may take a short period to process. We may retain an email address and opt-out status on a suppression list to ensure that the preference is respected.

16. Automated outputs and human review

SalesBond may create rankings, risk indicators, forecasts, deal scores, summaries, and recommendations using rules, statistical analysis, and AI. These outputs are intended to support professional judgment. SalesBond does not itself make hiring, firing, compensation, credit, insurance, eligibility, or other decisions that produce legal or similarly significant effects for an individual.

Customers must not rely on SalesBond output as the sole basis for a legally or similarly significant decision. They must review inputs and outputs, consider context, allow appropriate human intervention, provide explanations or challenge mechanisms where required, test for errors and bias, and comply with employment, AI, discrimination, consumer, and sector-specific laws.

17. Business users only; no children

SalesBond is intended solely for businesses and professional users aged 18 or over. It is not directed to consumers or children, and minors may not create accounts or use the Services. Customers must not submit children’s personal data. If you believe a child’s data has been provided, contact support@salesbond.app so we can investigate and take appropriate action.

18. Third-party services

The Services may link to or interoperate with customer-selected CRMs, marketplaces, websites, and third-party services. Their privacy practices are governed by their own notices and agreements. A customer’s authorization of an integration instructs us to exchange the data necessary to provide that integration. We are not responsible for independent processing by a third party that is not acting as our processor.

19. Changes to this Notice

We may update this Privacy Notice to reflect changes in the Services, providers, law, or our practices. We will post the updated version with a revised effective date. If a change is material, we will provide additional notice where required, for example by email, in-product notice, or a prominent website notice. A change to this Notice does not authorize materially different processing of Customer Data contrary to the DPA or applicable law.

20. Contact and complaints

Privacy requests and questions may be sent to:

Rifeberry OÜ Registry code 16488400 Tornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia Email: support@salesbond.app

You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, aki.ee/en, or with the supervisory authority in your habitual residence, place of work, or place of the alleged infringement where applicable. We encourage you to contact us first so we can try to resolve the issue.

Table of contents

1. Purpose and scope

This Security and Trust Statement summarizes the approach Rifeberry OÜ (Rifeberry, SalesBond, we, us or our) takes to protect the SalesBond website, SaaS platform, CRM integrations, AI-assisted features and related systems (the Services).

This is a public summary, not a certification, audit report, service-level agreement or guarantee that security incidents cannot occur. Contractual security and data-processing obligations are governed by the applicable SalesBond agreement and Data Processing Addendum (DPA). If this statement conflicts with those documents, the agreement and DPA control.

2. Shared responsibility

SalesBond is responsible for security measures within the systems it controls. Customers are responsible for their devices, networks, CRM accounts, user administration, access decisions, credentials, connected applications, lawful configuration, data scope and actions taken on SalesBond outputs.

Security depends on both parties. Customer should use least privilege, promptly remove access for departing personnel, protect email accounts used for login, review integrations, limit imported CRM data and report suspected compromise without delay.

3. Security governance

SalesBond maintains a security program intended to identify and manage risks appropriate to the nature, scope and sensitivity of the Services. Measures may include documented responsibilities, confidentiality commitments, access reviews, vendor assessment, incident procedures, change control, security awareness and periodic control review.

Access to production systems and Customer Personal Data is limited to personnel and providers with a legitimate need and is subject to appropriate confidentiality and access restrictions.

4. Authentication and access control

SalesBond uses account authentication and authorization controls designed to prevent unauthorized access. Administrative and service access should follow least-privilege principles and be removed or changed when no longer needed.

Customer controls its Authorized Users and organization-level permissions. A login link, session or connected CRM credential must not be shared. Customer must secure the email account used for authentication and promptly notify SalesBond if it believes an account or integration token has been compromised.

5. Tenant separation and application security

SalesBond is designed as a multi-tenant service. Logical authorization controls should prevent one Customer from accessing another Customer’s data. Server-side authorization must be enforced independently of the user interface.

The application should validate inputs, enforce permission checks, protect against common web vulnerabilities and restrict internal interfaces. Security-relevant changes should be reviewed and tested in proportion to risk.

6. Encryption and secret management

SalesBond intends to protect data in transit using current, industry-standard transport encryption. Secrets, integration credentials and other sensitive values should be stored and transmitted only through designated protected mechanisms and must not be placed in source code or logs.

7. Infrastructure, availability and backups

SalesBond uses third-party infrastructure providers identified in the Subprocessor List. Infrastructure architecture, primary region, database placement and backup location must be recorded and kept consistent with public privacy disclosures.

Backups should be protected against unauthorized access and tested for restoration. Availability and recovery measures should be proportionate to Customer risk, but no recovery-time or recovery-point commitment applies unless stated in a written order form or service-level agreement.

8. Logging, monitoring and detection

SalesBond may collect security, authentication, application, infrastructure and error logs to operate the Services, investigate anomalies, prevent abuse and respond to incidents. Logging should be limited to what is necessary and should avoid recording credentials, access tokens, unnecessary CRM content or full AI prompts.

Sentry or another disclosed provider may be used for diagnostics and error monitoring if enabled. Payload filtering and data scrubbing must be configured before Customer Personal Data is sent.

9. Secure development and vulnerability management

SalesBond aims to integrate security into design, development, testing, deployment and maintenance. Depending on risk, practices should include code review, dependency management, automated checks, separation of duties, controlled deployment, vulnerability triage and timely remediation.

No statement about independent penetration testing, certification or a formal secure-development standard should be published unless the activity has been completed and evidence is current.

10. Vendors and subprocessors

SalesBond assesses providers that may process Customer Personal Data and uses contractual protections appropriate to their role. The current Subprocessor List identifies providers involved in hosting, AI, monitoring, network security, email/support and backups where applicable.

Where required, SalesBond enters into data-processing terms and implements lawful international-transfer safeguards. Provider access and data scope should be minimized and reviewed when a provider or configuration changes.

11. AI security

AI-assisted workflows introduce risks such as inaccurate output, prompt injection, unintended disclosure and excessive data submission. SalesBond seeks to reduce these risks through data minimization, commercial provider accounts, restricted integrations, safety controls and human oversight.

Customers must not place passwords, access tokens, payment credentials or unnecessary sensitive data in prompts. AI output must not directly authorize a high-risk action without independent validation and appropriate human approval.

12. Security incident response

SalesBond maintains or will maintain procedures for identifying, containing, investigating, remediating and learning from security incidents. Where a confirmed incident affects Customer Personal Data processed on behalf of a Customer, SalesBond will notify and assist the Customer as required by the DPA and applicable law.

Notifications may be provided in phases as information becomes available. SalesBond will not delay an initial legally required notification solely because every detail is not yet known.

13. Retention and deletion

SalesBond applies the retention and deletion approach described in the Privacy Notice and DPA. Ordinary access ends when the subscription ends. Customer Personal Data is then returned, deleted or irreversibly anonymized as required by the DPA, subject to legal obligations and agreed retention. Backups may age out within the disclosed maximum period.

Deletion from active systems does not necessarily cause immediate deletion from protected backups, but backup data must remain access-restricted and age out under the applicable schedule.

14. Customer security responsibilities

Customer must:

  • authorize only appropriate users and permissions;
  • secure email accounts, devices, networks and CRM credentials;
  • promptly revoke access for departing or reassigned personnel;
  • configure connected CRM scope and retention proportionately;
  • avoid importing unsupported sensitive data;
  • review audit information and unusual activity available to Customer;
  • maintain independent backups or exports where necessary for Customer’s continuity obligations; and
  • report suspected compromise, misuse or vulnerabilities promptly.

15. Reporting a vulnerability or security concern

Security concerns may be reported to support@salesbond.app. Reports should include a clear description, affected URL or feature, reproducible steps and potential impact. Do not access another person’s data, disrupt the Services, use social engineering, exfiltrate data or continue testing after demonstrating the issue.

SalesBond does not currently promise a bug bounty, payment, safe-harbor program or response SLA unless separately published in writing.

16. Certifications, updates and contact

SalesBond does not claim SOC 2, ISO 27001, PCI DSS or another security certification unless a current certification or report is expressly identified on an official SalesBond page. Use of certified infrastructure providers does not mean SalesBond itself is certified.

SalesBond may update this statement as architecture, controls, providers and risks evolve. An update will not materially reduce contractual protections where the DPA prohibits such reduction.

Rifeberry OÜ

Registry code: 16488400

Tornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia

Email: support@salesbond.app

Table of contents

1. Scope and contractual effect

This Acceptable Use Policy (the Policy) applies to access to and use of the SalesBond website, SaaS platform, CRM integrations, AI-assisted features, APIs, support channels and related services (the Services) provided by Rifeberry OÜ (Rifeberry, SalesBond, we, us or our).

The Policy forms part of the SalesBond Terms of Service or other agreement governing the Services (the Agreement). Customer must ensure that its Authorized Users, contractors and anyone using the Services through Customer comply with this Policy. Capitalized terms not defined here have the meanings given in the Agreement.

The Services are offered only for lawful business and professional use by persons aged 18 or over. Customer is responsible for determining whether its intended use is lawful and appropriate in every relevant jurisdiction.

2. General obligations

Customer must:

  • use the Services lawfully, honestly and in accordance with the Agreement, this Policy and applicable third-party terms;
  • obtain all notices, rights, permissions and consents necessary for Customer Data and Customer’s instructions;
  • maintain appropriate human supervision over AI outputs, analytics, rankings, recommendations and automated workflows;
  • protect accounts, CRM credentials, integration tokens and access links;
  • limit access and submitted data to what is reasonably necessary for the authorized business purpose; and
  • promptly notify SalesBond of suspected unauthorized access, misuse or security incidents.

3. Illegal, harmful and abusive activity

Customer must not use the Services to create, facilitate, promote, conceal or materially assist:

  • conduct that violates applicable law, a binding order or another person’s rights;
  • fraud, scams, deceptive impersonation, phishing, identity theft, money laundering, sanctions evasion or unlawful financial activity;
  • exploitation, trafficking, sexual abuse or exploitation of any person, or any sexual content involving minors;
  • credible threats, stalking, harassment, unlawful discrimination, hateful abuse or incitement to violence;
  • development, procurement or use of weapons where prohibited by law or applicable provider policies;
  • sale or distribution of illegal goods, controlled substances or unlawfully obtained data;
  • obstruction of an investigation, destruction of legally required records or other concealment of unlawful activity; or
  • any activity reasonably likely to cause serious physical, financial, reputational or psychological harm.

4. Restricted and unauthorized data

Unless SalesBond has expressly agreed in writing and appropriate safeguards are in place, Customer must not submit or intentionally process through the Services:

  • payment-card numbers, card security codes, bank credentials or authentication secrets;
  • passwords, private cryptographic keys or access tokens except through designated secure integration fields;
  • protected health information or medical records;
  • biometric identifiers used to uniquely identify a person;
  • government identification numbers where not strictly necessary and expressly supported;
  • precise location data used to track an individual;
  • information about children or persons under 18;
  • special-category or highly sensitive personal data; or
  • data subject to sector-specific localization, secrecy or professional-confidentiality rules that the Services are not contractually configured to support.

Customer must not place unnecessary personal or confidential information in AI prompts, support tickets, free-text fields or error reports.

5. Sales communications and outreach

Customer must not use the Services to send or facilitate:

  • spam, unlawful direct marketing or messages sent without a required consent or other lawful basis;
  • communications that conceal the sender, use deceptive subject lines or misrepresent identity, affiliation, pricing, availability or commercial intent;
  • automated calls, texts, email sequences or similar outreach in violation of electronic-communications, telemarketing, anti-spam or consumer-protection law;
  • messages to persons who have validly opted out, objected or registered on an applicable suppression list; or
  • scraping, enrichment or outreach using data obtained unlawfully or contrary to a binding platform restriction.

Customer is responsible for honoring unsubscribe, objection, suppression and do-not-contact requirements and for retaining evidence required to demonstrate compliance.

6. Privacy, surveillance and worker-related use

Customer must not use the Services for covert, disproportionate or unlawful monitoring of employees, contractors, prospects, customers or other persons.

Before using CRM activity, communications, rankings, coaching indicators or performance analytics relating to individuals, Customer must determine and document an appropriate legal basis, provide required notices, consult workers or works councils where required, and configure access, data scope and retention proportionately.

The Services must not be used to infer highly sensitive traits, conduct emotion recognition, perform biometric categorization or create discriminatory profiles unless the use is expressly supported by SalesBond and demonstrably lawful. SalesBond does not currently support such uses.

7. High-impact and regulated decisions

Customer must not use a SalesBond output as the sole or determinative basis for a decision that produces legal or similarly significant effects for a person, including decisions concerning:

  • hiring, termination, promotion, discipline, compensation or access to work;
  • credit, lending, insurance, housing, education or essential services;
  • medical diagnosis or treatment;
  • legal rights, eligibility, public benefits or law-enforcement action; or
  • any other high-impact decision regulated by applicable law.

SalesBond is not designed or authorized as a medical device, credit-scoring service, background-check service, employment decision system, legal advice service or other regulated decision engine. A qualified person must independently assess relevant facts, limitations and applicable law.

8. AI-assisted features

Customer must not:

  • represent an AI output as verified fact when it has not been appropriately reviewed;
  • use AI to fabricate evidence, reviews, endorsements, identities, credentials or customer communications;
  • remove or conceal an AI disclosure or provenance marker where disclosure is legally required;
  • use prompts or data designed to bypass safety controls, extract confidential system information or compromise another tenant;
  • use outputs to unlawfully discriminate, manipulate a vulnerable person or exploit sensitive characteristics; or
  • use the Services to train, benchmark or develop a competing model or service where prohibited by the Agreement.

AI outputs may be incomplete, inaccurate, outdated, biased or unsuitable. Customer must apply meaningful human review before relying on, sending or acting on an output.

9. Cybersecurity and service integrity

Customer must not:

  • probe, scan, test or exploit a vulnerability without SalesBond’s prior written authorization;
  • introduce malware, ransomware, destructive code, denial-of-service traffic or harmful payloads;
  • bypass authentication, authorization, tenant boundaries, rate limits, safety controls or usage restrictions;
  • access or attempt to access another customer’s account, data or systems;
  • share login links or credentials, impersonate another user or conceal the source of automated requests;
  • interfere with availability, performance, monitoring, billing or security controls;
  • reverse engineer, decompile or extract source code, models, prompts or non-public system components except where mandatory law expressly permits; or
  • use the Services to coordinate an attack, credential theft, unauthorized surveillance or intrusion.

Good-faith vulnerability reports must be submitted under Section 13 and not exploited beyond what is necessary to demonstrate the issue.

10. Intellectual property and third-party rights

Customer must not submit, reproduce, distribute or generate content that infringes intellectual-property, privacy, confidentiality, publicity or contractual rights. Customer must have the authority to use Customer Data and connected CRM information and to instruct SalesBond to process them.

The Services must not be used to remove ownership notices, misappropriate trade secrets or create a misleading impression of sponsorship, certification or endorsement.

11. Unauthorized commercial use

Except as expressly permitted by the Agreement, Customer must not resell, sublicense, lease, timeshare or provide the Services as a service bureau; disclose non-public product information to a competitor; conduct abusive automated extraction; or use the Services to avoid applicable fees or usage limits.

12. Enforcement

SalesBond may investigate suspected violations and may use automated and manual controls to prevent abuse. To the extent permitted by the Agreement and law, SalesBond may:

  • warn Customer or require corrective action;
  • remove or restrict content, integrations, features or workflows;
  • limit requests or block traffic;
  • suspend or terminate an account or affected Services;
  • preserve relevant records;
  • notify the affected Customer administrator, provider or authority where legally required or reasonably necessary to prevent serious harm; and
  • cooperate with valid legal process.

SalesBond may act without advance notice where reasonably necessary to address an urgent security risk, unlawful activity, third-party rights violation or material harm. Customer remains responsible for its users and use of the Services.

13. Reporting concerns

Report suspected abuse, unlawful content, security issues or violations to support@salesbond.app. Include sufficient detail to identify the account, relevant activity and reason for concern, but do not send unnecessary sensitive data.

14. Changes and contact

SalesBond may update this Policy to reflect changes in the Services, risks, provider requirements or law. Material changes will be notified as required by the Agreement or applicable law. Continued use after the effective date constitutes acceptance to the extent permitted by the Agreement.

Rifeberry OÜ

Registry code: 16488400

Tornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia

Email: support@salesbond.app

Authorized providers for processing Customer Personal Data

1. Scope

This Subprocessor List forms part of the SalesBond Data Processing Addendum (the “DPA”). It identifies third parties that Rifeberry OÜ may appoint to process Customer Personal Data on behalf of a Customer in connection with the SalesBond Services. Capitalized terms not defined here have the meanings given in the DPA.

A provider is a Subprocessor only to the extent it processes Customer Personal Data on behalf of Rifeberry OÜ in its role as processor or subprocessor. The list does not automatically include providers that process data for Rifeberry OÜ’s own billing, contract administration, website analytics, marketing, or legal-compliance purposes.

2. Authorized and planned Subprocessors

Provider / contracting entityService and Customer Personal DataProcessing location / transfer status Contabo GmbHApplication hosting, database, object storage and backup dumps; potentially all Customer Personal Data and service metadata.European Economic Area; the primary application server, database, backup copies and related infrastructure are hosted on Contabo infrastructure in the EEA. Limited authorized support access may occur from other locations subject to appropriate safeguards. OpenAI Ireland LimitedCommercial AI API; selected prompts, CRM context, outputs, model identifiers and technical metadata.United States, EEA and other disclosed locations depending on product/configuration; appropriate transfer safeguards where required. Anthropic, PBCCommercial AI API; selected prompts, CRM context, outputs, model identifiers and technical metadata.United States and other disclosed locations; multi-region routing may apply; appropriate safeguards where required. Mistral (France)Commercial AI API; selected prompts, CRM context, outputs, model identifiers and technical metadata.EEA and other disclosed locations depending on product/configuration; appropriate safeguards where required. Google Cloud EMEA Limited — Vertex AI / paid Gemini APICommercial AI API; selected prompts, CRM context, outputs, model identifiers and technical metadata.EEA, United States and other disclosed locations depending on product, region and support; appropriate safeguards where required. Functional Software, Inc. (Sentry), if enabledError/performance monitoring and diagnostics; technical events, identifiers and limited Customer Personal Data if included in traces. Payloads must be scrubbed.United States or European Union depending on the selected account region; limited account, configuration and support metadata may be processed in other disclosed locations. Appropriate transfer safeguards apply where required. Cloudflare, Inc., if enabledDNS, CDN, WAF, bot protection and network security; IP addresses, request headers, traffic metadata and security logs.Global network subject to enabled services, account configuration and applicable safeguards. Google Cloud EMEA Limited — Google Workspace, if enabledAccount, authentication, transactional and support communications; business contact details, message content and data voluntarily included in support requests.EEA, United States and other disclosed Google processing and support locations; appropriate transfer safeguards apply where required.

SalesBond may use one or more disclosed AI providers depending on the relevant feature, availability, model selection, Customer configuration, security requirements and service performance. A provider must not receive Customer Personal Data until the applicable commercial terms, DPA, transfer mechanism and production configuration have been reviewed.

3. Providers generally outside this list

Stripe. Stripe processes billing, transaction, fraud-prevention and payment-method data under its own payment terms and applicable legal roles. Stripe is not intended to receive CRM Customer Content and is not included as a Subprocessor under the DPA unless the actual implementation causes Stripe to process Customer Personal Data on a Customer’s behalf beyond ordinary payment processing.

Google Analytics and similar website analytics. These services are used, if enabled and consented to where required, for Rifeberry OÜ’s own website and product analytics. They must not receive CRM Customer Content and are addressed in the SalesBond Privacy Notice and Cookie Policy rather than this list, unless their actual use makes them a Subprocessor for Customer Personal Data.

Customer-directed CRM and marketplace integrations. A CRM, marketplace or other third-party service separately selected and contracted by the Customer is generally not a Rifeberry OÜ Subprocessor merely because the Customer instructs SalesBond to connect to that service. The third party’s own terms and privacy documentation apply to the Customer’s relationship with that provider.

4. Changes, notice and objections

Rifeberry OÜ may add or replace Subprocessors in accordance with Section 10 of the DPA. Rifeberry OÜ will provide at least fifteen (15) days’ advance notice before a new Subprocessor begins processing Customer Personal Data, ordinarily by email, in-product notice or another update-notification method.

A Customer may object during the notice period by emailing support@salesbond.app and explaining its reasonable and documented data-protection grounds. The objection process and available remedies are governed by the DPA.

Urgent replacements needed to address a security incident, availability failure, legal requirement or material security risk may be notified as soon as reasonably practicable, as provided in the DPA.

5. International transfers

Where use of a Subprocessor involves a Restricted Transfer, Rifeberry OÜ will implement an applicable lawful transfer mechanism, such as an adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum or another mechanism permitted by Applicable Data Protection Law, together with supplementary measures where required.

6. Contact

Questions about this list or Subprocessor changes may be sent to:

Rifeberry OÜ

Registry code: 16488400

Tornimäe tn 5

10145 Kesklinna linnaosa, Tallinn

Harju maakond

Estonia

Email: support@salesbond.app

Table of contents
ControllerRifeberry OÜ Public URLsalesbond.app/legal/cookies Effective date20 July 2026 Version1.0 Contactsupport@salesbond.app

Rifeberry OÜ

Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia

Registry code 16488400

1. Scope

This Cookie Policy explains how Rifeberry OÜ (“Rifeberry”, “SalesBond”, “we”, “us”, or “our”) uses cookies and similar technologies on the SalesBond website, application, account pages, and related online services (the “Services”). It should be read with the SalesBond Privacy Notice available at salesbond.app/legal/privacy.

The Services are intended for business and professional users aged 18 or over. This Policy applies to visitors and users regardless of whether they have a SalesBond account.

2. What cookies and similar technologies are

Cookies are small text files placed on a browser or device. They can allow a site to remember a session, security status, preferences, or activity. We may also use local storage, session storage, pixels, software development kits, server-side identifiers, tags, and similar technologies. In this Policy, “cookies” includes these technologies unless the context requires otherwise.

Cookies may be first-party, meaning set by SalesBond, or third-party, meaning set or accessed by another provider. Session cookies usually expire when the browser closes. Persistent cookies remain until their stated expiry, deletion by the user, or replacement.

3. Who is responsible

For the use of cookies described in this Policy, the controller is Rifeberry OÜ, registry code 16488400, Tornimäe tn 5, 10145 Kesklinna linnaosa, Tallinn, Harju maakond, Estonia. Privacy and cookie questions may be sent to support@salesbond.app.

Some third parties may act as our processor, joint controller, or independent controller depending on the technology and context. Their notices may also apply.

4. Categories and purposes

CategoryPurposeConsent status Strictly necessaryProvide requested pages and features; authenticate users; maintain sessions; route traffic; protect accounts; prevent fraud and attacks; remember privacy choices; preserve load balancing and core settings.Used without optional-cookie consent where permitted because they are necessary to provide a service requested by the user or secure it. PreferencesRemember optional interface choices such as language, display, or other convenience settings that are not strictly necessary.Disabled until consent where required, unless a specific setting is requested by the user and legally exempt. AnalyticsUnderstand visits, navigation, feature adoption, errors, and performance; produce aggregated reports; improve usability. Google Analytics is the planned analytics provider.Disabled until the user gives analytics consent in the EEA, UK, Switzerland, and other jurisdictions requiring prior consent. Advertising/targetingMeasure or personalize advertising across services or build advertising profiles.SalesBond does not currently intend to use advertising or targeted-advertising cookies. They must not be activated without updating this Policy and obtaining any required consent.

Rejecting optional cookies will not prevent access to the core website or paid Services, although optional analytics or preference features may not operate.

5. Cookie and technology inventory

The inventory below describes the standard SalesBond configuration. Technologies used in a particular environment may vary by enabled feature. We update this inventory after material changes and periodically verify it against the production website and application.

5.1 Strictly necessary

Cookie / technologyProviderPurposeDuration salesbond_sessionRifeberry OÜAuthenticate a user and maintain a secure application session.Session; up to 30 days only where persistent sign-in is enabled. salesbond_csrfRifeberry OÜPrevent cross-site request forgery and protect submitted requests.Session. salesbond_cookie_consentRifeberry OÜ — in-house consent managerRemember accept, reject, and category choices and the applicable policy version.Recommended: 6 months, applied equally to acceptance and refusal. __cf_bm / cf_clearance, if Cloudflare security features are enabledCloudflareBot management, abuse prevention, and security challenge status.__cf_bm: 30 minutes after inactivity; cf_clearance: configuration dependent. Stripe checkout technologiesStripeSecure payment checkout, fraud prevention, and transaction processing when a user opens Stripe-hosted or embedded payment functionality.Provider and checkout-session dependent; verify production scan and Stripe notice.

5.2 Preferences

Cookie / technologyProviderPurposeDuration salesbond_localeRifeberry OÜRemember the user’s selected language or regional format.12 months. salesbond_ui_preferencesRifeberry OÜRemember optional display, layout, or similar choices.12 months.

5.3 Analytics and diagnostics

Cookie / technologyProviderPurposeExpected duration _ga, if analytics consent is grantedGoogle AnalyticsDistinguish browsers/users for aggregated analytics reporting.Up to 2 years, subject to configuration and consent. _ga_<GA4 property identifier>, if analytics consent is grantedGoogle AnalyticsMaintain and count session state for the relevant GA4 property.Up to 2 years, subject to configuration and consent. Additional Google Analytics cookies, if generated by the deployed configurationGoogle AnalyticsAnalytics, rate limiting, or campaign/session measurement if enabled by the deployed configuration.Provider/configuration dependent. Sentry diagnostic session/local storage, if Sentry is enabledSentryError diagnostics, performance monitoring, and technical session correlation; Customer Content should be scrubbed from payloads where feasible.Session or configuration-dependent; retained only as long as necessary for diagnostics.

No CRM Customer Content should be placed in analytics cookies or analytics event parameters. Google Analytics and diagnostic tags must not receive names, email addresses, message content, deal notes, or other direct CRM identifiers.

6. Third-party technologies

Third-party providers may receive online identifiers, IP addresses, browser/device information, consent state, page or event information, and other data described in the Privacy Notice. The providers currently planned or under consideration include Google Analytics, Stripe, Cloudflare, and Sentry. Only providers actually enabled in production should appear in the final inventory.

Third parties may change their technologies and lifetimes. We periodically review the inventory and may refer to the provider’s own notice for dynamic or provider-controlled cookies, but this does not replace our obligation to describe the technologies actually used on SalesBond.

7. Consent and lawful use

Where applicable law requires consent, we do not set or access preference, analytics, advertising, or other non-essential cookies until the user gives a freely given, specific, informed, and unambiguous choice. Optional categories are off by default and are not pre-selected.

Strictly necessary cookies may be used without optional-cookie consent where permitted because they are required to provide a service requested by the user, transmit communications, preserve security, remember privacy choices, or perform equivalent essential functions.

Consent is not bundled with acceptance of the Terms of Service or Data Processing Addendum. An account, subscription, or core Service is not conditional on accepting analytics cookies.

8. Managing or withdrawing choices

Users can accept, reject, or select categories through the consent banner. Choices can be changed at any time through the persistent “Cookie settings” link in the website and application footer. Withdrawal is effective for future processing and does not affect processing already carried out on the basis of valid consent.

After withdrawal or refusal, non-essential tags will not load on future page views and optional cookies accessible to SalesBond will be deleted where technically feasible. Third-party or previously collected data may remain for the provider’s applicable retention period.

We intend to ask users to renew their choice after six months and sooner if purposes, categories, or providers materially change. If cookies are cleared, another browser or device is used, or storage is unavailable, the banner may appear again.

9. Browser and device controls

Most browsers allow users to view, block, or delete cookies. Blocking strictly necessary cookies may prevent login, checkout, security checks, or other core functions. Browser settings are device- and browser-specific and may not communicate a legally valid category choice to every website.

SalesBond does not currently use Customer Content for targeted advertising. Where applicable law requires recognition of an opt-out preference signal such as Global Privacy Control, we will treat a recognized signal as an opt-out for covered sale, sharing, or targeted-advertising processing. A Do Not Track signal does not have a single legally defined response in all jurisdictions.

10. International transfers

Cookie and analytics providers may process data in the EEA, United States, and other countries. Where required, we use an applicable transfer mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK transfer instruments, and supplementary safeguards. Further information is in the Privacy Notice and Data Processing Addendum.

11. Retention

Cookie lifetimes are listed in the inventory. We retain consent records for as long as reasonably necessary to demonstrate the choice and comply with law. Analytics data is intended to be configured for a maximum of 14 months unless a shorter period is selected. Security records may be retained longer where needed to investigate abuse or an incident. Data is deleted, aggregated, or anonymized when no longer required.

Google Analytics data retention is configured for 14 months. Advertising personalization and Google Signals remain disabled unless separately disclosed and lawfully consented to. Where supported, user-level deletion requests are handled through the available Google Analytics controls.

12. Rights and contact

Depending on applicable law, individuals may have rights regarding Personal Data generated through cookies, including access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. Requests may be sent to support@salesbond.app. More information, including the Estonian Data Protection Inspectorate’s details, appears in the Privacy Notice.

13. Changes

We may update this Cookie Policy when technologies, providers, purposes, law, or the Services change. The updated version will show a revised effective date. We will request renewed consent where required, including when a change materially affects an existing choice.

Table of contents
ProcessorRifeberry OÜ CustomerThe organization accepting the SalesBond Terms of Service Effective dateThe date the Customer accepts the Terms or first submits Customer Personal Data, whichever occurs first Version1.0 Privacy contactsupport@salesbond.app

Rifeberry OÜ

Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia

Registry code 16488400

Agreement overview

This Data Processing Addendum (“DPA”) forms part of the SalesBond Terms of Service or other written agreement governing the Customer’s use of the Services (the “Agreement”). It applies where Rifeberry OÜ processes Customer Personal Data on behalf of the Customer.

The Customer enters into this DPA for itself and, where permitted, for its Affiliates that use the Services. By accepting the Agreement, enabling an integration, or submitting Customer Personal Data, the Customer accepts this DPA. No separate signature is required unless the parties agree otherwise in writing.

IssuePosition Primary rolesCustomer is controller; Rifeberry OÜ is processor. If Customer is itself a processor, Rifeberry OÜ acts as Customer’s subprocessor. Processing scopeCRM synchronization, storage, analysis, AI-assisted features, security, support, and other processing necessary to provide the SalesBond Services. SubprocessorsGeneral written authorization subject to advance notice and a right to object on reasonable data-protection grounds. International transfersAppropriate safeguards, including the 2021 EU SCCs and UK Addendum where required. End of subscriptionOrdinary service access ends under the Agreement. Customer Personal Data is returned, deleted, or irreversibly anonymized under Section 13; backups age out within 180 days. LiabilityThe Agreement’s exclusions and liability caps apply to this DPA to the fullest extent permitted by law, without reducing mandatory rights under the SCCs.

1. Definitions and interpretation

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

Affiliate. an entity that directly or indirectly controls, is controlled by, or is under common control with a party.

Applicable Data Protection Law. all privacy, data protection, and breach-notification laws applicable to the processing under this DPA, including where applicable the GDPR, UK GDPR, Swiss FADP, and U.S. State Privacy Laws.

Customer Personal Data. Personal Data contained in Customer Data and processed by Rifeberry OÜ on behalf of Customer to provide the Services.

Data Subject. an identified or identifiable natural person to whom Customer Personal Data relates.

EEA. the European Economic Area.

GDPR. Regulation (EU) 2016/679.

Restricted Transfer. a transfer of Personal Data requiring a transfer mechanism under Applicable Data Protection Law.

Security Incident. a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Rifeberry OÜ. It excludes unsuccessful attempts and events that do not compromise Customer Personal Data.

Services. the SalesBond website, SaaS platform, CRM integrations, AI-assisted functions, support, and related services under the Agreement.

Subprocessor. a third party appointed by Rifeberry OÜ to process Customer Personal Data on Customer’s behalf.

U.S. State Privacy Laws. the CCPA and other U.S. state comprehensive privacy laws applicable to Customer Personal Data and the processing under this DPA.

The terms controller, processor, processing, Personal Data, and supervisory authority have the meanings given by Applicable Data Protection Law. References to writing include electronic form. “Including” means including without limitation.

2. Scope and hierarchy

2.1 This DPA applies only to Customer Personal Data processed by Rifeberry OÜ as processor or subprocessor. It does not govern data for which Rifeberry OÜ acts as an independent controller, such as its own billing, contract administration, website marketing, and legal-compliance data, which is covered by the SalesBond Privacy Notice.

2.2 If a conflict concerns Personal Data processing, the following order controls: (a) applicable mandatory law; (b) applicable Standard Contractual Clauses or UK transfer instrument; (c) this DPA; and (d) the Agreement. The Agreement otherwise remains in full force, including commercial terms, warranty disclaimers, and liability limitations.

2.3 This DPA does not require Rifeberry OÜ to process data in a way that violates law, a binding order, the rights of another person, or the Agreement.

3. Roles and Customer instructions

3.1 Roles

Customer is controller and Rifeberry OÜ is processor. Where Customer processes Personal Data on behalf of another controller, Customer is processor and Rifeberry OÜ is Customer’s subprocessor. Each party will comply with the obligations applicable to its role.

3.2 Documented instructions

Customer instructs Rifeberry OÜ to process Customer Personal Data as necessary to: provide, host, configure, support, secure, monitor, and improve the contracted Services; synchronize authorized CRMs; perform requested AI-assisted workflows; prevent fraud and abuse; maintain continuity and backups; comply with law; and act on additional documented instructions consistent with the Agreement and this DPA.

The Agreement, Customer’s configuration and use of the Services, support requests, and other written directions constitute documented instructions. Rifeberry OÜ will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so. Rifeberry OÜ may suspend the affected processing until the parties agree on a lawful instruction.

3.3 Customer responsibilities

Customer represents and warrants that its instructions and use of the Services comply with law. Customer is responsible for:

  • providing all required notices and identifying a valid legal basis for collection, integration, monitoring, AI analysis, disclosure, and retention;
  • ensuring it has authority to provide Customer Personal Data and appoint Rifeberry OÜ and its Subprocessors;
  • complying with employment, works council, surveillance, communications, recording, AI, discrimination, and sector-specific requirements;
  • configuring permissions, data scope, integrations, retention, and human review proportionately;
  • responding to Data Subjects and regulators as controller; and
  • not submitting prohibited special-category, health, payment-card, government-identifier, children’s, criminal-offence, or similarly sensitive data unless expressly agreed in writing and lawfully supported.

Customer will not instruct Rifeberry OÜ to make solely automated employment, credit, insurance, eligibility, or similarly significant decisions about individuals.

4. Processor obligations

Rifeberry OÜ will:

  • process Customer Personal Data only on documented instructions, including for Restricted Transfers, unless Union, Member State, or other applicable law requires processing; where permitted, Rifeberry OÜ will notify Customer of that legal requirement before processing;
  • ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations;
  • implement and maintain measures designed to provide a level of security appropriate to the risk, as described in Annex II;
  • appoint Subprocessors only in accordance with Section 10 and impose materially equivalent data protection obligations;
  • taking into account the nature of processing, assist Customer through appropriate technical and organizational measures with Data Subject requests;
  • assist Customer with obligations concerning security, breach notification, DPIAs, and prior consultation, taking account of the nature of processing and information available;
  • at the end of Services, return, delete, or irreversibly anonymize Customer Personal Data as provided in Section 13;
  • make information reasonably necessary to demonstrate compliance with this DPA available under Section 12; and
  • maintain records and cooperate with competent supervisory authorities where required by law.

Rifeberry OÜ may create and use aggregated or irreversibly anonymized information that cannot reasonably identify Customer, a user, or another Data Subject. Such information is not Customer Personal Data. Pseudonymized or hashed data remains Customer Personal Data where re-identification is reasonably possible.

5. Confidentiality and personnel

Rifeberry OÜ will limit access to Customer Personal Data to personnel and contractors who need access for the Services, security, support, or legal compliance. Authorized persons will receive appropriate instructions and be subject to confidentiality obligations that survive the end of their engagement. Rifeberry OÜ remains responsible for its personnel’s compliance with this DPA to the extent required by law.

Customer acknowledges that remote access may occur from locations disclosed in the current Subprocessor List or otherwise permitted under Section 11, subject to access controls and transfer safeguards.

6. Security measures

6.1 Rifeberry OÜ will implement and maintain the technical and organizational measures in Annex II. Measures are designed in light of the state of the art, implementation costs, nature, scope, context, purposes, and risks of processing. Customer acknowledges that security measures may evolve without materially decreasing the overall protection of Customer Personal Data.

6.2 Customer is responsible for secure administration of its account, including authorized users, authentication methods, credentials, CRM tokens, least-privilege permissions, endpoint security, exports, and prompt content. Customer must promptly notify Rifeberry OÜ of suspected unauthorized use.

6.3 No service can guarantee absolute security. Rifeberry OÜ’s obligations are obligations to implement appropriate measures, not a warranty that every incident will be prevented.

7. Security Incidents

7.1 Rifeberry OÜ will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notification will be sent to Customer’s designated administrator or other contact in the account. Customer is responsible for keeping contact information current.

7.2 To the extent known and reasonably available, notice will describe the nature of the incident, affected data and Data Subjects, likely consequences, measures taken or proposed, and a contact point. Rifeberry OÜ may provide information in phases. Notification does not constitute an admission of fault or liability.

7.3 Rifeberry OÜ will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident and will reasonably assist Customer with legally required notifications. Customer is responsible for determining whether and how to notify Data Subjects, regulators, customers, employees, or others, unless law assigns that duty directly to Rifeberry OÜ.

7.4 Security Incident does not include unsuccessful login attempts, port scans, blocked attacks, pings, denial-of-service attempts that do not compromise Customer Personal Data, or incidents caused solely by Customer systems, credentials, instructions, or users. Rifeberry OÜ may charge reasonable fees for assistance arising from such excluded events or Customer’s breach, to the extent permitted by law.

8. Data subject requests

8.1 If Rifeberry OÜ receives a request from a Data Subject concerning Customer Personal Data, it will not respond on the merits except on Customer’s instructions or as required by law. Where reasonably identifiable, Rifeberry OÜ will direct the Data Subject to Customer or notify Customer.

8.2 Taking into account the nature of processing, Rifeberry OÜ will provide reasonable self-service functionality or assistance so Customer can respond to access, correction, deletion, restriction, objection, portability, or similar requests.

8.3 Customer is responsible for verifying the requester, determining the request’s validity and scope, and communicating the response. Assistance beyond standard functionality may be charged at reasonable then-current rates if extensive, repetitive, or caused by Customer’s configuration, unless the assistance is required because of Rifeberry OÜ’s breach of this DPA.

9. Compliance assistance

9.1 On reasonable request, Rifeberry OÜ will provide information available to it that Customer reasonably needs for a data protection impact assessment, transfer assessment, prior consultation, records of processing, or security review concerning the Services.

9.2 Customer remains responsible for its assessment, legal basis, notices, and regulatory filings. Rifeberry OÜ is not required to provide legal advice, disclose privileged information, reveal trade secrets or information that would compromise other customers or security, or develop custom systems unless separately agreed.

9.3 If Customer’s request requires material resources beyond standard compliance documentation, Rifeberry OÜ may charge reasonable fees after giving an estimate, except where the work is required because Rifeberry OÜ breached this DPA or mandatory law prohibits a charge.

10. Subprocessors

10.1 General authorization

Customer gives Rifeberry OÜ general written authorization to engage the Subprocessors listed in Annex III and in the current online Subprocessor List at salesbond.app/legal/subprocessors.

10.2 Notice of changes

Rifeberry OÜ will provide at least fifteen (15) days’ advance notice before a new Subprocessor begins processing Customer Personal Data, ordinarily by email, in-product notice, or update notification. Notice is not required for replacement made urgently to address an incident, availability failure, legal requirement, or material security risk, but Rifeberry OÜ will notify Customer as soon as reasonably practicable.

10.3 Objections

Customer may object during the notice period by sending a detailed written objection to support@salesbond.app based on reasonable and documented data-protection grounds. The parties will work in good faith to resolve the objection. If no commercially reasonable resolution is available, Rifeberry OÜ may avoid the Subprocessor for the affected Services where feasible or Customer may terminate only the affected Services before the Subprocessor begins processing. Customer’s sole remedy is termination of the affected Services and any refund only if expressly required by the Agreement or mandatory law. Failure to object within the notice period constitutes authorization.

10.4 Flow-down and responsibility

Rifeberry OÜ will enter into a written agreement with each Subprocessor imposing data-protection obligations no less protective in all material respects than those required by Applicable Data Protection Law for the relevant processing. Rifeberry OÜ remains responsible for a Subprocessor’s performance of those obligations to the same extent Rifeberry OÜ would be responsible if performing the services directly, subject to the Agreement and mandatory law.

11. International transfers and government access

11.1 Transfer mechanisms

Rifeberry OÜ is established in Estonia. If processing under this DPA involves a Restricted Transfer, the parties will use an applicable lawful mechanism, including an adequacy decision, the EU Standard Contractual Clauses described in Annex IV, the UK Addendum or IDTA, the Swiss adaptations described in Annex IV, or another valid mechanism.

11.2 Onward transfers

Rifeberry OÜ will ensure that Restricted Transfers to Subprocessors are covered by an appropriate transfer mechanism and supplementary measures where required. Customer authorizes such transfers subject to Sections 10 and 11.

11.3 Government requests

Unless prohibited by law, Rifeberry OÜ will review requests from public authorities for validity, seek clarification or challenge disproportionate requests where there are reasonable grounds, disclose only the minimum legally required data, and notify Customer when legally permitted. Nothing in this DPA requires Rifeberry OÜ to violate a binding legal obligation.

11.4 Transfer assessments

Rifeberry OÜ will provide information reasonably available to it to support Customer’s transfer assessment. The parties will cooperate in good faith regarding supplementary safeguards. If a required transfer mechanism becomes invalid and no lawful alternative is reasonably available, either party may suspend the affected transfer or terminate the affected processing without liability beyond amounts expressly required by the Agreement or mandatory law.

12. Audit and information rights

12.1 Rifeberry OÜ will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The parties will first use current third-party certifications, audit reports, penetration-test summaries, security questionnaires, and other standard documentation available from Rifeberry OÜ.

12.2 If that information is reasonably insufficient, Customer may conduct one audit in any twelve-month period, except that additional audits are permitted following a Security Incident affecting Customer Personal Data or where a competent authority requires one. Customer must give at least thirty (30) days’ written notice unless urgency is legally required.

12.3 Audits must occur during normal business hours, minimize disruption, comply with security and confidentiality requirements, and avoid access to other customers’ data, source code, privileged materials, trade secrets unrelated to compliance, or information that would create a security risk. The auditor must be independent, qualified, not a competitor, and bound by confidentiality.

12.4 Customer bears its audit costs and Rifeberry OÜ may charge reasonable costs of supporting an audit, unless the audit identifies a material breach by Rifeberry OÜ. Customer will provide the final report and allow reasonable time for remediation. These limits do not restrict a competent supervisory authority’s mandatory powers.

13. Return, deletion, and retention

13.1 During the term

Customer may access and export Customer Data through available functionality while the subscription is active, subject to the Agreement. Customer should maintain its own copies of data it needs.

13.2 End of Services

When the Services end, ordinary product access ends as stated in the Agreement. On Customer’s written choice, Rifeberry OÜ will return or delete Customer Personal Data, unless law requires retention. If Customer does not give a valid instruction, Rifeberry OÜ will delete or irreversibly anonymize active-system Customer Personal Data within up to ninety (90) days after termination, subject to a mandatory retrieval period, a legal hold, security or fraud investigation, or unresolved dispute.

Where mandatory law, including applicable EU Data Act switching rules, requires a data-retrieval period, Rifeberry OÜ may provide a limited export-only mechanism. That mechanism does not restore general service access and does not extend the paid subscription.

13.3 Backups

Customer Personal Data may remain in access-restricted backup copies until overwritten through the ordinary backup cycle, for up to one hundred eighty (180) days after active-system deletion. Backups will not be used for ordinary business analytics or production processing. If restored for disaster recovery, applicable deletion instructions will be reapplied.

13.4 Legal retention and anonymization

Rifeberry OÜ may retain data required by law or reasonably necessary to establish, exercise, or defend legal claims, subject to restricted access and no processing beyond that purpose. Rifeberry OÜ may retain genuinely anonymous aggregate statistics indefinitely. Pseudonymized data remains Personal Data where re-identification is reasonably possible.

13.5 Certification

On reasonable written request after expiry of the applicable deletion period, Rifeberry OÜ will confirm completion of deletion in accordance with this DPA, subject to backups and legally retained copies.

14. U.S. state privacy terms

14.1 To the extent U.S. State Privacy Laws apply and Customer is a business/controller while Rifeberry OÜ is a service provider, contractor, or processor, Rifeberry OÜ will process Customer Personal Data only for the specific business purposes in Annex I and as otherwise permitted by those laws.

14.2 Rifeberry OÜ will not:

  • sell or share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data for a purpose other than the specific business purposes in Annex I or as otherwise permitted by law;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer, except as permitted by law;
  • combine Customer Personal Data with Personal Data received from another person or collected from Rifeberry OÜ’s own interaction with a consumer, except as permitted by law; or
  • use Customer Personal Data for targeted or cross-context behavioral advertising.

14.3 Rifeberry OÜ will provide the same level of privacy protection required of an applicable service provider, contractor, or processor; assist Customer with verified consumer requests; notify Customer if Rifeberry OÜ determines it can no longer meet applicable obligations; and permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use, subject to Section 12.

14.4 Customer discloses Customer Personal Data to Rifeberry OÜ only for the limited purposes in Annex I and represents that it has provided required notices and rights. Each Subprocessor processing such data will be bound by equivalent restrictions where required.

15. Liability and indemnities

15.1 To the fullest extent permitted by law, all liability arising from or related to this DPA, the SCCs, privacy, security, or Customer Personal Data is subject to the exclusions, disclaimers, limitations, and aggregate liability caps in the Agreement. Liabilities under this DPA and the Agreement are combined, not separate or cumulative.

15.2 Nothing in this DPA limits liability to the extent such limitation is prohibited by Applicable Data Protection Law or prevents a Data Subject from exercising mandatory third-party beneficiary rights under the applicable SCCs.

15.3 The indemnities in the Agreement, if any, apply to this DPA. This DPA does not create a separate indemnity unless expressly stated in a signed order form.

16. Term and termination

This DPA begins when Customer accepts the Agreement or first submits Customer Personal Data, whichever occurs first, and continues while Rifeberry OÜ processes Customer Personal Data. Provisions that by nature should survive—including confidentiality, transfers, audits relating to prior processing, deletion, liability, and governing law—survive termination.

17. General provisions

17.1 Notices under this DPA may be sent electronically. Customer’s privacy and security notices will be sent to the account administrator or designated contact. Notices to Rifeberry OÜ must be sent to support@salesbond.app.

17.2 Except where transfer clauses require otherwise, this DPA is governed by Estonian law and disputes are subject to the exclusive jurisdiction specified in the Agreement. The supervisory authority and courts specified in Annex IV apply for SCC purposes.

17.3 If part of this DPA is invalid, it will be interpreted or modified to the minimum extent necessary and the remainder remains effective. Failure to enforce a provision is not a waiver. Customer may not assign this DPA separately from the Agreement.

17.4 Rifeberry OÜ may update this DPA to reflect law, provider, or Service changes, provided an update does not materially reduce mandatory data-protection obligations. Material changes will be notified as required by the Agreement or law.

Annex I — Processing details

ElementDescription Subject matterProvision of the SalesBond professional SaaS platform, CRM integrations, AI-assisted analytics, security, support, and related Services. DurationFor the term of the Agreement and the deletion/backup periods in Section 13, unless law requires longer retention. Nature of processingCollection; receipt; access; recording; organization; structuring; hosting; storage; retrieval; synchronization; consultation; use; analysis; inference; classification; summarization; AI generation; transmission; support; restriction; export; deletion; anonymization. PurposesOperate and support the Services; synchronize customer-authorized CRMs; generate requested analytics, summaries, forecasts, rankings, recommendations, and text; secure and troubleshoot the Services; prevent abuse; maintain backups and continuity; comply with documented lawful instructions. FrequencyContinuous or event-driven during the subscription, based on Customer configuration, CRM synchronization, user activity, and requested workflows. Data subjectsCustomer administrators and authorized users; employees, workers, contractors, sales representatives and managers; prospects, leads, contacts, customers, suppliers and their representatives; communication participants; partners and referrers; other individuals whose data Customer lawfully submits. Personal Data categoriesNames; work emails and business contact details; organization, role and permissions; CRM identifiers; company/contact/lead data; deals, values, stages and custom fields; tasks, calls, meetings and activities; notes; email and message content; change history; goals, KPIs, rankings and performance results; prompts, selected AI context and outputs; usage, device, log, security and diagnostic data. CRM file attachments are not intentionally imported. Special categoriesNot intended or permitted unless Rifeberry OÜ expressly agrees in writing and the parties document lawful instructions and additional safeguards. Processing locationsPrimary hosting intended in the EEA; selected processing in the United States and other disclosed locations through authorized AI and infrastructure Subprocessors. Return/deletionUnder Section 13: Customer choice of return or deletion where required; active-system default within up to 90 days; backups up to 180 days; anonymous statistics may be retained.

Annex II — Technical and organizational measures

Rifeberry OÜ maintains a risk-based security program appropriate to a professional SaaS service. The measures below are commitments at a control-family level and may be implemented through equivalent or stronger controls. They do not guarantee that an incident cannot occur.

Control familyMeasures Security governanceAssigned security responsibilities; documented policies and procedures proportionate to company size and risk; periodic review; confidentiality obligations; security awareness. Access controlRole-based and least-privilege access; unique accounts; authentication controls; prompt revocation when access is no longer required; restricted production and backup access; logging of privileged activity where appropriate. AuthenticationStrong password and session controls; protection of secrets and API credentials; multi-factor authentication for privileged or administrative access where supported. EncryptionEncryption in transit using current industry-standard protocols; encryption at rest or equivalent storage protections where supported by the hosting and database services; managed protection of keys and secrets. Tenant and data separationLogical separation of customer workspaces and authorization checks designed to prevent unauthorized cross-tenant access. Network and infrastructureFirewalls or security groups; restricted administrative interfaces; secure configuration; network monitoring and attack mitigation through hosting/CDN providers where applicable. Application securityChange control; peer review or equivalent review for material changes; dependency management; testing; vulnerability remediation based on risk; separation of development and production where practicable; no production Customer Personal Data in non-production except where controlled and necessary. Logging and monitoringOperational, security, access, and error logging proportionate to risk; monitoring for anomalous or unauthorized activity; time-bounded log retention; protection against unauthorized alteration. Availability and continuityBackups; recovery procedures; redundancy appropriate to the architecture; service and incident monitoring; restoration processes; backups retained under Section 13. Incident responseProcesses to identify, triage, contain, investigate, remediate, document, and communicate Security Incidents; preservation of relevant evidence where appropriate. Data minimization and retentionFeature-appropriate data scope; avoidance of CRM file attachments; restricted support access; retention controls; deletion or irreversible anonymization; minimization of data submitted to AI providers. Subprocessor managementRisk-based provider review; written data-protection and confidentiality terms; transfer mechanisms; access limited to necessary services; monitoring of material provider changes. Physical securityPhysical and environmental controls are primarily provided by selected hosting, data-center, office, and cloud providers, with access limited to authorized personnel. AI safeguardsCommercial API access; no intentional model-training opt-in for Customer Content; data minimization; review of provider privacy controls; disabling unnecessary retention and feedback features where available; human review expectations for outputs.

Rifeberry OÜ’s measures include multi-factor authentication for privileged access; encryption in transit and encryption at rest where supported by the relevant service; managed secrets and credential rotation; need-to-know production access with approval and periodic review; vulnerability scanning and risk-based remediation; protected backups and periodic restore testing; security logging with defined retention; tenant-isolation testing; an incident-response procedure; prompt access revocation during employee or contractor offboarding; and commercial no-training or limited-retention AI API configurations where available.

Annex III — Subprocessor list

This Annex identifies intended and potential providers. Only providers actually enabled in production should appear in the published Subprocessor List. The contracting entity and region must match the applicable account and vendor agreement.

ProviderService and Customer Personal DataLocation / transfer status Contabo GmbHApplication hosting, database, storage and backup dumps; potentially all Customer Personal Data and service metadata.European Economic Area; the primary application server, database and backup copies are hosted on Contabo infrastructure in the EEA. Limited authorized support access may occur from other locations subject to appropriate safeguards. OpenAI Ireland LimitedCommercial AI API; selected prompts, CRM context, outputs, model and technical metadata.United States and other disclosed locations; SCCs/appropriate safeguards where required. Anthropic, PBCCommercial AI API; selected prompts, CRM context, outputs, model and technical metadata.United States and other disclosed locations; SCCs/appropriate safeguards where required. Mistral (France)Commercial AI API; selected prompts, CRM context, outputs, model and technical metadata.EEA and other disclosed locations; safeguards where required. Google Cloud EMEA Limited — Vertex AI / paid Gemini APIPaid commercial Gemini API; selected prompts, CRM context, outputs and technical metadata.EEA, United States and other disclosed locations; SCCs/appropriate safeguards where required. Functional Software, Inc. (Sentry), if enabledError monitoring and diagnostics; technical events and limited Customer Personal Data included in error traces.United States or European Union depending on the selected account region; limited account, configuration and support metadata may be processed in other disclosed locations. Customer Personal Data is minimized or scrubbed from diagnostic payloads where feasible. Cloudflare, Inc., if enabledDNS, CDN and network security; IP addresses, request headers, traffic and security logs.Global network subject to selected region and safeguards. Google Cloud EMEA Limited — Google Workspace, if enabledSupport communications that may include Customer Personal Data voluntarily sent by Customer.EEA, United States and other disclosed Google processing and support locations; appropriate transfer safeguards apply where required.

Providers generally outside this DPA

Stripe normally processes billing and full card data under its own payment terms and legal roles and is not intended to receive CRM Customer Content. Google Analytics is intended for website/application analytics and must not receive CRM Customer Content. These providers are described in the Privacy Notice and Cookie Notice; they are included as Subprocessors only to the extent they actually process Customer Personal Data on Customer’s behalf.

Annex IV — EU SCC and UK Addendum specifications

A. EU Standard Contractual Clauses

Where a Restricted Transfer is governed by the EU GDPR and requires the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 (“EU SCCs”), the EU SCCs are incorporated by reference and completed as follows:

SCC itemSelection / completion ModuleModule Two (controller to processor) applies when Customer is controller. Module Three (processor to processor) applies when Customer acts as processor. Clause 7The optional docking clause applies. Clause 9Option 2, general written authorization, applies. The notice period is 15 days under Section 10. Clause 11The optional independent dispute-resolution language does not apply. Clause 17Option 1 applies; governing law is Estonia. Clause 18The courts of Estonia have jurisdiction. Annex I.A — Data exporterCustomer and relevant Affiliates. Identity and contact details are those in the Agreement, order form, account, or marketplace installation. Activities: use of SalesBond and transfer of Customer Personal Data. Annex I.A — Data importerRifeberry OÜ, registry code 16488400, Tornimäe tn 5, 10145 Tallinn, Harju maakond, Estonia; support@salesbond.app. Activities: provision of the Services. Annex I.BThe transfer and processing details are in Annex I of this DPA. Annex I.CCompetent supervisory authority is determined under Clause 13; where applicable, the Estonian Data Protection Inspectorate. Annex IIThe technical and organizational measures are in Annex II of this DPA. Annex IIIThe authorized Subprocessors are in Annex III and the current online Subprocessor List.

If the EU SCCs apply, their unmodified official text controls. Nothing in this DPA varies the EU SCCs in a way that prejudices Data Subjects’ rights or contradicts the SCCs.

B. United Kingdom

For a Restricted Transfer subject to the UK GDPR, the parties incorporate the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued under section 119A of the UK Data Protection Act 2018 (“UK Addendum”), unless they use the UK IDTA or another valid mechanism. The EU SCC selections and Annex information above populate the corresponding tables. Either party may terminate the UK Addendum as permitted by its mandatory termination provision if the ICO issues a revised approved addendum.

C. Switzerland

For a Restricted Transfer governed by the Swiss FADP, references in the EU SCCs to the GDPR include the Swiss FADP as applicable; references to EU/Member State law and supervisory authority include Swiss law and the Swiss Federal Data Protection and Information Commissioner; Data Subjects in Switzerland may exercise applicable rights; and the governing-law and forum provisions apply only to the extent permitted by the Swiss FADP.

D. Alternative mechanisms

If the parties can lawfully rely on an adequacy decision, recognized certification, binding corporate rules, or another transfer mechanism, that mechanism applies to the relevant transfer instead of or in addition to the clauses above. If a new mandatory transfer instrument replaces an existing one, this DPA incorporates the replacement to the minimum extent necessary, subject to legally required steps.

This document has not been published yet

The final legal text is being prepared and will be published at this address. No summary or draft is shown here, because legal documents must be published verbatim from the approved source.

Questions in the meantime? Contact support@salesbond.app.