Terms, Privacy & Data Processing

Last updated 2026-09-18. Operator: create.repeat Oy, Business ID 2662670-6. Data-protection contact: privacy@vakeva.app.

VAKEVA is in presale: accounts open now, paid agent runtime starts when the beta opens. These documents already describe the Service as it will run; we will email account holders about material changes.

Terms of Service (business customers)

These Terms of Service ("Terms") govern the use of the VAKEVA service ("Service") provided by create.repeat Oy (Business ID 2662670-6, Eteläinen Hesperiankatu 26 E 63, 00100 Helsinki, Finland) ("we", "us"). By creating an account, placing a presale order or using the Service you ("Customer", "you") agree to these Terms on behalf of the company or organisation you represent, and you confirm you have the authority to do so.

1. Business customers only

The Service is offered to companies, organisations and sole traders acting in the course of their business. It is not offered to consumers, and consumer-protection rules (including the 14-day right of withdrawal for distance sales) do not apply. If you are a consumer, do not use the Service.

2. What the Service is

VAKEVA lets you compose teams of AI agents from a role and an open-weight language model, connect them to data resources you choose, and run them as workflows on a schedule you set, managed from the VAKEVA mobile app and the web. We operate the infrastructure in a private cloud in the European Union. You own your configuration, your inputs and your outputs. AI outputs are generated by statistical models and can be wrong, incomplete or unsuitable; you decide how they are used and you review them before relying on them.

3. Presale, plans and payment

  • During the presale the only purchasable option is a Prepurchase of a monthly plan at the stated presale discount. A presale purchase opens your account immediately so you can create your team, agents and workflows; paid agent runtime starts when the beta opens, at the time shown on the pricing page.
  • A plan is runtime minutes per week for your team, with a minimum of 120 minutes a week. Unused weekly minutes reset at the start of each week and do not carry over.
  • Prices are shown in euro excluding VAT unless stated otherwise; VAT is added where the law requires. Payment is processed by SumUp; we never see or store your card number.
  • A Prepurchase is a binding order. Because the Service is opened for you at once, it is refundable only if we fail to open the beta within 60 days of the announced date, in which case you may cancel for a full refund. Later plan changes take effect from the next billing period.

4. Your account

Keep your credentials confidential and use multi-factor authentication where offered. You are responsible for everything done under your account and by the people you invite. Tell us at once at the address below if you suspect misuse.

5. Your data and your responsibilities as controller

You decide what data your agents receive, which systems they connect to and what they produce. For any personal data in that material you are the controller within the meaning of the EU General Data Protection Regulation (GDPR) and we are your processor under the Data Processing Addendum below. Because we cannot know what you put in, you are responsible for meeting every legal requirement that applies to your data and your use of the outputs, including as applicable:

  • GDPR (EU 2016/679) and the Finnish Data Protection Act (1050/2018): a lawful basis for each processing purpose, transparency to the people concerned, honouring their rights, records of processing, data-protection impact assessments where required, data minimisation, and lawful transfer mechanisms for any data you move outside the EU/EEA.
  • Special categories of personal data (health, biometrics, beliefs, sexual orientation and the like), criminal-record data and data about children may be processed only where you have a specific legal basis, and you must tell us in writing before you do.
  • Payment-card data (PCI DSS) and other regulated financial data must not be entered into the Service.
  • Employee data: the Finnish Act on the Protection of Privacy in Working Life (759/2004) and co-determination rules where agents process data about your staff.
  • Marketing and electronic communications law (the ePrivacy rules, the Finnish Act on Electronic Communications Services 917/2014) and the Consumer Protection Act for anything your agents send to your prospects or customers.
  • The EU Artificial Intelligence Act (EU 2024/1689): as the deployer of AI systems you must not use them for prohibited practices, must apply human oversight, must tell people when they interact with an AI where the Act requires it, and must not use the Service for a high-risk purpose under Annex III without our prior written agreement.
  • The EU Data Act (EU 2023/2854) and sector rules on data sharing and access where your data resources come from connected products or regulated sources; the Digital Services Act where you publish agent outputs.
  • Intellectual-property and trade-secret law for your inputs and outputs, contractual confidentiality you owe to third parties, and the terms of every external system or API you connect.
  • Export-control and sanctions law, and any professional-secrecy duty (legal, medical, financial) attached to the material you process.

6. Acceptable use

You will not use the Service to break the law, to infringe rights, to generate or send unsolicited bulk messages, to attack or probe systems you are not authorised to test, to process data you have no right to process, or to attempt to extract our models, prompts or infrastructure details. We may suspend an account that puts other customers, the people whose data is processed or the platform at risk, and we will tell you why.

7. Our commitments

We run the Service on infrastructure we control in the EU, with encryption at rest for external credentials, per-team namespacing of data resources, a plain-language audit trail of every access your agents make, and no use of your data to train models. We aim for high availability but do not promise a particular uptime during the beta. Support is by email in English and Finnish on business days.

8. Confidentiality

Each party keeps the other's non-public information confidential and uses it only to perform under these Terms. Your inputs and outputs are your confidential information. We may disclose information where the law compels it, telling you first where permitted.

9. Intellectual property

You retain all rights in your inputs and, as far as the law allows, in the outputs generated for you. We retain all rights in the Service, its software, its roles and skills library and its documentation. You grant us only the licence needed to run the Service for you. Open-weight models are used under their own licences, which you agree to respect.

10. Warranties and liability

The Service is provided as described, with reasonable skill and care. To the fullest extent the law allows, we exclude other warranties, including any warranty that outputs are accurate or fit for a particular purpose. Neither party is liable for indirect or consequential loss, lost profits or lost data beyond our backup obligations. Our total liability under these Terms in any twelve-month period is limited to the fees you paid us in that period. Nothing limits liability for fraud, wilful misconduct, gross negligence, death or personal injury, or breach of the Data Processing Addendum to the extent the GDPR does not permit such limitation.

11. Term, termination and your data

These Terms apply while you hold an account. Either party may terminate for convenience at the end of a paid period, and at once for a material breach not cured within 30 days of notice. On termination you may export your configuration and data for 30 days, after which we delete them, keeping only what the law requires us to keep, for as long as it requires.

12. Changes

We may update these Terms and the Service as the beta develops. We will announce material changes by email at least 30 days before they take effect; continued use after that date is acceptance. We will not reduce the minutes or the discount of a Prepurchase you have already made.

13. Governing law and disputes

These Terms are governed by the laws of Finland, excluding its conflict-of-law rules and the CISG. Disputes are settled first by good-faith negotiation and otherwise in the Helsinki District Court (Helsingin käräjäoikeus) as the court of first instance.

14. Contact

create.repeat Oy, Eteläinen Hesperiankatu 26 E 63, 00100 Helsinki, Finland · hello@vakeva.app

Privacy Policy

This Privacy Policy explains how create.repeat Oy (Business ID 2662670-6, Eteläinen Hesperiankatu 26 E 63, 00100 Helsinki, Finland) processes personal data as CONTROLLER when you visit vakeva.app, contact us, create an account or buy a plan. Personal data your agents process inside the Service is processed on your instructions as your processor under the Data Processing Addendum, not under this Policy. Contact for all data-protection matters, including under the GDPR and the EU Data Act: privacy@vakeva.app.

1. What we collect and why

  • Account and billing data — company name, your name, work email, hashed password, orders, invoices, payment status (never the card number, which SumUp handles). Basis: performance of the contract; legal obligation for bookkeeping (Finnish Accounting Act, 6 years).
  • Service configuration — teams, agents, roles, workflows, schedules, connected data-resource settings (external credentials encrypted at rest and shown only as a fingerprint). Basis: contract.
  • Audit and security logs — which agent accessed which resource under which right, sign-ins, IP addresses, errors. Basis: legitimate interest in security and accountability, and your contract's audit view. Kept 12 months, then aggregated or deleted.
  • Website measurement — with your consent at the level you choose in the banner: none, anonymous (random visitor and session ids, page, referrer, campaign) or personalised (linked to your account). No third-party analytics or advertising script is loaded at any level; data goes to our own servers in the EU. Your choice is kept for 180 days and can be changed from “Cookie settings” in the footer. Basis: consent.
  • Correspondence — emails you send us and our replies. Basis: legitimate interest in answering you; kept 24 months.
  • Transactional email — order confirmations, account and security notices, sent through our own mail server with Resend as fallback. Basis: contract. Marketing email only with consent, revocable in every message.

2. Cookies

One strictly necessary cookie keeps you signed in. The consent cookie remembers your banner answer. Measurement identifiers exist only if you allow them. Nothing is set for advertising.

3. Recipients and sub-processors

Our hosting and delivery partners process data for us under written agreements: Vercel Inc. (website hosting and edge delivery, EU region with standard contractual clauses), Supabase Inc. (managed PostgreSQL, EU region), Resend Inc. (fallback email delivery, US, standard contractual clauses), SumUp Payments Limited / SumUp EU Payments UAB (payment processing, EU). Agent runtime and data resources live on servers we operate in Finland. We do not sell personal data and we do not share it with advertisers.

4. Transfers outside the EU/EEA

We keep processing in the EU wherever we can. Where a partner processes data outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses with supplementary measures, or on an adequacy decision (including the EU–US Data Privacy Framework where the partner is certified).

5. Your rights

Under the GDPR you may ask for access to, correction or deletion of your personal data, restriction of processing, portability of data you gave us, and you may object to processing based on legitimate interest and withdraw consent at any time. Write to privacy@vakeva.app; we answer within one month. You may also lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Finland, or with the supervisory authority of your own EU member state.

6. Security

Encrypted transport (TLS), encryption at rest for secrets, per-team isolation, least-privilege access for our staff, multi-factor authentication for administrators, and a complete audit trail. We will notify you and, where required, the supervisory authority of a personal-data breach without undue delay.

7. Children

The Service is for business use and is not directed at anyone under 18.

8. Changes

We will post changes here with a new date and email account holders about material changes.

Data Processing Addendum (GDPR Art. 28)

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer (as CONTROLLER) and create.repeat Oy (as PROCESSOR) and meets Article 28 of the GDPR. It applies to all personal data the Customer, its users or its connected data resources make available to the Service ("Customer Data"). Where the Customer is itself a processor for its own clients, we act as sub-processor and the same terms apply.

1. Subject matter, duration, nature and purpose

Processing of Customer Data by AI agents, workflows and data resources configured by the Customer, for the Customer's own business purposes, for the term of the Terms of Service. Categories of data subjects and data are determined solely by the Customer, who confirms it will not upload special categories of data or data about children without our written agreement.

2. Instructions

We process Customer Data only on the Customer's documented instructions — the configuration the Customer sets in the Service is the primary instruction — and never for our own purposes, never to train models, and never to build profiles across customers. We will tell the Customer if, in our opinion, an instruction infringes data-protection law.

3. Confidentiality and personnel

Our personnel with access to Customer Data are bound by confidentiality and receive data-protection training. Access is granted on a need-to-know basis and is logged.

4. Security (Article 32)

  • Private-cloud infrastructure in the EU operated by us; open-weight models running on our servers, with no customer data sent to third-party model providers.
  • Encryption in transit (TLS 1.2+) and at rest for external credentials (AES-256-GCM); per-team namespacing of data resources; runtime isolation between teams.
  • Rights granted one resource at a time; every access recorded with agent, workflow, step and right, and shown to the Customer in the audit view.
  • Multi-factor authentication for administrative access; least privilege; patching; backups with restore testing; incident-response procedure.

5. Sub-processors

The Customer authorises the sub-processors listed in the Privacy Policy (hosting, database, fallback email, payments). We will announce any addition or replacement by email at least 30 days in advance; the Customer may object on reasonable data-protection grounds, in which case either party may terminate the affected part of the Service. We remain fully liable for our sub-processors.

6. Assistance

Taking into account the nature of processing, we assist the Customer with data-subject requests (the Customer can export, correct and delete data within the Service; requests reaching us are forwarded to the Customer within 5 business days), with security, breach notification, data-protection impact assessments and prior consultation.

7. Personal-data breach

We notify the Customer without undue delay, and in any case within 48 hours of becoming aware of a personal-data breach affecting Customer Data, with the information Article 33(3) requires as it becomes available, and we cooperate in the Customer's own notifications.

8. Transfers

Customer Data is processed and stored in the EU. Any transfer outside the EU/EEA happens only on the Customer's instruction (for example a data resource the Customer connects) or under a valid Chapter V mechanism.

9. Deletion and return

On termination, or earlier at the Customer's request, we return Customer Data in a machine-readable form and delete all copies within 30 days, unless EU or member-state law requires storage, and we confirm the deletion on request.

10. Audit

We make available the information necessary to demonstrate compliance with Article 28 and allow audits, including inspections, by the Customer or an auditor mandated by it, once a year on 30 days' notice or at once after a breach, at the Customer's cost, under confidentiality, without disrupting other customers.

11. Liability and precedence

Liability follows the Terms of Service, save that the limitations do not apply where the GDPR does not permit them. In case of conflict this DPA prevails over the Terms for data-protection matters.

12. Contact for the Customer's DPO or supervisory authority

create.repeat Oy, Eteläinen Hesperiankatu 26 E 63, 00100 Helsinki, Finland · privacy@vakeva.app