Data Processing Agreement (DPA)
Applies to: 42 Support, 42 Ekonomi
When you store personal data in our Services:
- You are normally the Data Controller.
- We are normally the Data Processor.
- You decide why personal data is processed.
- We process it only on your documented instructions.
- We never sell your Customer Data.
- We help you comply with GDPR.
- We use approved subprocessors.
- We notify you of personal data breaches as required by law.
This summary is provided for convenience only. The legally binding terms are set out below.
Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between 42 Scandinavia AB ("Processor") and the business customer using a Service ("Controller").
This DPA supplements the Master Terms of Service and applies whenever 42 Scandinavia processes Personal Data on behalf of the Customer.
The purpose of this DPA is to satisfy Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
It governs all processing of Personal Data carried out by 42 Scandinavia on behalf of the Customer through the Services.
Definitions
Unless otherwise defined in this DPA, capitalised terms have the meanings given in the Master Terms of Service.
Controller, Processor, Personal Data, Processing, Supervisory Authority and Data Subject have the meanings given in the GDPR.
Subject Matter
42 Scandinavia provides hosted software services that process Customer Data on behalf of the Customer.
The nature of processing depends on the applicable Product Schedule.
Duration
This DPA remains in force for as long as 42 Scandinavia processes Personal Data on behalf of the Customer.
Categories of Personal Data
Depending on the Service, Personal Data may include:
- names
- email addresses
- usernames
- contact information
- communications
- accounting records
- audit logs
- IP addresses
- metadata
The Customer determines which Personal Data is uploaded to the Services.
Categories of Data Subjects
Data Subjects may include:
- employees
- contractors
- customers
- suppliers
- authorised users
- support contacts
The Customer determines the categories of Data Subjects.
Nature and Purpose of Processing
42 Scandinavia processes Personal Data solely to:
- provide the Services;
- host Customer Data;
- authenticate users;
- provide support;
- maintain security;
- perform backups;
- restore data;
- maintain availability;
- comply with applicable law.
42 Scandinavia does not process Customer Data for advertising purposes.
42 Scandinavia does not sell Customer Data.
Documented Instructions
42 Scandinavia will process Personal Data only on documented instructions from the Customer unless otherwise required by applicable law.
The Master Terms of Service, Product Schedule and Customer's use of the Services together constitute the Customer's documented instructions.
If 42 Scandinavia believes an instruction infringes GDPR or other applicable law, we will inform the Customer unless prohibited by law.
Confidentiality
42 Scandinavia ensures that persons authorised to process Personal Data:
- are subject to confidentiality obligations;
- receive appropriate training where relevant;
- access Personal Data only where necessary.
Security Measures
42 Scandinavia implements appropriate technical and organisational measures designed to protect Personal Data, taking into account:
- the nature of processing;
- implementation costs;
- risks to Data Subjects;
- current technology.
Security measures may include:
- encrypted communications (TLS)
- logical access controls
- authentication
- logging
- backups
- infrastructure security
- vulnerability management
Specific technical measures may evolve over time provided overall protection is not materially reduced.
Subprocessors
The Customer authorises 42 Scandinavia to engage subprocessors.
Current subprocessors include services supporting:
- application hosting
- cloud infrastructure
- transactional email
- payment processing
Current providers include:
- Lovable
- infrastructure providers used through Lovable (such as Supabase where applicable)
- Resend
- Stripe
42 Scandinavia remains responsible for ensuring subprocessors are subject to appropriate contractual obligations.
An up-to-date Subprocessor List is published separately.
Customers will be notified of material changes to subprocessors where required by applicable law.
International Transfers
Where Personal Data is transferred outside the EEA, 42 Scandinavia will implement appropriate safeguards under Chapter V GDPR.
Such safeguards may include:
- adequacy decisions
- Standard Contractual Clauses
- other lawful transfer mechanisms
Assistance
Taking into account the nature of processing, 42 Scandinavia will provide reasonable assistance to enable the Customer to comply with obligations relating to:
- Data Subject requests
- security
- breach notification
- Data Protection Impact Assessments
- consultations with Supervisory Authorities
Where extensive assistance is requested, reasonable professional service fees may apply.
Personal Data Breaches
42 Scandinavia maintains procedures for identifying and responding to Personal Data breaches.
Where required by GDPR, the Customer will be notified without undue delay after becoming aware of a Personal Data breach affecting Customer Data.
Notifications will include available information necessary for the Customer to comply with GDPR.
Audits
The Customer may request information reasonably necessary to demonstrate compliance with this DPA.
Where documentary evidence is insufficient, the parties may agree on a reasonable audit.
Audits shall:
- occur during normal business hours;
- minimise disruption;
- protect other customers' confidentiality;
- be subject to appropriate confidentiality obligations.
The Customer bears its own audit costs unless otherwise required by law.
Return and Deletion
Upon termination of the Services:
- Customer Data remains available for export for thirty (30) days unless otherwise required by law;
- Customer Data is then deleted in accordance with the Data Retention Policy;
- residual encrypted backup copies may remain for up to ninety (90) days before automatic deletion.
Liability
Liability relating to this DPA is governed by the liability provisions contained in the Master Terms of Service except where GDPR provides otherwise.
Nothing in this DPA limits liability where such limitation is prohibited by applicable law.
Governing Law
This DPA is governed by Swedish law.
Disputes shall be resolved in accordance with the dispute resolution provisions of the Master Terms of Service.
Annex A — Processing Description
Controller: Customer
Processor: 42 Scandinavia AB
Purpose:
Provision of SaaS applications.
Processing Activities:
- hosting
- storage
- authentication
- support
- backups
- transmission
- restoration
Duration:
For the duration of the Subscription plus applicable retention periods.
Annex B — Technical and Organisational Measures
42 Scandinavia maintains appropriate technical and organisational measures appropriate to the risk.
These measures are reviewed periodically and may evolve as technology and threats develop.
Examples include:
- secure communications
- access controls
- authentication
- backup procedures
- infrastructure monitoring
- incident response procedures
- personnel confidentiality obligations
Document History
| Version | Date | Description |
|---|---|---|
| 1.0 | Publication | Initial release |
