GDPR & Data Processing Agreement (DPA)

Language notice: This English translation is provided for convenience. If it conflicts with the Swedish version, the Swedish version governs.

This document constitutes a legally binding Data Processing Agreement (DPA) between you as the customer (the "Controller") and Datarens.se (the "Processor") for the processing of personal data through our digital service.

1. Subject matter and purpose

Datarens.se processes the personal data and records that you upload to the Service solely to perform automated data cleaning, structuring, and fuzzy matching in accordance with your instructions through the platform. Under no circumstances may the Processor use the personal data for its own purposes, resale, or commercial analysis.

2. Nature and duration of processing

3. Types of personal data and categories of data subjects

Because the Service is an automated tool, the Processor does not control what data you choose to upload. It is the Controller's responsibility to ensure that special categories of personal data (under Article 9 of the GDPR) are not uploaded to the Service. Typical data processed includes names, addresses, email addresses, telephone numbers, and company information in customer or marketing records.

4. Technical and organisational security measures

The Processor has implemented the following industry-leading security measures to protect the personal data:

5. Approved subprocessors

The Controller hereby grants general authorisation for the Processor to use the following subprocessors to provide the Service:

6. Rights of the data subject

Because the Processor does not save or retain personal data from uploaded files after the request has been completed, the Processor has no technical ability to retrieve, correct, port, or delete data at the request of a data subject. The Controller is independently responsible for responding to and handling such requests directly in its own source systems.

7. Security incidents and notification

In the event of a confirmed personal data breach in any of the Service's underlying system environments that affects the Controller's data, the Processor undertakes to notify the Controller without undue delay, and no later than 72 hours after discovery, using the email address registered to the account.

8. Audit and review

The Controller has the right, once per calendar year, to request available security documentation and system architecture from the Processor to verify that the requirements of this agreement are being met.

9. Return and deletion of data

Because all data is processed temporarily in the server's working memory and deleted immediately after cleaning is complete, no personal data remains to be returned or deleted when the Service or the agreement ends. Account information (email and payment history) is permanently deleted on request within 30 days after the account has been closed.

10. Governing law and disputes

This agreement shall be interpreted in accordance with Swedish law and the GDPR. Disputes arising in connection with this agreement shall be finally decided by Stockholm District Court as the court of first instance.

Does your company need a formally signed DPA?
Email us at datarens@outlook.com and we will send a signed PDF copy for your organisation.