GDPR & Data Processing Agreement (DPA)
Language notice: This English translation is provided for convenience. If it conflicts with the Swedish version, the Swedish version governs.
This document constitutes a legally binding Data Processing Agreement (DPA) between you as the customer (the "Controller") and Datarens.se (the "Processor") for the processing of personal data through our digital service.
1. Subject matter and purpose
Datarens.se processes the personal data and records that you upload to the Service solely to perform automated data cleaning, structuring, and fuzzy matching in accordance with your instructions through the platform. Under no circumstances may the Processor use the personal data for its own purposes, resale, or commercial analysis.
2. Nature and duration of processing
- Nature: Automated reading, normalisation, and cleaning of data in the server's temporary working memory (RAM), followed by immediate generation and return of the cleaned file.
- Scope: The Service supports Excel, CSV, TSV, JSON, XML, DOCX, PDF, Parquet, ODS, and TXT files, as well as ZIP archives containing multiple files.
- Duration: Processing and transient storage take place only in RAM during the active API request (normally less than 60 seconds).
- Storage: No files, tables, or personal data from uploaded files are stored permanently on disks, in databases, or on physical storage media by the Processor. The data is completely removed from working memory as soon as the file has been returned to the user.
3. Types of personal data and categories of data subjects
Because the Service is an automated tool, the Processor does not control what data you choose to upload. It is the Controller's responsibility to ensure that special categories of personal data (under Article 9 of the GDPR) are not uploaded to the Service. Typical data processed includes names, addresses, email addresses, telephone numbers, and company information in customer or marketing records.
4. Technical and organisational security measures
The Processor has implemented the following industry-leading security measures to protect the personal data:
- Full encryption in transit using TLS 1.3 for all data traffic to and from the Service.
- RAM-only processing: no persistent disk writes take place during the cleaning process.
- Strict rate limiting and IP-based protection logic to prevent unauthorised access and misuse.
- A restricted and strict CORS (Cross-Origin Resource Sharing) policy limited to Datarens.se.
- No logging of file contents, raw data, or processed personal data in the system's application logs.
- Pseudonymised and minimised access logs (masked IP address and endpoint only), retained for a maximum of 24 hours for troubleshooting purposes.
5. Approved subprocessors
The Controller hereby grants general authorisation for the Processor to use the following subprocessors to provide the Service:
- Railway (USA/EU): Operation and hosting of the backend application's infrastructure. All data passes only through the server's working memory (RAM) within approved data-centre regions.
- Supabase (USA/EU): Management of encrypted user authentication, JWT sessions, and account statistics. It does not process personal data from the user's uploaded files.
- Anthropic (USA): Provision of Claude AI models for semantic normalisation and text cleaning. Data is sent in encrypted form through an API in real time and, under the applicable agreement, is never used to train commercial models. Anthropic is certified under the EU-US Data Privacy Framework.
- Stripe (Ireland/USA): Management of payments, card details, and invoicing for Business subscriptions.
6. Rights of the data subject
Because the Processor does not save or retain personal data from uploaded files after the request has been completed, the Processor has no technical ability to retrieve, correct, port, or delete data at the request of a data subject. The Controller is independently responsible for responding to and handling such requests directly in its own source systems.
7. Security incidents and notification
In the event of a confirmed personal data breach in any of the Service's underlying system environments that affects the Controller's data, the Processor undertakes to notify the Controller without undue delay, and no later than 72 hours after discovery, using the email address registered to the account.
8. Audit and review
The Controller has the right, once per calendar year, to request available security documentation and system architecture from the Processor to verify that the requirements of this agreement are being met.
9. Return and deletion of data
Because all data is processed temporarily in the server's working memory and deleted immediately after cleaning is complete, no personal data remains to be returned or deleted when the Service or the agreement ends. Account information (email and payment history) is permanently deleted on request within 30 days after the account has been closed.
10. Governing law and disputes
This agreement shall be interpreted in accordance with Swedish law and the GDPR. Disputes arising in connection with this agreement shall be finally decided by Stockholm District Court as the court of first instance.
Does your company need a formally signed DPA?
Email us at datarens@outlook.com and we will send a signed PDF copy for your organisation.