Terms
Data processing agreement
Updated
Background
The parties have entered into an agreement covering the service or services set out in the main agreement (the “Terms”) purchased by the Customer (the “Services”). Under the Terms and in accordance with this data processing agreement (the “Agreement”), the Supplier will process personal data on the Customer’s behalf as a data processor (“Personal Data”).
The purpose of this Agreement is to regulate the Supplier’s processing of Personal Data in the context of the Services, taking into account the requirements of the EU General Data Protection Regulation EU 2016/679 (the “GDPR”). This Agreement is an integral part of the Terms. If the provisions on the processing of Personal Data in this Agreement and in the Terms conflict, the provisions of this Agreement shall prevail.
The Agreement applies to all agreements entered into between the Parties in which Wndy AB is a data processor for the Customer, and the Agreement applies for as long as the Data Processor processes personal data on the Customer’s behalf.
Definitions
Unless the circumstances clearly indicate otherwise, definitions or terms used in this Agreement, and which are not otherwise defined in the Agreement, shall have the corresponding definition set out in Article 4 of the GDPR. Terms not capitalised, such as “processing”, “data subject”, “personal data breach” and others, shall have the same meaning as in the GDPR. Terms stated in the singular shall have the corresponding meaning when used in the plural or inflected in another way.
Processing of personal data and the data processor’s undertakings
- The Customer is the data controller for the personal data processed within the framework of the Terms. Wndy AB is to be regarded as a data processor for the Customer.
- The Parties agree that the data processor:
- may only process personal data on documented instructions from the Customer, including with regard to transfers of personal data to a third country or an international organisation, unless such processing is required by Union law or by the national law of a Member State to which the data processor is subject; in that case the data processor shall inform the Customer of the legal requirement before the data is processed, unless such information is prohibited on important grounds of public interest under that law;
- may not transfer personal data to a third country or international organisation unless the Customer has approved it;
- in the event of changed or updated instructions from the Customer, the Customer must inform the Data Processor in writing within 1 month;
- shall ensure that persons authorised to process the personal data have undertaken to observe confidentiality or are subject to an appropriate statutory duty of confidentiality. The undertaking applies also after the agreement has ended, however at the latest until such time as applies under specifically applicable legal requirements;
- shall ensure that all natural persons working under its direction comply with this agreement including appendices and instructions, and that those natural persons comply with relevant legislation;
- shall, taking into account the nature of the processing, assist the Customer through appropriate technical and organisational measures, insofar as this is possible, so that the Customer can fulfil its obligation to respond to requests for exercising the data subject’s rights in accordance with the GDPR;
- shall, at the Customer’s request, assist the Customer in fulfilling its obligations under applicable data protection legislation, such as carrying out data protection impact assessments, taking appropriate technical and organisational measures to ensure an appropriate level of protection for the personal data, prior consultation with the competent supervisory authority, and assisting in the investigation of personal data breaches that have occurred. Unless the Parties have agreed otherwise, such assistance as referred to in this paragraph shall not entitle the Data Processor to separate remuneration;
- shall give the Customer access to all information required to demonstrate that the obligations laid down in Article 28 of the GDPR have been fulfilled, and shall allow for and contribute to audits, including inspections, conducted by the Customer or by another auditor mandated by the Customer;
- shall immediately inform the Customer if it considers that an instruction infringes the GDPR or other Union or Member State data protection provisions. While awaiting new instructions, the Data Processor is entitled to stop processing the personal data, which does not entail any liability or compensation;
- undertakes to process only such personal data as is necessary to achieve the purpose of the respective processing. This undertaking concerns, for example, the amount of personal data, the extent of the processing, how long the personal data is processed and its accessibility.
- The Parties agree that the Customer:
- is responsible for ensuring that there is a legal basis for the Processing of personal data and for drawing up correct Instructions so that the Data Processor and the Sub-processor can fulfil their assignments under this agreement and the Terms;
- is responsible for informing Data Subjects about the Processing and for safeguarding Data Subjects’ rights under data protection legislation, and for taking every other measure incumbent on the Customer, that is, the data controller, under data protection legislation.
Personal data breach
- In the event that a situation arises leading to accidental or unlawful destruction, loss or alteration of, or unauthorised disclosure of or unauthorised access to, the personal data (a “Personal Data Breach”), the Data Processor shall, without undue delay and at the latest within 72 hours from the Personal Data Breach being discovered, inform the Customer in writing using the contact details set out in Appendix 3.
- The information shall, insofar as it is available to the Data Processor, contain at least the following:
- A description of the circumstances surrounding the Personal Data Breach
- A description of the nature of the Personal Data Breach and, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate volume of personal data concerned
- A description of the likely consequences of the Personal Data Breach
- A description of the measures taken or proposed to address the Personal Data Breach and, where appropriate, measures to mitigate its potential adverse effects
- Contact details for the data protection officer or other contact person who can provide more information to the Customer
- If it is not possible for the Data Processor to provide the information at one time, the information may be provided in stages without undue further delay.
Transfer of personal data outside the EU/EEA
We aim to process your personal data within the EU. If we use service providers that transfer your personal data to countries outside the EU and the EEA, we will take measures to protect your data in accordance with applicable legal requirements, for example by requiring the provider to protect the data in accordance with applicable data protection rules.
Audit and review
The Data Processor shall, at the Customer’s request, give the Customer access to all information required to demonstrate that the Data Processor’s obligations under Article 28 of the GDPR and under the Agreement have been fulfilled. If the information under the preceding point cannot reasonably be considered sufficient to demonstrate that the obligations laid down in Article 28 of the GDPR are met, the Customer is entitled to carry out physical audits.
The Data Processor shall allow for and contribute to audits and inspections conducted by the Customer or by an impartial third party appointed by the Customer. The Customer shall notify the Data Processor in writing of the planned audit at least ten (10) working days in advance. The audit may only be carried out:
- during normal office hours;
- after the Customer has ensured that the person carrying out the audit is subject to a confidentiality undertaking appropriate in relation to the personal data and the information to be audited; and
- in accordance with the Data Processor’s internal policies and security routines.
The Customer may carry out audits and inspections in a manner that does not obstruct the Data Processor’s obligations towards its customers, subcontractors or third parties. The Customer and others who are to take part in auditing or inspecting the Data Processor shall first sign customary confidentiality undertakings with the Data Processor.
Each party bears its own costs arising in connection with an audit. If a further audit takes place within one (1) year of an audit carried out, the Customer shall bear all costs.
Sub-processors
- Through this Agreement, the Data Processor is authorised to engage the specified subcontractors to process personal data (see Appendix 2).
- Where the Data Processor plans to engage a sub-processor or replace an existing sub-processor, the Data Processor shall inform the Customer at least 30 working days in advance so that the Customer has the opportunity to object to the change.
If there are reasonable grounds for the Customer to object to a sub-processor, the parties shall in the first instance cooperate to find a suitable alternative, and the Data Processor shall have the opportunity to find another sub-processor before termination becomes relevant. In the second instance, the Customer has the right to terminate this Agreement and the applicable Terms. The agreement period under the Terms will then apply.
When engaging a sub-processor, the Data Processor shall by agreement (a “Sub-processor Agreement”) ensure that the sub-processor has the same obligations as the Data Processor has under the Agreement. This applies in particular with regard to sufficient guarantees of implementing the appropriate technical and organisational measures required to comply with applicable law.
- The Customer always has the right to review the Data Processor’s sub-processor agreements (strictly commercial information may be redacted).
- The Data Processor shall maintain an up-to-date list of its sub-processors. The list shall be made available to the Customer on request.
- If the sub-processor fails to fulfil its obligations under the sub-processor agreement, the Data Processor shall be fully liable to the Customer for the sub-processor’s acts or failure to act.
- The Data Processor is not entitled to transfer the personal data to a Sub-processor without the Customer’s permission.
- Engaging a new sub-processor does not change the allocation of responsibility between the parties.
Records and data protection officer
The Data Processor undertakes to maintain a written record of the processing of personal data with the content set out in Article 30(2) of the GDPR. The record shall be available to the Customer on request.
Contact with the supervisory authority and the data subject
The Data Processor shall without delay inform the Customer of all contact with the Data Subject, a supervisory authority or another third party concerning the Data Processor’s processing of the personal data.
In the event that the Data Subject makes a request to the Data Processor regarding their rights in connection with the processing, the Data Processor shall refer the Data Subject to the Customer.
The Data Processor shall permit the inspections that a supervisory authority may require under applicable law.
The Data Processor is not entitled to represent the Customer or otherwise act on the Customer’s behalf towards the Data Subject, a supervisory authority or another third party.
Liability and obligation to compensate
- A Party is released from liability for undertakings under the Agreement where performance is prevented by a circumstance of an extraordinary nature beyond the Party’s control, which the Party could not reasonably have been expected to have taken into account, and the consequences of which the Party could not reasonably have avoided or overcome.
- The provisions in the general terms and conditions concerning liability and the obligation to compensate apply also to this Agreement.
- The Data Processor is not liable for the Customer’s costs for legal representation.
- The Data Processor’s liability shall not cover indirect damage or consequential damage such as lost revenue or profits, contracts, customers or business opportunities, loss of goodwill, or anticipated savings.
Confidential information
The Data Processor may not use information or other material to which it is given access within the framework of the Agreement or the Terms for any purpose other than to fulfil the obligations under this Agreement or the Terms.
The Data Processor may not disclose or reveal to a third party or to any other unauthorised person information about the processing of personal data or the content of personal data covered by this Agreement, or other information to which the Data Processor has been given access as a result of this Agreement. This does not apply to information that the Data Processor is required to disclose by law. The confidentiality obligation is valid from the day both Parties have signed the Agreement and indefinitely thereafter. The Data Processor shall ensure that the confidentiality undertaking applies to all employees and other persons working at or on behalf of the Data Processor who are authorised to process personal data.
Term and termination
The Agreement is valid for the period stated under the General Terms and Conditions, Term of the agreement. During this period the Data Processor processes personal data on the Customer’s behalf.
Deletion of account and personal data
On termination of the Agreement, the Data Processor and any sub-processors shall either delete or return the personal data covered by the Agreement, unless storage of the personal data is required by Union law or by the national law of a Member State.
After the Agreement has ended, the Data Processor shall within one (1) month either delete or return all personal data covered by the Agreement, in accordance with the Customer’s documented instructions.
See Appendix 3 for further information on deletion processes and time frames.
Assignment of the Agreement
A Party is not entitled to assign, in whole or in part, its rights and/or obligations under the Agreement without the other Party’s prior written consent.
Applicable law and disputes
- Swedish law shall apply to the Agreement.
- The dispute resolution mechanism set out in the Terms shall apply also to this Agreement.
Appendix 1 — Processing of personal data
Clarification:
Wndy processes only such personal data as is necessary to deliver the service in question and in accordance with the customer’s written instructions. Optional data is processed only if it is provided or uploaded by the customer. Data minimisation is always applied. For each service, only the data relevant according to the description below applies.
Categories of personal data per service
1. Basic employee administration
Mandatory data:
- Name (first name and surname)
Optional data (only if the customer provides or uploads it):
- Personal identity number
- Contact details (e-mail, telephone)
- Address (street address, postcode, city)
- Employment contract
- Salary
- Holiday days
- Probationary employment / notice period
- Trade union membership
- Notes made within the scope of the advisory service
- Other documents uploaded by the customer
2. Document management
Optional data (only if the customer provides or uploads it):
- Employment contract
- Notes made within the scope of the advisory service
- Other documents
Categories of processing
The Data Processor may, to the extent necessary for the respective service, carry out the following processing operations:
- Collection
- Registration
- Storage
- Adaptation
- Erasure
Categories of data subjects
Personal data may be processed for the following categories of data subjects, depending on the customer’s use of the service:
- Employees
- Consultants
Purposes of the processing
The Data Processor processes personal data for the following purposes, only to the extent required for the service in question and in accordance with the customer’s instructions:
1. Basic employee administration
- Management of employee information
- Communication with employees
- Documentation of employment relationships
2. Document management
- Storage of employment contracts
- Documentation of advisory services
- Archiving of other documents
Technical and organisational security measures
The Data Processor shall take appropriate technical and organisational security measures to protect the personal data against unauthorised or unlawful access, loss or other impermissible processing. These measures include, among others:
System access and security:
- Restrictive and role-based system access
- Encryption of data (SSL)
- Secure password management
- Continuous security review
Physical security:
- Fire protection
- Theft protection on the premises
- Secure storage of equipment
- Controlled access to the premises
Organisational measures:
- Internal governing documents (policies/instructions)
- Confidentiality agreements for staff
- Continuous training in data security
- Routines for incident management
Control over personal data
The Data Processor never processes more data than is necessary for the purpose of the service and in accordance with the customer’s instructions.
Personal data is protected against accidental or unlawful destruction, alteration or corruption.
Data is protected against unauthorised access during storage, transfer and other processing.
Personal data is disclosed to the customer only after identity has been verified.
All processing is documented and traceable.
Contact details
Wndy AB
Appendix 2 — Existing and approved sub-processors
1. Google Cloud Platform, Google Workspace, Firebase and Analytics
Type of service:
Data storage and cloud services used to deliver advisory services, information and digital services to customers through Wndy’s platform.
Data processed:
All categories of personal data used in the service by the customer and included in Appendix 1.
Storage location:
Personal data is stored primarily within the EU/EEA, specifically in the region “europe-west1” (Belgium) for Cloud Firestore. For certain other services (for example parts of Firebase, Workspace and Analytics), data, or certain metadata, may also be processed or accessible outside the EU/EEA — in particular in connection with technical support, backup or administration.
Transfer mechanism:
Any transfer of personal data to the USA or another third country takes place mainly on the basis of the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework (DPF), as Google is a certified participant in the DPF programme. If the DPF is not applicable, other approved transfer mechanisms are used instead, for example standard contractual clauses (SCC).
Links: Google and the Data Privacy Framework (DPF), Google privacy, Google Cloud & GDPR, Firebase & GDPR
2. HubSpot
Type of service:
CRM system for managing customer records, customer information, service and support, and sales and marketing activities.
Data processed:
Name, company name, company registration number, contact details and invoicing details provided in the service or via web forms. Also other customer information stored in order to deliver and improve the service.
Storage location:
Personal data is stored mainly within the regional data centre selected when the account is created (for example EU, Germany). HubSpot uses Amazon Web Services (AWS) for data storage. In certain cases processing may take place outside the selected data centre, for example when using third-party apps, support services, development work or backup.
Transfer mechanism:
For any transfer outside the EU/EEA, approved safeguards under the GDPR are used, including the European Commission’s standard contractual clauses (SCC) and participation in the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework. HubSpot and its subcontractors comply with these data protection mechanisms when processing and transferring personal data.
Data Processing Agreement (DPA):
HubSpot’s Data Processing Agreement (DPA) applies automatically to all users and is integrated into HubSpot’s general terms. The agreement includes rules on data protection, data processing and transfers outside the EU/EEA under the GDPR. The full agreement can be reviewed and downloaded via HubSpot’s Trust Center or on request.
Links: HubSpot Data Processing Agreement, Trust Center, Privacy Policy
3. Jitsi as a Service
Type of service:
Video meeting service used for ad hoc video meetings between customers and HR experts.
Data processed:
Only the name is stored temporarily in connection with an ongoing video meeting. No long-term storage of personal data takes place.
Storage location:
Personal data is stored only temporarily and is processed primarily within the EU/EEA. When certain cloud providers are used, technical data may in exceptional cases be processed outside the EU/EEA, but no personal data is stored permanently.
Transfer mechanism:
For any transfer outside the EU/EEA, approved safeguards under the GDPR are used, for example standard contractual clauses (SCC). No personal data is stored long-term.
Links: 8×8 Jitsi as a Service, meet.jit.si Privacy Supplement
4. Sysarb
Type of service:
Salary mapping tool. Used at the customer’s request when a salary mapping is to be carried out. Certain personal data from the platform is then shared with Sysarb for processing and reporting under the Swedish Discrimination Act.
Data processed:
Name, contact details, employment details (position, salary), CV, any next-of-kin details and other relevant data required in order to carry out salary mapping and related HR processes. Only data necessary for the purpose is processed.
Storage location:
Personal data is processed and stored mainly within the EU/EEA. Under the sub-processor agreement, no transfer of employment data to a third country takes place.
Transfer mechanism:
If, in exceptional cases, a transfer of personal data to a country outside the EU/EEA were to become relevant, the European Commission’s standard contractual clauses (SCC) and other relevant safeguards under the GDPR are applied.
Data Processing Agreement (DPA):
A sub-processor agreement (DPA) between Wndy and Sysarb governs the handling of personal data. The agreement is not public but can be disclosed to the customer on request.
Links: Sysarb Privacy Policy, Sysarb Security & Compliance
5. MongoDB Atlas
Type of service:
Database management and cloud service used to store and manage personal data connected to Wndy’s platform.
Data processed:
All categories of personal data used in the service by the customer and included in Appendix 1.
Storage location:
Personal data is stored within the EU/EEA, specifically in the region europe-west1 (Belgium) via MongoDB Atlas. The underlying infrastructure service is provided by Google Cloud Platform (GCP). All data is stored and processed on dedicated and replicated servers in this region.
Transfer mechanism:
Any transfer of personal data to a country outside the EU/EEA takes place on the basis of approved transfer mechanisms under the GDPR, such as standard contractual clauses (SCC) or other applicable legal safeguards in accordance with MongoDB’s routines.
Links: MongoDB Data Processing Agreement (DPA), MongoDB Privacy Policy
6. Zoom Video Communications Inc.
Type of service:
Video meeting service used for online training and events offered to customers via Wndy.
Data processed:
Name, e-mail address and any audio, video and chat messages voluntarily provided by participants in connection with training or events. No sensitive personal data is processed systematically.
Storage location:
Personal data is processed and stored primarily within the EU/EEA where possible. Certain metadata or content (for example recordings) may in exceptional cases be processed or accessible outside the EU/EEA depending on the user’s location and settings.
Transfer mechanism:
For any transfer of personal data to the USA or another third country, approved safeguards under the GDPR are used, such as standard contractual clauses (SCC). Zoom is in addition certified under the EU–U.S. Data Privacy Framework (DPF).
Data Processing Agreement (DPA):
Zoom’s DPA applies automatically to business users. The full agreement can be disclosed on request.
Links: Zoom Privacy Policy
7. Intercom, Inc.
Type of service:
Chat and communication service used on Wndy’s platform to handle support matters between customers and HR experts.
Data processed:
First and last name, e-mail address, company name and message content, and technical metadata such as IP address and browser information.
Storage location:
Personal data is processed mainly within the EU/EEA. Certain processing may take place in a third country, for example in connection with technical support or system operation.
Transfer mechanism:
For transfers to a third country, approved safeguards under the GDPR are used, such as standard contractual clauses (SCC). Intercom is in addition certified under the EU–U.S. Data Privacy Framework (DPF).
Data Processing Agreement (DPA):
Intercom’s DPA applies automatically to business users. The full agreement can be provided on request.
Links: Intercom Legal, Intercom Privacy Policy
Appendix 3 — Retention policy for personal data
1. Purpose
This policy describes how Wndy AB stores and deletes personal data processed on the Customer’s behalf in accordance with the GDPR.
2. Retention periods
2.1 Data in the platform
During the term of the agreement
The Customer has full control over the storage and deletion of data via the platform. The Customer may at any time delete or export data directly in the system.
On termination of the agreement
When the agreement ceases to apply, the Customer has fourteen (14) days to export or request its data. If more time is required, the Customer may contact us at kontakt@wndy.se to request an extension of the period.
After fourteen (14) days — and unless otherwise agreed — the Customer’s account is locked for further use. All data connected to the Customer’s account is then permanently deleted within thirty (30) days from the platform and from any sub-processors, in accordance with applicable data protection legislation.
2.2 Backups
Deleted data may remain in backups for a maximum of ninety (90) days, after which it is deleted automatically and permanently.
2.3 System logs
System logs that may contain personal data (for example user ID, IP addresses and API calls) are stored for a maximum of thirty (30) days for purposes related to security, troubleshooting and traceability. This follows the standard retention policy of Google Cloud Functions.
After thirty (30) days the logs are deleted automatically and permanently from the system.
3. HR experts’ downloading of data
3.1 Responsibility when downloading
When the Customer shares data with our HR experts and the expert downloads files locally, the following applies:
The Customer is responsible for:
- Deleting data from the platform as described above
- Instructing the HR expert to delete locally downloaded files where this needs to happen earlier than 30 days after the end of the assignment
The HR expert is responsible for:
- Deleting locally downloaded files no later than 30 days after the end of the assignment, or earlier at the Customer’s request
3.2 Deletion process for downloaded data
- 30 days after the assignment ends, or earlier if the Customer requests it, the HR expert deletes downloaded files connected to the Customer.
3.3 Contractual undertakings
All HR experts who are given access to the Customer’s data are contractually bound to:
- Follow our instructions on deletion
- Not retain data longer than necessary
- Delete data securely from all devices and storage locations
4. The Customer’s rights
You may at any time:
- Delete data directly in the platform
- Request confirmation that downloaded data has been deleted by the HR expert
- Export your data before the agreement ends