LAST UPDATED: 2026-08-05 · Version 1
Parties and background
This Data Processing Agreement (“DPA”) is entered into between the business customer identified in the Order (the “Customer” / “Controller”) and Henrik Hellbe, Enskild firma, org.nr 950809-XXXX, Sandelsgatan 14, 115 34 Stockholm, Sweden, trading as SVARA (“SVARA” / “Processor”).
This DPA forms part of, and is incorporated by reference into, the Terms & Conditions between the parties (the “Agreement”). It governs SVARA’s processing of personal data on behalf of the Customer when providing the Service — principally the content of messages exchanged between the Customer and its end-customers. Where SVARA processes personal data as a controller (e.g. Customer account and billing data), the Privacy Policy applies instead of this DPA.
In case of conflict between this DPA and the rest of the Agreement regarding the processing of personal data on the Customer’s behalf, this DPA prevails.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR (Regulation (EU) 2016/679). “Applicable Data Protection Law” means the GDPR and Swedish laws supplementing it.
2. Roles of the parties
The Customer is the controller and SVARA is the processor in respect of the personal data processed under this DPA (as further described in Appendix 1). The Customer warrants that it has a valid legal basis for the processing, that its instructions are lawful, and that it is entitled to engage SVARA to process the personal data. Where a data subject’s personal data is that of a person other than the Customer’s own staff (e.g. an end-customer), the Customer remains the controller and is responsible for providing any required notices and legal bases.
3. Scope and instructions
SVARA shall process personal data only on the Customer’s documented instructions, including with regard to transfers, unless required to do otherwise by EU or Member State law (in which case SVARA will inform the Customer, unless that law prohibits it on important grounds of public interest). The Agreement, this DPA, and the Customer’s configuration and use of the Service constitute the Customer’s complete and documented instructions. SVARA will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Duration
This DPA applies for as long as SVARA processes personal data on behalf of the Customer under the Agreement.
5. Confidentiality
SVARA shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide the Service.
6. Security (Article 32)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to data subjects, SVARA shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in place are described in Appendix 2.
7. Sub-processors
- The Customer gives SVARA a general authorisation to engage the sub-processors listed in Appendix 3 to process personal data.
- SVARA shall inform the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer reasonably objects and the parties cannot resolve the matter, the Customer may terminate the affected part of the Service.
- SVARA shall impose on each sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA.
- SVARA remains fully liable to the Customer for the performance of each sub-processor's obligations.
8. Assistance with data-subject rights
Taking into account the nature of the processing, SVARA shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (Articles 12–23). If SVARA receives such a request directly, it will, unless legally required to act, refer the data subject to the Customer.
9. Assistance with the controller's obligations
SVARA shall assist the Customer, taking into account the nature of processing and the information available to SVARA, in ensuring compliance with the Customer’s obligations under Articles 32–36 GDPR — namely security of processing, notification of personal data breaches, communication of breaches to data subjects, data-protection impact assessments, and prior consultation with the supervisory authority.
10. Personal data breach
SVARA shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer’s behalf, and shall provide the information reasonably available to it to assist the Customer in meeting its obligations under Articles 33 and 34 GDPR. SVARA shall take reasonable steps to mitigate and remediate the breach.
11. International transfers
Where SVARA or a sub-processor processes personal data outside the EU/EEA, such transfer shall be subject to appropriate safeguards under Chapter V of the GDPR, principally the EU Standard Contractual Clauses (SCCs), and/or an adequacy decision (e.g. the EU-US Data Privacy Framework where applicable). The current sub-processors and their transfer basis are set out in Appendix 3.
12. Deletion and return of data
On termination or expiry of the Agreement, SVARA shall, at the Customer’s choice, delete or return all personal data processed on the Customer’s behalf, and delete existing copies, unless EU or Member State law requires storage. Message content is in any event automatically purged within 30 days. On termination, the Customer’s isolated instance and its unique encryption key are destroyed, rendering any residual data cryptographically unrecoverable (crypto-erasure); secure deletion therefore does not depend on any single storage system.
13. Audits
SVARA shall make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by it. SVARA may satisfy audit requests, in the first instance, by providing relevant documentation, security summaries and completed questionnaires. Any on-site audit shall be limited to once per 12 months (unless required by a supervisory authority or following a breach), on reasonable prior written notice, during business hours, subject to confidentiality, without disrupting SVARA’s operations, and at the Customer’s cost.
14. AI processing
Personal data contained in message and Brand Knowledge content is transmitted to SVARA’s AI subprocessor (Anthropic) solely to generate the Draft Reply. Such content is not used to train AI models and is processed transiently.
15. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA affects any right of a data subject, or the powers of a supervisory authority, under the GDPR.
16. Governing law
This DPA is governed by Swedish law, and disputes are subject to the jurisdiction clause in the Agreement (Stockholm District Court (Stockholms tingsrätt) as court of first instance).
Appendix 1 — Description of the processing
| Item | Description |
|---|---|
| Subject matter | Processing of personal data contained in messages and related content in order to generate suggested (Draft) replies for the Customer to review and approve. |
| Nature and purpose | Fetching incoming messages from Connected Accounts, generating AI Draft Replies, surfacing them for approval, sending Customer-approved replies, and — where the Customer enables it — sending optional automated messages (e.g. a first-contact redirect) per the Customer's configuration. Purpose: provision of the Service. |
| Duration | For the term of the Agreement; message content is automatically purged within 30 days and drafts are retained only while awaiting approval. |
| Categories of data subjects | The Customer's end-customers and other persons who communicate with the Customer through Connected Accounts; the Customer's authorised users. |
| Types of personal data | Identifiers and contact details (e.g. name, social handle, email address) and the content of messages, comments and emails, which may contain any personal data the data subject chooses to include. The Customer must not use the Service to process special-category data. |
Appendix 2 — Technical and organisational security measures (Article 32)
SVARA maintains, at a minimum, the following measures (reviewed and updated as the Service evolves):
- Encryption at rest — all customer message content (drafts and conversation history) and the internal audit log are encrypted using authenticated symmetric encryption (AES-based, via Fernet), with a unique encryption key per customer instance.
- Key management — encryption keys are held only within the isolated instance environment and are never stored in SVARA's central database.
- Encryption in transit — all connections use TLS.
- Tenant isolation — each customer runs in an isolated instance with its own compute, storage, credentials and encryption key.
- Credential handling — connected-account credentials/tokens are stored (encrypted) in the instance environment, never in SVARA's central database.
- Least-privilege email access — sending uses the minimal send-only gmail.send scope (cannot read mail); incoming mail is read over IMAP in read-only mode (cannot modify, move or delete mail) and can be scoped to a dedicated support folder/label.
- Data minimisation & retention — message content is automatically purged within 30 days; drafts are retained only while awaiting approval; internal identifiers are minimised.
- Secure erasure (crypto-erasure) — on termination, the instance and its encryption key are destroyed, rendering residual data cryptographically unrecoverable, independent of any single storage system.
- No AI training — message and knowledge content is not used to train AI models.
- Human-in-the-loop (default) — no reply is sent without the Customer's approval, except where the Customer explicitly enables the optional automated-message feature, which is off by default.
- Access, logging and subprocessors — access management, authentication and logging for SVARA systems; reputable subprocessors bound by written data-protection terms and appropriate transfer safeguards.
- Ongoing review — measures are reviewed in light of the state of the art and evolving risk.
Appendix 3 — Approved sub-processors
| Subprocessor | Purpose | Location / transfer basis |
|---|---|---|
| Stripe | Payment processing | US / EU — SCCs / adequacy (EU-US DPF where applicable) |
| Anthropic | AI draft generation (Claude API) | US — SCCs |
| Metricool (Metricool Software, S.L., Spain) | Access to social inbox (Instagram / Facebook DMs & comments) | EU / EEA — stored & processed within the EU/EEA; no third-country transfer |
| Slack (Salesforce) | Approval / review interface | US — SCCs |
| Railway | Hosting / infrastructure | US — SCCs |
| Sending approved email replies (gmail.send) | US — SCCs / adequacy |