This Data Processing Agreement has been entered into between “the Supplier” Vyer Technologies AB, corporate identity number 559089-5891, Storgatan 23C 12, 114 55 Stockholm, (Data Processor) and “the Customer” (Data Controller) in connection with the Customer's acceptance of the terms and conditions in the Supplier's Subscription Agreement upon electronic signing of the Order Form concerning the “Vyer” service. The Agreement implies, among other things, that the Supplier, acting as a data processor, will process personal data on behalf of the Customer (Personal Data).

Definitions

Concepts not capitalized, such as ”processing”, ”data subject”, ”personal data breach” etc., shall have the same meaning as in the Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (”GDPR”). Other capitalized concepts not defined in the Data Processing Agreement shall have the same meaning as in the Subscription Agreement.

Processing

GDPR

The Parties undertake to fulfil their obligations under the GDPR and laws that implement or supplement the GDPR (”Applicable Data Protection Legislation”).

Purpose-bound

The Supplier may only process Personal Data for the purposes set out in Appendix A and/or according to the Customer's written instructions. The Supplier shall immediately inform the Customer if the Supplier considers that the Customer's instructions violate the Applicable Data Protection Legislation.

Security and confidentiality

Requirements for authorized persons

The Supplier shall implement and maintain all measures required under Article 32 GDPR. The Supplier shall ensure that all persons authorized to process Personal Data have committed themselves to confidentiality, or are under an appropriate statutory obligation of confidentiality.

Personal data breaches

Procedure

The Supplier shall notify the Customer without undue delay (if possible, never later than 36 hours) if the Supplier discovers any personal data breach concerning Personal Data. The notification shall contain the information required for the Customer to be able to fulfil their obligations under Articles 33–34 GDPR.

Data Protection Impact Assessments and prior consultation

Advice

The Supplier shall assist the Customer with data protection impact assessments and prior consultation with the supervisory authority in accordance with Articles 35–36 GDPR, if requested by the Customer.

Communication

Referral

If any data subject, supervisory authority, or other external party contacts the Supplier regarding Personal Data, the Supplier shall immediately refer the request to the Customer.

Rights of the data subject

Rights

Where possible and considering the nature of the processing, the Supplier shall assist the Customer through appropriate technical and organizational measures in fulfilling their obligation to respond to requests for exercising the rights of the data subject under the GDPR.

Sub-processors

Prior authorization

The Supplier is hereby granted a general prior authorization to engage subcontractors for the processing of Personal Data (”Sub-processors”). The Supplier shall enter into written data processing agreements with all its Sub-processors, with at least the same level of obligations as the Supplier has under this Data Processing Agreement.

Duty to inform

The Supplier shall inform the Customer of any plans to engage new or replace Sub-processors, so that the Customer has the opportunity to object to such changes. Such objection must be notified to the Supplier within thirty (30) days from the Supplier informing the Customer of its plans, after which the Customer shall be deemed to have accepted the Sub-processor in question.

Exception

In the event that the Customer's objection to the engagement of a Sub-processor, in the Supplier's opinion, counteracts an effective provision of the Supplier's services, the Supplier may withdraw from the Subscription Agreement without any liability or obligation to pay a fine due to such withdrawal with a notice period of thirty (30) days.

Liability

The Supplier is responsible for its Sub-processors as if the processing had been carried out by the Supplier itself. A list of sub-processors, considered approved when the Data Processing Agreement is entered into, is set out in Appendix A.

Transfer outside the EU/EEA

Safeguards

The Supplier may only transfer Personal Data outside the EU/EEA if the Supplier ensures that the transfer is covered by appropriate safeguards, or is otherwise permitted under the Applicable Data Protection Legislation.

Permitted transfer mechanism

If the transfer mechanism used to ensure that the transfer is permitted under the Applicable Data Protection Legislation were to be declared invalid or unlawful by the Court of Justice of the European Union, the European Commission, or another competent EU institution or national court or authority, the Supplier shall ensure that all processing of Personal Data outside the EU/EEA takes place on the basis of another permitted transfer mechanism according to the Applicable Data Protection Legislation.

Power of attorney

By entering into this Data Processing Agreement, the Customer grants the Supplier a power of attorney to represent the Customer in signing standard contractual clauses (appendix to the European Commission's decision 2010/87/EU of 5 February 2010 concerning the transfer of Personal Data outside the EU/EEA, or such approved clauses that replace or supplement these, in the Customer's name and on the Customer's behalf. Furthermore, the Customer expressly agrees that the Supplier may also represent the sub-processor in question in relation to the standard contractual clauses.

Review and control

Controls

The Supplier shall give the Customer access to all information that the Customer needs to verify that the Supplier fulfils its obligations under this Data Processing Agreement. The Supplier shall also enable and contribute to audits/inspections that the Customer, with at least ten (10) days' notice, conducts themselves or with the help of a third party (however, not a competitor of the Supplier).

Confidentiality undertakings

The Customer may only carry out audits/inspections on the Supplier's premises during the Supplier's normal office hours and shall be carried out in a manner that does not impede the Supplier's obligations towards its customers, subcontractors, or third parties. The Customer and others who will participate in auditing/inspecting the Supplier, shall first sign customary confidentiality undertakings with the Supplier.

Transfer and erasure

Upon termination of the agreement

When the Subscription Agreement expires or when the Customer requests it, the Supplier shall, without undue delay and according to the Customer's instruction, erase all Personal Data or transfer all Personal Data to the Customer and subsequently erase existing copies.

Exception

The Supplier may save/process Personal Data without hindrance to this Data Processing Agreement if required by the Supplier in order for the Supplier to fulfil its legal obligations and the Supplier first informs the Customer of the legal requirement.

Applicable law and dispute resolution

Application of law

Swedish law applies to this Data Processing Agreement, with the exception of choice of law rules that imply the application of foreign law. The provisions of the Subscription Agreement regarding dispute resolution also apply to this Data Processing Agreement.

Liability

In case of breach of contract

The Supplier shall compensate the customer for its damages to the extent that the Supplier's action has constituted a breach of the Data Processing Agreement or the Applicable Data Protection Legislation. To the extent permitted by Applicable Data Protection Legislation, the Supplier's liability shall under no circumstances exceed 100% of the compensation paid by the Customer during a calendar year. Otherwise, the same liability limitations as stated in the Subscription Agreement apply.

Agreement term

Validity

This Data Processing Agreement applies from the day it is signed by the parties until the day the Supplier stops processing Personal Data.

Compensation

Cost price

The Supplier is entitled to invoice the Customer for its costs (at cost price) for assisting the Customer with impact assessments, prior consultations, individual requests for exercising the rights of the data subject, and for transferring and erasing Personal Data. The Supplier is also entitled to invoice the Customer for the Supplier's costs (at cost price) in connection with any audits/inspections by the Customer, unless these show that the Supplier has significantly failed in its obligations under this Data Processing Agreement.

Interpretation

Priority of interpretation

This Data Processing Agreement shall take precedence over the Subscription Agreement in all matters relating to Personal Data.

Appendix A

Subject of processing

In connection with the use of the Vyer service, the Customer and the Customer's Users have the opportunity to save information on their Organization Account, for example when marking details in the premises and reporting errors. The information may contain personal data.

Nature and purpose of processing

The Supplier will process Personal Data for the purpose of:

  • Providing the service in accordance with the Subscription Agreement, and otherwise in accordance with the Customer's documented instructions.

  • Storing information for the Customer that the customer chooses to save on their Organization Account in the Vyer service.

Categories of data subjects

The Customer's employees and other individuals whose data is needed for the use of the Vyer service.

Categories of Personal Data

  • Name

  • Phone

  • Email

  • Position

  • Responsibility

Processing time - retention periods

The Supplier will process Personal Data for as long as the Subscription Agreement runs and for a limited time thereafter in accordance with this Data Processing Agreement, unless Personal Data is erased beforehand by the Customer.

Sub-processors

  • Google Cloud Services, Germany, storage of building information

  • Sendgrid, USA, email notifications

  • Intercom, EU, support communication

  • Flagsmith, UK, Control access to specific features

  • Mixpanel, EU, Usage analysis for service improvement

  • Attio, UK, User groups for support communication