Product

Nova · The loopIt does the work, then it stops and asks

Company

Client case · EskilstunaErgonomic bars, designed and installed worldwide

Findings

Latest · Field researchFour stages, four documents

Security

Security · How it is builtEvery control, and how it is enforced

LegalData Processing AgreementEffective April 1, 2026

Data Processing Agreement

Venuvo AB, org. nr 559499‑4484. This is the document as it stands today. When it changes, the effective date above changes with it.

All documents are indexed on the legal page. A Swedish version of this document is available on request from info@venuvo.net.

This Data Processing Agreement ("DPA") is entered into between Venuvo AB (org.nr 559499-4484), a company registered under the laws of Sweden ("Processor", "Venuvo", "we", or "our"), and the entity or individual that has accepted the Terms of Service ("Controller", "Customer", "you", or "your"). This DPA forms an integral part of the Terms of Service (the "Agreement") and governs the processing of Personal Data by Venuvo on behalf of the Customer.

This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and shall apply to all processing of Personal Data by Venuvo on behalf of Customer in connection with the Service.

Plain language

This agreement defines how Venuvo handles your customers' personal data when you use our platform. It's legally required under GDPR whenever a "processor" (us) handles data on behalf of a "controller" (you).

1. Definitions

In this DPA, capitalized terms not otherwise defined herein shall have the meanings given to them in the Agreement or in Article 4 of the GDPR:

Personal Data
Any information relating to an identified or identifiable natural person that is processed by Venuvo on behalf of Customer in connection with the Service. This includes any data that you or your Authorized Users upload, import, or otherwise submit to the Service that relates to or can be used to identify a natural person.
Data Protection Laws
The GDPR, the Swedish Data Protection Act (dataskyddslagen, SFS 2018:218), the ePrivacy Directive (2002/58/EC) as implemented in Swedish law, and any other applicable data protection or privacy legislation in any relevant jurisdiction.
Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by Venuvo on behalf of Customer.
Sub-Processor
Any third party engaged by Venuvo to process Personal Data on behalf of Customer in connection with the Service.
Data Subject
An identified or identifiable natural person whose Personal Data is processed under this DPA.
Supervisory Authority
An independent public authority responsible for monitoring the application of Data Protection Laws. For Venuvo, the primary Supervisory Authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY").

2. Scope and details of processing

2.1 Subject Matter and Duration

The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the Service as described in the Agreement. Processing shall continue for the duration of the Agreement and any applicable post-termination data retention period specified in Section 10.

2.2 Nature and Purpose of Processing

The nature of processing includes the following operations, performed as necessary to deliver the Service:

  • Collection and recording (when Customer imports or enters data)
  • Organization and structuring (categorizing contacts, associating records)
  • Storage and hosting (maintaining data on Venuvo's infrastructure)
  • Retrieval and consultation (displaying data to Authorized Users)
  • Use and adaptation (processing data through Service features, including search, filtering, reporting, and AI features)
  • Disclosure by transmission (sharing data between Authorized Users within the same account, generating exports)
  • Erasure and destruction (deleting data upon Controller's instruction or contract termination)

2.3 Types of Personal Data

The Personal Data processed under this DPA may include, but is not limited to:

  • Contact information: names, email addresses, telephone numbers, postal addresses
  • Professional information: job titles, company names, departments, roles
  • Communication records: email correspondence, meeting notes, call logs, chat messages stored in the Service
  • Business information: deal values, transaction history, service records
  • Custom fields: any additional data fields created by Controller
  • Files and documents: attachments uploaded by Controller

Controller shall not submit special categories of Personal Data (Article 9 GDPR) to the Service without Venuvo's prior written agreement and implementation of additional safeguards.

2.4 Categories of Data Subjects

Data subjects may include: Controller's customers, clients, prospects, leads, business contacts, vendors, partners, employees, contractors, and any other individuals whose Personal Data is submitted to the Service by Controller.

3. Obligations of the processor

Venuvo shall, with respect to the processing of Personal Data under this DPA:

3.1 Processing on Instructions

Process Personal Data only on the Controller's documented instructions, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by EU or Swedish law to which the Processor is subject. In such case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.

3.2 Confidentiality

Ensure that all persons authorized to process Personal Data — including employees, contractors, and agents — have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Venuvo shall ensure that access to Personal Data is limited to those individuals who need access to perform their duties in connection with the Service.

3.3 Security Measures

Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. These measures include:

  • Encryption: AES-256 encryption for data at rest; TLS 1.2 or higher for data in transit.
  • Tenant Isolation: Row-Level Security (RLS) policies at the database level ensuring strict logical separation of each Controller's data from all other customers' data.
  • Access Controls: Role-based access controls implementing the principle of least privilege, with authentication mechanisms including support for multi-factor authentication.
  • Backup and Recovery: Regular automated backups with encryption, stored within the European Union, with tested recovery procedures.
  • Vulnerability Management: Regular security assessments, automated dependency scanning, and prompt patching of identified vulnerabilities.
  • Audit Logging: Comprehensive logging of all access to and modifications of Personal Data, with logs retained for security monitoring and forensic investigation.
  • Incident Response: Documented incident response procedures with defined roles, escalation paths, and notification timelines.

3.4 Assistance with Data Subject Rights

Assist the Controller, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). If Venuvo receives a request directly from a Data Subject, Venuvo shall promptly redirect the Data Subject to the Controller and inform the Controller of the request.

3.5 Assistance with Compliance Obligations

Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 through 36 of the GDPR, taking into account the nature of processing and the information available to the Processor. This includes assistance with Data Protection Impact Assessments (DPIAs) and prior consultations with Supervisory Authorities.

3.6 Data Return and Deletion

At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies, unless EU or Swedish law requires storage of the Personal Data. See Section 10 for detailed timelines.

3.7 Audit and Compliance Demonstration

Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. See Section 9 for detailed audit provisions.

4. Obligations of the controller

The Controller shall:

  • Ensure that there is a lawful basis for the processing of Personal Data in the Service, including obtaining necessary consents and providing appropriate privacy notices to Data Subjects.
  • Provide documented processing instructions to the Processor and promptly inform the Processor if any instruction is, in the Controller's view, contrary to Data Protection Laws.
  • Ensure that the Personal Data submitted to the Service is accurate, relevant, and limited to what is necessary for the purposes of processing.
  • Comply with all applicable Data Protection Laws with respect to its use of the Service.

5. Sub-processors

5.1 General Authorization

The Controller hereby grants the Processor general written authorization to engage Sub-Processors for the processing of Personal Data, subject to the requirements of this Section 5.

5.2 Current Sub-Processors

A current list of Sub-Processors is maintained and available at https://www.venuvo.net and as a separate document (Sub-Processor List). The Processor shall keep this list current and accurate.

5.3 Notification of Changes

The Processor shall notify the Controller in writing at least thirty (30) calendar days prior to the engagement of any new Sub-Processor or the replacement of an existing Sub-Processor. The notification shall include the name of the Sub-Processor, the processing activities to be performed, and the location of processing.

5.4 Right to Object

If the Controller has reasonable, documented objections to a new or replacement Sub-Processor on legitimate data protection grounds, the Controller shall notify the Processor in writing within fifteen (15) calendar days of receiving the notification. The parties shall discuss the objection in good faith with a view to achieving a commercially reasonable resolution. If no resolution can be reached, the Controller may terminate the affected Service and receive a pro-rata refund of prepaid fees.

5.5 Sub-Processor Obligations

The Processor shall impose data protection obligations on each Sub-Processor by way of a written contract that provides at least the same level of protection for Personal Data as this DPA. The Processor shall remain fully liable to the Controller for the performance of each Sub-Processor's obligations.

6. Data breach notification

6.1 Notification Timeline

In the event of a Data Breach, the Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours after becoming aware of the Data Breach.

6.2 Content of Notification

The notification shall include, to the extent available:

  • A description of the nature of the Data Breach, including the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Data records affected.
  • The name and contact details of the point of contact at Venuvo for further information.
  • A description of the likely consequences of the Data Breach.
  • A description of the measures taken or proposed to be taken to address the Data Breach, including measures to mitigate its possible adverse effects.

6.3 Cooperation

The Processor shall cooperate with the Controller and take all reasonable commercial steps to assist in the investigation, containment, mitigation, and remediation of the Data Breach. The Processor shall not publicly disclose the Data Breach without the Controller's prior consent, except where required by applicable law.

7. International transfers

The Processor shall not transfer Personal Data to any country outside the European Economic Area (EEA) without ensuring that appropriate safeguards are in place as required by Chapter V of the GDPR. Where transfers are necessary, the Processor shall ensure they are protected by: (a) an adequacy decision under Article 45 GDPR; (b) Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR; or (c) another lawful transfer mechanism recognized under applicable Data Protection Laws. The Processor shall conduct transfer impact assessments where required and implement supplementary measures as recommended by the EDPB where necessary.

8. Data protection impact assessments

Where required under Article 35 of the GDPR, the Processor shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments and, if necessary, prior consultations with the Supervisory Authority under Article 36 of the GDPR. The scope of assistance shall be limited to the processing performed by the Processor and the information available to the Processor.

9. Audits

9.1 Audit Rights

The Controller (or an independent third-party auditor mandated by the Controller and subject to confidentiality obligations) may audit the Processor's compliance with this DPA. Audits shall be conducted: (a) with at least thirty (30) calendar days' prior written notice; (b) during normal business hours; (c) in a manner that does not disrupt the Processor's operations or the security of other customers' data; and (d) no more than once per twelve-month period, unless a Data Breach has occurred or the Controller is required to conduct an audit by a Supervisory Authority.

9.2 Audit Costs

The Controller shall bear its own costs in connection with any audit. If the audit requires the Processor to dedicate personnel time beyond what is reasonable, the Processor may charge the Controller for such additional costs at its then-current professional services rates.

9.3 Compliance Documentation

As an alternative to a physical audit, the Processor may provide the Controller with: (a) a summary of the Processor's current security measures and certifications; (b) the results of any third-party security audit or penetration test conducted within the preceding twelve months (subject to confidentiality); or (c) responses to a reasonable security questionnaire provided by the Controller.

10. Data return and deletion

10.1 Export Period

Upon expiration or termination of the Agreement, the Processor shall make all Personal Data processed on behalf of the Controller available for export in a structured, commonly used, machine-readable format (CSV or JSON) for a period of thirty (30) calendar days following the effective date of termination.

10.2 Deletion

After the thirty-day export period, the Processor shall permanently delete all Personal Data processed on behalf of the Controller within sixty (60) additional calendar days (i.e., ninety (90) days total from termination), using industry-standard secure deletion methods. This includes deletion from all production systems, backup systems, and disaster recovery systems.

10.3 Exceptions

The Processor may retain Personal Data beyond the deletion timeline where: (a) required by EU or Swedish law (for example, billing records under the Swedish Bookkeeping Act); (b) necessary for the Processor's legitimate compliance purposes; or (c) the data exists in backup systems that follow a scheduled rotation (in which case, the data will be deleted when the backup is overwritten in the normal course, but will not be actively restored or used).

10.4 Certification

Upon the Controller's written request, the Processor shall provide written certification confirming the deletion of Personal Data.

11. Liability

Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement. Nothing in this DPA shall limit either party's liability for violations of applicable Data Protection Laws to the extent that such limitation is prohibited by applicable mandatory law. Each party shall be responsible for its own compliance with Data Protection Laws as applicable to its role (Controller or Processor).

12. Governing law and dispute resolution

This DPA shall be governed by and construed in accordance with the laws of Sweden. Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions of the Agreement. This DPA shall be interpreted in accordance with the GDPR, and in the event of any ambiguity, shall be interpreted in a manner that best ensures compliance with the GDPR.

13. Amendments

This DPA may be amended by Venuvo to reflect changes in Data Protection Laws or regulatory guidance. Material amendments shall be notified to the Controller at least thirty (30) days in advance. Continued use of the Service after the effective date of an amendment constitutes acceptance.

14. Contact

Data Protection Contact:

Venuvo AB

Org.nr: 559499-4484

Örebro, Sweden

Email: info@venuvo.net

Website: https://www.venuvo.net

Questions about this document?

Legal and privacy enquiries go to info@venuvo.net and reach a founder, not a queue.

Book a demo /30 min