Den utför arbetet, och stannar sedan för att fråga
Nova läser er arbetsyta, redovisar varje anrop den gjort, och föreslår ändringen. Ingenting skrivs förrän en människa bekräftar det.
↳ Se förloppetProdukt

Legal / Data Processing AgreementEffective April 1, 2026
Venuvo AB, org. nr 559499‑4484. This is the document as it stands today. When it changes, the effective date above changes with it.
All documents are indexed on the legal page. A Swedish version of this document is available on request from info@venuvo.net.
This Data Processing Agreement ("DPA") is entered into between Venuvo AB (org.nr 559499-4484), a company registered under the laws of Sweden ("Processor", "Venuvo", "we", or "our"), and the entity or individual that has accepted the Terms of Service ("Controller", "Customer", "you", or "your"). This DPA forms an integral part of the Terms of Service (the "Agreement") and governs the processing of Personal Data by Venuvo on behalf of the Customer.
This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and shall apply to all processing of Personal Data by Venuvo on behalf of Customer in connection with the Service.
This agreement defines how Venuvo handles your customers' personal data when you use our platform. It's legally required under GDPR whenever a "processor" (us) handles data on behalf of a "controller" (you).
In this DPA, capitalized terms not otherwise defined herein shall have the meanings given to them in the Agreement or in Article 4 of the GDPR:
The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the Service as described in the Agreement. Processing shall continue for the duration of the Agreement and any applicable post-termination data retention period specified in Section 10.
The nature of processing includes the following operations, performed as necessary to deliver the Service:
The Personal Data processed under this DPA may include, but is not limited to:
Controller shall not submit special categories of Personal Data (Article 9 GDPR) to the Service without Venuvo's prior written agreement and implementation of additional safeguards.
Data subjects may include: Controller's customers, clients, prospects, leads, business contacts, vendors, partners, employees, contractors, and any other individuals whose Personal Data is submitted to the Service by Controller.
Venuvo shall, with respect to the processing of Personal Data under this DPA:
Process Personal Data only on the Controller's documented instructions, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by EU or Swedish law to which the Processor is subject. In such case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
Ensure that all persons authorized to process Personal Data — including employees, contractors, and agents — have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Venuvo shall ensure that access to Personal Data is limited to those individuals who need access to perform their duties in connection with the Service.
Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. These measures include:
Assist the Controller, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). If Venuvo receives a request directly from a Data Subject, Venuvo shall promptly redirect the Data Subject to the Controller and inform the Controller of the request.
Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 through 36 of the GDPR, taking into account the nature of processing and the information available to the Processor. This includes assistance with Data Protection Impact Assessments (DPIAs) and prior consultations with Supervisory Authorities.
At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies, unless EU or Swedish law requires storage of the Personal Data. See Section 10 for detailed timelines.
Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. See Section 9 for detailed audit provisions.
The Controller shall:
The Controller hereby grants the Processor general written authorization to engage Sub-Processors for the processing of Personal Data, subject to the requirements of this Section 5.
A current list of Sub-Processors is maintained and available at https://www.venuvo.net and as a separate document (Sub-Processor List). The Processor shall keep this list current and accurate.
The Processor shall notify the Controller in writing at least thirty (30) calendar days prior to the engagement of any new Sub-Processor or the replacement of an existing Sub-Processor. The notification shall include the name of the Sub-Processor, the processing activities to be performed, and the location of processing.
If the Controller has reasonable, documented objections to a new or replacement Sub-Processor on legitimate data protection grounds, the Controller shall notify the Processor in writing within fifteen (15) calendar days of receiving the notification. The parties shall discuss the objection in good faith with a view to achieving a commercially reasonable resolution. If no resolution can be reached, the Controller may terminate the affected Service and receive a pro-rata refund of prepaid fees.
The Processor shall impose data protection obligations on each Sub-Processor by way of a written contract that provides at least the same level of protection for Personal Data as this DPA. The Processor shall remain fully liable to the Controller for the performance of each Sub-Processor's obligations.
In the event of a Data Breach, the Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours after becoming aware of the Data Breach.
The notification shall include, to the extent available:
The Processor shall cooperate with the Controller and take all reasonable commercial steps to assist in the investigation, containment, mitigation, and remediation of the Data Breach. The Processor shall not publicly disclose the Data Breach without the Controller's prior consent, except where required by applicable law.
The Processor shall not transfer Personal Data to any country outside the European Economic Area (EEA) without ensuring that appropriate safeguards are in place as required by Chapter V of the GDPR. Where transfers are necessary, the Processor shall ensure they are protected by: (a) an adequacy decision under Article 45 GDPR; (b) Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR; or (c) another lawful transfer mechanism recognized under applicable Data Protection Laws. The Processor shall conduct transfer impact assessments where required and implement supplementary measures as recommended by the EDPB where necessary.
Where required under Article 35 of the GDPR, the Processor shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments and, if necessary, prior consultations with the Supervisory Authority under Article 36 of the GDPR. The scope of assistance shall be limited to the processing performed by the Processor and the information available to the Processor.
The Controller (or an independent third-party auditor mandated by the Controller and subject to confidentiality obligations) may audit the Processor's compliance with this DPA. Audits shall be conducted: (a) with at least thirty (30) calendar days' prior written notice; (b) during normal business hours; (c) in a manner that does not disrupt the Processor's operations or the security of other customers' data; and (d) no more than once per twelve-month period, unless a Data Breach has occurred or the Controller is required to conduct an audit by a Supervisory Authority.
The Controller shall bear its own costs in connection with any audit. If the audit requires the Processor to dedicate personnel time beyond what is reasonable, the Processor may charge the Controller for such additional costs at its then-current professional services rates.
As an alternative to a physical audit, the Processor may provide the Controller with: (a) a summary of the Processor's current security measures and certifications; (b) the results of any third-party security audit or penetration test conducted within the preceding twelve months (subject to confidentiality); or (c) responses to a reasonable security questionnaire provided by the Controller.
Upon expiration or termination of the Agreement, the Processor shall make all Personal Data processed on behalf of the Controller available for export in a structured, commonly used, machine-readable format (CSV or JSON) for a period of thirty (30) calendar days following the effective date of termination.
After the thirty-day export period, the Processor shall permanently delete all Personal Data processed on behalf of the Controller within sixty (60) additional calendar days (i.e., ninety (90) days total from termination), using industry-standard secure deletion methods. This includes deletion from all production systems, backup systems, and disaster recovery systems.
The Processor may retain Personal Data beyond the deletion timeline where: (a) required by EU or Swedish law (for example, billing records under the Swedish Bookkeeping Act); (b) necessary for the Processor's legitimate compliance purposes; or (c) the data exists in backup systems that follow a scheduled rotation (in which case, the data will be deleted when the backup is overwritten in the normal course, but will not be actively restored or used).
Upon the Controller's written request, the Processor shall provide written certification confirming the deletion of Personal Data.
Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement. Nothing in this DPA shall limit either party's liability for violations of applicable Data Protection Laws to the extent that such limitation is prohibited by applicable mandatory law. Each party shall be responsible for its own compliance with Data Protection Laws as applicable to its role (Controller or Processor).
This DPA shall be governed by and construed in accordance with the laws of Sweden. Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions of the Agreement. This DPA shall be interpreted in accordance with the GDPR, and in the event of any ambiguity, shall be interpreted in a manner that best ensures compliance with the GDPR.
This DPA may be amended by Venuvo to reflect changes in Data Protection Laws or regulatory guidance. Material amendments shall be notified to the Controller at least thirty (30) days in advance. Continued use of the Service after the effective date of an amendment constitutes acceptance.
Data Protection Contact:
Venuvo AB
Org.nr: 559499-4484
Örebro, Sweden
Email: info@venuvo.net
Website: https://www.venuvo.net
Legal and privacy enquiries go to info@venuvo.net and reach a founder, not a queue.