Data Processing Agreement / Personuppgiftsbiträdesavtal

Gäller från / Effective date: 30. 4. 2026

Version: 1.0

This document is bilingual. Swedish (legally binding) version comes first, English (for convenience) follows. In case of any conflict between the two, the Swedish version prevails.

This DPA is automatically accepted by the User upon accepting the Terms of Service. No separate signature is needed for individual sole proprietors.

🇸🇪 SVENSKA VERSIONEN

Bakgrund och syfte

Detta Personuppgiftsbiträdesavtal (“Biträdesavtalet” eller “DPA”) reglerar Leverantörens behandling av personuppgifter för Användarens räkning i samband med användning av Tjänsten EasyEnskildFirma. Biträdesavtalet uppfyller kraven i artikel 28 i EU:s allmänna dataskyddsförordning (förordning (EU) 2016/679, “GDPR”).

Genom att acceptera Användarvillkoren accepterar Användaren samtidigt detta Biträdesavtal.

1. Parter

Personuppgiftsbiträde (“Leverantören” eller “Biträdet”): Milos Tintor (enskild näringsverksamhet) Personnummer/Org.nr: 911010-6276 Adress: Östra Förstadsgatan 9A 211 31 Malmö E-post: support@easyenskildfirma.se

Personuppgiftsansvarig (“Användaren” eller “Den ansvarige”): Den fysiska eller juridiska person som registrerat ett konto på Tjänsten och därmed accepterat Användarvillkoren.

2. Definitioner

Begrepp som “personuppgift”, “behandling”, “personuppgiftsansvarig”, “personuppgiftsbiträde”, “registrerad”, “personuppgiftsincident” m.m. har samma betydelse som i GDPR.

Användardata” avser personuppgifter som Användaren matar in eller laddar upp i Tjänsten avseende sina egna kunder, leverantörer eller andra affärskontakter.

Tjänsten” avser EasyEnskildFirma så som den definieras i Användarvillkoren.

3. Föremål, varaktighet, art och syfte (art. 28.3 GDPR)

3.1 Föremål

Detta Biträdesavtal reglerar behandling av Användardata som Leverantören utför för Användarens räkning vid tillhandahållande av Tjänsten.

3.2 Varaktighet

Behandlingen sker under den tid Användarens avtal med Leverantören är i kraft, samt under den tid det krävs för korrekt avslutande av avtalet (inklusive 30-dagars dataexportperiod efter uppsägning enligt Användarvillkoren).

3.3 Behandlingens art

Behandlingen omfattar:

  • Lagring av Användardata i molntjänst
  • Visning och hantering av Användardata via Tjänstens gränssnitt
  • Generering av rapporter och dokument (fakturor, bokföringsverifikationer m.m.) baserat på Användardata
  • Säkerhetskopiering
  • Säkerhetsövervakning

3.4 Behandlingens syfte

Att tillhandahålla bokföringstjänsten EasyEnskildFirma till Användaren enligt Användarvillkoren.

4. Kategorier av registrerade och personuppgifter (art. 28.3 GDPR)

4.1 Kategorier av registrerade

  • Användarens kunder (fakturamottagare)
  • Användarens leverantörer (utgiftsmottagare)
  • Andra affärskontakter (t.ex. payout-källor)

4.2 Kategorier av personuppgifter

KategoriExempel
IdentitetsuppgifterNamn, företagsnamn
KontaktuppgifterAdress, e-post, telefon
Finansiella uppgifterFakturabelopp, betalningsuppgifter, växelkurser
SkatteuppgifterOrg.nr, VAT-nr, F-skattestatus
AffärshistorikFaktureringshistorik, betalningshistorik
BilagorKvitton, fakturor, settlement reports som Användaren laddar upp

4.3 Inga särskilda kategorier

Tjänsten är inte avsedd för behandling av särskilda kategorier av personuppgifter enligt art. 9 GDPR (såsom hälsouppgifter, etniskt ursprung, religiösa övertygelser m.m.) eller uppgifter om brott enligt art. 10 GDPR. Användaren förbinder sig att inte mata in sådana uppgifter i Tjänsten.

5. Den ansvariges (Användarens) skyldigheter

Användaren bekräftar att:

a) Användaren har laglig grund för all behandling av personuppgifter som Användaren initierar i Tjänsten, b) Användaren har uppfyllt sin informationsskyldighet gentemot de registrerade enligt art. 13–14 GDPR, c) Användaren har gett Leverantören dokumenterade instruktioner för behandlingen genom att använda Tjänsten i enlighet med Användarvillkoren och dess funktionalitet, d) Användaren ansvarar för att inte mata in mer personuppgifter än nödvändigt för Tjänstens ändamål.

6. Biträdets (Leverantörens) skyldigheter

6.1 Behandling endast enligt instruktioner

Leverantören ska behandla Användardata endast enligt dokumenterade instruktioner från Användaren. Användarens användning av Tjänstens funktioner utgör sådana instruktioner.

Leverantören ska informera Användaren om Leverantören anser att en instruktion strider mot GDPR eller annan tillämplig dataskyddslagstiftning.

6.2 Konfidentialitet

Leverantören ska säkerställa att personer med åtkomst till Användardata har förbundit sig till sekretess eller omfattas av lämplig lagstadgad tystnadsplikt.

6.3 Säkerhetsåtgärder (art. 32 GDPR)

Leverantören ska vidta lämpliga tekniska och organisatoriska åtgärder för att säkerställa en lämplig säkerhetsnivå, inklusive:

  • Kryptering av data i vila och i transit (TLS 1.2 eller högre, AES-256)
  • Pseudonymisering där så är möjligt
  • Åtkomstkontroll: Row-Level Security (RLS) i databasen, hashade lösenord, sessionhantering
  • Loggning av administrativ åtkomst
  • Backup-rutiner med regelbundna kopior
  • Incidenthanteringsplan för personuppgiftsincidenter
  • Uppdateringar av säkerhetsrelaterade komponenter

6.4 Hjälp till den ansvarige

Leverantören ska, i den mån det är möjligt och med beaktande av behandlingens art, hjälpa Användaren genom lämpliga tekniska och organisatoriska åtgärder att fullgöra sina skyldigheter, särskilt:

a) Att besvara begäranden från registrerade om utövande av deras rättigheter (art. 12–22 GDPR). Tjänstens exportfunktioner och raderingsfunktioner möjliggör detta i de flesta fall.

b) Att uppfylla skyldigheter enligt art. 32–36 GDPR (säkerhet, anmälan av incident, konsekvensbedömning).

För hjälp som går utöver Tjänstens standardfunktioner kan Leverantören debitera rimlig timkostnad.

6.5 Hantering av personuppgiftsincidenter

Vid kännedom om personuppgiftsincident som påverkar Användardata ska Leverantören:

a) utan onödigt dröjsmål (senast 48 timmar efter upptäckt) informera Användaren skriftligen via e-post, b) lämna information som hjälper Användaren att uppfylla sin egen anmälningsskyldighet enligt art. 33 GDPR (72-timmarsregeln), c) vidta lämpliga åtgärder för att begränsa skadan.

6.6 Radering eller återlämnande

Vid avtalets upphörande ska Leverantören, enligt Användarens val:

a) radera all Användardata, eller b) återlämna Användardata till Användaren i läsbart format,

om inte EU-rätt eller medlemsstatens nationella rätt kräver fortsatt lagring.

I praktiken implementeras detta enligt Användarvillkoren:

  • Vid uppsägning av Premium-abonnemang (nedgradering till Gratisplan): Användardata raderas inte. Användaren behåller åtkomst till all sin data i Gratisplan.
  • Vid kontoradering (Användarvillkoren punkt 6.3): Användaren laddar ned en fullständig export av sin Användardata innan raderingen genomförs. Efter bekräftad radering tas data bort från aktiva system. En krypterad säkerhetskopia behålls i upp till fjorton (14) dagar och raderas därefter permanent.
  • Vid uppsägning från Leverantören (Användarvillkoren punkt 6.4): Användaren får trettio (30) dagars varsel att exportera sin data innan kontot stängs.

6.7 Tillgänglig dokumentation och granskning

Leverantören ska tillhandahålla Användaren all information som behövs för att visa att skyldigheterna i art. 28 GDPR uppfylls. På begäran kan Leverantören tillhandahålla:

  • Kopia av detta DPA
  • Lista över underbiträden
  • Beskrivning av tekniska och organisatoriska säkerhetsåtgärder

För större granskningar eller inspektioner som går utöver standarddokumentation kan Leverantören debitera rimlig timkostnad. Sådan granskning ska föregås av minst 30 dagars varsel och får inte störa Tjänstens normala drift eller äventyra andra Användares konfidentialitet.

7. Underbiträden (subprocessors) (art. 28.2 och 28.4 GDPR)

7.1 Generellt godkännande

Användaren ger härmed generellt skriftligt godkännande för att Leverantören anlitar underbiträden för att tillhandahålla Tjänsten.

7.2 Aktuella underbiträden

Vid tidpunkten för detta avtal anlitas följande underbiträden:

UnderbiträdeTjänstPlatsSkyddsåtgärd
Supabase Inc.Databas, autentisering, fillagringEU (Frankfurt)DPA + EU-region
Stripe Payments Europe Ltd.BetalningshanteringEU (Irland) + USADPA + SCC
Resend, Inc.Transaktionella e-postutskickUSADPA + SCC
Cloudflare, Inc.DNS, hosting, CDNGlobalt CDNDPA + SCC
Frankfurter APIVäxelkurser (ingen PII)Tyskland (EU)Ingen PII behandlas
VIES (EU-kommissionen)VAT-nummer-valideringEUOfficiell EU-tjänst

Leverantören har skriftliga personuppgiftsbiträdesavtal med samtliga underbiträden som behandlar personuppgifter, och dessa är skyldiga att följa väsentligen samma skyldigheter som anges i detta DPA.

7.3 Ändringar av underbiträden

Leverantören informerar Användaren om planerade förändringar i listan över underbiträden minst trettio (30) dagar i förväg via: a) e-post till den e-postadress Användaren registrerat, och/eller b) meddelande i Tjänsten.

Användaren har rätt att invända mot förändringen inom 30-dagarsperioden. Om Användaren invänder och parterna inte kan nå överenskommelse har Användaren rätt att säga upp avtalet med Leverantören utan kostnad. Avgifter som redan erlagts återbetalas dock inte enligt Användarvillkoren punkt 4.4.

7.4 Leverantörens ansvar för underbiträden

Leverantören ansvarar fullt ut för att underbiträden uppfyller sina skyldigheter enligt detta DPA, dock med beaktande av den övergripande ansvarsbegränsningen i Användarvillkoren punkt 9.

8. Överföring till tredje land (art. 44–49 GDPR)

Vissa underbiträden är etablerade utanför EU/EES (USA). I dessa fall säkerställer Leverantören att lämpliga skyddsåtgärder finns:

a) EU-kommissionens standardavtalsklausuler (SCC) av 4 juni 2021 (Modul 2 — controller till processor, eller Modul 3 — processor till processor), b) EU-US Data Privacy Framework där underbiträdet är certifierat, c) Tekniska och organisatoriska tilläggsåtgärder där så krävs efter en transfer impact assessment.

Användaren kan begära kopia av relevanta SCC genom att kontakta support@easyenskildfirma.se.

9. Ansvarsbegränsning

För skador som uppstår i samband med behandling av personuppgifter enligt detta DPA gäller den ansvarsbegränsning som anges i Användarvillkoren punkt 9, med följande tillägg:

Ingenting i detta DPA begränsar ansvar som inte får begränsas enligt tvingande dataskyddslagstiftning. Detta inkluderar bland annat de fall där en tillsynsmyndighet eller domstol fastställer ansvar för en personuppgiftsincident enligt art. 82 GDPR.

10. Ändringar av Biträdesavtalet

Leverantören har rätt att ändra detta DPA vid behov, t.ex. för att efterleva förändringar i lagstiftning eller krav från underbiträden. Vid väsentliga ändringar informeras Användaren minst trettio (30) dagar i förväg.

11. Tillämplig lag och tvistlösning

Detta DPA regleras av svensk lag och GDPR. Tvister avgörs enligt vad som anges i Användarvillkoren punkt 16 (Stockholms tingsrätt).

12. Förhållandet till Användarvillkoren

Om det skulle uppstå motstridighet mellan detta DPA och Användarvillkoren avseende behandling av personuppgifter, har detta DPA företräde i den delen.

I övrigt gäller Användarvillkoren i sin helhet.

13. Kontakt

För frågor om detta DPA, kontakta:

E-post: support@easyenskildfirma.se Postadress: Se avsnitt 1


🇬🇧 ENGLISH VERSION (for convenience only)

Note: This English translation is provided for convenience only. In case of any conflict between the Swedish and English version, the Swedish version prevails.

Background and Purpose

This Data Processing Agreement (“DPA”) regulates the Provider’s processing of personal data on behalf of the User in connection with the use of the EasyEnskildFirma Service. The DPA fulfills the requirements of Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

By accepting the Terms of Service, the User simultaneously accepts this DPA.

1. Parties

Data Processor (“Provider”): Milos Tintor (sole proprietorship / enskild näringsverksamhet) Personal ID/Business Registration Number: 911010-6276 Address: Östra Förstadsgatan 9A 211 31 Malmö Email: support@easyenskildfirma.se

Data Controller (“User”): The natural or legal person who has registered an account in the Service and thereby accepted the Terms of Service.

2. Definitions

Terms such as “personal data”, “processing”, “data controller”, “data processor”, “data subject”, “personal data breach”, etc., have the same meaning as in the GDPR.

User Data” means personal data that the User enters or uploads to the Service regarding their own customers, suppliers, or other business contacts.

Service” means EasyEnskildFirma as defined in the Terms of Service.

3. Subject Matter, Duration, Nature, and Purpose (art. 28.3 GDPR)

3.1 Subject matter

This DPA regulates processing of User Data that the Provider performs on behalf of the User in providing the Service.

3.2 Duration

Processing takes place during the term of the User’s agreement with the Provider, plus the time required for proper termination of the agreement (including 30-day data export period after termination according to the Terms of Service).

3.3 Nature of processing

Processing includes:

  • Storage of User Data in cloud service
  • Display and management of User Data via the Service’s interface
  • Generation of reports and documents (invoices, bookkeeping verifications, etc.) based on User Data
  • Backup
  • Security monitoring

3.4 Purpose of processing

To provide the EasyEnskildFirma bookkeeping service to the User in accordance with the Terms of Service.

4. Categories of Data Subjects and Personal Data (art. 28.3 GDPR)

4.1 Categories of data subjects

  • The User’s customers (invoice recipients)
  • The User’s suppliers (expense recipients)
  • Other business contacts (e.g., payout sources)

4.2 Categories of personal data

CategoryExamples
Identity dataName, company name
Contact informationAddress, email, phone
Financial dataInvoice amounts, payment information, exchange rates
Tax dataOrg. number, VAT number, F-tax status
Business historyBilling history, payment history
AttachmentsReceipts, invoices, settlement reports uploaded by the User

4.3 No special categories

The Service is not intended for processing of special categories of personal data under art. 9 GDPR (such as health data, ethnic origin, religious beliefs, etc.) or data concerning criminal convictions and offenses under art. 10 GDPR. The User undertakes not to enter such data into the Service.

5. The Controller’s (User’s) Obligations

The User confirms that:

a) The User has a lawful basis for all processing of personal data that the User initiates in the Service, b) The User has fulfilled their information obligation toward data subjects under art. 13–14 GDPR, c) The User has provided documented instructions to the Provider for processing by using the Service in accordance with the Terms of Service and its functionality, d) The User is responsible for not entering more personal data than necessary for the purpose of the Service.

6. The Processor’s (Provider’s) Obligations

6.1 Processing only on instructions

The Provider shall process User Data only on documented instructions from the User. The User’s use of the Service’s functions constitutes such instructions.

The Provider shall inform the User if the Provider considers that an instruction violates the GDPR or other applicable data protection legislation.

6.2 Confidentiality

The Provider shall ensure that persons with access to User Data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.

6.3 Security measures (art. 32 GDPR)

The Provider shall take appropriate technical and organizational measures to ensure an appropriate level of security, including:

  • Encryption of data at rest and in transit (TLS 1.2 or higher, AES-256)
  • Pseudonymization where possible
  • Access control: Row-Level Security (RLS) in the database, hashed passwords, session management
  • Logging of administrative access
  • Backup routines with regular copies
  • Incident response plan for personal data breaches
  • Updates of security-related components

6.4 Assistance to the controller

The Provider shall, to the extent possible and taking into account the nature of the processing, assist the User through appropriate technical and organizational measures to fulfill their obligations, in particular:

a) Responding to requests from data subjects to exercise their rights (art. 12–22 GDPR). The Service’s export and deletion functions enable this in most cases.

b) Fulfilling obligations under art. 32–36 GDPR (security, breach notification, impact assessment).

For assistance beyond the Service’s standard functions, the Provider may charge a reasonable hourly rate.

6.5 Handling of personal data breaches

Upon becoming aware of a personal data breach affecting User Data, the Provider shall:

a) Without undue delay (no later than 48 hours after detection) inform the User in writing via email, b) Provide information that helps the User to fulfill their own notification obligation under art. 33 GDPR (72-hour rule), c) Take appropriate measures to mitigate the damage.

6.6 Deletion or return

Upon termination of the agreement, the Provider shall, at the User’s choice:

a) delete all User Data, or b) return User Data to the User in readable format,

unless EU law or the national law of a Member State requires continued storage.

In practice, this is implemented according to the Terms of Service:

  • Upon termination of a Premium subscription (downgrade to Free plan): User Data is not deleted. The User retains access to all their data under the Free plan.
  • Upon account deletion (Terms of Service section 6.3): The User downloads a complete export of their User Data before deletion is performed. After confirmed deletion, data is removed from active systems. An encrypted backup copy is retained for up to fourteen (14) days and is then permanently deleted.
  • Upon termination by the Provider (Terms of Service section 6.4): The User receives thirty (30) days’ notice to export their data before the account is closed.

6.7 Available documentation and audit

The Provider shall make available to the User all information necessary to demonstrate compliance with the obligations in art. 28 GDPR. Upon request, the Provider can provide:

  • Copy of this DPA
  • List of subprocessors
  • Description of technical and organizational security measures

For more comprehensive audits or inspections that go beyond standard documentation, the Provider may charge a reasonable hourly rate. Such audit shall be preceded by at least 30 days’ notice and may not disrupt the Service’s normal operation or jeopardize the confidentiality of other Users.

7. Subprocessors (art. 28.2 and 28.4 GDPR)

7.1 General authorization

The User hereby gives general written authorization for the Provider to engage subprocessors to provide the Service.

7.2 Current subprocessors

At the time of this agreement, the following subprocessors are engaged:

SubprocessorServiceLocationSafeguard
Supabase Inc.Database, authentication, file storageEU (Frankfurt)DPA + EU region
Stripe Payments Europe Ltd.Payment processingEU (Ireland) + USADPA + SCC
Resend, Inc.Transactional emailUSADPA + SCC
Cloudflare, Inc.DNS, hosting, CDNGlobal CDNDPA + SCC
Frankfurter APIExchange rates (no PII)Germany (EU)No PII processed
VIES (European Commission)VAT number validationEUOfficial EU service

The Provider has written data processing agreements with all subprocessors that process personal data, and they are obligated to follow substantially the same obligations as set out in this DPA.

7.3 Changes of subprocessors

The Provider informs the User of planned changes to the list of subprocessors at least thirty (30) days in advance via: a) email to the email address registered by the User, and/or b) notification in the Service.

The User has the right to object to the change within the 30-day period. If the User objects and the parties cannot reach agreement, the User has the right to terminate the agreement with the Provider at no cost. Fees already paid are however not refunded according to Terms of Service section 4.4.

7.4 Provider’s responsibility for subprocessors

The Provider is fully responsible for the subprocessors’ fulfillment of their obligations under this DPA, however subject to the overall liability cap in the Terms of Service section 9.

8. Transfers to Third Countries (art. 44–49 GDPR)

Some subprocessors are established outside the EU/EEA (USA). In these cases, the Provider ensures that appropriate safeguards are in place:

a) EU Commission Standard Contractual Clauses (SCC) of 4 June 2021 (Module 2 — controller to processor, or Module 3 — processor to processor), b) EU-US Data Privacy Framework where the subprocessor is certified, c) Technical and organizational supplementary measures where required after a transfer impact assessment.

The User can request a copy of relevant SCCs by contacting support@easyenskildfirma.se.

9. Limitation of Liability

For damages arising in connection with processing of personal data under this DPA, the limitation of liability set forth in Terms of Service section 9 applies, with the following addition:

Nothing in this DPA limits liability that may not be limited under mandatory data protection legislation. This includes, among other things, cases where a supervisory authority or court establishes liability for a personal data breach under art. 82 GDPR.

10. Changes to the DPA

The Provider has the right to amend this DPA when necessary, e.g., to comply with changes in legislation or requirements from subprocessors. In case of material changes, the User is notified at least thirty (30) days in advance.

11. Governing Law and Disputes

This DPA is governed by Swedish law and the GDPR. Disputes are settled as set forth in Terms of Service section 16 (Stockholm District Court).

12. Relationship to the Terms of Service

In case of conflict between this DPA and the Terms of Service regarding processing of personal data, this DPA takes precedence in that part.

In all other respects, the Terms of Service apply in full.

13. Contact

For questions about this DPA, contact:

Email: support@easyenskildfirma.se Postal address: See section 1


Document version: 1.0 Last updated: 30. 4. 2026. Contact: support@easyenskildfirma.se