Data Processing Agreement (DPA)
Translation provided for convenience. In the event of any discrepancy, the Italian version prevails.
Last updated: June 2026.
This Data Processing Agreement (hereinafter the "DPA" or the "Agreement") supplements the Terms and governs the processing of personal data pursuant to Article 28 GDPR, in cases where DecaRoy AB processes personal data on behalf of the Customer.
1. Definitions
Save where the context otherwise requires, the terms listed below have, in this DPA, the meaning attributed to them here. The terms defined by Regulation (EU) 2016/679 (hereinafter the "GDPR") and not expressly defined in this DPA retain the meaning attributed to them by the GDPR.
- "GDPR": Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, together with any applicable national implementing and/or supplementary legislation.
- "Applicable data protection legislation": the GDPR, as well as any other law, regulation and measure of the European Union or of the Member States, including the Swedish implementing legislation (in particular the Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning), applicable to the processing of personal data covered by this DPA.
- "Data controller" or "Controller": the SveaHost Customer, within the meaning of Article 4(7) GDPR, who determines the purposes and means of the processing of the personal data covered by the Service.
- "Data processor" or "Processor": DecaRoy AB, an Aktiebolag incorporated under Swedish law, Org.nr 559560-4520, VAT number SE559560452001, with registered office at Hantverkaregatan 8, 231 44 Trelleborg, Sweden, operating under the SveaHost brand, within the meaning of Article 4(8) GDPR, which processes the personal data on behalf of the Controller.
- "Sub-processor": the third party engaged by the Processor to carry out specific processing activities on behalf of the Controller pursuant to Article 28(2) and (4) GDPR.
- "Data subject": the identified or identifiable natural person to whom the personal data relate, within the meaning of Article 4(1) GDPR.
- "Personal data": any information relating to a Data subject, processed by the Processor on behalf of the Controller in the context of the Service, within the meaning of Article 4(1) GDPR.
- "Processing": any operation or set of operations performed, whether or not by automated means, on personal data, within the meaning of Article 4(2) GDPR.
- "Personal data breach" or "Data Breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed, within the meaning of Article 4(12) GDPR.
- "Standard Contractual Clauses" or "SCC": the standard data protection clauses adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries pursuant to the GDPR.
- "Service": the overall set of services provided by the Processor in favour of the Controller, consisting of the building, hosting, maintenance and management of the Controller's website, the publication of content, search engine optimization (SEO) activities and any management of the domain, as governed by the Terms.
- "Supervisory authority": the competent independent public authority within the meaning of Article 51 GDPR, including the Swedish supervisory authority (Integritetsskyddsmyndigheten – IMY) and any other authority competent in respect of the Controller.
2. Subject matter, duration, nature and purpose of the processing
2.1. This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller in the context of the provision of the Service, in accordance with Article 28 GDPR, and sets out the rights and obligations of the Parties in relation to such processing.
2.2. The processing concerns the personal data of the Controller's visitors and end customers, collected and processed through the website built and hosted by the Processor (by way of example, the data transmitted through the contact forms and the data otherwise collected by the website). In respect of such data, the Customer acts as Controller and DecaRoy AB as Processor.
2.3. The nature of the processing consists of the operations of collection, recording, organization, structuring, storage, consultation, hosting, transmission, communication, erasure and destruction of personal data, necessary for the provision of the Service.
2.4. The purposes of the processing are limited to the provision of the Service and to the execution of the documented instructions of the Controller, as specified in Annex I.
2.5. The types of personal data processed and the categories of data subjects are set out in Annex I, which forms an integral part of this DPA.
2.6. The duration of the processing coincides with the duration of the Service and of the related contractual relationship governed by the Terms, without prejudice to the retention obligations laid down by law and to the provisions of clause 9 concerning the return or erasure of data.
3. Roles of the Parties, scope and documented instructions
3.1. The Parties acknowledge and agree that, in relation to the personal data covered by this DPA, the Controller is the data controller and the Processor is the data processor within the meaning of Article 28 GDPR. The Controller is and remains responsible for the lawfulness of the processing, for the adequacy of the legal basis pursuant to Article 6 GDPR, as well as for the fulfilment of the information obligations towards data subjects pursuant to Articles 13 and 14 GDPR.
3.2. The Processor processes the personal data solely on the basis of the documented instructions of the Controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which it is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless the applicable law prohibits this on important grounds of public interest (Article 28(3)(a) GDPR).
3.3. The following constitute documented instructions of the Controller: this DPA, the Terms, the configurations and settings selected by the Controller through the features of the Service, as well as any further instruction given in writing (including by email to info@sveahost.com) and accepted by the Processor. Instructions that fall outside the scope of the Service or that require significant technical changes may be subject to a separate agreement and to a possible adjustment of the consideration.
3.4. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other provisions of the applicable data protection legislation (Article 28(3), last sentence, GDPR). In such a case, the Processor shall be entitled to suspend the execution of the contested instruction until its confirmation, amendment or withdrawal by the Controller, without this constituting a breach.
4. Obligations of the Processor
4.1. Compliance and limits of the processing. The Processor processes the personal data solely for the purposes referred to in clause 2 and in Annex I and in accordance with the documented instructions of the Controller. The Processor does not use the personal data for its own purposes, nor does it sell or assign them to third parties beyond what is provided for in this DPA.
4.2. Confidentiality. The Processor ensures that the persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR). The Processor ensures that access to the personal data is limited to the personnel who need it for the purposes of carrying out the Service, in accordance with the need-to-know and least-privilege principles.
4.3. Security of the processing. The Processor adopts the technical and organizational measures appropriate to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, taking into account the state of the art, the costs of implementation, as well as the nature, scope, context and purposes of the processing, and the risks for the rights and freedoms of natural persons. The measures are described in Annex II.
4.4. Assistance with data subjects' rights. Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests from data subjects for the exercise of the rights set out in Articles 12 to 23 GDPR (in particular: the right of access, rectification, erasure, restriction, portability, objection) (Article 28(3)(e) GDPR). Should the Processor receive a request directly from a data subject relating to data processed on behalf of the Controller, it shall promptly notify the Controller and shall not act on it autonomously, save where otherwise instructed.
4.5. Assistance with the Controller's obligations. Taking into account the nature of the processing and the information available to the Processor, the latter assists the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR, that is, with regard to: security of the processing (Article 32); notification of personal data breaches to the Supervisory authority (Article 33) and communication to data subjects (Article 34); data protection impact assessment (DPIA, Article 35); prior consultation of the Supervisory authority (Article 36) (Article 28(3)(f) GDPR).
4.6. Record of processing activities. The Processor maintains a record of all categories of processing activities carried out on behalf of the Controller, pursuant to Article 30(2) GDPR, and makes it available to the Supervisory authority on request.
4.7. Point of contact. The Processor makes available to the Controller the address info@sveahost.com as the point of contact for any communication relating to this DPA and to data protection.
5. Engagement of sub-processors
5.1. General authorization. The Controller grants the Processor a general written authorization for the engagement of sub-processors pursuant to Article 28(2) and (4) GDPR. The sub-processors currently authorized are listed in Annex III.
5.2. Notice of changes and right to object. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving reasonable advance notice of, as a rule, no less than thirty (30) days, thereby giving the Controller the opportunity to object to such changes. The communication may be made by means of an update to the published list and/or notice to the Controller's email address. The Controller may object on reasonable and documented grounds relating to data protection, giving written notice thereof within the notice period.
5.3. Effects of the objection. In the event of a well-founded objection, the Parties shall cooperate in good faith to identify a suitable solution. Should it not be possible to reach a reasonable solution, each Party shall be entitled to withdraw from the part of the Service that cannot be provided without the contested sub-processor, in accordance with the provisions of the Terms.
5.4. Flow-down of obligations. The Processor imposes on the sub-processor, by means of a contract or other legal act under Union or Member State law, the same data protection obligations as set out in this DPA, providing in particular sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing meets the requirements of the GDPR (Article 28(4) GDPR).
5.5. Liability. Where the sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of the sub-processor's obligations, within the limits of the law and of the provisions of clause 10.
6. International data transfers
6.1. The Processor does not transfer personal data to third countries outside the European Economic Area (EEA) or to international organizations, except to the extent necessary for the provision of the Service and in compliance with Articles 44 to 49 GDPR.
6.2. Where a transfer takes place, the Processor ensures that it is supported by an appropriate safeguard pursuant to Chapter V of the GDPR, and in particular: (i) an adequacy decision of the European Commission pursuant to Article 45 GDPR; or, failing that, (ii) the Standard Contractual Clauses (SCC) set out in Implementing Decision (EU) 2021/914, supplemented by such technical, organizational and contractual supplementary measures as are deemed necessary following a transfer assessment (Transfer Impact Assessment), in accordance with the principles set out by the Court of Justice of the European Union in judgment C-311/18 (Schrems II) and with Recommendations 01/2020 of the European Data Protection Board (EDPB).
6.3. The safeguards applied to each sub-processor established in a third country are set out in Annex III. By way of supplementary measures, the Processor adopts, where applicable, the encryption of data in transit, the minimization of the data transferred, access controls and policies for the management of access requests by authorities.
6.4. At the Controller's request, the Processor makes available a copy of the applicable safeguards and of the relevant information relating to the transfers, within the limits of the confidentiality obligations towards the sub-processors.
7. Personal data breaches
7.1. The Processor notifies the Controller of any personal data breach of which it becomes aware without undue delay and, where possible, in any event within a reasonable timeframe such as to enable the Controller to fulfil its own obligation to notify the Supervisory authority within 72 hours pursuant to Article 33 GDPR.
7.2. The notification to the Controller contains, insofar as the information is available to the Processor, at least: (a) a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and of personal data records concerned; (b) the name and contact details of the point at which more information can be obtained; (c) a description of the likely consequences of the breach; (d) a description of the measures taken or proposed to be taken to address the breach and to mitigate its possible adverse effects. Where it is not possible to provide the information at the same time, it may be provided in phases without further undue delay.
7.3. The Processor provides the Controller with all reasonable assistance for the purposes of fulfilling the obligations set out in Articles 33 and 34 GDPR, including any communication to data subjects. The Processor documents the personal data breaches that concern it and promptly adopts suitable measures to contain their effects.
7.4. The notification of a breach by the Processor does not in itself constitute an acknowledgment of liability or fault in respect of the breach.
8. Audits and inspections
8.1. The Processor makes available to the Controller all the information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and contributes to review activities, including inspections, carried out by the Controller or by another party mandated by it (Article 28(3)(h) GDPR).
8.2. Audit activities take place subject to reasonable written advance notice, as a rule no less than thirty (30) days, during normal working hours, with a frequency, as a rule, no greater than once a year (save in the event of an established personal data breach or a specific request of a Supervisory authority), in such a way as not to cause disproportionate prejudice to the Processor's activity and in compliance with the obligations of confidentiality and security, including towards other customers and sub-processors.
8.3. The Processor may fulfil the obligations set out in this clause also by making available certifications, attestations of conformity, independent audit reports or completed security questionnaires, where available and suitable to demonstrate compliance.
8.4. The party mandated to carry out the audit by the Controller must not be a competitor of the Processor and is bound by confidentiality obligations. The costs of the audit are borne by the Controller, save where the audit reveals a material breach by the Processor.
9. Return or erasure of data
9.1. Upon the termination of the provision of the services relating to the processing, at the Controller's choice, the Processor deletes or returns to the Controller all the personal data and deletes the existing copies, unless Union or Member State law requires the retention of the data (Article 28(3)(g) GDPR).
9.2. The choice between return and erasure is exercised by the Controller in writing. In the absence of any indication within thirty (30) days of the cessation of the Service, the Processor proceeds to the erasure of the personal data, without prejudice to the statutory retention obligations.
9.3. The return of the data, where requested, takes place in a structured and commonly used format, within the limits of technical availability. The Processor may retain the personal data to the extent and for the time required by statutory obligations (for example in tax, accounting or relationship documentation matters), continuing to apply to them the security measures set out in Annex II and limiting their processing to the sole purpose of retention.
9.4. Upon request, the Processor provides the Controller with written attestation of the erasure having been carried out.
10. Liability and indemnification
10.1. Each Party is liable for the damage caused by processing which infringes the GDPR in accordance with the provisions of Article 82 GDPR and of the applicable data protection legislation.
10.2. The Processor is liable for the damage caused by processing only where it has not complied with the obligations of the GDPR specifically directed to data processors or has acted outside or contrary to the lawful instructions of the Controller, pursuant to Article 82(2) GDPR.
10.3. The overall liability of the Processor arising out of or in connection with this DPA is subject to the same exclusions and limitations of liability set out in the Terms, to the maximum extent permitted by applicable law. Such limitations do not apply in cases where the law does not allow their exclusion or limitation, including in cases of wilful misconduct or gross negligence.
10.4. Where a data subject obtains full compensation for the damage from one of the Parties, that Party is entitled to claim back from the other Party the part of the compensation corresponding to that other Party's respective part of responsibility for the damage, pursuant to Article 82(5) GDPR.
10.5. The Controller indemnifies and holds the Processor harmless from third-party claims and from penalties arising from the absence of a valid legal basis for the processing, from the failure to fulfil the information obligations towards data subjects, or from instructions given in breach of the applicable data protection legislation, within the limits permitted by law.
11. Duration, amendments, applicable law and jurisdiction
11.1. Duration. This DPA enters into force on the date of acceptance of the Terms and/or of commencement of the Service and remains effective for the entire duration of the processing of personal data by the Processor on behalf of the Controller. The clauses intended by their nature to survive (in particular those concerning confidentiality, liability, return/erasure of data and applicable law) remain effective also after the cessation of the relationship.
11.2. Amendments. The Processor may update this DPA in order to adapt it to supervening regulatory, statutory or technical requirements, giving appropriate notice thereof to the Controller. The provisions concerning sub-processors set out in clause 5 remain unaffected.
11.3. Prevalence. This DPA forms an integral part of the Terms and is to be read together with the Privacy Policy. In the event of conflict between this DPA and the Terms with regard to the subject matter of personal data protection, the provisions of this DPA prevail. As regards any SCC applicable to transfers, in the event of conflict with this DPA the SCC prevail, limited to the transfer governed by them.
11.4. Partial invalidity. The possible invalidity or ineffectiveness of one or more clauses of this DPA does not affect the validity and effectiveness of the remaining clauses.
11.5. Applicable law and jurisdiction. This DPA is governed by Swedish law, without prejudice to the mandatory application of the GDPR and of the applicable data protection legislation. For any dispute relating to this DPA, the courts of Trelleborg, Sweden, have jurisdiction, save for any different non-derogable jurisdiction provided for by law for the protection of the Controller as a possible consumer or for the protection of data subjects.
Annex I — Details of the processing
A. Categories of data subjects
- Visitors to the Controller's website;
- End customers, prospective customers (leads) and contacts of the Controller;
- Persons who send requests or communications through the contact forms or other collection tools of the website;
- Any recipients of communications and subscribers to newsletters or lists, where such features are activated by the Controller.
B. Types of personal data
- Identity and contact data: first name, surname, email address, telephone number, any business name;
- Content of the communications sent through contact forms and messages;
- Technical and browsing data: IP address, device identifiers, browser-related data, access logs, data collected through cookies and similar technologies (according to the Controller's settings);
- Data relating to any payments managed through the website (processed by the relevant payment service providers, in the capacity of independent controllers or processors, where applicable);
- Any other personal data that the Controller chooses to collect through the website.
The Controller is required not to configure the website for the collection of special categories of personal data (Article 9 GDPR) or of data relating to criminal convictions and offences (Article 10 GDPR) without having first agreed the arrangements thereof in writing with the Processor and without having put in place the additional safeguards required by law.
C. Nature and purpose of the processing
- Building, hosting, maintenance and technical management of the Controller's website;
- Collection, recording, storage and transmission to the Controller of the data submitted by data subjects through the website;
- Publication of content and search engine optimization (SEO) activities;
- Any management of the domain and of the mail/routing services connected to it;
- Sending of transactional and service emails on behalf of the Controller, where activated;
- Management of the customer relationship (CRM) and of contacts, where activated by the Controller.
D. Duration of the processing
The processing has a duration equal to that of the Service and of the contractual relationship governed by the Terms, without prejudice to the statutory retention obligations and to the provisions of clause 9 concerning the return or erasure of data.
Annex II — Technical and organizational security measures (Article 32 GDPR)
The Processor adopts, directly and through its sub-processors, the following technical and organizational measures, periodically reviewed and updated in line with the evolution of the risk and the state of the art.
A. Encryption and data protection
- Encryption of personal data in transit by means of TLS (HTTPS) protocols for communications between the browser, the website and the management systems;
- Encryption of data at rest where technically applicable and supported by the infrastructure and by the sub-processors;
- Secure management of keys, secrets and credentials.
B. Access control and identity
- Access to personal data limited to authorized personnel in accordance with the least-privilege and need-to-know principles;
- Individual authentication and, where available, multi-factor authentication (MFA) for access to administrative systems;
- Password management policies and prompt revocation of user accounts that are no longer necessary.
C. Segregation and minimization
- Logical separation of the data relating to different Controllers (multi-tenancy);
- Minimization of the data processed and transferred in relation to the purposes of the Service;
- Separation, where appropriate, of the development, test and production environments.
D. Business continuity and backup
- Performance of periodic backups and verification of the recoverability of the data;
- Measures aimed at ensuring the availability and resilience of systems and services;
- Procedures for restoring the availability of and access to data in the event of a physical or technical incident.
E. Logging, monitoring and vulnerability management
- Recording of access and relevant events (logging) and monitoring of systems;
- Perimeter and application protection measures (firewall, DDoS protection, WAF through the security/CDN sub-processors);
- Prompt updating and application of security patches and vulnerability management.
F. Organizational measures
- Confidentiality obligations for the personnel authorized to carry out the processing;
- Awareness-raising and instructions to personnel on data protection and security matters;
- Selection of sub-processors that offer sufficient guarantees pursuant to Article 28 GDPR;
- Procedures for the management and notification of personal data breaches (see clause 7);
- Periodic verification, examination and assessment of the effectiveness of the security measures adopted (Article 32(1)(d) GDPR).
Annex III — List of authorized sub-processors
As at the date of this DPA, the Processor makes use of the following sub-processors. For transfers to third countries outside the EEA, the safeguard indicated is to be understood as supplemented, where applicable, by the supplementary measures set out in clause 6.
| Name | Service / purpose | Location | Safeguard for non-EU transfer |
|---|---|---|---|
| Stripe | Management of payments and transaction data | USA / EU | SCC (EU Decision 2021/914) and supplementary measures |
| Cloudflare | DNS, CDN, email routing, security and DDoS/WAF protection | USA / EU | SCC (EU Decision 2021/914) and supplementary measures |
| DreamHost | Hosting of customers' websites | USA | SCC (EU Decision 2021/914) and supplementary measures |
| Hetzner | Infrastructure / VPS | Germany (EU) | Intra-EEA transfer: no Chapter V safeguard required |
| Resend | Sending of transactional emails | USA | SCC (EU Decision 2021/914) and supplementary measures |
| OpenSRS / Tucows | Domain registration and management | Canada | EU adequacy decision for Canada (commercial organizations, Article 45 GDPR); where not applicable, SCC and supplementary measures |
| HighLevel (GoHighLevel) | CRM and contact management | USA | SCC (EU Decision 2021/914) and supplementary measures |
| Anthropic | AI model provider for text generation | USA | SCC (EU Decision 2021/914) and supplementary measures |
| Replicate | AI model provider for text/image generation | USA | SCC (EU Decision 2021/914) and supplementary measures |
The list of sub-processors is subject to update in accordance with the provisions of clause 5. The mention of a sub-processor does not imply that personal data are disclosed to it in all cases: disclosure takes place solely where necessary for the provision of the specific service activated by the Controller.