UPDATED 2026-09-30
Data processing agreement
This agreement applies between the party that uses VeraBIM for its projects and is the controller of the data in them (the “Customer”), normally a company that has been created in the service, and Bäckman, the operator of VeraBIM (processor, the “Processor”). The agreement is entered into under Article 28 of the General Data Protection Regulation (GDPR) and forms part of the terms of use.
1. Conclusion and scope of the agreement
The agreement applies from when the Customer creates a company or a project in the service, or otherwise allows the Processor to process personal data on the Customer's behalf, and is accepted when the Customer's administrator or project owner accepts the terms of use. It covers the personal data that the Customer's users and others enter in the Customer's projects. The Processor processes account data and data about how the service is used as controller in accordance with the privacy policy. In the event of conflict, this agreement takes precedence over the terms of use in matters concerning the processing of personal data.
2. Nature, purpose and duration of the processing
The Processor processes the personal data solely to provide the service to the Customer: storage, display, search, sharing within the project, sending of email and push notifications, backup, troubleshooting and support. The processing continues for as long as the agreement applies and thereafter until the data has been erased in accordance with section 12.
3. Categories of data subjects and data
- Data subjects: the Customer's employees and hired-in staff, personnel of the Customer's business partners, recipients of distribution lists, persons who submit safety observations, visitors and others who appear in photos or notes.
- Personal data: identity and contact details, professional role and employer, times and locations in the project, photos and free text. No special categories of personal data (Article 9) shall be processed in the service; the Customer is responsible for ensuring that this does not happen.
4. The Customer's responsibilities and instructions
The Customer is the controller and is responsible for ensuring that the processing is lawful: that there is a legal basis, that the data subjects are informed, that only authorised persons are invited, that roles are set correctly and that no unnecessary data is entered. The Customer is responsible for the content of what is uploaded, including photos of people.
The Customer's documented instructions are this agreement, the terms of use and the settings and choices that the Customer makes in the service. Further instructions shall be given in writing and be compatible with the functions of the service. The Processor may decline instructions that require changes to the service or that are not reasonable; the Customer may then terminate the agreement by ceasing to use the service. The Customer bears its own costs of complying with the General Data Protection Regulation.
5. The Processor's obligations
- The Processor processes the personal data only on the Customer's documented instructions, including with regard to transfers to a third country, unless Union law or Swedish law requires otherwise. In such a case, the Processor informs the Customer before the processing, unless the law prohibits this.
- The Processor informs the Customer if, in the Processor's opinion, an instruction infringes the General Data Protection Regulation or other data protection legislation, without being obliged to carry out any legal review of its own of the Customer's instructions.
- The Processor ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
- The Processor takes the security measures required under Article 32 and described in section 6.
- The Processor engages sub-processors only in accordance with section 7.
- The Processor assists the Customer, taking into account the nature of the processing and insofar as possible, in responding to requests from data subjects and in fulfilling the obligations under Articles 32–36, in accordance with sections 9 and 10.
- The Processor erases or returns the personal data when the agreement ends, in accordance with section 12.
- The Processor makes available to the Customer the information necessary to demonstrate that the obligations in Article 28 have been fulfilled and allows for audits in accordance with section 11.
6. Security measures
- Traffic between users' devices and the service is encrypted with HTTPS (TLS). Passwords are stored as salted PBKDF2 hashes, and two-factor sign-in is offered. Sign-in via the Customer's own directory (OpenID Connect) can be connected after verified domain ownership.
- Access to project data is checked on the server for every request based on the Customer's roles. Sessions can be ended by the user; sign-in is throttled after repeated failed attempts.
- Data is stored on a server in Sweden. The database and files are backed up daily; copies are kept for 14 days. Server logs are kept for 30 days.
- Only the Processor and persons engaged by the Processor under a duty of confidentiality have access to the server, and only to the extent necessary for operation, troubleshooting and support.
- Deleted items remain in the project's trash for 30 days and are then deleted automatically; permanent deletion can be carried out immediately by the project owner.
The Customer has assessed that the measures provide an appropriate level of security for the data that the Customer enters in the service. The Processor may change the measures as long as the overall level of protection is not reduced.
7. Sub-processors and other recipients
The Customer gives a general prior authorisation for the Processor to engage sub-processors. The server, database and file storage are operated by the Processor itself on our own server in Sweden. At the time the agreement is entered into, Simply.com in Denmark, within the EU, is engaged for outgoing email (recipient address, subject and message text).
Push notifications are delivered through the push services belonging to the recipient's browser or operating system (for example Google, Apple, Microsoft or Mozilla). The push services are used only when a user has turned on push notifications themselves, and the content of the notifications is encrypted so that the push service cannot read it.
The Processor informs the Customer of any intended addition or replacement of sub-processors by updating this agreement and announcing it in the service or by email in good time before the change is made. The Customer may object within 14 days of the notice. If the parties do not reach agreement, the Customer's sole right is to terminate the agreement by ceasing to use the service. The Processor imposes on sub-processors the same data protection obligations as follow from this agreement and is liable to the Customer for the performance of the sub-processors' obligations under Article 28(4), subject to the limitation of liability set out in section 13.
8. Transfers to third countries
The Processor stores and processes the Customer's project data in Sweden, and email is sent via a sub-processor within the EU. The push services may, outside the EU/EEA, process the device's push address and information about when notifications are sent, but cannot read the content. Otherwise, the Processor does not transfer the personal data to a third country without the Customer's written instruction.
9. Personal data breaches
The Processor notifies the Customer without undue delay after becoming aware of a personal data breach concerning the Customer's personal data. The notification is sent to the email address of the Customer's administrator or project owner and contains the information that the Processor has about the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The information may be provided in phases. The Customer itself assesses whether the breach is to be notified to the supervisory authority and communicated to the data subjects.
10. Assistance and costs
Requests from data subjects are primarily handled by the Customer itself using the functions of the service, for example export, rectification and erasure. If the Processor receives a request concerning the Customer's data, the Processor refers the data subject to the Customer. The Processor otherwise assists the Customer with requests from data subjects, impact assessments and prior consultations to a reasonable extent, taking into account the nature of the processing and the information available to the Processor. Assistance beyond the functions of the service is provided against compensation for the Processor's reasonable costs, unless the assistance is needed because the Processor has breached this agreement.
11. Audits
The Processor demonstrates compliance with its obligations primarily through written information, for example this agreement, the description of the security measures and written answers to the Customer's reasonable questions. If the Customer shows that an on-site audit is nevertheless required under the General Data Protection Regulation, the Customer may have it carried out by an independent auditor bound by a duty of confidentiality. The audit shall be notified at least 30 days in advance, may take place at most once a year, shall be carried out without disrupting operations or disclosing other customers' data and shall be paid for entirely by the Customer, including reasonable compensation for the Processor's time. An audit requested by a supervisory authority is carried out in accordance with the authority's requirements.
12. Term, erasure and return
The agreement applies for as long as the Processor processes personal data on the Customer's behalf. The Customer can at any time itself export project data (for example reports, Excel, BCF and files) and delete projects in the service. Return takes place by the Customer exporting the data before the agreement ends. If the Processor discontinues the service or the Customer's access, the Processor will, where possible, give the Customer reasonable time to export first. After the agreement has ended, the Processor erases the Customer's personal data within a reasonable time, and the data disappears from the backups as these are rotated out. Data that the Processor is required by law to retain is erased when that obligation ends.
13. Liability
The data subject's right to compensation under Article 82 of the General Data Protection Regulation cannot be limited by this agreement. As between the parties, the following applies:
- Each party bears liability for its own share of any damage and for administrative fines imposed on that party itself.
- The Processor is liable to the Customer only for damage that has arisen because the Processor has not complied with the obligations of the General Data Protection Regulation specifically directed to processors, or has acted outside or contrary to the Customer's lawful instructions.
- The Processor's liability is limited in the same way as in the terms of use. The Processor is not liable for indirect or consequential damage, and the total liability is limited to the amount that the Customer has paid for the service during the twelve months immediately preceding the event giving rise to the damage, that is, zero (0) Swedish kronor as long as the service is free of charge. The limitation does not apply in the event of intent or gross negligence, or to the extent that mandatory law prevents it.
- The Customer shall indemnify and hold the Processor harmless against claims from data subjects, supervisory authorities and other third parties, and against compensation and costs, arising from the Customer's instructions, the Customer's content or the Customer's breach of this agreement or the General Data Protection Regulation.
- If the Processor has paid full compensation to a data subject under Article 82(4), the Processor is entitled to claim back from the Customer the part corresponding to the Customer's responsibility (Article 82(5)).
14. Amendments and governing law
The Processor may amend the agreement in the same way as the terms of use, for example when sub-processors are replaced or the law so requires. The agreement supersedes previous arrangements concerning the same processing. Swedish law applies, and disputes are resolved in accordance with the terms of use.
15. Contact
Questions about the agreement, notifications and requests from data subjects: support@verabim.com.