UPDATED 2026-09-30

Data processing agreement

1. Conclusion and scope of the agreement

The agreement applies from when the Customer creates a company or a project in the service, or otherwise allows the Processor to process personal data on the Customer's behalf, and is accepted when the Customer's administrator or project owner accepts the terms of use. It covers the personal data that the Customer's users and others enter in the Customer's projects. The Processor processes account data and data about how the service is used as controller in accordance with the privacy policy. In the event of conflict, this agreement takes precedence over the terms of use in matters concerning the processing of personal data.

2. Nature, purpose and duration of the processing

The Processor processes the personal data solely to provide the service to the Customer: storage, display, search, sharing within the project, sending of email and push notifications, backup, troubleshooting and support. The processing continues for as long as the agreement applies and thereafter until the data has been erased in accordance with section 12.

3. Categories of data subjects and data

4. The Customer's responsibilities and instructions

The Customer is the controller and is responsible for ensuring that the processing is lawful: that there is a legal basis, that the data subjects are informed, that only authorised persons are invited, that roles are set correctly and that no unnecessary data is entered. The Customer is responsible for the content of what is uploaded, including photos of people.

The Customer's documented instructions are this agreement, the terms of use and the settings and choices that the Customer makes in the service. Further instructions shall be given in writing and be compatible with the functions of the service. The Processor may decline instructions that require changes to the service or that are not reasonable; the Customer may then terminate the agreement by ceasing to use the service. The Customer bears its own costs of complying with the General Data Protection Regulation.

5. The Processor's obligations

6. Security measures

The Customer has assessed that the measures provide an appropriate level of security for the data that the Customer enters in the service. The Processor may change the measures as long as the overall level of protection is not reduced.

7. Sub-processors and other recipients

The Customer gives a general prior authorisation for the Processor to engage sub-processors. The server, database and file storage are operated by the Processor itself on our own server in Sweden. At the time the agreement is entered into, Simply.com in Denmark, within the EU, is engaged for outgoing email (recipient address, subject and message text).

Push notifications are delivered through the push services belonging to the recipient's browser or operating system (for example Google, Apple, Microsoft or Mozilla). The push services are used only when a user has turned on push notifications themselves, and the content of the notifications is encrypted so that the push service cannot read it.

The Processor informs the Customer of any intended addition or replacement of sub-processors by updating this agreement and announcing it in the service or by email in good time before the change is made. The Customer may object within 14 days of the notice. If the parties do not reach agreement, the Customer's sole right is to terminate the agreement by ceasing to use the service. The Processor imposes on sub-processors the same data protection obligations as follow from this agreement and is liable to the Customer for the performance of the sub-processors' obligations under Article 28(4), subject to the limitation of liability set out in section 13.

8. Transfers to third countries

The Processor stores and processes the Customer's project data in Sweden, and email is sent via a sub-processor within the EU. The push services may, outside the EU/EEA, process the device's push address and information about when notifications are sent, but cannot read the content. Otherwise, the Processor does not transfer the personal data to a third country without the Customer's written instruction.

9. Personal data breaches

The Processor notifies the Customer without undue delay after becoming aware of a personal data breach concerning the Customer's personal data. The notification is sent to the email address of the Customer's administrator or project owner and contains the information that the Processor has about the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The information may be provided in phases. The Customer itself assesses whether the breach is to be notified to the supervisory authority and communicated to the data subjects.

10. Assistance and costs

Requests from data subjects are primarily handled by the Customer itself using the functions of the service, for example export, rectification and erasure. If the Processor receives a request concerning the Customer's data, the Processor refers the data subject to the Customer. The Processor otherwise assists the Customer with requests from data subjects, impact assessments and prior consultations to a reasonable extent, taking into account the nature of the processing and the information available to the Processor. Assistance beyond the functions of the service is provided against compensation for the Processor's reasonable costs, unless the assistance is needed because the Processor has breached this agreement.

11. Audits

The Processor demonstrates compliance with its obligations primarily through written information, for example this agreement, the description of the security measures and written answers to the Customer's reasonable questions. If the Customer shows that an on-site audit is nevertheless required under the General Data Protection Regulation, the Customer may have it carried out by an independent auditor bound by a duty of confidentiality. The audit shall be notified at least 30 days in advance, may take place at most once a year, shall be carried out without disrupting operations or disclosing other customers' data and shall be paid for entirely by the Customer, including reasonable compensation for the Processor's time. An audit requested by a supervisory authority is carried out in accordance with the authority's requirements.

12. Term, erasure and return

The agreement applies for as long as the Processor processes personal data on the Customer's behalf. The Customer can at any time itself export project data (for example reports, Excel, BCF and files) and delete projects in the service. Return takes place by the Customer exporting the data before the agreement ends. If the Processor discontinues the service or the Customer's access, the Processor will, where possible, give the Customer reasonable time to export first. After the agreement has ended, the Processor erases the Customer's personal data within a reasonable time, and the data disappears from the backups as these are rotated out. Data that the Processor is required by law to retain is erased when that obligation ends.

13. Liability

The data subject's right to compensation under Article 82 of the General Data Protection Regulation cannot be limited by this agreement. As between the parties, the following applies:

14. Amendments and governing law

The Processor may amend the agreement in the same way as the terms of use, for example when sub-processors are replaced or the law so requires. The agreement supersedes previous arrangements concerning the same processing. Swedish law applies, and disputes are resolved in accordance with the terms of use.

15. Contact

Questions about the agreement, notifications and requests from data subjects: support@verabim.com.

© 2026 VeraBIM