Data Processing Agreement (DPA)
Version 1.1 — 31 August 2026. This version updates Appendix 2 (approved sub-processors) only. No other clause, obligation or deadline differs from version 1.0.
This Data Processing Agreement ("DPA") is entered into by and between:
- The Customer (acting as "Data Controller"); and
- Dalarna Digital Marketing Agency AB, corporate identity number 556942-8427, Slaggatan 13, 791 71 Falun, Sweden (acting as "Data Processor", hereinafter referred to as the "Company").
Each a "Party", together the "Parties".
1. Background and Purpose
1.1 The Parties have entered into a principal agreement regarding the Customer’s use of the Company's AI-driven design and development platform (the "Main Agreement").
1.2 In providing the services under the Main Agreement, the Company will process personal data on behalf of the Customer. This DPA ensures that the Parties comply with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Scope and Instructions
2.1 The Company shall only process personal data in accordance with the Customer’s documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law.
2.2 The Main Agreement and this DPA constitute the Customer's complete instructions to the Company.
2.3 The details of the processing operations (categories of data, data subjects, and purpose) are specified in Appendix 1 of this DPA.
3. Obligations of the Data Processor
3.1 Confidentiality: The Company shall ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Security Measures: The Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
3.3 Assistance: Taking into account the nature of the processing, the Company shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
3.4 Compliance Assistance: The Company shall assist the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (Security, Breach Notification, DPIAs), taking into account the nature of processing and the information available to the Company.
4. Sub-processors (Underbiträden)
4.1 The Customer grants a general written authorization to the Company to engage sub-processors for the performance of the services.
4.2 The Company’s current sub-processors are listed in Appendix 2. The Company shall inform the Customer of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance, giving the Customer the opportunity to object.
4.3 The Company remains fully liable to the Customer for the performance of the sub-processor’s obligations.
5. International Data Transfers
5.1 Personal data may be transferred to and processed in countries outside the EU/EEA (third countries).
5.2 The Company ensures that any such transfer is compliant with Chapter V of the GDPR.
6. Personal Data Breaches
6.1 In the event of a personal data breach affecting the Customer's data, the Company shall notify the Customer without undue delay, and no later than 48 hours after becoming aware of the breach.
7. Audit Rights
7.1 The Company shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. The Customer shall bear all costs for such audits.
8. Term and Termination
8.1 This DPA remains in force as long as the Company processes personal data on behalf of the Customer under the Main Agreement.
8.2 Upon termination of the services, the Company shall, at the choice of the Customer, delete or return all personal data, and delete existing copies unless Union or Member State law requires storage of the personal data.
Appendix 1: Details of the Processing
1. Categories of Data Subjects
- Users/Employees of the Customer using the platform.
- End-users whose data may inadvertently or intentionally be included in the code, prompters, or mock data uploaded to the platform by the Customer.
2. Categories of Personal Data
- Account details (Name, email address, username).
- Technical data (IP address, logs, device information).
- Content data: Text prompters, source code, database structures, or design files provided by the user, which may contain names, contact details, or other free-text personal data.
3. Purpose and Nature of Processing
- To provide, maintain, and improve the AI-driven design and code generation platform.
- To execute API-calls to Third-Party Large Language Models (specifically Anthropic Claude API) to generate code and assets.
Appendix 2: Approved Sub-processors
The Customer approves the use of the following sub-processors at the time of signing.
AI providers. Which of these is reached depends on the Customer's AI region, a setting on the Customer's account. Where it has not been chosen, the region is US.
| # | Sub-processor | Purpose | Region | Safeguard |
|---|---|---|---|---|
| 1 | Anthropic, PBC | Text generation, analysis and reasoning. Reached in region US (default). |
USA | EU-US Data Privacy Framework / SCC |
| 2 | OpenAI | Image generation. Reached in region US (default). |
USA | EU-US Data Privacy Framework / SCC |
| 3 | Replicate | Image generation. Reached in region US (default). |
USA | EU-US Data Privacy Framework / SCC |
| 4 | Berget AI | Text and image generation for Customers in region SE. |
Sweden | Swedish infrastructure. No data leaves Sweden. |
| 5 | Requesty | Model router for Customers in region EU. |
EU | European hosting. See note 3 below. |
Infrastructure.
| # | Sub-processor | Purpose | Region | Safeguard |
|---|---|---|---|---|
| 6 | Oderland Webbhotell AB | Hosting of the platform, databases and backups. | Gothenburg, Sweden | Data stored within the EU/EEA |
| 7 | Oderland Webbhotell AB (Postal) | Inbound and outbound email, including the platform's email module. | Gothenburg, Sweden | Data stored within the EU/EEA |
| 8 | Oderland Webbhotell AB (object storage) | Storage of uploaded files. | Gothenburg, Sweden | Data stored within the EU/EEA |
Third-party services reached from published sites and research tools.
| # | Sub-processor | Purpose | Region | Safeguard |
|---|---|---|---|---|
| 9 | Google — Fonts | Web fonts on published sites. The visitor's IP address is transmitted on every page load. Being removed — see note 1. | USA | SCC 2021/914 |
| 10 | Google — Analytics 4 / Tag Manager | Visitor statistics. Only where the Customer has configured it and the visitor has consented. | USA | SCC 2021/914 |
| 11 | Google — PageSpeed Insights | Performance measurement of public URLs the Customer submits. | USA | SCC 2021/914 |
| 12 | Google — YouTube | Playback of embedded video in cookieless mode. Visitor's IP address. | USA | SCC 2021/914 |
| 13 | Unsplash | Stock image search. Search terms only — no personal data is transmitted. | USA | SCC 2021/914 |
| 14 | ScreenshotOne | Screenshots of public URLs the Customer submits. Being removed — see note 2. | USA | No DPA in place |
Three notes the Customer should read.
- Google Fonts (#9) is scheduled for removal. Published sites currently load fonts from Google's servers, which transmits each visitor's IP address to Google on every page load, without a cookie and without consent. The Company has decided to self-host the fonts; this entry will be removed once that is done.
- ScreenshotOne (#14) is scheduled for removal. The provider's own privacy policy states it is not yet GDPR compliant and offers a data processing agreement only on request; none has been entered into. The feature is disabled when no API key is configured, and transmits only a public URL the Customer has supplied. It is being migrated to the Company's own rendering service.
- Requesty (#5) is a router. It forwards requests to upstream model vendors. The claim that no data leaves Europe holds only for upstream vendors within the EU; the Company is confirming the applicable routing scope with the provider.
The Company shall inform the Customer of any intended addition or replacement of a sub-processor in accordance with clause 4.2.
For Dalarna Digital Marketing Agency AB
- Name: Daniel Åberg
- Title: Owner