Third Party Index

Snapshot 39952

Document
Data processing addendum
URL
https://website-cdn.skovik.net/static-files/DPA-25-1.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
143044 bytes
SHA-256 (raw)
c867ab1f8ef65fab6a4a20ac982d0a75d64438d24b12f1f17ced9d312a932faa
SHA-256 (normalized text)
1279bc47c787f153505cb5023c9030460847839cf8069a36e8f1da4212f57a30

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                                Data Processing Addendum

1.     Introduction
1.1.   This data processing addendum ("Addendum") forms part of the Agreement between Skovik AB ("Skovik"),
       as data processor, and the customer that is party to the Agreement ("Customer"), as data controller. If there
       is any conflict between this Addendum and the Agreement, this Addendum shall prevail.

1.2.   The terms controller, processor, processing, data subject, personal data, personal data breach and supervisory
       authority shall have the same meaning as in the EU regulation 2016/679 ("GDPR").

1.3.   This Addendum applies where and only to the extent that Skovik processes personal data under the GDPR
       acting on behalf of the Customer, in the course of providing services pursuant to the Agreement.

1.4.   The purpose of this Addendum is to ensure that personal data is processed in accordance with applicable
       data privacy laws and with respect for the rights and freedoms of individuals whose data are processed.

1.5.   This Addendum comes into effect when it is signed by both parties and shall remain in force as long as
       Skovik processes personal data on behalf of the Customer.

2.     Addendum documents

2.1.   The following appendices are hereby incorporated by reference into this Addendum:
       Appendix I: List of parties and description of processing
       Appendix II: Technical and organisational Measures
       Appendix III: List of sub-processors

2.2.   In the event of any conflict or inconsistency between this main document and the appendices, this main
       document shall prevail. In the event of any conflict or inconsistency between the Addendum and the
       Agreement related to the processing of personal data, the Addendum shall prevail.

3.     Processing of personal data
3.1.   The Customer is responsible for the processing of personal data and that such processing is compliant
       with the GDPR, including ensuring that there is a legal basis for the processing and providing Skovik with
       correct and sufficient instructions for processing of personal data.

3.2.   Skovik undertakes to only process personal data in accordance with the Customer’s documented
       instructions, including any transfer of data to third countries or international organisations, specified in
       this Addendum, unless required to do so by EU or EU member state national law to which Skovik is
       subject. In this case, Skovik shall inform the Customer at legal requirement before processing, unless the
       law prohibits this on important grounds of public interest. Skovik shall inform the Customer if, in Skovik’s
       reasonable opinion, an instruction infringes the GDPR. In such case, the Customer shall promptly provide
       further instructions regarding the processing of personal data.

Data Processing Addendum 25.1                          skovik.com                                                     1/7
3.3.   The Customer confirms that the provisions of this Addendum, including all appendices, constitute the
       complete instructions regarding Skovik’s processing of personal data on behalf of the Customer. The
       Customer may provide additional instructions to Skovik as necessary due to changes to the Agreement or
       to the extent required under applicable data protection legislation. Skovik shall be entitled to
       compensation on a time and material basis for its reasonable and documented costs arising from the
       Customer’s additional instructions that go beyond what is reasonably necessary in order for Skovik to
       comply with applicable data protection legislation.

4.     Exercise of access rights etc.
4.1.   Skovik shall notify the Customer of any request Skovik has received from a data subject. Skovik shall not
       respond to the request itself, unless authorised to do so by the Customer.

4.2.   If data subjects or supervisory authorities request information from Skovik regarding the processing of
       personal data, Skovik shall refer such request to the Customer. Skovik shall not act as a representative of
       Customer or disclose personal data as a response to any such request.

4.3.   In the event that Skovik, according to applicable laws, is required to disclose personal data that Skovik
       processes on behalf of the Customer to supervisory authorities, Skovik shall inform the Customer thereof
       and request confidentiality in connection with the disclosure of the requested information, unless legally
       prohibited to do so.

5.     Assistance and cooperation

5.1.   Skovik shall, taking into account the nature of processing and the information available to Skovik, upon
       the Customer’s reasonable request assist the Customer in fulfilling the Customer’s obligations under
       articles 32-36 of the GDPR.

5.2.   Skovik shall make available to the Customer all information necessary to demonstrate compliance with
       Skovik’s obligations set out in this Addendum.

5.3.   Skovik shall inform the Customer without undue delay after becoming aware of any accidental or
       unauthorised access to personal data or any other security incidents (personal data breach).

6.     Sub-processors and transfers
6.1.   In accordance with article 28.2 of the GDPR, the Customer hereby grants to Skovik a general written
       authorisation to engage sub-processors to process personal data. Appendix III contains a list of the sub-
       processors engaged in the processing of personal data under this Addendum approved by the Customer as
       of when this Addendum came into effect. The Customer may use the sub-processor subscription
       mechanism on the Skovik website, to receive notifications of Skovik’s appointment of any new sub-
       processor prior to such new sub-processor being authorised to process personal data under this
       Addendum. The Customer may object to the appointment of a new sub-processor within 30 days of such
       notification, if the Customer reasonably deems that such sub-processor does not fulfil the requirements of
       the GDPR, the parties shall work in good faith to find an alternative solution.

Data Processing Addendum 25.1                         skovik.com                                                   2/7
6.2.   Skovik shall enter into written agreements with each appointed sub-processor, under which the sub-
       processor undertakes obligations corresponding to those undertaken by Skovik under this Addendum.
       Skovik shall remain liable to the Customer for the performance of the sub-processors’ obligations.

6.3.   The Customer hereby grants Skovik permission to transfer personal data to countries outside the EU/EEA
       as further set out in Appendix III. If personal data is transferred outside the EU/EEA, Skovik shall ensure
       that such transfer is subject to a legal transfer mechanism in accordance with chapter 5 of the GDPR, for
       example entering into the relevant module of EUs standard contractual clauses or binding corporate rules.

6.4.   Transfer to countries outside the EU/EEA shall be documented in the appendices to this Addendum. To the
       extent necessary to ensure the adequate protection of personal data, the parties shall agree upon
       additional safeguards in the appendices to this Addendum.

7.     Information security and confidentiality
7.1.   Taking into account the state of the art, implementation costs and the nature, scope, context and purposes
       of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of the
       data subjects, Skovik shall implement and maintain appropriate technical and organisational security
       measures to protect personal data against accidental destruction, unauthorised disclosure or access, and
       against all other unlawful forms of processing. The parties have agreed that the technical and
       organisational security measures set forth in Appendix II constitute an appropriate level of security for the
       processing of personal data under this Addendum. The Customer is responsible for ensuring that the
       technical and organisational measures fulfil the requirements of the GDPR.

7.2.   Skovik undertakes not to disclose or otherwise make personal data processed under this Addendum
       available to any third party without the Customer's prior written consent, except for sub-processors
       engaged in accordance with this Addendum.

7.3.   Skovik shall ensure that only staff and other representatives that require access to personal data in order
       to fulfil Skovik's obligations in accordance with this Addendum have access to such information. Skovik
       shall ensure that such staff and other representatives have committed themselves to appropriate
       confidentiality undertakings.

8.     Audit rights
8.1.   Whilst it is the parties' intention to rely on the provision of documentation to verify that Skovik is
       complying with its obligations under this Addendum, Skovik shall permit the Customer, or an auditor
       appointed by the Customer, to audit that Skovik is in compliance with this Addendum. The Customer must
       give Skovik reasonable prior notice of such intention to audit, conduct the audit during normal business
       hours, and take all reasonable measures to prevent unnecessary disruption to Skovik's operations. For any
       on-site inspection, the parties shall mutually agree upon the scope and duration of the audit. Any audit
       shall be subject to Skovik’s security and confidentiality terms and guidelines.

8.2.   Skovik shall be entitled to compensation on a time and material basis, applying Skovik’s at the time
       applicable hourly rates, for assisting in an audit. Any third-party auditor is at the expense of the Customer.

Data Processing Addendum 25.1                         skovik.com                                                  3/7
9.     Limitation of liability

9.1.   The parties acknowledge that they each respectively are liable, accountable and responsible in their
       respective roles as Controller and Processor under the requirements set forth in the GDPR and this
       Addendum. Any administrative fines, fees or sanctions imposed by the supervisory authority or
       compensation to data subjects shall be subject to the liability provisions set out in articles 82-84 of the
       GDPR. If a party processes personal data in violation of this Addendum, such party shall compensate the
       other party for any direct damages suffered due to such wrongful processing or violation of this
       Addendum, in accordance with the liability provisions of the Agreement.

10.    Return or deletion of data
10.1. Upon termination or expiry of this Addendum, Skovik shall, at the Customer’s request, either delete or
       return to the Customer all personal data, and delete any remaining copies, unless applicable laws require
       otherwise. If the Customer elect to have the data returned, it will be provided in a machine-readable
       format via Skovik’s standardised API.

11.    Applicable law and dispute resolution
11.1. This Addendum is regulated by Swedish law, regardless of applicable principles on the choice of law. Any
       dispute regarding the interpretation of application of this Addendum shall be settled according to the
       dispute resolution provisions in the Agreement.

          Skovik AB
          Skovik legal name                               Customer legal name

          Signature                                       Signature

          Alexander Sandström
          Name of representative                          Name of representative

          2025-06-10
          Date                                            Date

Data Processing Addendum 25.1                         skovik.com                                                 4/7
                                     Appendix I
                   List of parties and description of processing

1 Introduction
This Appendix I sets out the parties to the Addendum and describes the processing of personal data under the
Addendum.

2 List of parties
In addition to the company identified as the Customer, any legal entities controlled by it as a part of a company
group shall be deemed as controllers under the Addendum.

3 Description of data processing
The following table describes Skovik's data processing:

 Categories of data subjects       The following categories of data subjects will be included in the processing:

                                   The Customer’s employees and contractors.

 Categories of personal data       The following personal data will be processed by Skovik:

                                   Name, username, email, address, phone number, employee department, employee
                                   number, device data and other data provided by the data subject in the context of
                                   Skovik’s services.

                                   The following special categories of personal data will be included in the processing:

                                   No categories of sensitive data are anticipated.

 Nature and purpose of the         The nature and purpose of the processing is to, and Skovik shall only process the
 processing                        personal data to:

                                   Provide automated services for administrative tasks, such as expense reports,
                                   mileage, allowances and preparation of data for bookkeeping and salary
                                   calculations. Full details about Skovik’s products and services can be found at
                                   https://skovik.com.

 Duration of processing            The period for which the personal data will be retained, or, if that is not possible, the
                                   criteria used to determine that period:

                                   Personal data will be processed by processor for as long as the Agreement is
                                   effective.

Data Processing Addendum 25.1                         skovik.com                                                         5/7
                                    Appendix II
                       Technical and organisational measures

1 Introduction
This Appendix II details the technical and organisational measures, including technical and organisational
measures to ensure the security of the data that Skovik at least shall apply.

2 List of technical and organisational measures
The parties have agreed upon the technical and organisational measures to ensure an appropriate level of
security for the personal data processed by Skovik as described at https://skovik.com/resources/security/.

Data Processing Addendum 25.1                        skovik.com                                              6/7
                                        Appendix III
                                Pre-approved sub-processors

1 Introduction
This Appendix III sets out Skovik’s sub-processors that the Customer has approved may be engaged as sub-
processors under the Addendum per its signature date. An updated list of approved sub-processors from time to
time can be found at https://skovik.com/legal/sub-processors.

2 List of sub-processors
The Customer has authorised the use of the following sub-processors:

 Sub-processor         Address                               Processing Location   Description of Processing

 Microsoft Ireland      South County Business Park           Netherlands           Storage, computation services
 Operations Ltd.        Dublin 18 D18 P521                                         and physical data centres.
                        Ireland

 Amazon Web             38 Avenue John F. Kennedy            Ireland and Germany   Storage, computation services
 Services EMEA          L-1855 Luxembourg                                          and physical data centres.
 SàRL.                  Luxembourg

 Google Ireland Ltd.    Gordon House, Barrow Street          Ireland               Storage, computation services
                        Dublin 4                                                   and physical data centres.
                        Ireland

 Stripe Payments        IFSC, North Wall Quay                Ireland               Payment processing, credit cards
 Europe Ltd.            Dublin, D01 H104                                           and invoices.
                        Ireland

 Mixpanel SàRL.        92 Av. des Champs-Élysées             Netherlands           Product usage statistics.
                       Paris 75008
                       France

 Sinch AB               Lindhagensgatan 112                  Germany               Email delivery services.
                        112 51, Stockholm
                        Sweden

 Message Bird B.V.      Trompenburgstraat 2 C                Netherlands           Delivery of text messages,
                        1079 TX, Amsterdam                                         notifications and other
                        Netherlands                                                communications.

Data Processing Addendum 25.1                         skovik.com                                                   7/7