Skip to content

    Data Processing Agreement

    Last updated 2026-03-05

    Preamble

    By using our website, software and service, you and any company or entity that you are acting for (hereinafter referred called the "Controller") acknowledge that your use of the website, software and service may involve transfer of personal to SeqOps AB (hereinafter called the "Processor") and hence, you agree to enter into this DPA with SeqOps AB and accept that you shall be bound by the contents thereof. The expressions "Controller" and "Processor" shall, unless the context or meaning be otherwise repugnant, mean and include their respective successors, legal representatives, administrators and assigns. The Controller and Processor are referred to herein collectively as "Parties".

    1. Definitions

    In this Agreement, the following capitalised terms shall have the following meanings, except where the context otherwise requires: Business Days means a day in India when the banks (excluding Internet banking operations) are generally open for business i.e., normally excluding Saturdays, Sundays and public holidays. Where references are made to 'days' without using the capitalized expression "Business Day(s)", such references shall be deemed to be to calendar days; Commencement Date shall mean the date of signing of DPA by both parties; Commission has the meaning given in the Data Protection Legislation; Controller Personal Data means any Personal Data processed by the Processor on behalf of Controller pursuant to or in connection with the Service Agreement; Data Controller or Controller has the meaning given in the Data Protection Legislation; Data Processor or Processor has the meaning given in the Data Protection Legislation; Data Protection Legislation means the General Data Protection Regulation of the European Parliament and of the Council as per Regulation (EU) 2016/679 dated 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, including any amendments made thereto from time to time, and such other data protection legislation and regulations that are applicable in Sweden; Data Subject Rights has the meaning given in the Data Protection Legislation; Data Transfer means 1) a transfer of Controller Personal Data from the Controller to the Processor; or 2) an onward transfer of Controller Personal Data from the Processor to a Subcontracted Processor, or between two establishments of a Processor, in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws); DPA or Data Protection Agreement shall mean this Agreement as amended from time to time; EEA shall mean the European Economic Area; GDPR means the General Data Protection Regulation of the European Parliament and of the Council as per Regulation (EU) 2016/679 dated 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, including any amendments made thereto from time to time; Personal Data means personal data under any of the Data Protection Legislation; Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed by the Processor; Processing has the same meaning given in the Data Protection Legislation; Service Agreement means the Agreement for Provision of Services entered into between the Controller and Processor; Services means the services to be provided by the Processor pursuant to the Service Agreement entered into between the Controller and Processor; Special Category Personal Data has the meaning given in the Data Protection Legislation; Sub-processor means any person appointed by or on behalf of Processor to process Controller Personal Data on behalf of the Controller in connection with this Agreement;

    2. Recitals

    2.1. Whereas, the Controller is a private entity which has entered into a Service Agreement with the Processor for the provision of Services, wherein the Controller shall receive Services from the Processor. 2.2. And whereas, the Processor herein is a private IT consultancy entity specialising in online security services whose core business is the provision of an online platform focused on providing data security to its clients and users. 2.3. The Controller and Processor have entered into a Service Agreement wherein the Processor has undertaken to provide Services to the Controller. Since the provision of the said Services may involve Processing of Controller Personal Data by the Processor, both parties hereto have agreed to enter into this DPA in order to govern the manner in which the Controller Personal Data is processed by the Processor.

    3. Commencement and Duration

    3.1. This DPA shall commence on the Commencement Date and shall continue till to be in force for the duration of the Service Agreement entered into between the Controller and Processor. 3.2. Upon termination of this DPA, the provisions contained in the Service Agreement entered into between the Controller and Processor in relation to effects of termination of the said Service Agreement shall be applicable to this DPA.

    4. Processing of Personal Data

    4.1. The Processor shall: 4.1.1. comply with all applicable Data Protection Legislation in the processing of Controller Personal Data; and 4.1.2. not process Controller Personal Data other than on the relevant Controller's documented instructions. 4.1.3. immediately inform the Controller if, in its opinion, an instruction infringes applicable Data Protection Legislation.

    5. Processor Personnel

    5.1. The Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any processor who may have access to Controller Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Controller Personal Data, as strictly necessary for the purposes of the Service Agreement, and to comply with applicable laws in the context of that individual's duties to the Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality and also undertaking to provide adequate training and review to its personnel from time to time.

    6. Security

    6.1. Considering the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall in relation to Controller Personal Data, implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk; 6.2. In assessing the appropriate level of security, the Processor shall take account in particular of the risks that are presented by processing, in particular from a Personal Data Breach.

    7. Sub-Processing

    7.1. The Processor shall not appoint (or disclose any Controller Personal Data to) any Sub-processor unless required or authorized by the Controller to do so. 7.2. With respect to each Sub-processor appointed by the Processor as required or authorised by the Controller, the Processor shall: 7.2.1. undertake appropriate due diligence prior to the processing of personal data by such Sub-processor to ensure that it is capable of providing the level of protection for personal data required by the terms of the Service Agreement and this DPA; 7.2.2. enter into a written agreement with the Sub-processor incorporating terms which are substantially similar (and no less onerous) than those set out in this DPA; and 7.2.3. as between the Controller and the Processor, remain fully liable to the Controller for all acts or omissions of such Sub-processor as though they were its own. 7.3. To the extent that the Processor has already appointed any Sub-processors prior to the processing of any personal data under this DPA, the Processor shall ensure that its obligations under Clause 7.2 are met as soon as practicable. 7.4. Where the Processor proposes any changes concerning the addition or replacement of any Sub-processor, it shall notify the Controller in writing as soon as reasonably practicable prior to implementing such change specifying: 7.4.1. the name of any Sub-processor which it proposes to add or replace; 7.4.2. the processing activity or activities affected by the proposed change; 7.4.3. the reasons for the proposed change; and 7.4.4. the proposed date for implementation of the change. 7.5. If within thirty (30) days of receipt of a notice under Clause 7.4 the Controller (acting reasonably and in good faith) notifies the Processor in writing of any objections to the proposed change, the parties shall use their respective reasonable endeavours to resolve the Controller's objections. Where such resolution cannot be agreed within thirty (30) days of the Processor's receipt of the Controller's objections (or such longer period as the parties may agree in writing) the Controller may, notwithstanding the terms of the Service Agreement, serve written notice on the Processor to terminate the Service Agreement (to the extent that the provision of the Services is or would be affected by the proposed change). 7.6. The Processor shall, upon the Controller's request, provide the Controller with copies of any agreements between the Processor and its Sub-processors (which may be redacted to remove information which is confidential to the Processor and/or its Sub-processors and which is not relevant to the terms of this DPA).

    8. Data Subject Rights

    8.1. Taking into account the nature of processing, the Processor shall assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligations, as reasonably understood by Controller, to respond to requests to exercise Data Subject Rights under the Data Protection Laws; 8.2. The Processor shall: 8.2.1. promptly notify Controller if it receives a request from a Data Subject under any Data Protection Law in respect of Controller Personal Data; and 8.2.2. ensure that it does not respond to that request except on the documented instructions of the Controller or as required by applicable laws to which the Processor is subject, in which case the Processor shall to the extent permitted by applicable laws inform Controller of that legal requirement before the responding to the request.

    9. Personal Data Breach

    9.1. The Processor shall notify the Controller without undue delay upon the Processor becoming aware of a Personal Data Breach affecting Controller Personal Data, providing the Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects or the Supervisory Authority or such other person/s as required to be informed under the Data Protection Laws about the said Personal Data Breach; 9.2. The Processor shall co-operate with the Controller and take all reasonable commercial steps as are directed by Controller to assist in the investigation, mitigation and remediation of each such Personal Data Breach.

    10. Data Protection Impact Assessment and Prior Consultation

    10.1. The Processor shall provide all reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which the Controller reasonably considers to be required, in each case solely in relation to processing of Controller Personal Data by, and taking into account the nature of the processing and information available to, the Processor or Sub-processors.

    11. Limitation of Liability

    11.1. Each party is responsible for direct damages incurred by the other party due to a breach of obligations under this Data Processing Agreement (DPA) or Data Protection Legislation by such party. As such, each party shall indemnify the other party from and against all losses due to claims from third parties resulting from or arising out of any breach by such party of this DPA. However, the total liability of each party under this DPA is subject to the specified limitation of liability outlined in the Service Agreement. Neither party shall be held liable for any indirect damages. These liability limitations are applicable within the constraints of relevant laws and do not restrict the liability of either party in cases of wilful misconduct or gross negligence that leads to a breach.

    12. Deletion or Return of Controller Personal Data

    12.1. Subject to this Clause 12, the Processor shall promptly without undue delay and within 30 business days of the date of cessation of any Services involving the Processing of Controller Personal Data (the "Cessation Date"), delete and procure the deletion of or return all copies of those Controller Personal Data, as per the instructions of the Controller.

    13. Audit Rights

    13.1. Subject to this Clause 13, the Processor shall make available to the Controller on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller in relation to the processing of the Controller Personal Data by the Processor or sub-processors; 13.2. The information and audit rights of the Controller shall arise under Clause 13.1 only to the extent that the Service Agreement does not otherwise give to the Controller information and audit rights meeting the relevant requirements of Data Protection Law.

    14. International Data Transfer

    14.1. The Processor may not transfer or authorize the transfer of Personal Data to countries outside the EU and/or the European Economic Area (EEA) without the prior written consent of the Controller.

    15. Co-operation with Regulators

    15.1. Unless otherwise agreed upon between the parties in writing, the Controller shall: 15.1.1. manage all communications and correspondence with the regulator regarding the processing of personal data under this Data Processing Agreement (DPA), and 15.1.2. be required to keep the Processor informed about such communications or correspondence on a need-to-know basis, to the extent allowed by applicable law.

    16. Confidentiality and Non-Disclosure

    16.1. Each party must keep this Agreement and information it receives about the other party and its business in connection with this Agreement ("Confidential Information") confidential and must not use or disclose that Confidential Information without the prior written consent of the other party except to the extent that: 16.1.1. disclosure is required by law; 16.1.2. the relevant information is already in the public domain.

    17. Dispute Resolution

    17.1. This Agreement will be interpreted, construed and enforced in accordance with the laws of Sweden, without reference to its rules relating to choice of law. The parties expressly exclude application of the U.N. Convention on Contracts for the International Sale of Goods (1980) to this Agreement. 17.2. Any dispute, controversy or claim arising out of or in connection with this Agreement, or the breach, termination or invalidity thereof, shall be finally settled by arbitration administered by the Arbitration Institute of the Stockholm Chamber of Commerce. The Rules for Expedited Arbitrations shall apply where the amount in dispute does not exceed SEK 1 000 000, and in such case the Arbitral Tribunal shall be composed of a sole arbitrator. Where the amount in dispute exceeds SEK 1 000 000, the Arbitration Rules shall apply, and the Arbitral Tribunal shall be composed of three arbitrators. The amount in dispute includes the claims made in the Request for Arbitration and any counterclaims made in the Answer to the Request for Arbitration. 17.3. The seat of arbitration shall be Stockholm, Sweden. The language of the proceedings shall be English. 17.4. Any proceedings pertaining to any disputes between the parties hereto shall be treated as strictly confidential and neither party shall disclose the same to any third party under any circumstances and in case of any default in this regard, the defaulting party shall be liable to pay to the non-defaulting party all such damages which may arise to the non-defaulting party as a consequence of disclosure of information pertaining to proceedings of such dispute.

    18. Governing Law and Jurisdiction

    18.1. This DPA shall be governed by the laws of Sweden; 18.2. The parties irrevocably agree that the courts of Stockholm, Sweden, shall have the exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this DPA or its subject matter or formation subject to the provisions contained in Clause 17.

    19. Variations

    19.1. No variation of this DPA or of any of the documents referred to in it shall be valid unless it is in writing and signed by, or on behalf of, each of the parties.

    20. Severability

    20.1. In case any one or more of the provisions contained in this DPA is for any reason held to be invalid, illegal or unenforceable in any respect, such invalidity, illegality, or unenforceability shall not affect any other provision of this DPA, and such invalid, illegal, or unenforceable provision shall be reformed and construed by both parties so that it will be valid, legal, and enforceable to the maximum extent permitted by law.

    Acceptance

    By ticking the box below, you confirm that you have read, understood and agreed to the provisions contained in this DPA.

    We use cookies

    We use essential cookies to run this site. With your permission, we'd also like to use analytics cookies to see how the site is used, and functional cookies for chat and videos. Change your choice any time under Cookie settings. Read our Cookies Policy