Draft for review by Swedish counsel before publication
These are working drafts written from the product decisions on record. They are not legal advice and have not been reviewed by a lawyer. The clauses on liability, warranties, indemnities and limitation periods in particular need a Swedish commercial lawyer, and the processing annexes need confirming against the infrastructure as actually deployed.
Data processing agreement · draft 1.0
Data processing agreement
The agreement under Article 28 of the General Data Protection Regulation between you as controller and Sunny Ventures AB as processor. It applies whenever we process personal data on your behalf, and it forms part of the terms of service.
- Controller
- You, the customer
- Processor
- Sunny Ventures AB
- Processing location
- Ireland · European Union
- Transfers outside the EEA
- None for hosting
01
Roles and scope
You are the controller of the personal data you submit to the service and of the personal data of the people you admit to your workspace. We are the processor of that data and process it only on your instructions.
We are an independent controller for a limited set of data we process for our own purposes: the identity and contact details of the people who administer and pay for a workspace, billing records we are required to keep, and the security and operational logs we need to run the service. That processing is described in the privacy policy, not here.
This agreement applies for as long as we process personal data on your behalf, and prevails over the terms of service on any question about the processing of personal data.
Your instructions are given by your use of the service and by the settings you choose in it. If we consider an instruction to be in breach of data protection law, we will tell you and may suspend the processing concerned until it is resolved.
02
The processing
The details required by Article 28(3) are set out here and in Annex I. The processing is characteristically light on personal data: the service is about products and rules, and the people in it are a small number of named professionals.
Subject matter: the provision of regulatory compliance checking of product labels, recipes and records, and the documents produced from it.
Duration: for the term of the subscription, and afterwards only for the retention periods stated in Annex I and in section 8.
Nature and purpose: storing, reading, analysing and reporting on the material you submit; identifying and authenticating your people; recording who did what; and producing, sharing and verifying documents at your instruction.
We do not carry out automated decision-making with legal effect on a person, and we do not profile. The service assesses products, not people.
You must not submit special category data or criminal offence data to the service. It is not designed for it and there is no purpose for which it would be needed.
| Category of person | Categories of data | Why it is processed |
|---|---|---|
| Your people, and external consultants you admit | Name, business email, role, scope, access dates, actions taken with timestamps, authentication data | Access control, and the append-only record of who did what |
| Your suppliers' contacts | Business email, company, the document requested and uploaded | Requesting and receiving specifications by scoped link, without an account |
| Recipients of a document you send | Business email, the fact and time of sending, whether a reference was verified | Delivering a document you chose to send, and answering verification |
| Individuals named in your own material | Whatever appears in artwork or documents you upload, typically a responsible operator's contact details | Because it is on the label; we neither seek nor use it beyond the check |
03
Security
The measures are listed in Annex II. Three of them are load-bearing and are stated here because they are architectural rather than operational.
Tenant separation is enforced in the database itself, by row-level security policies keyed to your workspace, rather than by application code. A defect in the application cannot expose one customer's data to another.
The event store and the certificate chain accept inserts only. Update and delete rights are revoked from every application role and rejected at the database level. Neither we nor you can alter a historical record.
The public verification endpoint has no read access to customer tables. It returns a document's status, issue date and ruleset version against an unguessable reference, and never its content, its findings or your identity beyond what is on the document itself.
Data is encrypted in transit with TLS and at rest. Access by our personnel is limited to named individuals who need it, is authenticated with a second factor, and is logged.
We will not materially reduce the measures in Annex II during the term. We may change how a measure is implemented, provided the level of protection is maintained.
04
Our personnel
Only personnel who need access to provide, secure or support the service are given it, and only to the extent needed.
Every person with access is bound by a written confidentiality obligation that survives the end of their engagement.
We do not access the content of your workspace to answer a support request unless you ask us to, and such access is recorded.
05
Sub-processors
You give general authorisation for us to engage the sub-processors listed below. We remain responsible to you for their performance.
We will give thirty days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds you may terminate the affected part of the service without penalty, and we will refund the unused part of any prepaid term.
Every sub-processor is bound by obligations no less protective than those in this agreement.
| Sub-processor | What it does | Where it processes |
|---|---|---|
| Supabase (Supabase Inc., on Amazon Web Services infrastructure) | Database, authentication, file storage, realtime updates | Ireland · eu-west-1 |
| Amazon Web Services EMEA SARL | Underlying compute, storage and network | Ireland · eu-west-1 |
| An EU-established transactional email provider | Delivering documents you send, invitations and notifications | European Union |
| Stripe Payments Europe Ltd | Card payment processing and invoicing | Ireland, with transfers under its own safeguards |
| A model provider for the assistant and for extraction | Model inference on the text you submit, under a no-training commitment | European Union where the provider offers EU processing |
06
Transfers outside the EEA
Your workspace is hosted in Ireland and the processing of your material takes place within the European Union. We do not transfer it outside the European Economic Area for hosting or for backup.
Where a sub-processor is established outside the EEA or may access data from outside it, the transfer is made under the Standard Contractual Clauses adopted by the European Commission, together with a transfer impact assessment and any supplementary measures it identifies.
We will tell you if we ever need to change the hosting region, with the notice period in section 5.2, and you may object on the same basis.
07
Your rights and obligations, and ours
We will assist you in responding to a request from a data subject. Because you control your workspace, you can find, correct and export most such data yourself; where you cannot, we will help within a reasonable time and without charge for a reasonable volume of requests.
Where a data subject's request would require altering an append-only record, we will tell you so and explain what can and cannot be done. A record of who ran a check is retained on the legal basis of our legitimate interest and yours in the integrity of a compliance record, and it is a small and proportionate amount of data.
We will notify you without undue delay, and in any event within forty-eight hours of becoming aware, of a personal data breach affecting your data, with the information you need for your own notification obligations under Articles 33 and 34.
We will assist you with a data protection impact assessment and with a prior consultation, to the extent the processing under this agreement is relevant to it.
You may audit our compliance with this agreement once in any twelve-month period, on thirty days' notice, at your own cost, and subject to confidentiality. We may satisfy an audit by providing a current third-party report or completed security questionnaire where it answers your questions.
08
Deletion and return
On termination you may export everything, and we will delete or return personal data at your choice, subject to the exceptions in 8.2 and 8.3.
We retain the minimum record needed to keep answering the public verification page for documents you shared before termination, because a third party may still hold one and its unverifiability would be a harm to them. That record is a reference, a status, a date and a ruleset version.
We retain billing records for the period required by Swedish accounting law, currently seven years, and we retain the append-only event record for the periods in Annex I.
Backups are retained on a rolling basis for thirty days and are then overwritten. A deletion request is executed against live systems immediately and takes effect in backups as they roll.
09
Annex I · retention
Retention is stated per kind of record rather than as one period, because the reasons differ.
| Record | Retained for | Why |
|---|---|---|
| Checks, findings and results | For the life of the workspace, and beyond it as in 8.2 | It is an append-only compliance record |
| Reports and certificates | Permanently, as a reference and status | A third party may hold a copy that has to verify |
| Artwork files you upload | While the product is active, then two years | The extracted text and identifier are kept; the file itself is not needed |
| Supplier documents | While current, then six years after expiry | The span most audits reach back over |
| Access and audit events | For the life of the workspace | The integrity of the record depends on it |
| Billing records | Seven years | Swedish accounting law |
| Security and operational logs | Twelve months | Investigating incidents |
10
Annex II · technical and organisational measures
Access control: individual credentials, second factor available on every account and required for anybody holding signing authority, role and scope enforced per workspace, immediate revocation, optional end dates on external access.
Tenant separation: row-level security in the database keyed to the workspace, applied to every table holding customer data.
Integrity: insert-only event and certificate tables with update and delete revoked from all application roles and rejected by a database trigger; documents pinned to ruleset version and artwork identifier.
Encryption: TLS in transit; encryption at rest for the database, file storage and backups.
Segregation of environments: no customer data in development or test environments.
Availability: managed database with point-in-time recovery, daily backups retained thirty days, restore tested periodically.
Personnel: confidentiality undertakings, need-to-know access, logged administrative access, security training on joining and annually.
Vendor management: a written agreement and data protection terms with every sub-processor, and a review before any is added.
Incident response: a defined process with named responsibility, notification to you within forty-eight hours of becoming aware, and a written account of cause and remediation.