Legal
Data Processing Agreement
Last updated: 2026-08-31
This Data Processing Agreement ("Agreement") forms part of the Terms of Service published by Bitfront AB (the "Principal Agreement") between the Bytesafe customer (the "Company") identified by the information provided upon account creation, and Bitfront AB, Swedish Registration number 559155-7912 (the "Data Processor"), with address Mellanvägen 5, 136 70 Vendelsö, Sweden (together the "Parties").
The Company acts as a Data Controller. The Company wishes to subcontract certain Services, which involve the processing of personal data, to the Data Processor. The Parties seek to implement a data processing agreement that complies with the requirements of Regulation (EU) 2016/679 (GDPR).
This Agreement applies where the Company uses the Services without a separately signed data processing agreement. Where Bitfront AB and the Company have entered into a written data processing agreement covering the Services, that agreement applies instead of this one.
1. Definitions
"Company Personal Data" means any Personal Data processed by a Contracted Processor on behalf of the Company under the Principal Agreement. "Contracted Processor" means a Subprocessor. "Data Protection Laws" means EU Data Protection Laws and, where applicable, the data protection laws of any other relevant country. "EEA" means the European Economic Area. "GDPR" means EU General Data Protection Regulation 2016/679. "Services" means the Bytesafe services that Bitfront AB provides to the Company under the Principal Agreement. "Subprocessor" means any person appointed by the Processor to process Personal Data on behalf of the Company.
The terms "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing", and "Supervisory Authority" have the same meaning as in the GDPR.
2. Processing of company personal data
The Processor shall comply with all applicable Data Protection Laws in the Processing of Company Personal Data, and shall not Process Company Personal Data other than on the Company's documented instructions, including with regard to transfers of Company Personal Data to a third country or an international organization, unless required to do so by Union or Member State law to which the Processor is subject. Where such a requirement applies, the Processor shall inform the Company of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
The Company instructs the Processor to process Company Personal Data as necessary to deliver the Services.
The Processor shall immediately inform the Company if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
3. Processor personnel
The Processor shall take reasonable steps to ensure the reliability of any employee, agent, or contractor who may have access to Company Personal Data. Access is strictly limited to those who need it to fulfill obligations under the Principal Agreement. All such individuals are subject to confidentiality undertakings or professional obligations of confidentiality.
4. Security
Taking into account the state of the art, implementation costs, and the nature, scope, and context of Processing, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including measures referred to in Article 32(1) of the GDPR.
The measures in place are described on the Security page.
5. Subprocessing
The Company gives the Processor general written authorization to engage Subprocessors. The current list of Subprocessors is published on our Subprocessors page.
The Processor shall inform the Company of any intended addition or replacement of a Subprocessor by updating that page at least 30 days before the change takes effect. The Company may object to the change on reasonable grounds relating to data protection, by written notice to the Processor within that period. Where the Parties cannot resolve the objection, the Company may terminate the affected subscription.
The Processor shall impose on each Subprocessor, by written contract, data protection obligations no less protective than those set out in this Agreement, and remains fully liable to the Company for the performance of each Subprocessor's obligations.
6. Data subject rights
The Processor shall assist the Company by implementing appropriate technical and organizational measures to fulfill the Company's obligations to respond to Data Subject rights requests under applicable Data Protection Laws.
The Processor shall promptly notify the Company of any Data Subject request received, and shall not respond to such requests except on the Company's documented instructions, or as required by applicable law.
7. Personal data breach
The Processor shall notify the Company without undue delay, and in any event within 72 hours, upon becoming aware of a Personal Data Breach affecting Company Personal Data, providing sufficient information for the Company to meet any reporting obligations under applicable Data Protection Laws.
The Processor shall cooperate with the Company to investigate, mitigate, and remediate any such breach.
8. Data protection impact assessments
The Processor shall provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities where the Company reasonably considers these required under Article 35 or 36 of the GDPR.
9. Deletion or return of data
At the choice of the Company, the Processor shall delete or return all Company Personal Data to the Company after the end of the provision of Services relating to Processing, and shall delete existing copies, unless Union or Member State law requires storage of the personal data.
The Company may export its data from the Services during the subscription and for 30 days after it ends. The Processor shall complete deletion or return of production data within 30 days after the end of that export period.
Company Personal Data contained in routine encrypted backups is deleted on expiry of the applicable backup retention cycle, and in any event within 90 days after the end of the export period. Until deletion, that data remains subject to this Agreement and is not actively Processed for any other purpose. Written certification of deletion is available on request.
10. Information and audit
The Processor shall make available to the Company all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, including the description of processing in Section 14, the security measures published on the Security page, the Subprocessor list, and responses to reasonable written questions.
Where the Company requires an audit or inspection to meet an obligation under Article 28(3)(h) of the GDPR, the Parties shall agree its scope, timing, and cost in advance. Any such audit shall be conducted remotely, no more than once in any twelve (12) month period, at the Company's cost, subject to confidentiality obligations, and on at least thirty (30) days' written notice. The Processor is not required to provide access to source code, infrastructure, identity and access management configuration, account identifiers, or data belonging to any other customer.
11. Data transfers
The Processor processes Company Personal Data within the European Union and does not store it outside the EU/EEA. The Processor selects an EU region for every Subprocessor that offers a choice of region.
Where a Subprocessor is established outside the EEA and may therefore access Company Personal Data from outside it, the Processor shall ensure the transfer is covered by an adequacy decision under Article 45 GDPR or by appropriate safeguards under Article 46 GDPR, including the EU Standard Contractual Clauses, and shall identify the Subprocessor and the mechanism relied on in the list published under Section 5.
12. Confidentiality
Each Party must keep this Agreement and information received about the other Party confidential, and may not use or disclose it without prior written consent, except where disclosure is required by law or where the information is already in the public domain.
13. Term
This Agreement remains in effect for as long as Bitfront AB carries out Personal Data processing operations on behalf of the Company, or until termination of the Services subscription and deletion of all Personal Data in accordance with Section 9.
14. Description of the processing
Subject matter: provision of the Services.
Duration: the period during which the Company holds an active subscription, and thereafter as set out in Section 9.
Nature and purpose: hosting, storage, access control, logging, and support necessary to make the Services available, to authenticate users, to record and audit usage, and to provide support.
Types of personal data: name; business email address; user identifier; authentication and session metadata; role and permission assignments; IP address; audit log records of actions taken in the Services; support correspondence.
Categories of Data Subjects: the Company's employees and individual contractors who use the Services, and the Company's administrative and billing contacts.
Special categories of personal data: none. The Company shall not submit special category data as defined in Article 9 GDPR, criminal conviction data under Article 10 GDPR, or personal data of children.
15. Governing law
This Agreement is governed by the laws of Sweden. Disputes that cannot be resolved amicably will be settled by a Swedish court of general jurisdiction, with the Stockholm District Court as court of first instance.