Personuppgiftsbiträdesavtal

1. Background and parties

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between OrbGIS AB, org. no. 559598-2785, Olaus Magnus väg 48, 121 38 Johanneshov, Sweden (“the Processor”, “we”) and the organization using the OrbGIS service (“the Controller”, “Customer”). It implements Article 28(3) of Regulation (EU) 2016/679 (“GDPR”) for the personal data contained in Customer Content that we process on the Customer’s behalf.

For personal data we process as a controller (account data, logs, support), the Privacy Policy applies instead. If this DPA conflicts with the Terms of Service, this DPA prevails for data protection matters.

2. Subject matter and instructions

We process personal data in Customer Content solely to provide, support, and secure the service, in accordance with the Customer’s documented instructions. The Terms of Service, this DPA, and the Customer’s use of the service’s settings and features (uploading, styling, publishing, sharing, deleting) constitute the complete instructions. We will inform the Customer if, in our opinion, an instruction infringes the GDPR.

3. Confidentiality

We ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4. Security

We implement and maintain the technical and organizational measures described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, so as to ensure a level of security appropriate to the risk (Article 32 GDPR).

5. Sub-processors

The Customer grants a general authorization to engage the sub-processors listed in Annex C. We will give at least 30 days’ notice before adding or replacing a sub-processor (by email or in the service), during which the Customer may object on reasonable data protection grounds; if no solution is found, the Customer may terminate the affected service and export its data. We impose data protection obligations on sub-processors equivalent to those in this DPA and remain fully liable for their performance.

6. Assistance to the Controller

Taking into account the nature of the processing, we will assist the Customer with appropriate technical and organizational measures in fulfilling its obligations to respond to data subject requests (Chapter III GDPR), and in ensuring compliance with Articles 32–36 (security, breach notification, impact assessments, prior consultation), insofar as the information is available to us. The service’s built-in export, editing, and deletion features are the primary means of such assistance.

7. Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and will provide the information reasonably required for the Customer to meet its own notification obligations under Articles 33–34 GDPR, as it becomes available.

8. Deletion and return

The Customer can export Customer Content in standard formats at any time. Upon termination of the service, we will delete Customer Content within 90 days, unless Union or Member State law requires storage. Copies in backups are deleted as backups rotate out. Content deleted by the Customer in the service is purged permanently after the 30-day recycle-bin window.

9. Audits

We will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer — with reasonable prior notice, during business hours, at the Customer’s expense, and no more than once per year unless a supervisory authority requires otherwise or a breach has occurred.

10. International transfers

Customer Content is stored and processed in Sweden (Annex C). Personal data is transferred outside the EU/EES only where Annex C says so and only with an appropriate transfer mechanism under Chapter V GDPR (adequacy decision, EU-U.S. Data Privacy Framework certification, or Standard Contractual Clauses).

11. Term and liability

This DPA applies for as long as we process personal data in Customer Content and automatically terminates when that processing ends. Liability is governed by the limitation of liability in the Terms of Service, to the extent permitted by mandatory law.

Annex A — Details of processing

Subject matter and natureHosting, storage, rendering, transformation (e.g. coordinate reprojection, tiling, generalization), display, and transmission of geographic data and related content uploaded to or collected via the service.
PurposeProviding the OrbGIS web GIS service to the Customer.
DurationThe term of the service agreement, plus the deletion periods in Section 8.
Categories of data subjectsDetermined by the Customer. Typically: persons appearing in uploaded geodata (e.g. property owners, residents, addresses), respondents to surveys the Customer publishes, and the Customer’s own staff appearing in content.
Categories of personal dataDetermined by the Customer. Typically: names, contact details, addresses and other location data, property/parcel identifiers, and free-text survey answers. The service is not intended for special categories of data (Art. 9 GDPR); the Customer must not upload such data without a separate written agreement.

Annex B — Technical and organizational measures

  • All data encrypted in transit (TLS 1.2+).
  • Logical tenant isolation: every organization’s data is separated by row-level security enforced in the database layer, on all tables.
  • Authentication with hashed passwords and signed, expiring session tokens.
  • Role- and privilege-based access control within each organization, managed by the Customer.
  • Administrative access to production systems restricted to authorized personnel over an encrypted private network (VPN), with key-based authentication.
  • Hosting in ISO 27001-certified data centers in Sweden (GleSYS).
  • Regular backups, including an encrypted copy kept at a secondary location in Sweden; deleted data leaves backups as they rotate out.
  • Security-relevant events logged; logs rotated on a short cycle.

Annex C — Approved sub-processors

Sub-processorLocationPurposeTransfer mechanism
GleSYS ABSwedenInfrastructure hostingNone needed (EU/EES)
Google Ireland LimitedIrelandTransactional email delivery (account confirmations, invitations, password resets)EU entity; group-internal onward transfers under Google’s Chapter V safeguards (SCCs / EU–US Data Privacy Framework)
Berget AI ABSwedenAI text generation — engaged only for content a user actively submits to an AI feature; not used to train modelsNone needed (EU/EES)

Note: basemap tiles are fetched by end users’ browsers directly from third-party map providers; those providers process end-user IP addresses as independent controllers and are not sub-processors of Customer Content.