Skip to main content
Welcome to KFN Media

Legal Centre

KFN Media's legal framework

Data Processing Addendum (DPA)

Version 1.0Last updated: 30 December 2025

These documents form part of KFN Media's legal framework and may be updated periodically.

Parties

This Data Processing Agreement (“Agreement”) is entered into between KFN Media (“Processor”) and the client organisation (“Controller”). This Agreement applies where KFN Media processes personal data on behalf of the Controller in connection with the provision of digital services.

Purpose and Scope

The purpose of this Agreement is to define the rights and obligations of the parties regarding the processing of personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).

KFN Media processes personal data solely for the purpose of delivering agreed services, including but not limited to software development, hosting, infrastructure management, automation systems, AI integrations, SEO services, and technical support.

Relationship to the Terms of Service

This Agreement forms part of and must be read together with KFN Media's Terms of Service. In the event of conflict, the order of precedence set out in the Terms of Service applies.

Roles of the Parties

The Controller determines the purposes and means of processing personal data.

The Processor processes personal data only on documented instructions from the Controller unless required by law.

Types of Personal Data

Depending on the services provided, the Processor may process the following categories of data:

  • Contact information (name, email, phone number)
  • Business information (company name, job title)
  • Technical data (IP addresses, device data, logs)
  • User-generated or client-provided content
  • System and usage data

No sensitive personal data is intentionally processed unless explicitly agreed in writing.

Categories of Data Subjects

Data subjects may include:

  • Client employees and representatives
  • End-users of client systems or platforms
  • Website visitors or customers of the Controller

Processing Activities

Processing may include:

  • Storage and hosting of data
  • Transmission and communication of data
  • Technical processing for system functionality
  • Backup and recovery operations
  • Security monitoring and logging

Confidentiality

The Processor ensures that all personnel authorised to process personal data are bound by confidentiality obligations and only access data as necessary for service delivery.

Security Measures

The Processor implements appropriate technical and organisational security measures, including but not limited to:

  • Encryption of data in transit and at rest where applicable
  • Access control and authentication mechanisms
  • Logging and monitoring of system activity
  • Regular updates and vulnerability management
  • Secure hosting and infrastructure practices

However, no system can guarantee absolute security.

Subprocessors

The Processor may engage third-party subprocessors (such as hosting providers, cloud services, analytics tools, or communication platforms) to support service delivery.

All subprocessors are required to maintain appropriate data protection and security standards.

The Processor remains responsible for ensuring GDPR-compliant processing by subprocessors.

International Transfers

Personal data may be transferred and processed outside the European Economic Area (EEA). Where such transfers occur, appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms will be applied.

Assistance to Controller

The Processor shall assist the Controller, where reasonably possible, in fulfilling obligations under GDPR, including:

  • Data subject access requests
  • Requests for rectification or deletion
  • Data portability requests
  • Security and breach notifications

Data Retention and Deletion

Personal data will be retained only for the duration necessary to provide services or comply with legal obligations.

Upon termination of services, personal data will be deleted or returned to the Controller upon request, unless retention is required by law.

Data Breach Notification

In the event of a personal data breach affecting processed data, the Processor will notify the Controller without undue delay after becoming aware of the breach and will provide relevant information to support compliance with legal obligations.

Audits and Compliance

Upon reasonable request, the Processor may provide information necessary to demonstrate compliance with this Agreement. Formal audits may be agreed separately in writing.

Limitation of Liability

To the maximum extent permitted by law, liability arising under this Agreement is subject to the limitation of liability provisions in the main Terms of Service between the parties.

Term and Termination

This Agreement remains in effect for the duration of the service relationship. Upon termination, data processing obligations will continue for any data retained under legal obligations until deletion is completed.

Governing Law

This Agreement is governed by the laws of Sweden. Any disputes shall be resolved in Swedish courts unless mandatory law provides otherwise.