Data Processing Addendum (DPA)
These documents form part of KFN Media's legal framework and may be updated periodically.
Parties
This Data Processing Agreement (“Agreement”) is entered into between KFN Media (“Processor”) and the client organisation (“Controller”). This Agreement applies where KFN Media processes personal data on behalf of the Controller in connection with the provision of digital services.
Purpose and Scope
The purpose of this Agreement is to define the rights and obligations of the parties regarding the processing of personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
KFN Media processes personal data solely for the purpose of delivering agreed services, including but not limited to software development, hosting, infrastructure management, automation systems, AI integrations, SEO services, and technical support.
Relationship to the Terms of Service
This Agreement forms part of and must be read together with KFN Media's Terms of Service. In the event of conflict, the order of precedence set out in the Terms of Service applies.
Roles of the Parties
The Controller determines the purposes and means of processing personal data.
The Processor processes personal data only on documented instructions from the Controller unless required by law.
Types of Personal Data
Depending on the services provided, the Processor may process the following categories of data:
- Contact information (name, email, phone number)
- Business information (company name, job title)
- Technical data (IP addresses, device data, logs)
- User-generated or client-provided content
- System and usage data
No sensitive personal data is intentionally processed unless explicitly agreed in writing.
Categories of Data Subjects
Data subjects may include:
- Client employees and representatives
- End-users of client systems or platforms
- Website visitors or customers of the Controller
Processing Activities
Processing may include:
- Storage and hosting of data
- Transmission and communication of data
- Technical processing for system functionality
- Backup and recovery operations
- Security monitoring and logging
Confidentiality
The Processor ensures that all personnel authorised to process personal data are bound by confidentiality obligations and only access data as necessary for service delivery.
Security Measures
The Processor implements appropriate technical and organisational security measures, including but not limited to:
- Encryption of data in transit and at rest where applicable
- Access control and authentication mechanisms
- Logging and monitoring of system activity
- Regular updates and vulnerability management
- Secure hosting and infrastructure practices
However, no system can guarantee absolute security.
Subprocessors
The Processor may engage third-party subprocessors (such as hosting providers, cloud services, analytics tools, or communication platforms) to support service delivery.
All subprocessors are required to maintain appropriate data protection and security standards.
The Processor remains responsible for ensuring GDPR-compliant processing by subprocessors.
International Transfers
Personal data may be transferred and processed outside the European Economic Area (EEA). Where such transfers occur, appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms will be applied.
Assistance to Controller
The Processor shall assist the Controller, where reasonably possible, in fulfilling obligations under GDPR, including:
- Data subject access requests
- Requests for rectification or deletion
- Data portability requests
- Security and breach notifications
Data Retention and Deletion
Personal data will be retained only for the duration necessary to provide services or comply with legal obligations.
Upon termination of services, personal data will be deleted or returned to the Controller upon request, unless retention is required by law.
Data Breach Notification
In the event of a personal data breach affecting processed data, the Processor will notify the Controller without undue delay after becoming aware of the breach and will provide relevant information to support compliance with legal obligations.
Audits and Compliance
Upon reasonable request, the Processor may provide information necessary to demonstrate compliance with this Agreement. Formal audits may be agreed separately in writing.
Limitation of Liability
To the maximum extent permitted by law, liability arising under this Agreement is subject to the limitation of liability provisions in the main Terms of Service between the parties.
Term and Termination
This Agreement remains in effect for the duration of the service relationship. Upon termination, data processing obligations will continue for any data retained under legal obligations until deletion is completed.
Governing Law
This Agreement is governed by the laws of Sweden. Any disputes shall be resolved in Swedish courts unless mandatory law provides otherwise.