Processor addendum covering roles, subject matter, categories, security, subprocessors, transfers, assistance, incident handling, deletion, and audit support.
Version 1.2 · Effective July 3, 2026
Status: Customer-facing information
Contact: info@sefira.se
This Data Processing Addendum ("DPA") forms part of the agreement between Sefira and the customer for the provision of the Sefira service (the "Agreement").
This DPA applies where Sefira processes Customer Personal Data on behalf of Customer as processor.
For purposes of this DPA:
For Customer Personal Data, Customer acts as controller and Sefira acts as processor.
Sefira shall process Customer Personal Data only on documented instructions from Customer, unless otherwise required by applicable Union or Member State law. Where Sefira is required by law to process Customer Personal Data other than on Customer’s instructions, Sefira shall inform Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
Sefira Controller Data is outside the processor scope of this DPA and is described in the privacy notice and related service terms.
The subject matter of the processing is the provision, operation, support, security, and improvement of the Sefira service under the Agreement.
The nature and purpose of the processing may include:
The processing shall continue for the term of the Agreement and for any limited post-termination period required to return, delete, anonymize, retain, or evidence data in accordance with the Agreement, this DPA, and applicable law.
Depending on Customer’s use of the service, Customer Personal Data may relate to:
Depending on Customer’s use of the service, Customer Personal Data may include:
Customer instructs Sefira to process Customer Personal Data as necessary to:
Customer is responsible for:
If Sefira considers that an instruction from Customer infringes applicable data protection law, Sefira shall inform Customer without undue delay.
Sefira shall ensure that persons authorized to process Customer Personal Data:
Sefira shall implement appropriate technical and organizational measures designed to protect Customer Personal Data in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to natural persons.
Those measures shall include, as appropriate to the relevant service path:
The parties agree that the more detailed technical and organizational measures may be described in an annex, security schedule, or equivalent customer package materials, including the Security White Paper and customer-specific diligence responses where applicable.
Customer grants Sefira a general authorization to engage Subprocessors in connection with the service.
Sefira shall:
/subprocessors;Customer may object to a new Subprocessor on reasonable data protection grounds. Where Customer raises a reasonable objection, the parties shall work in good faith to address the concern through a commercially reasonable alternative, a restriction of the affected feature path, or another reasonable solution. If no reasonable solution is available, either party may address the affected processing path under the Agreement.
Where Customer Personal Data is transferred outside the EEA or another restricted-transfer jurisdiction, Sefira shall ensure that such transfer is subject to an applicable lawful transfer mechanism, including adequacy decisions, the EU Standard Contractual Clauses, or another valid mechanism under applicable data protection law.
Where relevant to the transfer path, Sefira shall apply supplementary safeguards appropriate to the circumstances and shall make transfer-path information available through the Subprocessor List or customer diligence materials where the processing path depends on enabled features or configured providers.
Taking into account the nature of the processing and the information available to Sefira, Sefira shall provide reasonable assistance to Customer to enable Customer to respond to requests from data subjects exercising their rights under applicable data protection law.
Taking into account the nature of the processing and the information available to Sefira, Sefira shall provide reasonable assistance to Customer with:
If Sefira becomes aware of a Personal Data Breach affecting Customer Personal Data, Sefira shall:
Unless otherwise agreed in writing, Sefira will aim to provide initial notice within 72 hours after confirming that Customer Personal Data is affected.
The notice may include, as available at the relevant time:
Upon termination or expiry of the Agreement, Sefira shall, at Customer’s choice and subject to the Agreement and applicable law, delete or return Customer Personal Data, unless applicable law requires storage of some or all Customer Personal Data.
The parties acknowledge that the service includes retained-history, audit, and integrity-sensitive records. Accordingly:
The parties may supplement this DPA with a more detailed retention and deletion schedule describing default retention by data class, deletion path, backup handling, and justified exceptions.
Where Customer enables AI-assisted features, Sefira may process Customer Personal Data through AI-related service paths strictly as part of providing the enabled feature.
Sefira shall identify AI-related providers through the Subprocessor List and related customer-facing materials where those providers process Customer Personal Data on behalf of Customer.
Unless expressly agreed otherwise in writing, Sefira shall not use Customer Personal Data to train general-purpose AI models for its own independent purposes.
Customer remains responsible for deciding whether AI-assisted features are enabled for its environment and whether Customer Personal Data may be submitted into those feature paths.
Sefira shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA.
For most customers, this may be satisfied in the first instance through:
Where required by applicable law or reasonably necessary to demonstrate compliance, Sefira shall allow for audits or inspections, subject to reasonable notice, confidentiality obligations, security restrictions, proportionality, and measures designed to avoid disruption to Sefira’s operations or exposure of other customers’ data.
Sefira may satisfy overlapping audit requests through shared audit artifacts, questionnaires, certifications, or summaries where appropriate. Customer shall bear its own audit costs except where otherwise required by applicable law or agreed in writing.
The DPA package may include, at minimum: