# Data Processing Agreement

Last updated: September 21, 2026

This Data Processing Agreement (“DPA”) forms part of the [Terms of Service](/terms) (the “Terms”) between Dibbla AB (“Dibbla”) and the customer that accepts the Terms (the “Customer”). It sets out the terms under which Dibbla processes Personal Data on the Customer’s behalf as a processor under Article 28 of the EU General Data Protection Regulation (“GDPR”). It applies to the managed Dibbla platform (the “Service”) and is binding on both parties when the Customer accepts the Terms. No signature is required. A Swedish version is available at [dibbla.com/dpa/sv](/dpa/sv); in the event of any inconsistency, the English version prevails.

## 1\. Definitions

“Personal Data”, “Controller”, “Processor”, “Processing”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data contained in Customer Data (as defined in the Terms) that Dibbla processes on the Customer’s behalf, including Personal Data belonging to the Customer’s own end users. “Sub-processor” means a third party engaged by Dibbla to process Customer Personal Data. Capitalised terms not defined here have the meanings given in the Terms.

## 2\. Roles and scope

For Customer Personal Data, the Customer is the Controller (or, where the Customer acts on behalf of a third party, a Processor) and Dibbla is the Processor. The Customer is responsible for the lawfulness of the Personal Data it and its end users bring to the Service, for having a legal basis for the Processing, and for informing Data Subjects as required. Where the Customer is itself a Processor, it warrants that its instructions to Dibbla are covered by its own agreement with the Controller.

This DPA does not cover the Personal Data Dibbla processes as a Controller for its own purposes — account details, billing, support correspondence and usage data needed to operate and secure the Service. That Processing is described in the [Privacy Policy](/privacy).

## 3\. Subject matter, duration, nature and purpose

The subject matter of the Processing is the hosting and operation of the applications, databases, storage, workflows and related resources the Customer deploys to the Service. The Processing lasts for the term of the Terms plus the deletion period in Section 10. The nature and purpose of the Processing, the categories of Data Subjects and the types of Personal Data are described in Annex 1.

## 4\. Instructions

Dibbla processes Customer Personal Data only on documented instructions from the Customer, unless required to do so by EU or Member State law, in which case Dibbla informs the Customer of that legal requirement before Processing, unless the law prohibits it. The Terms, this DPA and the Customer’s use of the Service’s features — including deploying an application, provisioning a database, configuring a workflow, enabling an integration or AI feature, and deleting a resource — constitute the Customer’s complete instructions. Additional instructions are agreed in writing. Dibbla informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

Dibbla does not use Customer Personal Data for its own purposes, does not sell it, and does not use it to train general-purpose AI models.

## 5\. Confidentiality

Dibbla ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary to provide, support and secure the Service.

## 6\. Security

Dibbla implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including the measures described in Annex 2. Dibbla may update these measures over time, provided the overall level of protection is not reduced. Dibbla’s current security description is published on [dibbla.com/enterprise](/enterprise) and in the Privacy Policy. The Customer is responsible for the security of the applications it deploys, for the access it grants to its own users and connected AI agents, and for choosing appropriate settings within the Service.

## 7\. Sub-processors

The Customer gives Dibbla a general authorisation to engage Sub-processors. The Sub-processors currently engaged are listed in Dibbla’s [Sub-processor List](/subprocessors), which is published at dibbla.com/subprocessors and incorporated into this DPA by reference. The list states which Sub-processors apply to every customer (such as infrastructure and authentication providers) and which apply only when the Customer enables an optional feature, such as a specific AI model provider.

Dibbla gives the Customer at least thirty (30) days’ notice before a new Sub-processor starts processing Customer Personal Data, by updating the Sub-processor List and sending notice to the Customer’s registered contact or subscribers to the list. The Customer may object in writing to [privacy@dibbla.com](mailto:privacy@dibbla.com) on reasonable data protection grounds within the notice period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected part of the Service, or the Terms, with immediate effect and without penalty, and Section 10 applies. Dibbla imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of its Sub-processors.

## 8\. Assistance

Taking into account the nature of the Processing, Dibbla assists the Customer with appropriate technical and organisational measures in responding to requests from Data Subjects exercising their rights under Chapter III of the GDPR. If Dibbla receives such a request directly, it forwards it to the Customer without undue delay and does not respond to it except on the Customer’s instruction or where required by law. Dibbla also assists the Customer, taking into account the nature of the Processing and the information available to Dibbla, in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation). Assistance that goes materially beyond the functions of the Service may be charged at Dibbla’s then-current rates.

## 9\. Personal Data Breach

Dibbla notifies the Customer without undue delay, and no later than forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice describes, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases as it becomes available. Dibbla cooperates with the Customer and takes reasonable steps to contain and remediate the breach. Notifying the Supervisory Authority and Data Subjects is the Customer’s responsibility as Controller.

## 10\. Deletion and return

During the term the Customer can export its Customer Data at any time in open, machine-readable formats, and delete applications, databases, storage and organisations through the Service, as described in Section 12 of the Terms. When the Terms terminate, the Customer chooses whether Dibbla returns or deletes the Customer Personal Data: Customer Data remains available for export during the retrieval period of at least thirty (30) days set out in the Terms, after which Dibbla deletes all Customer Personal Data within thirty (30) days and confirms the deletion on request, unless EU or Member State law requires it to be retained. Copies in backups are deleted in accordance with the backup retention periods published in the Privacy Policy.

## 11\. Audits

Dibbla makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are conducted no more than once per twelve (12) months, unless required by a Supervisory Authority or following a Personal Data Breach, on at least thirty (30) days’ written notice, during business hours, in a manner that does not unreasonably disrupt the Service or compromise the security of other customers, and subject to reasonable confidentiality obligations. Dibbla first satisfies audit requests through documentation, third-party audit reports and written responses where these reasonably address the request. The Customer bears its own audit costs.

## 12\. International transfers

Dibbla stores Customer Personal Data in the European Union. Dibbla does not transfer Customer Personal Data to a country outside the EU/EEA, and does not permit a Sub-processor to do so, unless the transfer is covered by an adequacy decision or by the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented where necessary by additional measures, or another transfer mechanism recognised under Chapter V GDPR. The Sub-processor List states the location of Processing and the transfer mechanism for each Sub-processor. Where an optional AI feature routes data to a provider outside the EU/EEA, this is stated in the list, and the Processing takes place only if the Customer enables that feature.

## 13\. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms, except to the extent liability cannot be limited under applicable law. Nothing in this DPA limits either party’s liability to Data Subjects under Article 82 GDPR.

## 14\. Term, changes and precedence

This DPA enters into force when the Customer accepts the Terms and remains in force for as long as Dibbla processes Customer Personal Data. Dibbla may update this DPA to reflect changes in law, in the Service or in the Sub-processor List; the current version, with its effective date, is always published at [dibbla.com/dpa](/dpa), and Section 14 of the Terms applies to material changes. In the event of a conflict, this DPA prevails over the Terms with respect to the Processing of Customer Personal Data. If a customer-specific data processing agreement has been signed by both parties, that agreement prevails over this DPA.

## 15\. Governing law and supervisory authority

This DPA is governed by the laws of Sweden, and disputes are resolved as set out in the Terms. Dibbla’s lead Supervisory Authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). Nothing in this DPA prevents a Data Subject from lodging a complaint with a Supervisory Authority.

## 16\. Contact

**Dibbla AB**  
Stockholm, Sweden  
Email: [privacy@dibbla.com](mailto:privacy@dibbla.com)  
Website: [dibbla.com](https://dibbla.com)

## Annex 1 — Details of the Processing

Item

Description

Nature and purpose

Hosting, storing, executing, backing up, transmitting, monitoring and otherwise processing Customer Data as needed to run the applications, databases, storage, workflows and scheduled jobs the Customer deploys, including the optional AI features the Customer enables, and to provide support at the Customer’s request.

Duration

The term of the Terms, plus the deletion period in Section 10.

Categories of Data Subjects

Determined by the Customer. Typically the Customer’s employees, contractors and users of the Customer’s applications (end users), and third parties whose data the Customer stores in the Service.

Types of Personal Data

Determined by the Customer. Typically identity and contact details (name, e-mail address), account and login data, application content and records, logs, and any other Personal Data the Customer’s applications store or process. Special categories of Personal Data (Article 9 GDPR) may be processed only where the Customer has a legal basis and has implemented appropriate safeguards in its application.

Location

European Union. See Section 12 for transfers.

## Annex 2 — Technical and organisational measures

-   **Encryption:** all data in transit is protected with TLS; sensitive data at rest is encrypted.
-   **Isolation:** each customer organisation is logically separated, with role-based access control and organisation-level isolation of data, network and secrets.
-   **Access control:** access to production systems is restricted to authorised Dibbla personnel, granted on a least-privilege basis and reviewed regularly; authentication uses secure, HTTP-only session cookies with CSRF protection and short-lived tokens.
-   **Auditability:** deployments and administrative actions are logged with the acting user; actions taken by a connected AI agent are attributed to the user who authorised it.
-   **Review on deploy:** every deployment goes through a code review gate covering common web application security risks.
-   **Availability and recovery:** databases are backed up regularly and the platform runs on redundant infrastructure within the EU.
-   **Vulnerability and incident management:** platform components are kept up to date, and Dibbla maintains an incident process that includes the breach notification in Section 9.
-   **Personnel:** personnel with access to Customer Personal Data are bound by confidentiality and receive security and data protection guidance.
-   **Deletion:** deletion of an application, database, storage bucket or organisation removes the data from the Service, with backups expiring according to the published retention periods.
