Data processing agreement
Last updated: 8 June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of service between Abiton Ventures AB (“Maditon”, “we”, the processor) and the organisation that uses the Service (the “Customer”, the controller). It governs our processing of personal data on the Customer’s behalf and is concluded pursuant to Article 28 GDPR (Regulation (EU) 2016/679). Where this DPA conflicts with the Terms of service on data protection, this DPA prevails.
1. Roles of the parties
The Customer is the controller of the personal data it and its users put into the Service (“Customer Content”) — for example the AI systems it describes, the evidence files it uploads, and the colleagues it identifies. Maditon acts as the Customer’s processor for that Customer Content. For account, authentication, and billing data Maditon is an independent controller; that processing is described in our Privacy policy and is not governed by this DPA.
2. Subject matter, duration, nature, and purpose
We process Customer Content only to provide the Service — preparing draft EU AI Act risk classifications, compliance documents, and learning content, and storing the records the Customer creates. The processing lasts for the term of the subscription and the 30-day export window after it ends.
3. Personal data and data subjects
The Customer decides what it puts into the Service. Typically the personal data is limited to business contact details of the Customer’s own staff (names, work emails, roles) and any personal data the Customer chooses to include in system descriptions or evidence files. Data subjects are the Customer’s employees and authorised users. The Service is not designed for special categories of data (Article 9 GDPR); the Customer should not upload them.
4. Our obligations as processor
In line with Article 28(3) GDPR, we will:
- process Customer Content only on the Customer’s documented instructions — the Terms of service, this DPA, and the use of the Service’s features are those instructions — unless EU or Member State law requires otherwise, in which case we inform the Customer first unless that law forbids it;
- ensure that people authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Schedule 2 (Article 32 GDPR);
- respect the conditions in Section 5 for engaging sub-processors;
- assist the Customer, by appropriate technical and organisational measures, to respond to data-subject requests — the in-product export and deletion tools cover access, portability, and erasure directly;
- assist the Customer with security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36 GDPR);
- at the Customer’s choice, delete or return all Customer Content at the end of the service (Section 7); and
- make available the information needed to demonstrate compliance and allow for audits (Section 8).
5. Sub-processors
The Customer gives general authorisation for us to engage the sub-processors listed in Schedule 1. Each is bound by a written contract imposing data-protection obligations equivalent to this DPA. We remain fully liable to the Customer for a sub-processor’s performance. We will give at least 30 days’ notice before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds, and if we cannot resolve the objection the Customer may terminate the affected part of the Service.
6. International transfers
We process Customer Content in the EU/EEA. The only sub-processor located outside the EU/EEA is Zitadel (Switzerland), which benefits from a European Commission adequacy decision, so no additional transfer safeguards are required. We do not transfer Customer Content to the United States or to any other third country lacking an adequacy decision.
7. Personal data breach
We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Content, and will assist the Customer with its own notification obligations under Articles 33 and 34 GDPR.
8. Return and deletion
On termination the Customer can export all Customer Content itself, in machine-readable JSON or CSV, for 30 days through the self-serve tools. After that window we permanently delete or anonymise Customer Content, except where EU or Member State law requires us to retain it.
9. Audits
We will make available the information necessary to demonstrate compliance with Article 28 GDPR. The Customer may audit no more than once a year (and after a breach) on reasonable prior notice; we may satisfy an audit by providing our security documentation and third-party reports where available, to protect the confidentiality and security of other customers in our multi-tenant environment.
10. Liability and governing law
Liability under this DPA is subject to the limitations in the Terms of service. This DPA is governed by the laws of Sweden, and disputes are resolved as set out in the Terms of service.
Schedule 1 — Authorised sub-processors
Each sub-processor acts under a signed data processing agreement and processes data only for the purpose shown.
- Zitadel Cloud — identity provider, SSO, MFA — Switzerland (EU adequacy decision).
- Stripe Payments Europe Ltd — billing and payment processing — Ireland (EU).
- Brevo (Sendinblue SA) — transactional email and newsletter — France (EU).
- Mistral AI SAS — AI classification and content generation; no training on submitted data — France (EU).
- UpCloud Ltd — managed PostgreSQL (production database) — Finland (EU).
- Hetzner Online GmbH — compute and object storage — Germany / Finland (EU).
- Plausible Insights OÜ — aggregate, cookieless analytics; no personal data transmitted — Estonia (EU, hosted on Hetzner DE).
- BunnyCDN — website content delivery — Slovenia (EU-only edge nodes).
Schedule 2 — Technical and organisational measures
- Encryption: TLS in transit and encryption at rest for Customer Content.
- Access control: Zitadel-managed authentication with MFA available, role-based access, and least-privilege service credentials.
- Tenant isolation: logical separation so one customer can never read another customer’s data.
- Logging: structured audit logging of security-relevant events, retained for at least 90 days; no plaintext personal data in logs.
- Resilience: automated daily database backups with at least 30-day retention.
- Incident response: a documented runbook and a 72-hour breach-notification commitment.
Contact
Data-protection enquiries and requests to sign a countersigned copy of this DPA: privacy@maditon.com .