Juridik & förtroende

Data Processing (DPA Outline)

The outline of the data processing agreement (DPA) used for B2B engagements where Rexora processes personal data on a client's behalf. The signed DPA for each engagement prevails.

Operativt utkast — granskning av ägare/jurist krävs. Den här texten är ett arbetsutkast framtaget för granskning och utgör ännu inte granskad juridisk rådgivning. Vid avvikelser har den engelska versionen företräde (English version prevails).

1. Roles

The client is the controller of its business data; Rexora acts as processor for the agreed workflows. Where Rexora processes its own correspondence and contracts, it acts as an independent controller.

2. Scope and instructions

3. Subprocessors

4. Security measures

5. Retention and deletion

Retention periods are agreed per engagement. On termination or on request, personal data is deleted or returned, and deletion is confirmed in writing.

6. Incidents and audits

Personal data breaches are notified to the client without undue delay. The client may audit compliance as agreed in the DPA (typically via documentation and written answers first).

Alla juridiska dokument