Data Processing Agreement
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.
1. Parties & role allocation
This Data Processing Agreement ("DPA") is entered into between:
and
together the "Parties".
The Customer is the controller of the personal data processed via the SimpleSecurity service (the "Service"). SimpleSecurity acts as the processor on the Customer's behalf and processes personal data solely for the purpose of, and to the extent necessary to, provide the Service.
This DPA forms part of, and is incorporated into, the agreement between the Parties governing the Customer's use of the Service (the "Terms of Service" or "Service Agreement"). In the event of any conflict between this DPA and the Terms of Service on matters of data protection, this DPA prevails (see Section 8).
2. Definitions
Terms used in this DPA have the meaning given to them in Regulation (EU) 2016/679 ("GDPR"). In particular:
- "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings set out in GDPR Art. 4.
- "Sub-processor" means any processor engaged by SimpleSecurity to process personal data on behalf of the Customer in connection with the Service.
- "Annex 1" means the Technical & Organisational Measures document at toms.html.
- "Annex 2" means the Sub-processor list at subprocessors.html.
3. Subject matter, duration, nature & purpose of processing
SimpleSecurity provides a Swedish SaaS security-compliance platform covering CMDB asset inventory, uptime and SSL/TLS certificate monitoring, vulnerability scanning, a risk register, an incident register, vendor/third-party risk assessments, a policy register, and compliance-framework mapping (ISO 27001, SOC 2, NIS2, MSBFS 2020:6-8). The Service is delivered as serverless software on AWS in the eu-north-1 (Stockholm, Sweden) region.
Subject matter: the processing of personal data by SimpleSecurity as necessary to provide the Service to the Customer.
Duration: for as long as the Service Agreement is in effect, and thereafter only as required to fulfil the deletion/return obligations in Section 5(g) or applicable statutory retention periods (see Section 5(g) and Annex 1).
Nature of processing: collection, storage, organisation, structuring, retrieval, use, transmission, erasure and destruction of personal data by automated means, as required to operate the Service (account management and authentication, tenant-scoped data storage and retrieval, monitoring and scanning, notification delivery, billing).
Purpose: to provide, maintain, secure and support the Service for the Customer, including authenticating the Customer's users, storing and processing data the Customer enters into the platform, running the Customer's configured monitoring/scanning jobs, and processing subscription billing.
4. Categories of data subjects & categories of personal data
Categories of data subjects
- The Customer's authorised users and organisation administrators.
- Individuals whose personal data the Customer enters into the Service in the course of normal use — for example, contacts named in CMDB asset records, incident records, vendor records, or policy documents.
Categories of personal data
- Account data: names, business email addresses, authentication data (Cognito-managed credentials, MFA status).
- Access & usage data: IP addresses and log/audit data generated by use of the Service.
- Any personal data the Customer chooses to enter into the platform's records — e.g. CMDB asset records, incidents, risk entries, vendor records, or policy documents — which is determined entirely by the Customer and outside SimpleSecurity's control.
No special categories of personal data (GDPR Art. 9) are intentionally processed by the Service. The Customer is responsible for not entering special category data into free-text fields.
5. Processor obligations
SimpleSecurity shall, in respect of personal data processed on behalf of the Customer:
(a) Process only on documented instructions
Process personal data only on the Customer's documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by EU or Member State law to which SimpleSecurity is subject — in which case SimpleSecurity shall inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
(b) Confidentiality
Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(c) Security of processing
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Art. 32, as described in Annex 1 – Technical & Organisational Measures.
(d) Sub-processors
Engage sub-processors only under the conditions set out in Section 6 below.
(e) Data subject rights
Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising a data subject's rights under GDPR Chapter III.
(f) Assistance with Art. 32–36
Assist the Customer in ensuring compliance with the obligations under GDPR Art. 32 to 36, taking into account the nature of processing and the information available to SimpleSecurity, including assistance with personal data breach notifications. SimpleSecurity notifies affected customers of a personal data breach without undue delay and in any case within 72 hours of becoming aware of it, with the information required by GDPR Art 33(3).
(g) Deletion or return of data
At the choice of the Customer, delete or return all personal data to the Customer after the end of the provision of Service, and delete existing copies unless EU or Member State law requires storage. In practice: organisation administrators can permanently delete their entire organisation (all users, assets, monitors, incidents, policies including uploaded documents, vendor records and settings) self-service from the dashboard (User Management → Security → Danger Zone) with typed confirmation. Deletion is also honoured on written request to security@simplesecurity.se within 30 days. Billing records are retained for 7 years as required by the Swedish Bookkeeping Act (bokföringslagen 1999:1078).
(h) Audits & information
Make available to the Customer all information necessary to demonstrate compliance with the obligations in this Section 5, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to the following:
- SimpleSecurity will first provide relevant documentation and reports (e.g. this DPA, Annex 1, Annex 2, and available compliance-mapping documentation) to satisfy an audit request where possible.
- On-site or remote technical audits are limited to once per calendar year, unless required otherwise by a supervisory authority, and require at least 30 days' advance written notice.
- Audits are conducted at the Customer's cost, during normal business hours, without unreasonably disrupting SimpleSecurity's operations, and subject to confidentiality obligations protecting SimpleSecurity's and its other customers' information.
6. Sub-processors
The Customer grants SimpleSecurity general written authorisation to engage sub-processors to support delivery of the Service. The current list of sub-processors is maintained in Annex 2 – Sub-processor list.
SimpleSecurity will give the Customer at least 30 days' advance notice (via the Annex 2 page and by email to organisation administrators) before authorising any new sub-processor or replacing an existing one, and the Customer may object on reasonable data-protection grounds within that notice period.
Where SimpleSecurity engages a sub-processor, SimpleSecurity imposes data protection obligations on that sub-processor that are no less protective than those set out in this DPA, and remains fully liable to the Customer for the sub-processor's performance of its data-protection obligations.
7. International transfers
By design, no international transfers of personal data occur: all processing and storage of Customer personal data takes place exclusively in AWS eu-north-1 (Stockholm, Sweden). The only exception is that the configuration object for the AWS WAF web-ACL protecting the CloudFront distribution resides in AWS us-east-1, as required by AWS's platform architecture for CloudFront-scoped WAFs — this is rule configuration only and does not involve storage of customer personal data.
If a future change to the sub-processor list (Section 6, Annex 2) would introduce a transfer of personal data to a third country, SimpleSecurity will ensure a valid GDPR Chapter V transfer mechanism (such as the European Commission's Standard Contractual Clauses, or an applicable adequacy decision) is in place before any such transfer takes place.
8. Liability, precedence, term & governing law
Precedence: in the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
Liability: each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
Term: this DPA takes effect on the date it is agreed (or, where accepted by reference, on the date the Terms of Service are accepted) and remains in effect for as long as SimpleSecurity processes personal data on behalf of the Customer under the Service Agreement.
Governing law: this DPA is governed by the laws of Sweden. The relevant supervisory authority is Integritetsskyddsmyndigheten (IMY, imy.se).
9. Annexes
- Annex 1 – Technical & Organisational Measures
- Annex 2 – Sub-processor list
See also Data Retention and Incident Response for further detail referenced elsewhere in this DPA.
10. Signatures
This DPA may be executed by the Parties below, or is deemed accepted by reference when the Customer accepts the SimpleSecurity Terms of Service, without requiring a separate signed copy.
For the Customer (Controller)
Signature
For SimpleSecurity (Processor)
Signature