Den här texten finns bara på engelska.

Digilog Data Processing Agreement

Last updated: 28 September 2026

1. Parties and background

This data processing agreement (the "DPA") is made between the Customer, as controller, and Digirocket AB, org. no. 559541-5554, Midsommarvägen 23, 126 35 Hägersten, Sweden ("Digilog"), as processor. It is Appendix 1 to Digilog's Terms of Use (the "Terms") and applies when Digilog processes personal data on the Customer's behalf in providing the Service.

The DPA meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Terms defined in the GDPR have the same meaning here. If the DPA and the Terms conflict on the processing of personal data, the DPA applies.

2. Roles and scope

The Customer is controller of the personal data that it and its users enter into the Service, and decides the purposes and means of that processing. Digilog processes that data only as processor. Appendix A describes the processing.

The DPA does not cover data for which Digilog is itself controller, such as user accounts for sign-in and security, invoicing, support and marketing. Digilog's Privacy Policy covers that data.

3. The Customer's instructions and obligations

The Terms, this DPA and the Customer's use of the Service's functions are the Customer's complete documented instructions. Other instructions must be in writing, and Digilog may charge for work they cause beyond the Service.

The Customer is responsible for:

  • having a legal basis for the processing, and for informing data subjects, including its own customers, contact persons and staff;
  • the personal data entered being lawful, correct and necessary;
  • not entering special categories of personal data (such as health data), since the Service is not designed for them, or personal identity numbers unless needed;
  • the choices it makes in the Service, such as who it invites, what it sends and to whom, and which logbooks it makes public through QR codes.

4. Digilog's obligations

Digilog shall:

  • process the personal data only on the Customer's documented instructions, including with regard to transfers outside the EU/EEA, unless EU or Swedish law requires otherwise, in which case Digilog informs the Customer first where the law allows;
  • tell the Customer without delay if it believes an instruction breaks the GDPR or other data protection law;
  • ensure that everyone at Digilog who can access the personal data is bound by confidentiality;
  • help the Customer, through the Service's functions and otherwise as reasonable, to answer data subjects exercising their rights (such as access, correction, erasure and portability), and pass on any request sent to Digilog directly without answering it on the Customer's behalf;
  • help the Customer, as reasonable, with data protection impact assessments, prior consultation with the supervisory authority, and security obligations, considering the information available to Digilog;
  • not use the personal data for its own purposes. Digilog may access the personal data, also with internal tools, to the extent needed to give the Customer support, operate and secure the Service, and invoice for it, and may produce anonymised, aggregated statistics that do not identify any person or customer, for the purposes in section 5 of the Terms.

For help beyond what the Service offers, Digilog is entitled to reasonable compensation, agreed with the Customer in advance, unless the need arises from Digilog's breach of this DPA.

5. Security

Digilog takes the technical and organisational measures required by Article 32 GDPR to protect the personal data. Appendix B describes them. Digilog may change the measures as long as the overall level of protection does not fall.

6. Personal data breaches

Digilog notifies the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer's personal data. The notice describes, as far as known: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Information not available at once is provided as it becomes known.

Digilog takes reasonable steps to limit the breach and helps the Customer meet its obligations to notify the supervisory authority and data subjects. The Customer makes those notifications.

7. Sub-processors

The Customer gives Digilog general authorisation to use sub-processors. The sub-processors in use when the DPA is accepted are listed in Appendix C.

Digilog informs the Customer at least 30 days before adding or replacing a sub-processor, in the Service or by email. The Customer may object in writing on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the agreement before the change takes effect.

Digilog binds each sub-processor by written agreement to data protection obligations that give at least the protection of this DPA, and remains responsible to the Customer for the sub-processor's work.

8. Transfers outside the EU/EEA

Digilog stores and processes the personal data in Sweden, or elsewhere in the EU/EEA where necessary. A transfer outside the EU/EEA, including remote access from there, takes place only where Appendix C states it and one of the safeguards of Chapter V GDPR applies: an adequacy decision (such as the EU–US Data Privacy Framework for certified recipients) or the European Commission's standard contractual clauses with the supplementary measures needed.

9. Audits

Digilog makes available to the Customer the information needed to show compliance with this DPA. That is primarily this DPA and its appendices, and on request, written answers to reasonable questions and relevant reports from Digilog and its sub-processors.

If that is not enough, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, at most once a year and with at least 30 days' written notice. Audits take place during office hours, without disrupting operations or giving access to other customers' data. The Customer bears its own costs and pays reasonable compensation for Digilog's time, agreed in advance. Audits required by a supervisory authority, or after a personal data breach at Digilog, are not limited in this way and Digilog bears its own costs for them.

10. Term, return and deletion

The DPA applies as long as Digilog processes personal data on the Customer's behalf, including during the archive period below.

On termination of the agreement, Digilog shall, at the Customer's choice, return or delete the personal data, with the following exception.

Archive of installation documentation. The Customer instructs Digilog to keep installation CE documents and logbook, including personal data in it, for 10 years from each installation's installation date, where the purpose is to let the Customer meet its obligation to keep the technical file under the Machinery Directive (2006/42/EC), and from 20 January 2027 the Machinery Regulation (EU) 2023/1230. During this period the documentation is kept read-only and without charge, logbooks the Customer has made available through QR codes or links stay available, and the data is used for no other purpose. The Customer may at any time export the documentation and instruct Digilog in writing to delete it earlier.

Other personal data. The Customer may export it for 90 days after termination, after which Digilog deletes it.

Deleted data disappears from backups as they expire, within 35 days. On request, Digilog confirms deletion in writing.

11. Liability

Each party is liable for damages under Article 82 GDPR as the GDPR sets out. Otherwise the limitations of liability in the Terms apply to this DPA. A fine imposed on a party by a supervisory authority is borne by that party.

12. Changes and applicable law

The DPA is changed in the same way as the Terms (section 16 of the Terms), except that changes required by law or by a supervisory authority apply from the date they are required. Swedish law applies, and disputes are settled as set out in section 17 of the Terms.

Appendix A: Details of the processing

ItemDescription
Subject matterProviding the Service under the Terms
DurationThe term of the agreement, plus the archive period and export periods in section 10
Nature of the processingStorage, organisation, display, generating documents, sending email on the Customer's behalf, making logbooks available through QR codes and links, AI-assisted reading of uploaded PDFs and photos, backups, deletion
PurposeLetting the Customer document installation, inspection, service and maintenance of doors and related systems, meet its documentation obligations, and share documentation with its customers and building owners
Data subjectsThe Customer's employees and other users; subcontractors' staff; the Customer's customers and their contact persons; property owners and managers; people who report faults; recipients of documentation
Categories of personal dataNames, job roles, company affiliation, email addresses, phone numbers; signatures; addresses of properties with map positions; photos and documents; comments and fault descriptions; logbook entries with author and time; records of emails sent (recipient, time, delivery status)
Special categoriesNone intended. The Customer must not enter them (section 3)

Appendix B: Security measures

  • Location. The Service, database, file storage, backups and logs run on Microsoft Azure in Sweden (Sweden Central).
  • Encryption. All traffic is encrypted with TLS. Data is encrypted at rest by the storage services.
  • Network. The database has no public endpoint and is reachable only from the Service's private network.
  • Access control for users. Sign-in through Microsoft Entra ID (email one-time code or the user's own organisation's sign-in). Access is limited to the user's company, and within it by role and permission. The Customer controls its users.
  • Access control for Digilog staff. Staff access production data only when needed for operations or support, through personal accounts in Digilog's own Entra tenant, with role-based permissions and enforced multi-factor authentication.
  • Resilience. Point-in-time backups of the database are kept for 35 days. The platform runs as managed containers that restart automatically.
  • Monitoring. Technical logs are kept for 30 to 90 days and are used to detect faults and misuse.
  • Development. Changes are reviewed and tested before release; test environments use test data, not customer data.
  • Organisation. Staff are bound by confidentiality, and access is removed when someone leaves.

Appendix C: Sub-processors

Sub-processorProcessingLocation
Microsoft Ireland Operations Ltd (Azure, Entra ID, Communication Services, AI Foundry)Hosting, database, storage, backups, sign-in, sending email, AI-assisted reading of PDFs and photosSweden (Azure Sweden Central) for hosting, database, file storage, backups and logs. Other EU locations for sign-in, sending email and AI-assisted reading
Google Cloud EMEA Limited, Ireland (Google Maps Platform)Looking up and validating the addresses of propertiesGlobal; Google LLC (USA), its parent, is certified under the EU–US Data Privacy Framework. Google acts as an independent controller for this data, under its own terms

The suppliers Digilog uses for data it controls itself are listed in Appendix A of the Privacy Policy.