Data Processing Agreement (DPA)

This Data Processing Agreement (the "Agreement") is entered into between:

  1. Data Controller: The customer, who uses the SimplyPulse service and determines the purposes and means of processing personal data.
  2. Data Processor: SimplyPulse AB, reg. no. 559513-3561, with address Johannefredsgatan 4, 431 53 Mölndal, SWEDEN (the "Processor"), who processes personal data on behalf of the Customer under this Agreement.

This Agreement governs the processing of personal data by the Processor in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

1. Purpose and scope of the processing

The Processor processes personal data in order to provide the SimplyPulse Service to the Client. The processing includes the collection, storage, structuring, transfer and deletion of personal data as described below:

  • Categories of personal data: Names, e-mail addresses, as well as additional data entered by the Customer into the system, including employment number, date of birth and telephone number. The Customer also determines segmentation data such as departments, locations and types of employment as well as collected survey responses.
  • Data subjects: Customer users and employees whose data is processed in SimplyPulse.
  • Storage period: Personal data is stored as long as there is an active customer relationship. At the end of the contract, data is automatically deleted after 30 days unless otherwise agreed.

The Processor may not use the Customer's data for its own purposes or for purposes other than providing and optimizing the SimplyPulse Service.

2. Obligations of the processor

The agent undertakes to:

  • Process personal data in accordance with the Customer's instructions and applicable law.
  • Ensure that only authorized persons have access to personal data and that they are subject to confidentiality.
  • Implement appropriate technical and organizational measures to protect the personal data, including TLS encryption, two-factor authentication, server monitoring and restricted access.
  • Take the necessary steps to assist the Customer in the event of a record extraction or deletion request under the GDPR.
  • Inform the Customer without delay in the event of a security incident affecting personal data.
3. Sub-consultants

The processor engages the following sub-processors to carry out processing:

  • Oderland Webbhotell AB (email, hosting)
  • Microsoft (email, file storage)
  • OnlineCity.IO ApS (SMS)
  • OneSignal (Push Notifications)

In the event of a change of subcontractors, the Client shall be informed at least 30 days in advance. If the Customer objects to a new subcontractor, it has the right to terminate the contract.

4. Data management and deletion
  • The customer can request deletion of their personal data, however, data collected anonymously cannot be linked to an individual and therefore cannot be exported or deleted individually.
  • The Processor assists the Client in technical matters relating to rectification, erasure and extracts from the register.
  • Upon termination of the contract, all personal data is deleted after 30 days unless otherwise agreed.
5. Data transfer and place of processing
  • All processing of personal data takes place within the EU/EEA.
  • The processor does not transfer personal data to countries outside the EU/EEA.
6. Liability and disputes
  • The customer is responsible for informing data subjects about the processing of their personal data.
  • End users wishing to request a record extract or deletion should contact the Client, who in turn may request assistance from SimplyPulse.
  • In the event of a dispute arising from this Agreement, the parties shall in the first instance attempt to reach a solution through negotiation. If no agreement is reached, the dispute shall be settled by a Swedish general court applying Swedish law.
7. Validity of the contract

This Agreement is valid as long as the customer contract is active and unless otherwise agreed between the parties.

This agreement also applies when using SimplyPulse during a trial period.

By entering into this Agreement, the parties acknowledge that they understand and accept the terms and conditions for the processing of personal data.

Scroll to the top