Legally binding

Data Processing Agreement

This Data Processing Agreement (DPA) governs Tagile's processing of personal data on behalf of the Customer under Article 28 GDPR. It forms an integrated part of the agreement between Tagile and the Customer for the use of the Service.

Last updated: 22 July 2026  ·  Effective from: 22 July 2026  ·  Version 1.0

1. Parties and relationship to the main agreement

This DPA is entered into between the Customer (the "Controller") and Tagile AB, org. no. 559467-5802 (the "Processor"). It forms an integrated part of the Terms of Service or other main agreement between the parties (the "Agreement") and applies to all processing of personal data that the Processor carries out on behalf of the Controller in connection with the Service.

2. Subject matter and duration

The subject matter of the processing is the provision of the Service as described in the Agreement. This DPA applies for as long as the Processor processes personal data on behalf of the Controller.

3. Nature and purpose of processing

The Processor processes personal data to provide, maintain and support the Service, including hosting and storage, monitoring of publicly available information selected by the Controller, filtering and summarisation (including with the help of AI), display of results to the Controller's users, and related support and troubleshooting.

4. Categories of personal data

Contact and account details of the Controller's users (such as name and email address); publicly available professional information about persons the Controller chooses to monitor (such as name, role, employer and public professional activity); and technical data such as log data. Details are set out in Annex 1.

5. Categories of data subjects

The Controller's users and employees; and business contacts and other professionals whose publicly available information the Controller chooses to monitor through the Service. Details are set out in Annex 1.

6. Documented instructions

The Processor processes personal data only on documented instructions from the Controller, as set out in the Agreement, this DPA and the Controller's configuration of the Service, unless processing is required by EU or Member State law. In that case the Processor informs the Controller of the legal requirement before processing, unless the law prohibits it. The Processor informs the Controller if, in its opinion, an instruction infringes applicable data protection law.

7. Confidentiality

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8. Security measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures are described in Annex 2 and on the Security page.

9. Assistance with data subject requests

Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR.

10. Assistance with security and DPIAs

The Processor assists the Controller in ensuring compliance with the obligations in Articles 32–36 GDPR (security of processing, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Processor.

11. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data. The notification includes the information reasonably available to the Processor that the Controller needs to meet its own notification obligations, and is supplemented as further information becomes available.

12. Subprocessors

The Controller grants the Processor a general authorisation to engage subprocessors. The current list is set out in Annex 3 and on the Subprocessors page. The Processor informs the Controller in writing of any intended addition or replacement of subprocessors, giving the Controller the opportunity to object within 14 days. The Processor imposes data protection obligations on each subprocessor that are no less protective than those in this DPA and remains fully liable to the Controller for the subprocessor's performance.

13. International transfers

The Processor aims to process personal data within the EU/EEA. Where processing by a subprocessor takes place in a third country, the Processor ensures that the transfer is subject to appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where relevant.

14. Audit and information rights

The Processor makes available to the Controller the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits and inspections conducted by the Controller or an auditor mandated by the Controller. Audits may take place at most once per year, with at least 30 days' prior written notice, during normal business hours and without unreasonably disrupting the Processor's operations.

15. Deletion or return of data

Upon termination of the Agreement, the Processor, at the choice of the Controller, deletes or returns all personal data processed on the Controller's behalf, and deletes existing copies, unless EU or Member State law requires storage of the personal data.

16. Liability

Liability under this DPA follows the limitations of liability in the Agreement, except where mandatory data protection law provides otherwise.

17. Order of precedence

In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.

18. Governing law

This DPA is governed by the same law and dispute resolution provisions as the Agreement, which is Swedish law with the District Court of Stockholm as first instance, unless otherwise agreed.

Annex 1: Processing details

Subject matter: provision of the Tagile decision support service.

Duration: the term of the Agreement plus the period until deletion or return of data.

Nature and purpose: hosting, monitoring of publicly available information selected by the Controller, filtering, summarisation, presentation to users, support.

Categories of data subjects: the Controller's users; monitored business contacts and professionals.

Categories of personal data: contact and account details; publicly available professional information; log and usage data. No special categories of personal data are intended to be processed, and the Controller agrees not to instruct such processing.

Annex 2: Technical and organisational measures

  • Encryption of data in transit and at rest.
  • Access to production systems restricted to authorised personnel, on a least privilege basis, via logged connections.
  • Confidentiality undertakings for personnel with access to personal data.
  • Logging and monitoring appropriate to the nature of the service.
  • Backup routines with the aim of enabling restoration after loss of data.
  • A documented incident management process (see the Incident Response page).
  • Vendor assessment of subprocessors before engagement.

Annex 3: Approved subprocessors

The approved subprocessors at any given time are listed on the Subprocessors page, which forms part of this DPA. Changes are handled in accordance with section 12.

Questions about this page?

Contact us at hello@tagile.ai.