Back to Trust Center
    Version

    Data Processing Agreement.

    May 5, 2026 · Rev A

    1. Background.

    The Parties have entered into an agreement where Regweaver will provide Services to the User (the “Agreement”). This Data Processing Agreement (“DPA”) forms part of the Agreement since Regweaver may from time to time and on behalf of the User process personal data, as further detailed in Appendix 1. Under this DPA, Regweaver will act as a data processor, and User as a data controller, as defined by the General Data Protection Regulation 2016/679 (“GDPR”).

    2. Definitions.

    In this DPA, terms defined in the GDPR have the same meaning ascribed to them under the GDPR. In addition, the following capitalized terms will have the meanings ascribed to them below, and references to the singular will include the plural and vice versa.

    “Data Privacy Laws”
    means any law and regulation in force at any time concerning the processing of personal data, including but not limited to the GDPR, other European Union legislation relating to the processing of personal data, national legislation implemented under and in compliance with the GDPR and the decisions, advice, recommendations and opinions of the EU court(s), national courts, the European Data Protection Board and the applicable supervisory authority.
    “EU Model Clauses”
    means the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
    “Sub-Processor”
    means a processor engaged by Regweaver to fulfill Regweaver’s obligations under this DPA in whole or in part, and when doing so processes the User’s personal data on behalf of Regweaver.

    3. Processing of Personal Data.

    3.1Regweaver undertakes to comply with the Data Privacy Laws.

    3.2Regweaver undertakes to only process personal data to the extent necessary to fulfil its undertakings under the Agreement, and only in accordance with the User’s written instructions, Appendix 1. Regweaver may not process the personal data for its own purpose(s).

    3.3Regweaver will immediately inform the User if Regweaver lacks an instruction on how to process personal data in a particular situation or if it believes an instruction provided under this DPA infringes the Data Privacy Laws.

    3.4If Regweaver processes personal data in addition to or in violation of the User’s instructions, due to being required to do so by Union or Member State law to which Regweaver is subject, Regweaver will inform the User of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

    3.5If data subjects, competent authorities, or any other third parties request information from Regweaver regarding the processing of personal data covered by this DPA, Regweaver will refer such request to the User as soon as possible and no later than twenty-four (24) hours after receipt of such request, unless Regweaver is prohibited from doing so under Union or Member State law. Regweaver will assist the User to fulfill its obligations to respond to requests from supervisory authorities and data subjects to exercise their rights under Chapter III of the GDPR.

    3.6Regweaver will, upon the User’s request, assist the User with carrying out data protection impact assessment(s) where required under the Data Privacy Laws. Regweaver will in particular assist with:

    1. Describing the nature of the processing, including the personal data involved and the Processing location;
    2. Identifying and assessing risks to the rights and freedoms of data subjects;
    3. Providing information on the technical and organizational measures and safeguards taken or envisaged to address the identified risks in order to ensure the protection of personal data processed under this DPA; and
    4. Providing detailed information on any other parties involved in the processing of personal data (including information on their part of the process and their location).

    3.7Upon the User’s request, Regweaver will assist the User with carrying out prior consultations with the supervisory authority, where such consultations are required under the Data Privacy Laws.

    3.8Regweaver will immediately (and in no case later than forty-eight (48) hours) upon becoming aware of a personal data breach notify the User in writing thereof, providing a detailed description of the personal data breach and its effects. If the User requests, Regweaver will assist the User in fulfilling the User’s obligations under Article 33 of the GDPR, such as:

    1. In writing provide a detailed statement of the nature of the personal data breach in accordance with what is stated in Article 33(3)(a) in the GDPR;
    2. Take reasonable steps necessary to mitigate the consequences of the personal data breach or (if applicable) to protect against a threatened security incident; and
    3. As soon as practicable following the personal data breach, inform the User of the remedial action(s) Regweaver proposes to take to prevent any similar security incident occurring in the future.

    3.9The User shall compensate Regweaver for any assistance provided under this Section 3 at Regweaver’s then-current hourly rates, provided that Regweaver has notified the User in advance of the estimated time and costs involved.

    4. The User's Undertakings.

    4.1The User will provide clear and documented instructions to Regweaver, Appendix 1.

    4.2The User is responsible for ensuring that the instructions provided to Regweaver comply with the requirements of the Data Privacy Laws.

    4.3The User undertakes to oversee and audit Regweaver’s processing activities in accordance with the terms of this DPA.

    5. Sub-Processors.

    5.1Regweaver will notify the User in writing of the intention to engage new Sub-Processors or make changes to the already engaged Sub-Processors, giving the User at least fourteen (14) days to object to such changes on objectively and reasonable grounds. If the User does not object within the fourteen (14) day period, the User shall be deemed to have approved the new or changed Sub-Processor. If the User objectively and reasonably objects to the change, the Sub-Processor in question may not be engaged by Regweaver for the processing of the User’s personal data. If it is not reasonably possible to exclude the Sub-Processor from Regweaver’s delivery without a negative consequence to Regweaver’s business model, either Party may terminate the Agreement with thirty (30) days’ written notice, without any penalty or early termination fees.

    5.2Sub-Processors approved by the User are listed in Appendix 1.

    5.3Regweaver will ensure that any Sub-Processors approved by the User are bound by written agreements that require them to comply with not less stringent data processing obligations to those contained in this DPA and that meet the requirements of Article 28(3) of the GDPR.

    5.4If the Sub-Processor fails to perform its obligations, Regweaver will be fully liable to the User for the due performance of the Sub-Processor’s obligations.

    6. Technical and Organisational Measures.

    6.1Regweaver guarantees that it has implemented and, during the term of this DPA, will continue to implement and maintain appropriate technical and organizational measures to ensure that personal data processed under this DPA meets the requirements of the Data Privacy Laws (such as Article 32 of the GDPR) and ensures that the rights of data subjects can be upheld.

    6.2Regweaver ensures that only personnel that directly require access to personal data in order to fulfil its obligations in accordance with this DPA have access to such information. Regweaver ensures that such personnel are bound by a confidentiality obligation to the same extent as Regweaver in accordance with this DPA.

    6.3The technical and organizational security measures implemented by Regweaver are set out in Appendix 1 and maintained at the Regweaver Trust Center. Regweaver may update these measures from time to time provided that such updates do not result in a material degradation of the security level and Regweaver notifies User of any material changes.

    7. Data Localisation.

    7.1Regweaver may process personal data in the EU/EEA and the countries set out in Appendix 1.

    7.2If User instructs Regweaver to make personal data available to parties located in countries outside the EU/EEA, User shall make sure that there is a valid transfer mechanism in place (such as the EU Model Clauses or an adequacy decision).

    8. Audit Rights.

    8.1Upon the User’s request, Regweaver will make available information necessary to demonstrate compliance with this DPA and the Data Privacy Laws. This includes records on Regweaver’s processing of personal data under this DPA, as well as applicable privacy policies, confidentiality undertakings, records of personal data breaches, and any other such information necessary to verify Regweaver’s compliance with this DPA.

    8.2The User may request audit of Regweaver’s processing of personal data one (1) time per calendar year – unless the previous audit identified deviations from this DPA or the Data Privacy Laws. If so, the User may request one additional audit of Regweaver that calendar year.

    9. Liability.

    Regweaver’s total liability under this DPA shall be limited to the liability cap set out in the Agreement. Regweaver’s liability for Sub-Processors is limited to the selection and oversight of such Sub-Processors in accordance with Section 5.

    10. Return of Data etc..

    10.1Upon expiry of this DPA, Regweaver will return all personal data to the User and will ensure that any Sub-Processor does the same, unless it is required to keep copies of the data under Union or Member State law to which Regweaver is subject.

    10.2Regweaver shall provide the personal data in commonly used electronic format. The User shall have thirty (30) days from the expiry of this DPA to request return of data. After such period, Regweaver may delete all personal data unless legally required to retain it. Any assistance beyond standard export functionality shall be provided at Regweaver’s then-current hourly rates.

    11. Term.

    This DPA will take effect as of the date of signing by both Parties and remain effective as long as Regweaver processes personal data on behalf of the User.

    12. Assignment and Amendment.

    12.1Neither Party may assign its rights and/or obligations under this DPA without the prior written consent of the other Party.

    12.2This DPA may only be amended in writing signed by both Parties. However, Regweaver may update Appendix 1 (Sub-Processors and security measures) in accordance with the notification procedures set out in this DPA.

    13. Applicable Law.

    This DPA will be governed by, construed and enforced in accordance with the laws of Sweden. Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions set out in the Agreement.

    A1. Appendix 1 — Instruction Regarding Processing.

    1. Introduction

    This Appendix 1 specifies the processing of personal data carried out by Regweaver on behalf of the User under the DPA.

    The purpose is to clarify the processing and personal data that is covered by the Agreement and to comply with the GDPR’s requirements.

    2. Instructions

    2.1 Personal data

    Regweaver processes personal data contained in the business information entered into the Platform or Service by the User, this may include name, contact information and KYC-data of business representatives.

    2.2 Data subjects

    The data subjects include the business representatives of the User’s group companies, service provides, and their service providers.

    2.3 Purpose

    The purpose of the processing is for Regweaver to be able to provide the Platform and Service and associated services as detailed under the Agreement.

    2.4 Duration

    Personal data are processed until manually deleted by User or until this DPA is terminated.

    2.5 Sub-Processors and geography

    Sub-Processors are listed in the table below.

    Name and reg. no.LocationTypes of ProcessingContact person / privacy functionContact details
    Microsoft Ireland Operations Limited, reg. no. IE256796. Used through Microsoft for Startups / Microsoft Azure.Sweden – Microsoft Azure Sweden Central. Regweaver’s core platform data is hosted and processed in Microsoft’s Swedish datacenter region, including Microsoft’s Swedish datacenter locations in Gävle, Sandviken and Staffanstorp.Cloud infrastructure, hosting, compute, storage, backup, database services, security monitoring, logging and processing of personal data entered into or generated by the Regweaver Platform. This may include user account data, company data, supplier/stakeholder data, uploaded documents, metadata, compliance-related records, audit logs and technical/security logs.Microsoft Data Protection Officer / Microsoft Privacy TeamMicrosoft privacy response channels, Microsoft Trust Center and applicable Microsoft Product Terms / Data Protection Addendum channels.
    Microsoft Ireland Operations Limited, reg. no. IE256796. Used through Microsoft Entra ID / Azure identity services, if applicable.Sweden / EU, depending on the specific Microsoft identity service, tenant configuration and applicable Microsoft product terms. Regweaver’s core platform data is hosted in Sweden.Identity and access management, authentication, authorization and user login services for individuals accessing the Regweaver Platform. This may include name, business email address, login credentials, user role, access rights, authentication metadata, sign-in logs and security events.Microsoft Data Protection Officer / Microsoft Privacy TeamMicrosoft privacy response channels, Microsoft Trust Center and applicable Microsoft Product Terms / Data Protection Addendum channels.
    HubSpot Ireland Ltd · VAT: IE9849471F · Address: 1 Sir John Rogerson’s Quay, Dublin 2, Ireland.European Union. HubSpot’s order terms state that Regweaver’s data will be stored in the European Union during the subscription term.CRM, sales pipeline management, marketing automation, customer communication, lead management, contact management, support communication, content/marketing activities and related platform administration. Processing may include name, business email address, phone number, company name, job title/role, communication history, meeting notes, lead/customer status, marketing interaction data and other business contact information entered into HubSpot by Regweaver.HubSpot Privacy / Data Protection TeamFor privacy matters, use HubSpot’s privacy/contact channels as referenced in HubSpot’s Customer Terms, Privacy Policy and applicable data processing terms.

    2.6 Technical and organisational security measures

    As set out at the Regweaver Trust Center.

    © 2026 Regweaver AB. All rights reserved. Regweaver DPA 26:4 · Rev A.