Trust Center

Privacy & GDPR

Digital Plattform Sverige AB is a Swedish company. The platform is hosted in the EU and operated under the GDPR.

This page sets out the roles, the rights, and what actually happens to personal data in a Digital Platform system.

Roles

Controller and processor

The division matters, because it decides who is answerable for what. It is not the same in both directions.

DataControllerProcessor
Personal data inside your systemYouDigital Plattform Sverige AB
Your users' account and login dataYouDigital Plattform Sverige AB
Your contact details as our customerDigital Plattform Sverige AB
Visitors to this websiteDigital Plattform Sverige AB
Are you a data controller or a data processor?

Both, for different data. For the personal data your organisation puts into its system, you are the controller and we are the processor: we act on your documented instructions and do not decide the purposes of that processing.

For your own contact details as our customer, and for visitors to this website, we are the controller.

Is a Data Processing Agreement available?

Yes, on request, and we will sign it before processing begins. It covers the subject matter and duration of processing, the categories of data subject and personal data, our obligations as processor, the subprocessors we use, and what happens to data when the agreement ends.

If your organisation has its own DPA template we will review it. We would rather negotiate a document you already trust than insist on ours.

What is your legal basis for processing?

As processor, we do not establish a legal basis for the personal data inside your system — you do, as controller, for the processing you instruct us to carry out.

For the data where we are controller, the basis is contract performance for customer relationship data, and legitimate interest for ordinary business communication and website operation.

Rights

Data subject rights

Requests from your users reach you, not us — you are their controller. What we owe you is the ability to answer them.

How do we handle a data subject access request?

A request from one of your users goes to you as controller. Your system gives you access to that person's data directly, so an ordinary access, rectification or erasure request is something you can complete yourself without waiting on us.

Where a request needs something the interface does not expose, we assist you as processor. Contact us and it is treated as a request with a deadline attached rather than as a support ticket.

Which rights are supported?

Access, rectification, erasure, restriction of processing, data portability and objection — the rights under GDPR Articles 15 to 21.

In practice: data is readable and correctable in the system, exportable in a machine-readable format for portability, and deletable on request. Restriction and objection are decisions you make as controller; we act on your instruction.

How quickly can data be exported?

Export is available on request and your system's data is held in a standard database rather than a proprietary format, so producing a complete machine-readable extract is a straightforward operation rather than a project.

Retention

How long data is kept

Live data is kept for as long as your system needs it — that is your decision as controller. What we set is how long copies survive after deletion.

Deleted data disappears from the live system immediately and ages out of the copies above as each reaches the end of its window.
CopyWhereRetention
Live system dataPlatform database, EUUntil you delete it or the agreement ends
Daily server backupsEncrypted object storage, EU7 days
Daily machine imagesAWS Backup vault, EU3 days
Database operation logEncrypted object storage, EU7 days
How do customers request deletion?

Delete it in your system for ordinary record-level deletion. For deletion of a whole dataset, or of everything at the end of an agreement, email info@digitalplattform.se and it is carried out as an instructed processing action.

We confirm in writing when it is done, and we tell you the date the last backup copy expires rather than claiming every copy vanished the moment the live record did.

What happens to our data if we leave?

You export it, then we delete it. Export first is the order deliberately: we do not delete anything until you have confirmed you have what you need.

After deletion, remaining copies expire on the retention windows in the table above. Nothing is retained beyond them as a commercial lever.

Is data really deleted, or just marked as deleted?

Deletion on request removes the data. Where the application uses a soft-delete flag for ordinary user actions — so a mistaken deletion is recoverable — a deletion instruction under this section is not that; it removes the underlying records.

Transfers

Cross-border transfers

Where personal data goes, and the only circumstances in which it leaves the EU.

Is personal data transferred outside the EU?

Not by the platform. Compute, the platform database, file storage and backups are all in the EU — primarily AWS eu-north-1 in Stockholm, with transactional email through AWS eu-west-1 in Ireland.

A transfer happens only where you enable a capability whose provider processes data outside the EU. The AI capabilities are the main case: those model providers are US companies. Which ones, and what they process, is listed on the Subprocessors page.

If your organisation requires that no personal data leaves the EU, those capabilities can be left disabled and the rest of the platform is unaffected.

What safeguards apply to transfers that do happen?

Standard Contractual Clauses with the relevant provider, together with that provider's own supplementary measures.

We list every subprocessor publicly, including its region, so a transfer is something you can see before you enable it rather than discover afterwards.

Do you use US cloud providers?

AWS, in EU regions. We are aware that a US-parent provider operating EU infrastructure is a point of debate in some procurement processes, and we would rather you raise it now than late.

The data itself is stored and processed in the EU, on infrastructure in our own AWS accounts.

Principles

How we approach privacy

Four commitments that govern the decisions this page describes. They are stated as constraints on us, not as reassurance.

Collect only what the system needs

The platform stores the data your system requires to do its job. We do not add collection of our own on top of it, and we do not instrument customer systems to gather usage data about your users.

Your data is not our product

Customer data is not sold, not shared with third parties for their own purposes, not used for advertising, and not used to train AI models. There is no version of our business model where it is.

Leaving is a decision, not a negotiation

Export is available at any time, in a machine-readable format, regardless of why you are asking. Data portability is a right under GDPR, and a vendor who makes it difficult is telling you something.

Say what is not in place

Where a control is planned rather than implemented, this Trust Center labels it as planned. A privacy page that reads as complete when it is not costs you more than an honest gap does.

Contact

Privacy enquiries

Data protection enquiries, DPA requests and data subject request assistance: info@digitalplattform.se.

Digital Plattform Sverige AB, Industrigatan 14, 58255 Linköping, Sweden. VAT SE559221674001.

You also have the right to lodge a complaint with your national supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).

Need a DPA?

Ask and we will send one, or review yours. We will sign before processing begins rather than after go-live.