Data Processing Agreement
Version 1.2 · effective 2026-09-01
This agreement governs how Softsyde AB processes personal data on your behalf when you use Fidova as a trainer or organization. It is required by Article 28 of the GDPR and applies between you as controller and us as processor. You accept it when you apply to become a trainer on Fidova. It applies for as long as your organization uses the service. In the event of a conflict between the Swedish and English versions, the Swedish version prevails.
The parties
The processor is Softsyde AB (company reg. no. 559598-7354), which operates the Fidova service. Contact details are on our contact page. The controller is the organization that accepted this agreement when applying to become a trainer, and that subsequently uses Fidova in its business. You are the controller for data about your own customers. We are the controller for the platform itself – accounts, sign-in, the marketplace, security logs and retention periods. That boundary is described in our privacy policy. This agreement covers only the part where we process data on your behalf.
What we process, and why
The purpose is to provide Fidova to you, so that you can run courses and venue bookings. Nothing else. We do not use your customers' data for our own purposes, do not sell it on, and do not use it to train models. The processing covers: • storing and making available your participant lists, attendance registers, course and session data, forms and training material, • delivering your messages and announcements to your participants, • storing the files you upload, • backup and operation of the above. Categories of data subjects: your customers and participants, and the people they enter into the service themselves. Types of personal data: names and contact details, information about the dog, bookings and attendance, notes and assessments you write, answers to your forms, and messages between you and the participant. Duration: for as long as your organization uses Fidova, and thereafter as set out under deletion below.
We process only on your instructions
We process personal data only on your documented instructions. Those instructions consist of this agreement, the terms of service, and the settings and actions you take in the service – creating a course, sending a message or deleting a participant is an instruction. If we are required by law to process the data otherwise, we will inform you before doing so, unless the law prohibits us from telling you. If we consider an instruction to infringe data protection law, we will say so.
Confidentiality
Those of us who have access to your data are bound by confidentiality, and have access only to the extent the work requires. We do not read your participant lists or notes routinely. Access happens during troubleshooting or support, normally at your request, and is logged.
Security
We implement appropriate technical and organisational measures under Article 32. In practice that includes: • Access control in the database. Each organization's data is isolated at row level, so another organization cannot reach it – even if someone bypassed the interface. • Encrypted transport for all traffic, and encryption at rest with our sub-processors. • Logging of administrative actions and sensitive lookups. • Separate environments for development and production, so live data is not used in development. • Automatic deletion of data past its retention period. The security model is documented and checked automatically on every change to the service.
Sub-processors
You give us general authorisation to engage sub-processors. Today we use: • Supabase – database, authentication and file storage • Vercel – hosting, delivery, request logs and cookieless visitor statistics • Resend – transactional email • Sentry – error and performance monitoring Each sub-processor is bound by obligations equivalent to those in this agreement. We are responsible for their processing as for our own. If we change the list we will notify you in advance, and you have the right to object. If you object and we cannot agree, you have the right to terminate the service. That is why this agreement is versioned: we record which version you accepted, so we know who needs to be told when the list changes.
Assisting with data subject rights
If one of your customers approaches us with a request concerning you – access, rectification, erasure, objection – we refer them to you and inform you of the request. We help you respond. Data you entered yourself can be corrected and removed directly in the service. For access requests and data portability you retrieve the data yourself with the export under Settings. If you need something the export does not cover, contact us and we will produce it in time for you to answer the data subject within one month.
Personal data breaches
If we discover a personal data breach affecting your data, we will notify you without undue delay after becoming aware of it, so that you have time to make your own notification within 72 hours. We provide the information you need for that notification: what happened, which data and roughly how many people are affected, what consequences we assess it may have, and what we have done about it. We also assist with impact assessments and prior consultation under Articles 35 and 36, to the extent they concern our processing.
Deletion and return
When you stop using Fidova we delete your data, or return it, at your choice. You request that through our contact page and we carry it out within 30 days of the request reaching us. Data is returned in a structured, commonly used and machine-readable format (CSV and JSON). You can also export the data yourself at any time, under Settings in the service. That export contains the same data in the same formats, so you do not have to wait for us. We keep data longer only where the law requires it, for example records covered by the Swedish Accounting Act. What is deleted when is set out in our privacy policy.
Audits and information
We make available the information you need to demonstrate compliance with Article 28, and allow for and contribute to audits. Primarily this is through documentation we can provide. Where that is not sufficient we will agree an on-site audit, on reasonable notice and without exposing other customers' data.
Transfers outside the EU/EEA
Processing takes place primarily within the EU/EEA. Where a sub-processor processes data outside the EU/EEA, it does so under the European Commission's standard contractual clauses or an adequacy decision. We do not transfer your data outside the EU/EEA on our own initiative beyond what follows from the sub-processor list above.
Changes to this agreement
This agreement is versioned. We record which version your organization accepted, and when. If the agreement needs to change we will notify you in advance and ask for a new acceptance. Until then, the version you accepted applies. In the event of a conflict between this agreement and the terms of service, this agreement prevails on matters concerning the processing of personal data on your behalf. Swedish law applies.
Contact
Questions about this agreement, or about how we process data on your behalf, go through our contact page. We have not appointed a data protection officer – the Article 37 criteria are not met – so questions come to us directly.