Disciplines Products Pricing About Platform Start a conversation

Data Processing Agreement.

The controller-to-processor terms for the data you manage inside the stomwerk apps - worker data in Work Permit Intelligence, and the content and brand materials you bring to stomwerk content. Entered into under Article 28(3) GDPR.

ProcessorStomwerk AB, Sweden
ControllerYou, the customer
Data at restEU · Frankfurt + EU R2
Version6 July 2026
DRAFT - pending legal review. This DPA is a draft awaiting review by qualified counsel and is not yet for execution. It is published for transparency and may change before it takes effect.

This Data Processing Agreement ("DPA") forms part of the agreement for the Stomwerk services between the Customer (the "Controller"), as identified in the order or subscription, and Stomwerk AB, org number 559591-8755, Stockholm, Sweden (the "Processor"). It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and forms part of the Terms of Service for the processing it describes.

1. Subject matter and duration.

1.1 Subject matter: the Processor's hosting and operation of the Stomwerk platform apps, in the course of which the Processor processes personal data on the Controller's behalf. This covers in particular:

  • Work Permit Intelligence (wpi.stomwerk.com) and the other projekt apps, where the Processor processes personal data of the Controller's workers, contractors and site personnel; and
  • stomwerk content (engine.stomwerk.com) and the other scale apps, where the Processor processes any personal data contained in the content, brand materials, documents and connected publishing accounts the Controller submits.

1.2 Duration: this DPA applies for as long as the Processor processes personal data on behalf of the Controller under the agreement, and survives termination to the extent required for return and deletion under clause 9.

2. Nature and purpose of the processing.

2.1 Nature: storage, structuring, retrieval, display and transmission of the Controller's records and content; capture of signatures and isolation records; deterministic (non-AI) competency verification; generation of permit PDFs and QR status pages; AI-assisted generation, transformation and translation of content invoked by the Controller's users; storage and delivery of uploaded and generated media; publishing to channels the Controller connects; append-only audit logging.

2.2 Purpose: enabling the Controller to run its permit-to-work, SIMOPS coordination and related project-governance processes, and to produce, manage and publish its marketing and communications content.

2.3 The Processor does not use AI to evaluate individual workers. AI-assisted features in the projekt apps (risk briefs) operate on aggregated hazard and clash facts; worker names are excluded from AI prompts by design and this exclusion is maintained as a product invariant. In stomwerk content, AI features process the content the Controller's users submit, only when invoked by them. The Processor does not use the Controller's personal data to train AI models, and its AI subprocessor is contractually barred from doing so.

3. Data subjects and data categories.

3.1 Data subjects: the Controller's workers, contractors and site personnel; the Controller's authorised users of the services; individuals whose personal data appears in content the Controller submits to the services (for example people featured or named in brand materials, documents and campaign content).

3.2 Categories of personal data:

  • worker names (free-text) in competency cards, permits, isolation records and audit trails;
  • competency records: company, card references, expiry dates;
  • signatures: signer name, drawn signature image, declaration text;
  • isolation (LOTO) records: applied-by and verified-by names;
  • safety documents and attachments uploaded by the Controller (RAMS, certificates, photos), which may contain worker names and potentially health-adjacent content;
  • content and brand materials uploaded to or generated in stomwerk content (logos, imagery, guideline documents, drafts, media), to the extent they contain personal data such as names, likenesses or contact details;
  • identifiers of the Controller's connected publishing accounts (encrypted OAuth tokens, account handles);
  • audit-trail entries recording actor names and actions.

3.3 No special categories of data (Art 9) are required by the services. Where the Controller chooses to upload documents containing such data (e.g. medical-fitness content inside attachments), the Controller is responsible for its lawful basis; the Processor treats all attachments under the security measures in Annex 2.

4. Processor obligations - Art 28(3).

The Processor shall:

  • (a) process the personal data only on the Controller's documented instructions (including as configured by the Controller in the services), including with regard to international transfers, unless required to do so by Union or Member State law - in which case the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits it;
  • (b) ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • (c) implement and maintain the technical and organisational measures set out in Annex 2 (Art 32);
  • (d) respect the conditions in clause 5 (subprocessors) for engaging another processor;
  • (e) taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection). Requests received directly from the Controller's workers will be forwarded to the Controller without undue delay and not answered on the merits without the Controller's instruction;
  • (f) assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to the Processor;
  • (g) notify the Controller of a personal data breach affecting the Controller's personal data without undue delay and in any event within 48 hours of becoming aware of it, providing the information listed in Art 33(3) so far as available, and supplementing in phases as further information becomes available;
  • (h) at the Controller's choice, delete or return all the personal data at the end of the provision of the services, and delete existing copies, in accordance with clause 9;
  • (i) make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits in accordance with clause 10; and
  • (j) immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

5. Subprocessors.

5.1 The Controller gives general written authorisation to the subprocessors listed in the Stomwerk subprocessor list (Annex 3, maintained at stomwerk.com/subprocessors).

5.2 The Processor shall give the Controller at least 30 days' prior notice of any intended addition or replacement of a subprocessor, by email to the owner accounts of the Controller's workspaces and by a dated entry in the change log on the subprocessor page. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected services.

5.3 The Processor shall impose data protection obligations on each subprocessor equivalent to those in this DPA and remains fully liable to the Controller for the subprocessor's performance.

6. International transfers.

6.1 The Controller's personal data is stored and processed in the EU: the system of record is Postgres hosted in Frankfurt (Supabase, eu-central-1), with uploaded attachments held inside that EU database. stomwerk content media objects (uploaded brand assets, guideline documents and generated media) are stored in Cloudflare R2 in a bucket created in the EU jurisdiction, so those objects are stored and processed in EU data centres; where R2 is not configured, the same objects are held in Supabase Storage in the Frankfurt project or inside the EU database itself. Application compute is pinned to Frankfurt (fra1); routing middleware runs at the global edge and persists no personal data.

6.2 AI-assisted features route prompts to Anthropic (Claude API) in the United States under the EU Standard Contractual Clauses incorporated in Anthropic's Commercial Terms. Worker names are excluded from AI prompts by design - projekt-app prompts carry aggregated hazard and clash facts only. stomwerk content prompts carry the content the Controller's users submit to an AI feature at the moment they invoke it. Anthropic does not use API data for model training and retains API inputs/outputs for a maximum of 30 days.

6.3 Any other transfer of the Controller's personal data outside the EU/EEA occurs only via the subprocessors in Annex 3, each covered by the transfer mechanism recorded there (EU-US Data Privacy Framework and/or SCCs).

7. Retention and statutory safety-record duties.

7.1 The Processor retains the Controller's personal data for the duration of the agreement and processes it per the Controller's instructions.

7.2 The parties acknowledge that permit-to-work safety records (permits, signatures, isolation records, competency records, audit trails) may be subject to statutory retention obligations applicable to the Controller in its Member State. Where the Controller instructs deletion, records identified by the Controller as subject to such obligations are handled as "retain under legal obligation, delete on schedule" per the Controller's stated retention period, rather than immediate erasure.

8. Security.

The Processor implements the technical and organisational measures in Annex 2 and shall not materially decrease the overall security of the services during the term.

9. Deletion and return at contract end.

9.1 At termination or expiry, at the Controller's choice, the Processor shall return the Controller's personal data in a structured, commonly used, machine-readable export and/or delete it, and shall delete existing copies within 30 days, except to the extent Union or Member State law requires storage or clause 7.2 applies.

9.2 Deletion propagates through the database's cascading deletion relationships and through the object-storage ledger for stored media, and includes backups on the backup provider's rotation cycle.

10. Audit rights.

10.1 The Processor shall make available on request: this DPA, the subprocessor list, summaries of subprocessor certifications held by its providers (e.g. SOC 2 Type II / ISO 27001 for the hosting subprocessors), and its security-measures documentation.

10.2 Where that information is insufficient to demonstrate compliance, the Controller (or an independent auditor mandated by it and not a competitor of the Processor) may audit the Processor's compliance with this DPA, no more than once per 12 months except after a personal data breach, on at least 30 days' notice, during business hours, under confidentiality, and at the Controller's cost.

11. Liability and governing law.

11.1 Liability under this DPA is subject to the limitations and exclusions of the main agreement, to the extent permitted by law.

11.2 This DPA is governed by the law governing the main agreement - Swedish law under the Stomwerk Terms of Service - and, failing a choice there, by Swedish law.

Annex 1 - Description of processing.

As per clauses 1 to 3: subject matter (hosting/operation of the WPI and projekt apps and of stomwerk content and the scale apps), duration (term of the agreement), nature (storage, structuring, retrieval, display, signature and isolation capture, deterministic competency verification, PDF/QR generation, AI-assisted content generation and transformation on invocation, media storage and delivery, publishing to connected channels, audit logging), purpose (the Controller's permit-to-work and project-governance processes and its content production and publishing), data subjects (workers, contractors, site personnel, authorised users, individuals appearing in submitted content) and data categories (worker names, competency records, signatures, safety documents, isolation records, content and brand materials containing personal data, connected-account identifiers, audit entries).

Annex 2 - Technical and organisational measures.

  • EU-resident Postgres (Frankfurt) as the system of record; uploaded attachments stored inside the EU database, not on a US object store.
  • stomwerk content media objects stored in Cloudflare R2 in a bucket created in the EU jurisdiction (stored and processed in EU data centres, addressed only via the EU endpoint), with Supabase Storage (Frankfurt) or the EU database as the fallback stores; every stored object is tracked in a storage ledger for quota and deletion accounting.
  • TLS encryption in transit for all services.
  • Credentials: scrypt password hashing; session/invite/reset/verify tokens stored only as SHA-256 hashes; single-use, short-TTL token flows; httpOnly session cookies.
  • OAuth tokens for connected publishing accounts encrypted at rest with AES-256-GCM; production fails closed when the encryption key is absent.
  • Access control: membership-scoped workspace access; WPI Section 5 visibility scoping; attachments and media gated by membership through a single access-checked proxy; critical-clash hard block; operator access limited and audited.
  • Public QR permit pages fail closed and expose no worker names.
  • Append-only audit trails of user actions.
  • Billing integrity: signature-verified, idempotent payment webhooks; scheduled jobs gated by bearer secrets and failing closed.
  • Data-subject tooling: self-serve machine-readable export (account and workspace), erasure with cascade, and scheduled retention purges.
  • Development controls: private repository treated as public, with a pre-push secret-scanning gate; security review before merging auth/billing changes.
  • Subprocessor certifications: hosting subprocessors hold SOC 2 Type II and ISO 27001 (see Annex 3 vendors' trust centres).

Annex 3 - Authorised subprocessors.

The current list, including role, location of processing and transfer mechanism, is maintained at stomwerk.com/subprocessors. Summary as at 6 July 2026:

SubprocessorRoleLocationTransfer mechanism
SupabaseDatabase hosting (including in-database attachments)EU - FrankfurtSCCs + TIA
Cloudflare R2Object storage for stomwerk content customer assets (uploaded logos, brand imagery, guideline PDFs, generated media)EU jurisdiction bucket - stored and processed in EU data centresData Privacy Framework + SCCs
Supabase StorageFallback object store for stomwerk content assetsEU - FrankfurtSCCs + TIA (as Supabase)
VercelApplication computeEU - Frankfurt pinned; global edge routingData Privacy Framework + SCCs
CloudflareMarketing-site hosting and form relayGlobal edgeData Privacy Framework + SCCs
ResendTransactional email to the Controller's usersUnited StatesSCCs
AnthropicAI features (no worker names in prompts; no training on API data)United StatesSCCs
StripeBilling of the Controller (not worker data)United StatesData Privacy Framework + SCCs

This DPA is version 6 July 2026 and is pending review by qualified counsel. The repository source of record is docs/legal/CUSTOMER-DPA-TEMPLATE.md; questions to [email protected].