Back to Terms

Data Processing Agreement

Version 1.0 · Last updated 11 August 2026

1

Parties, incorporation and precedence

1.1 Parties

This Data Processing Agreement ("DPA") is between the Customer identified in an executed Order Form ("Customer") and Rwk Group Holding AB, Swedish company registration number 559544-6450, with registered address Törnrosvägen 74A, 181 61 Lidingö, Sweden, which operates Lane Labs ("Lane").

1.2 Incorporation

This DPA forms part of the written agreement under which Lane provides services to the Customer ("Agreement") only when the executed Order Form expressly incorporates it. It applies where Lane processes Personal Data on behalf of the Customer. The completed Specification of Data Processing ("Specification"), the dated sub-processor list identified in the Order Form, and the versioned Technical and Organisational Measures, version 1 ("TOMs") form part of this DPA once completed and expressly incorporated.

1.3 Conflicts

For processing subject to this DPA, this DPA prevails over conflicting general terms. A negotiated Order Form provision varies this DPA only if it expressly identifies the clause being varied, is signed by both parties and remains compliant with Applicable Data Protection Law. Mandatory data-protection law prevails in all cases.

2

Definitions and roles

"Applicable Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the Swedish Data Protection Act (2018:218), and other data-protection law applicable to the processing. "Personal Data", "processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings in the GDPR. "Sub-processor" means a processor engaged by Lane to process Personal Data covered by this DPA.

The Customer is the Controller and Lane is the Processor where the Customer determines the purposes and means of processing. Where the Customer acts as a Processor for another Controller, Lane acts as the Customer's Sub-processor and the Customer confirms it is authorised to give the instructions in this DPA. Each party remains independently responsible for processing for which it determines the purposes and means, such as its own contract administration or legal compliance.

3

Details and documented instructions

3.1 Required details

The Specification must state the subject matter and duration of processing; its nature and purpose; the types of Personal Data; categories of Data Subjects; enabled features and integrations; locations; retention and deletion; and the rights and obligations of the Customer. A Specification is effective only when completed and incorporated into the Order Form.

3.2 Instructions

Lane will process Personal Data only on the Customer's documented instructions, including the Agreement, the completed Specification and lawful instructions issued through agreed channels, and only as needed to provide, secure and support the subscribed service. An instruction to transfer Personal Data to a third country or international organisation must also comply with section 11.

3.3 Required processing and unlawful instructions

If EU or Member State law requires Lane to process Personal Data other than on the Customer's instruction, Lane will inform the Customer of that legal requirement before processing unless the law prohibits notice on important grounds of public interest. Lane will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties resolve it.

4

Customer obligations

The Customer will:

  • comply with Applicable Data Protection Law in its collection, instructions and use of Personal Data;
  • have a valid legal basis and provide all required notices, and obtain any required consents or authorisations;
  • ensure its instructions are lawful, accurate and limited to the agreed purposes;
  • apply data minimisation and avoid restricted data unless expressly authorised in the Specification;
  • configure users, permissions, integrations and retention settings appropriately; and
  • remain responsible for responding to Data Subjects and Supervisory Authorities as Controller, with Lane's assistance under this DPA.
5

Lane's general obligations

Lane will:

  • comply with obligations directly applicable to Processors under Applicable Data Protection Law;
  • ensure persons authorised to process Personal Data are committed to confidentiality or under an appropriate statutory duty of confidentiality and access it only as necessary;
  • maintain the processing records required by GDPR Article 30(2) and cooperate with a competent Supervisory Authority as required by law;
  • not sell Personal Data, use it for advertising, or combine it with unrelated data for Lane's independent purposes;
  • not use Personal Data to train a general-purpose AI model unless the Customer gives a separate, express documented instruction; and
  • make available the information reasonably necessary to demonstrate compliance with this DPA.

A restriction on training does not by itself establish zero retention. Temporary processing, abuse monitoring, service logs, backups and provider retention must be documented separately in the completed Specification and sub-processor records.

6

Security of processing

Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as risks to individuals, Lane will implement and maintain appropriate technical and organisational measures meeting GDPR Article 32. The applicable controls must be stated in the versioned TOMs incorporated into the Order Form.

Lane will not materially reduce the overall protection of incorporated TOMs during the term. Changes needed to address an urgent threat or legal requirement may be implemented promptly, with notice to the Customer where practicable. The public Security page is informational, may change independently and is not a contractual TOMs appendix.

TOMs version 1 describes the Lane workspace controls and limitations in its stated scope. It applies to Customer Data only when the Order Form expressly incorporates that version, together with any Customer-specific additional measures.

7

Personal Data Breaches

Lane will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data covered by this DPA. Notice will be sent through the security or contract notice channel in the Order Form. No fixed-hour commitment applies unless an executed Order Form expressly adds one.

To the extent known, notice will describe the nature of the breach, including categories and approximate numbers of affected Data Subjects and records; the likely consequences; measures taken or proposed to address and mitigate it; and a contact for follow-up. Lane may provide information in phases without undue further delay where it is not available at the same time.

Lane will take reasonable steps to contain, investigate, mitigate and remediate the breach and will reasonably assist the Customer with notifications under GDPR Articles 33 and 34. A notice is not an admission of fault or liability. The Customer remains responsible for determining whether it must notify a Supervisory Authority or Data Subjects.

8

Data Subject rights

Taking into account the nature of processing, Lane will assist the Customer through appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligations to respond to requests under GDPR Chapter III, including access, rectification, erasure, restriction, portability, objection and safeguards relating to automated decision-making.

If Lane receives a request directly from a Data Subject concerning Personal Data processed for the Customer, Lane will, where lawful, promptly forward it to the Customer and will not respond substantively except on the Customer's documented instruction or as required by law. The Customer will provide the information needed to locate and assess the relevant data and remains responsible for the response.

9

Compliance assistance

Taking into account the nature of processing and information available to it, Lane will reasonably assist the Customer with obligations under GDPR Articles 32–36, including security assessments, breach response, data-protection impact assessments and prior consultation with a Supervisory Authority. Lane will also reasonably cooperate with a competent Supervisory Authority in relation to processing under this DPA.

The parties may agree reasonable charges in advance for unusually extensive assistance not caused by Lane's breach, but a fee discussion will not delay assistance required to meet an applicable statutory deadline.

10

Sub-processors

10.1 Authorisation and list

The Customer gives general written authorisation for Lane to use only the Sub-processors identified in the dated inventory version incorporated into the Order Form. The public sub-processor inventory is a reference only; a later website update does not by itself amend an existing Agreement.

10.2 New Sub-processors and objections

Lane will give advance written notice through the contract notice channel before a new Sub-processor begins processing, including its identity, location, function and affected data. The notice period is stated in the Order Form and must give the Customer a reasonable opportunity to object on data-protection grounds before processing begins. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate the affected feature or service as stated in the Order Form.

10.3 Flow-down and responsibility

Before processing begins, Lane will enter into a written contract with each Sub-processor imposing data-protection obligations that provide at least the protection required by this DPA, as applicable to the services performed. Lane remains responsible to the Customer for the performance of each Sub-processor's obligations under that contract.

11

International transfers

Lane will not transfer Personal Data to a country or international organisation outside the EEA, or permit remote access constituting such a transfer, except on the Customer's documented instruction and in compliance with GDPR Chapter V. The completed Specification and sub-processor inventory must identify processing and storage locations, remote-access locations, applicable adequacy decisions or other safeguards, and any supplementary measures.

If the European Commission's Standard Contractual Clauses are needed, the relevant parties must separately complete and execute the correct module or modules and all required annexes. That package must identify the exporter and importer, categories of data and Data Subjects, transfer frequency and purpose, retention, competent Supervisory Authority, Sub-processors, security measures, optional clauses and any supplementary measures. The parties will complete a transfer assessment where required.

Nothing on this website deems SCCs signed, completed or incorporated. Publication of this DPA, a link to SCC text, or use of Lane does not execute transfer clauses. Where a Sub-processor is the data importer, Lane will ensure the relevant vendor transfer mechanism is contractually in place and will record it in the completed inventory before the transfer begins.

12

Government and third-party demands

Unless prohibited by law, Lane will promptly notify the Customer of a legally binding demand for Personal Data from a public authority. Lane will review the demand, challenge it where there are reasonable grounds, disclose only data legally required and document the response. Lane will not voluntarily provide bulk or indiscriminate access to Personal Data.

13

Information and audits

Lane will make available all information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA and will allow for and contribute to audits, including inspections, by the Customer or an independent auditor it mandates. The auditor must be appropriately qualified, independent and bound by confidentiality.

The parties will first use current independent reports or written responses where these adequately address the request; this does not remove the Customer's statutory audit rights. Unless a Supervisory Authority requires otherwise or there is a Personal Data Breach or reasonable evidence of material non-compliance, an on-site audit will occur no more than once in 12 months, on reasonable advance notice, during normal business hours and without exposing another customer's data or compromising security.

The Customer bears reasonable audit costs unless the audit identifies Lane's material breach, in which case cost allocation will follow the Agreement and applicable law. Lane will promptly inform the Customer if an audit instruction would infringe Applicable Data Protection Law.

14

Return, export and deletion

At the Customer's choice, Lane will delete or return all Personal Data after the end of the provision of processing services and delete existing copies, unless EU or Member State law requires storage. The Customer must communicate its choice through the agreed contract channel. Supported self-service export may be used during the term; format, transition assistance and timing must be stated in the Order Form.

Where retention is legally required, Lane will inform the Customer where lawful, identify the data and legal basis, isolate the data from ordinary processing, keep it protected and delete it when the requirement ends. Lane will require relevant Sub-processors to carry out the same return or deletion instruction and, on request, provide reasonable confirmation of completion.

Active-system, temporary-file, cache, queue, model-provider log and backup deletion periods are stated in the completed Specification. Data persisting in protected backups will remain isolated and be deleted on the documented backup cycle.

15

Term and effect of termination

This DPA begins when it is validly incorporated and continues for as long as Lane processes Personal Data on the Customer's behalf. Termination of the Agreement does not end confidentiality, security, audit, assistance, transfer or deletion duties that by their nature continue while Lane or a Sub-processor retains Personal Data.

16

Liability, law and notices

The liability allocation in the executed Agreement applies to this DPA only to the extent permitted by Applicable Data Protection Law and must not restrict Data Subjects' statutory rights.

Unless the Order Form lawfully provides otherwise, this DPA is governed by Swedish law and disputes are subject to the Swedish courts, with Stockholm District Court (Stockholms tingsrätt) as court of first instance, without limiting a competent Supervisory Authority's powers or a Data Subject's rights.

Operational, security and legal notices must use the contacts stated in the Order Form. Postal correspondence may be addressed to Rwk Group Holding AB, Törnrosvägen 74A, 181 61 Lidingö, Sweden.

Data Processing Agreement | Lane Labs