Specification of Data Processing
Version 1.0 · Last updated 11 August 2026
Parties and roles
The Customer named in the Order Form is Controller and Rwk Group Holding AB, Swedish company registration number 559544-6450, with registered address Törnrosvägen 74A, 181 61 Lidingö, Sweden, operating Lane Labs, is Processor. If the Customer is a Processor for another Controller, Lane is its Sub-processor. The Customer's rights and obligations are stated in the Data Processing Agreement ("DPA") and the Order Form.
Subject matter, duration, nature and purpose
Subject matter. Processing Personal Data on the Customer's documented instructions to provide the Lane features expressly enabled in the Order Form. Lane is an AI workspace for financial teams that brings documents, spreadsheets, data, and email into connected workflows.
Duration. For the Order Form term and any limited return, export, legal-retention or deletion period completed below. The DPA continues while Lane or a Sub-processor retains Personal Data.
Nature. Depending on enabled features: collection or receipt, transmission, storage, organisation, structuring, indexing, retrieval, consultation, extraction, comparison, calculation, transformation, analysis, generation, display, collaboration, export, restriction and deletion. Operational processing may include authentication, authorisation, security logging, troubleshooting, backup and recovery where included in the Order Form.
Purpose. To help the Customer move from source material to reviewed financial work, provide and secure the subscribed functions, respond to authorised support requests, and comply with law. Lane does not determine the Customer's professional or business purposes and does not replace human review or approval.
Feature-dependent processing
Only feature areas expressly enabled in the Order Form apply. This table does not represent that every feature is available.
| Feature area | Possible processing | Customer-specific Order Form scope |
|---|---|---|
| Accounts and workspaces | Create users and workspaces; authenticate; authorise access; record account and security events. | Identity provider, fields, enabled access capabilities, logs and retention as stated in the Order Form. |
| Documents | Upload, store, parse, index, search, extract, compare, summarise and prepare reviewed outputs; source references only where supported. | Formats, stores, OCR/parser/model providers, temporary files and deletion as stated in the Order Form. |
| Spreadsheets and outputs | Read selected cells or workbooks; structure and analyse data; prepare calculations, tables, formulas or files for human review. | Enabled functions, file storage, execution environment and export formats as stated in the Order Form. |
| Data and databases | Import or connect to authorised datasets; query, retrieve, structure, transform and analyse records; create derived data or search indexes. | Connectors, database/vector stores, credentials, query controls, regions and retention as stated in the Order Form. |
| Connect an authorised inbox; retrieve selected messages and attachments; search or analyse content; prepare drafts or outputs for user approval. | Providers, scopes, send capability, tokens, logs and deletion as stated in the Order Form. No autonomous sending is assumed. | |
| AI-assisted workflows | Transmit selected instructions and content to an approved model service; receive generated or structured output; apply human review. | Each model provider, legal entity, location, logging, retention, no-training term and transfer safeguard stated in the Order Form. |
| Support and operations | Handle authorised support material; maintain necessary application, audit, security, error, trace, cache, queue and backup data. | Systems, authorised access, fields, locations and retention periods as stated in the Order Form. |
Categories of Data Subjects
Depending on Customer Data and enabled features, Data Subjects may include:
- Customer users, personnel, contractors and representatives;
- the Customer's clients and prospective clients;
- investors, beneficial owners, shareholders and fund or account contacts;
- counterparties, targets, borrowers, lenders and other transaction participants;
- directors, officers and personnel of portfolio companies or other analysed organisations;
- professional advisers, auditors and consultants;
- vendors, service providers and their personnel; and
- people appearing in documents, spreadsheets, datasets, databases, email or other Customer Data.
Remove any category not relevant to the Customer's documented use. The Customer must not use this illustrative list to expand processing beyond its lawful purpose.
Categories of Personal Data
Depending on Customer Data and enabled features:
- identity and professional information, such as names, titles, roles, employers and signatures;
- business contact information, such as work email, telephone number and business address;
- account and access information, such as user identifiers, workspace membership, permissions, authentication events and integration identifiers;
- professional communications, email content, attachments, notes and meeting or correspondence metadata;
- financial, commercial and investment information, such as transaction, valuation, performance, ownership, portfolio, invoice, bank-account or contractual information;
- documents, spreadsheet cells, database records, prompts, instructions, annotations and user feedback containing Personal Data;
- derived or generated information, such as classifications, summaries, extracted fields, calculations and draft outputs; and
- technical and security metadata, such as IP address, device or browser information, timestamps, request identifiers, audit events, error logs and traces.
Restricted and sensitive data
The Customer must not submit GDPR Article 9 special-category data, personal data concerning criminal convictions or offences, full payment-card data, authentication secrets, government-issued identifiers or other unusually sensitive data unless an executed Order Form expressly identifies the category, lawful basis, necessity, access limits, security measures, provider eligibility and retention. Lane is not configured or approved for those categories merely because free-text fields or file uploads could technically contain them.
Financial and investment information is not automatically special-category data but may create significant confidentiality and harm risks. The Customer must minimise it and limit access. Passwords, private keys and secret tokens must not be placed in ordinary prompts or uploads; supported integration secrets, if any, must use the designated secure connection mechanism.
Integrations and instructions
No document repository, spreadsheet service, database, inbox, model provider or other integration is included unless the Order Form identifies it and the Customer enables it. For each integration, the completed Specification must record the data scope, permissions, read/write/send capability, provider, location, retention, revocation and deletion behaviour. The Customer's configuration and authorised user actions are documented instructions only within the agreed scope.
Sub-processors and processing locations
The Customer authorises only the providers in the dated Sub-processor Inventory incorporated into its Order Form. Providers used only for public website enquiries do not process Customer Data under this DPA unless the Order Form expressly states otherwise.
Storage, processing, support, logging, backup and remote-access locations are those stated in the Order Form and incorporated provider list. This Specification makes no default EU-only, Frankfurt-only or other residency commitment. A restricted transfer requires the completed Chapter V mechanism described in section 11 of the DPA.
Retention, return and deletion
The Customer chooses return or deletion at the end of processing, subject to the DPA and mandatory law. The Order Form states the applicable periods for each enabled store or flow.
| Data store or flow | Retention and deletion scope | Governing schedule |
|---|---|---|
| Active Customer Data and outputs | Deletion trigger, export window, soft-delete state and completion period. | Order Form. |
| Uploaded and temporary files | Parser, OCR and model staging locations and deletion period. | Order Form and provider schedule. |
| Database, search and vector data | Primary stores, replicas, indexes, queues, caches and derived-data deletion. | Order Form and provider schedule. |
| Email and integration data | Sync scope, local copies, tokens, revoked connections and provider copies. | Order Form for enabled integrations. |
| AI requests and responses | Application state, provider logs and temporary retention; no-training is not zero retention. | Order Form and model-provider schedule. |
| Audit, security, telemetry and support | Fields, purpose, access and operational or legal retention periods. | Order Form. |
| Backups and disaster recovery | Frequency, locations, recovery cycle and final deletion. | Order Form. |
| Legally retained copies | Legal basis, isolation, restricted use and deletion trigger. | Applicable law and Order Form. |
Customer-specific entries
The executed Order Form must identify the Customer-specific entries below. An item not selected or stated is not part of the Customer's processing instruction.
- Customer legal name, data-protection role and authorised contact;
- enabled features, integrations and processing purposes;
- applicable Data Subject and Personal Data categories;
- any restricted-data authorisation and safeguards;
- provider entities, locations and transfer mechanisms;
- retention, export, return, deletion and backup schedule; and
- the applicable product TOMs version.
