Back to Terms

Specification of Data Processing

Version 1.0 · Last updated 11 August 2026

1

Parties and roles

The Customer named in the Order Form is Controller and Rwk Group Holding AB, Swedish company registration number 559544-6450, with registered address Törnrosvägen 74A, 181 61 Lidingö, Sweden, operating Lane Labs, is Processor. If the Customer is a Processor for another Controller, Lane is its Sub-processor. The Customer's rights and obligations are stated in the Data Processing Agreement ("DPA") and the Order Form.

2

Subject matter, duration, nature and purpose

Subject matter. Processing Personal Data on the Customer's documented instructions to provide the Lane features expressly enabled in the Order Form. Lane is an AI workspace for financial teams that brings documents, spreadsheets, data, and email into connected workflows.

Duration. For the Order Form term and any limited return, export, legal-retention or deletion period completed below. The DPA continues while Lane or a Sub-processor retains Personal Data.

Nature. Depending on enabled features: collection or receipt, transmission, storage, organisation, structuring, indexing, retrieval, consultation, extraction, comparison, calculation, transformation, analysis, generation, display, collaboration, export, restriction and deletion. Operational processing may include authentication, authorisation, security logging, troubleshooting, backup and recovery where included in the Order Form.

Purpose. To help the Customer move from source material to reviewed financial work, provide and secure the subscribed functions, respond to authorised support requests, and comply with law. Lane does not determine the Customer's professional or business purposes and does not replace human review or approval.

3

Feature-dependent processing

Only feature areas expressly enabled in the Order Form apply. This table does not represent that every feature is available.

Feature areaPossible processingCustomer-specific Order Form scope
Accounts and workspacesCreate users and workspaces; authenticate; authorise access; record account and security events.Identity provider, fields, enabled access capabilities, logs and retention as stated in the Order Form.
DocumentsUpload, store, parse, index, search, extract, compare, summarise and prepare reviewed outputs; source references only where supported.Formats, stores, OCR/parser/model providers, temporary files and deletion as stated in the Order Form.
Spreadsheets and outputsRead selected cells or workbooks; structure and analyse data; prepare calculations, tables, formulas or files for human review.Enabled functions, file storage, execution environment and export formats as stated in the Order Form.
Data and databasesImport or connect to authorised datasets; query, retrieve, structure, transform and analyse records; create derived data or search indexes.Connectors, database/vector stores, credentials, query controls, regions and retention as stated in the Order Form.
EmailConnect an authorised inbox; retrieve selected messages and attachments; search or analyse content; prepare drafts or outputs for user approval.Providers, scopes, send capability, tokens, logs and deletion as stated in the Order Form. No autonomous sending is assumed.
AI-assisted workflowsTransmit selected instructions and content to an approved model service; receive generated or structured output; apply human review.Each model provider, legal entity, location, logging, retention, no-training term and transfer safeguard stated in the Order Form.
Support and operationsHandle authorised support material; maintain necessary application, audit, security, error, trace, cache, queue and backup data.Systems, authorised access, fields, locations and retention periods as stated in the Order Form.
4

Categories of Data Subjects

Depending on Customer Data and enabled features, Data Subjects may include:

  • Customer users, personnel, contractors and representatives;
  • the Customer's clients and prospective clients;
  • investors, beneficial owners, shareholders and fund or account contacts;
  • counterparties, targets, borrowers, lenders and other transaction participants;
  • directors, officers and personnel of portfolio companies or other analysed organisations;
  • professional advisers, auditors and consultants;
  • vendors, service providers and their personnel; and
  • people appearing in documents, spreadsheets, datasets, databases, email or other Customer Data.

Remove any category not relevant to the Customer's documented use. The Customer must not use this illustrative list to expand processing beyond its lawful purpose.

5

Categories of Personal Data

Depending on Customer Data and enabled features:

  • identity and professional information, such as names, titles, roles, employers and signatures;
  • business contact information, such as work email, telephone number and business address;
  • account and access information, such as user identifiers, workspace membership, permissions, authentication events and integration identifiers;
  • professional communications, email content, attachments, notes and meeting or correspondence metadata;
  • financial, commercial and investment information, such as transaction, valuation, performance, ownership, portfolio, invoice, bank-account or contractual information;
  • documents, spreadsheet cells, database records, prompts, instructions, annotations and user feedback containing Personal Data;
  • derived or generated information, such as classifications, summaries, extracted fields, calculations and draft outputs; and
  • technical and security metadata, such as IP address, device or browser information, timestamps, request identifiers, audit events, error logs and traces.
6

Restricted and sensitive data

The Customer must not submit GDPR Article 9 special-category data, personal data concerning criminal convictions or offences, full payment-card data, authentication secrets, government-issued identifiers or other unusually sensitive data unless an executed Order Form expressly identifies the category, lawful basis, necessity, access limits, security measures, provider eligibility and retention. Lane is not configured or approved for those categories merely because free-text fields or file uploads could technically contain them.

Financial and investment information is not automatically special-category data but may create significant confidentiality and harm risks. The Customer must minimise it and limit access. Passwords, private keys and secret tokens must not be placed in ordinary prompts or uploads; supported integration secrets, if any, must use the designated secure connection mechanism.

7

Integrations and instructions

No document repository, spreadsheet service, database, inbox, model provider or other integration is included unless the Order Form identifies it and the Customer enables it. For each integration, the completed Specification must record the data scope, permissions, read/write/send capability, provider, location, retention, revocation and deletion behaviour. The Customer's configuration and authorised user actions are documented instructions only within the agreed scope.

8

Sub-processors and processing locations

The Customer authorises only the providers in the dated Sub-processor Inventory incorporated into its Order Form. Providers used only for public website enquiries do not process Customer Data under this DPA unless the Order Form expressly states otherwise.

Storage, processing, support, logging, backup and remote-access locations are those stated in the Order Form and incorporated provider list. This Specification makes no default EU-only, Frankfurt-only or other residency commitment. A restricted transfer requires the completed Chapter V mechanism described in section 11 of the DPA.

9

Retention, return and deletion

The Customer chooses return or deletion at the end of processing, subject to the DPA and mandatory law. The Order Form states the applicable periods for each enabled store or flow.

Data store or flowRetention and deletion scopeGoverning schedule
Active Customer Data and outputsDeletion trigger, export window, soft-delete state and completion period.Order Form.
Uploaded and temporary filesParser, OCR and model staging locations and deletion period.Order Form and provider schedule.
Database, search and vector dataPrimary stores, replicas, indexes, queues, caches and derived-data deletion.Order Form and provider schedule.
Email and integration dataSync scope, local copies, tokens, revoked connections and provider copies.Order Form for enabled integrations.
AI requests and responsesApplication state, provider logs and temporary retention; no-training is not zero retention.Order Form and model-provider schedule.
Audit, security, telemetry and supportFields, purpose, access and operational or legal retention periods.Order Form.
Backups and disaster recoveryFrequency, locations, recovery cycle and final deletion.Order Form.
Legally retained copiesLegal basis, isolation, restricted use and deletion trigger.Applicable law and Order Form.
10

Customer-specific entries

The executed Order Form must identify the Customer-specific entries below. An item not selected or stated is not part of the Customer's processing instruction.

  • Customer legal name, data-protection role and authorised contact;
  • enabled features, integrations and processing purposes;
  • applicable Data Subject and Personal Data categories;
  • any restricted-data authorisation and safeguards;
  • provider entities, locations and transfer mechanisms;
  • retention, export, return, deletion and backup schedule; and
  • the applicable product TOMs version.
Specification of Data Processing | Lane Labs