Data Processing Agreement

Template version 2026-07-20 · Incorporating the Terms of Service and Privacy Policy, version 2026-07-19

This is ExhibitMail's standard GDPR Article 28 Data Processing Agreement, published for transparency and legal review. To execute it, download the signable copy, fill in the highlighted Customer fields, sign, and send it via the support button ("?") on exhibitmail.com — we return a countersigned copy by e-mail. Highlighted fields are completed per customer.
Download the signable copy (.docx)

Parties

The "Customer" (controller)The "Provider" (processor)
Legal name[Customer legal name]Soundcare AB
Reg. no.[Registration number]556882-6621 (Sweden)
Address[Address]Mailbox 1602, 411 42 Göteborg, Sweden
Contact e-mail[E-mail]via exhibitmail.com support

This Data Processing Agreement (the "DPA") forms part of the agreement between the Customer and the Provider for the use of the ExhibitMail service at exhibitmail.com (the "Service"), consisting of the ExhibitMail Terms of Service accepted by the Customer (the "Agreement"). It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (the "GDPR").

1. Definitions

Terms such as personal data, controller, processor, data subject, processing, personal data breach and supervisory authority have the meanings given in the GDPR. "Case Content" means the e-mail corpora and other material the Customer or its invited case members upload to a case on the Service, and all personal data contained in it. "Case" means a private case workspace created on the Service.

2. Roles and scope

For Case Content, the Customer is the controller and the Provider is the processor. This DPA governs all processing of Case Content by the Provider on the Customer's behalf.

Where the Customer is itself a processor for a third party (for example, a law firm processing a client's correspondence), the Provider acts as the Customer's sub-processor; the Customer warrants that its instructions to the Provider are authorised by the relevant controller and that it has made this DPA's terms available to that controller on request.

For account, billing and support data, the Provider is an independent controller as described in the Privacy Policy; such data is outside the scope of this DPA.

3. Instructions

The Provider processes Case Content only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which the Provider is subject; in that case the Provider informs the Customer of that legal requirement before processing, unless the law prohibits it.

The Customer's instructions are, in the first instance, given through the Service itself: uploading material, configuring the case, inviting members, and invoking features (search, indexing, relevance scoring, AI-assisted answers, exports and deletion) constitute instructions to perform the corresponding processing. Additional written instructions may be agreed where the Service supports them.

The Provider informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Confidentiality

The Provider ensures that every person it authorises to process Case Content is bound by a contractual or statutory obligation of confidentiality. The Provider's personnel access Case Content only where necessary to operate the Service, to investigate abuse or faults, or where the law requires, as stated in the Agreement.

5. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to data subjects, the Provider implements and maintains the technical and organisational measures described in Annex 2 (Article 32 GDPR). The Provider may update those measures over time, provided the overall level of protection is not reduced.

6. Sub-processors

The Customer grants a general authorisation for the Provider to engage the sub-processors listed in Annex 3. The Provider gives the Customer prior notice of any intended addition or replacement of a sub-processor (in the product or by e-mail), giving the Customer the opportunity to object; if the Customer objects on reasonable data-protection grounds and no resolution is found, the Customer may terminate the affected Case and delete its content as described in clause 10.

The Provider imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Customer for the sub-processor's performance.

7. International transfers

Where processing by the Provider or a sub-processor takes place outside the EU/EEA, the transfer relies on an adequacy decision (including the EU–U.S. Data Privacy Framework where the recipient is certified) and/or the EU Standard Contractual Clauses, together with supplementary measures where appropriate, as identified per provider in Annex 3.

8. Assistance

Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests (access, rectification, erasure, restriction, portability, objection). The Service's own search, tagging, export and deletion functions are the primary means of such assistance. If a data subject contacts the Provider directly about Case Content, the Provider refers the request to the Customer without undue delay.

The Provider further assists the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Provider.

9. Personal data breach

The Provider notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Case Content. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The Provider documents such breaches and cooperates with the Customer's reasonable requests for further information.

10. Deletion and return

The Customer controls deletion self-service: deleting a Case destroys that Case's unique encryption key, which renders the Case Content — including copies in any backups — permanently unreadable (crypto-shredding). This is the agreed method of deletion and is irreversible.

Upon request before deletion, the Provider makes Case Content available to the Customer in a commonly used electronic format (including the uploaded mailbox files as provided). Upon termination of the Agreement, the Provider deletes all remaining Case Content in the same manner, unless Union or Member State law requires continued storage.

11. Audits and information

The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are subject to reasonable prior notice, at most once per twelve months (except after a personal data breach or where required by a supervisory authority), during business hours, without access to other customers' data or to the Provider's master keys, and at the Customer's cost. The Provider may first satisfy an audit request with relevant documentation of its measures.

12. Liability, term and law

Liability under this DPA follows the liability provisions of the Agreement, without prejudice to data subjects' rights under the GDPR. This DPA applies for as long as the Provider processes Case Content and, for obligations that by nature survive, thereafter. This DPA is governed by Swedish law and subject to the jurisdiction of the Swedish courts, with Göteborgs tingsrätt as first instance, as set out in the Agreement. In case of conflict between this DPA and the Agreement concerning the processing of Case Content, this DPA prevails.

Annex 1 — Details of the processing

ItemDescription
Subject matterHosting and processing of e-mail corpora uploaded to the Customer's Case(s) on the ExhibitMail service for the purpose of organising, reviewing and analysing correspondence in connection with a legal dispute.
DurationFor as long as the Case exists; ends upon deletion of the Case (crypto-shredding) or termination of the Agreement.
Nature and purposeStorage, indexing and full-text search; relevance scoring of messages against the Customer's case description; AI-assisted question answering with citations; tagging; display to invited case members; audit logging within the Case; export; deletion. All processing is initiated by the Customer's use of the Service.
Categories of data subjectsThe Customer and its personnel; case members invited by the Customer; senders and recipients of the uploaded correspondence; third parties mentioned in the correspondence.
Categories of personal dataNames, e-mail addresses and other contact details; message content and subject lines; attachments and their contents; message metadata (dates, threading); any further personal data incidentally contained in correspondence, which — given the nature of e-mail archives — may include special categories of data (Art. 9 GDPR) or data relating to criminal matters (Art. 10 GDPR). The Customer is responsible for the lawfulness of uploading such material.
FrequencyContinuous while the Case exists; individual processing operations occur when the Customer or its case members use the corresponding features.

Annex 2 — Technical and organisational measures

Annex 3 — Authorised sub-processors

The following sub-processors are engaged in the processing of Case Content:

Sub-processorRole (Case Content touched)LocationTransfer mechanism
Railway Corp.Cloud hosting of the application and encrypted Case storageUnited States (hosting region per deployment)EU–U.S. DPF and/or SCCs
Anthropic, PBCAI processing (relevance scoring, assistant answers); no training on customer dataUnited StatesEU–U.S. DPF and/or SCCs
Twilio Inc. (SendGrid)Transactional e-mail (sign-in codes, notifications); may carry Case names and member e-mail addresses, never corpus contentUnited StatesEU–U.S. DPF and/or SCCs

Stripe, Inc. processes payment data for the Provider as described in the Privacy Policy; it does not process Case Content and is therefore not a sub-processor under this DPA.