This agreement is between the customer, as controller (the "Customer"), and Edström Business AB (org.nr 559101-7750), as processor ("Tindom").
It applies when Tindom processes personal data on the Customer’s behalf under a pilot agreement or other customer agreement (the "Main Agreement"), for example when the Customer sends signed documents to validate@tindom.se. It does not apply to the open web validator, where Tindom is itself the controller under the privacy policy.
The agreement takes effect when the Customer has accepted it in the Main Agreement, by a signed copy, or by sending documents to Tindom after being given the agreement. If it conflicts with the Main Agreement, this agreement prevails on matters of personal data.
Tindom processes the personal data only to validate the electronic signatures in the documents the Customer sends and to send a validation report back to the Customer. Processing lasts as long as the Main Agreement.
Details of the processing are in Annex 1.
The Customer is responsible for having a legal basis for the processing, for being entitled to submit the documents, and for data subjects having received the information they are due. The Customer should not submit data not needed for validation, and in particular not data covered by Article 9 or 10 GDPR unless necessary.
Reports to pilot customers may contain full personal identity numbers and technical signing details, such as IP address and timestamps. The Customer is responsible for processing personal identity numbers being permitted under Chapter 3, Section 10 of the Swedish Data Protection Act.
The Customer gives Tindom general authorisation to use the sub-processors listed in Annex 3. Tindom has agreements with them imposing the same obligations as this agreement, and is liable to the Customer for their performance.
If Tindom wishes to add or replace a sub-processor, it will inform the Customer by email at least 30 days in advance. The Customer may object on reasonable grounds within that time. If the parties cannot agree, the Customer may terminate the Main Agreement at no cost.
The personal data is processed within the EU/EEA, except for sub-processors in Annex 3 that are US companies. Transfer there takes place only on the basis of an adequacy decision (the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses, with the supplementary safeguards needed. The Customer approves these transfers.
If Tindom discovers a personal data breach affecting the Customer’s data, Tindom will notify the Customer without undue delay and within 48 hours of becoming aware of it. The notice will, as far as the information is available, describe the nature of the breach, the data and number of data subjects concerned, the likely consequences and the measures taken. Tindom will help the Customer investigate and remedy the breach.
Documents are not stored after validation. When the Main Agreement ends, Tindom deletes the personal data still held on the Customer’s behalf, including the operations-log data belonging to the Customer, within 30 days of a request or of termination, unless law requires it to be kept. The Customer may request written confirmation of the deletion.
On request, Tindom will provide the information needed to show that the Article 28 obligations are met. The Customer, or an auditor it engages who is bound by confidentiality, may carry out audits, at most once a year unless an incident or a supervisory authority requires otherwise. An audit must be announced at least 30 days in advance, take place in office hours and not disrupt operations unnecessarily. Each party bears its own costs.
The limitations of liability in the Main Agreement also apply to this agreement, unless mandatory law provides otherwise. This does not affect data subjects’ right to compensation under Article 82 GDPR.
The agreement applies for as long as Tindom processes personal data on the Customer’s behalf. Changes must be in writing, except changes to Annex 3 made under section 5. Swedish law applies, and disputes will be settled by a Swedish general court.
| Question | Answer |
|---|---|
| Purpose | Validate electronic signatures in documents the Customer sends and deliver a validation report |
| Nature of processing | Receipt, temporary in-memory reading of the file’s signature data, validation against trusted lists, report generation, delivery by email |
| Categories of data subjects | People appearing in the documents, mainly signers, and the Customer’s contacts who send documents |
| Categories of personal data | Name, organisation, personal identity number, email address, technical signing details (certificate details, timestamps, IP address and audit events where the document contains them), anything else that happens to be in the document |
| Sensitive data | Not intended. Validation needs only the signature |
| Retention | The document is not stored. The report is sent immediately. An operations log (sender, subject line, filenames, fingerprint, result) is kept for 12 months. The sub-processor Postmark keeps the inbound message, including attachments, for 45 days |
| Contact point for questions and incidents | contact@tindom.se |
| Sub-processor | Task | Location |
|---|---|---|
| Vercel Inc. | Hosting of the APIs that receive and forward the document | Sweden (Stockholm) |
| Railway Corp. | Runs the validation engine (EC DSS) | The Netherlands |
| Resend, Inc. | Sends the report to the customer by email | USA |
| Postmark (ActiveCampaign, LLC) | Receives email sent to validate@tindom.se | USA |
| Google Ireland Ltd (Google Workspace) | Tindom’s email, for support cases where the customer attaches a document themselves | EU, with possible transfer to the USA |