DATA PROCESSING AGREEMENT

Data Processing Agreement

VAERG AB (STOCKHOLM, SWEDEN) · LAST UPDATED: AUGUST 10, 2026
This Data Processing Agreement ("DPA") forms part of the VAERG Terms of Service (the "Agreement") between VAERG AB, Stockholm, Sweden ("VAERG", the "Processor") and the customer identified in the Agreement (the "Customer", the "Controller"). It is incorporated into the Agreement by reference and applies whenever VAERG processes personal data on the Customer's behalf in connection with the Services. No separate signature is required.

01Background and roles

The Customer uploads deal materials such as information memoranda, annual reports and related documents ("Customer Materials") and receives an analytical report (the "Report"). Customer Materials may contain personal data relating to individuals connected with the company described in the materials, such as members of management, employees, shareholders and customer contacts. For such personal data, the Customer is the controller and VAERG is the processor within the meaning of Regulation (EU) 2016/679 (the "GDPR").

This DPA does not apply to personal data for which VAERG is itself the controller, such as the Customer's account and billing data.

02Subject matter, nature and purpose

VAERG processes Customer Materials solely to produce the Report and to operate, secure and support the Services. The details of processing are specified in Annex 1.

VAERG does not use Customer Materials or Reports to train, fine-tune or otherwise improve any machine-learning model, whether its own or a third party's. VAERG contractually requires the same commitment from every sub-processor that performs AI inference, and engages such sub-processors only on commercial terms under which customer content is not used for model training.

Customer Materials are processed in isolation per engagement. Content from one customer is never used in, combined with, or made retrievable from the processing of another customer's engagement, and is never added to any shared knowledge base.

03Instructions

VAERG processes personal data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by EU or Member State law, in which case VAERG will inform the Customer of that legal requirement before processing, unless the law prohibits this.

The Agreement, this DPA, and the Customer's use of the Services, including the act of uploading Customer Materials for analysis, constitute the Customer's complete documented instructions. Additional instructions require written agreement. VAERG will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

04Confidentiality

VAERG ensures that every person authorised to process personal data under this DPA is bound by a contractual or statutory obligation of confidentiality. Access to Customer Materials is restricted to personnel who need it to deliver or support the Services, and all access is logged.

05Security

VAERG implements and maintains the technical and organisational measures described in Annex 2, in accordance with Article 32 GDPR. VAERG may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.

06Sub-processors

The Customer provides a general authorisation for VAERG to engage the sub-processors listed at vaerg.com/subprocessors, which is incorporated into this DPA by reference.

VAERG will give at least fourteen (14) days' prior notice of any intended addition or replacement of a sub-processor, by updating the published list and notifying customers registered for such notice. If the Customer has reasonable data-protection grounds to object, the parties will discuss in good faith; if no resolution is found, the Customer may terminate the affected Services with a pro-rata refund of any prepaid, unused fees.

VAERG imposes on each sub-processor, by way of contract, data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.

07International transfers

Customer Materials are stored and orchestrated within the European Union (see Annex 2). Certain sub-processors performing AI inference or ancillary services are established in the United States.

Where processing by a sub-processor involves a transfer of personal data to a country without an adequacy decision, the transfer is made subject to the Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, as incorporated into VAERG's agreement with the relevant sub-processor (Module 3, processor to processor), or another valid transfer mechanism under Chapter V GDPR. On request, VAERG will provide the Customer with information reasonably necessary to conduct a transfer impact assessment.

08Assistance to the Controller

Taking into account the nature of the processing, VAERG will assist the Customer with appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data subject requests under Chapter III GDPR. If a data subject contacts VAERG directly, VAERG will refer the request to the Customer without undue delay.

VAERG will assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to VAERG.

09Personal data breach

VAERG will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will, to the extent known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available.

10Retention and deletion

Uploaded Customer Materials are automatically and permanently deleted upon generation of the Report; they are not stored after delivery. If a screening fails, uploaded materials may be retained solely for troubleshooting, never longer than thirty (30) days, and are then deleted. Delivered Reports are archived to enable re-download and internal quality control of VAERG's own work, under the confidentiality obligations of the Agreement. The Customer may request deletion of the archived Report at any time, and VAERG will complete such deletion within seven (7) days of the request.

Upon termination of the Agreement, VAERG will, at the Customer's choice, delete or return all personal data processed under this DPA and delete existing copies, unless EU or Member State law requires further storage. Deletion from encrypted backups occurs in the ordinary backup rotation cycle, and backup copies remain protected by the measures in Annex 2 until deleted.

11Audit and information

VAERG will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including summaries of relevant third-party attestations for VAERG's infrastructure providers, and will allow for and contribute to audits.

Audits are in the first instance conducted through written questionnaires and documentation review. On-site inspection may be requested where documentation is insufficient or where required by a supervisory authority, with at least thirty (30) days' notice, during business hours, no more than once per twelve-month period, and subject to reasonable confidentiality undertakings. Each party bears its own costs.

12Liability, term and governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except where mandatory law provides otherwise. This DPA enters into force when the Agreement is accepted and remains in force for as long as VAERG processes personal data on the Customer's behalf. It is governed by Swedish law, with disputes resolved as set out in the Agreement and the Stockholm District Court as first instance where the Agreement does not provide otherwise.

A1Annex 1: Details of processing

Subject matter: Analysis of Customer-uploaded deal materials to produce a commercial screening report.

Duration: The duration of the engagement plus the retention periods in Section 10.

Nature and purpose: Ingestion, text and data extraction, AI-assisted analysis, report generation, delivery, and related storage, security and support.

Categories of data subjects: Directors, officers and employees of the company described in the Customer Materials; its shareholders and beneficial owners; contact persons at its customers, suppliers and advisers; other individuals mentioned in the Customer Materials.

Categories of personal data: Names, roles and titles; professional contact details; employment-related information including tenure and, where included in the materials, remuneration and incentive arrangements; shareholdings and related-party relationships; other personal data incidentally contained in the Customer Materials. The Services are not intended for special categories of personal data (Article 9 GDPR), and the Customer agrees not to upload materials containing such data beyond what may incidentally appear in ordinary corporate documentation.

A2Annex 2: Technical and organisational measures

  • Hosting and processing region. Application, processing pipeline and storage run in an EU region (Amsterdam, Netherlands). Uploaded Customer Materials are stored only in this environment.
  • Encryption. All data in transit is encrypted with TLS 1.2 or higher; data at rest is encrypted using the infrastructure provider's storage encryption.
  • Isolation. Each engagement is processed in an isolated job workspace, with no cross-customer access paths and no customer content in shared indices or knowledge bases.
  • Access control. Individually attributed credentials with multi-factor authentication; access limited to personnel with an operational need and logged.
  • Deletion. Automated deletion of Customer Materials upon Report generation (failed jobs at most 30 days); Report deletion on request within 7 days.
  • AI processing safeguards. AI inference exclusively through commercial API tiers under data processing terms that prohibit the use of customer content for model training.
  • Logging and monitoring. System-level logging of processing jobs, administrative access and errors, without the content of Customer Materials beyond what error diagnosis strictly requires.
  • Organisational measures. Confidentiality undertakings for all personnel; documented incident response with the notification commitment in Section 09; vendor due diligence and data processing agreements with all sub-processors; least privilege; regular access review.

A3Annex 3: Authorised sub-processors

The current list, including purpose, location and transfer safeguard for each sub-processor, is published at vaerg.com/subprocessors and incorporated into this DPA by reference.

Questions: contact@vaerg.com