Data Processing Agreement (DPA)

Version 1.0, October 10, 2026

The Swedish version prevails if the two differ.

1. The Customer: each limited company (aktiebolag) added to an account in Inzenda (the "Customer"). This agreement applies separately to each such company. The Customer is the controller.
2. Inzenda AB, company registration number 559480-1580, Sysslomansgatan 20, 112 42 Stockholm, privacy@inzenda.se ("Inzenda"). Inzenda is the processor.

This agreement forms part of Inzenda's terms of service. For an account created after this agreement is published, it applies from the day the account is created. For an existing account, it applies from the date stated in the notice of this agreement; Inzenda nevertheless follows its own commitments under this agreement from publication.

1.1 Inzenda provides a digital service in which the Customer can keep its books, handle payroll and the employer declaration (AGI), VAT returns, the annual report and the income tax return (INK2), and file them digitally with Bolagsverket (the Swedish Companies Registration Office) and Skatteverket (the Swedish Tax Agency) (the "Service").

1.2 When the Customer enters personal data about other people into the Service, or has Inzenda fetch such data from authorities on the Customer's behalf, Inzenda processes it as the Customer's processor. This agreement governs that processing under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1.3 This agreement does not cover data Inzenda processes as a controller: data about the Customer's account holders and users (account, sign-in, payment, support, email from Inzenda, security, troubleshooting and statistics on how the Service is used). That is described in Inzenda's privacy policy.

1.4 Terms in this agreement have the meaning given to them in the GDPR.

2.1 Inzenda processes the personal data only on the Customer's documented instructions. The instructions are this agreement with Appendix 1, the terms of service, and the choices the Customer makes in the Service, for example adding an employee, running payroll, sending a return or authorising Inzenda as a read-only agent (läsombud) at Skatteverket.

2.2 The Customer instructs Inzenda, when the Customer asks for it in the Service, to send data to Bolagsverket and Skatteverket and fetch data from them. The authorities receive the data as controllers in their own right and are not Inzenda's sub-processors.

2.3 Inzenda may process the personal data without an instruction where required to do so by Union or Swedish law. Inzenda then informs the Customer before processing, unless the law prohibits it.

2.4 Inzenda informs the Customer immediately if, in Inzenda's opinion, an instruction infringes the GDPR or other data protection law.

2.5 Inzenda may produce anonymised or aggregated statistics on how the Service is used that cannot be traced back to an individual data subject.

3.1 The Customer is responsible for having a legal basis for the processing, for informing the data subjects (employees, for example) and for the accuracy of the data.

3.2 The Customer enters no more personal data than the purposes of the Service require. Free-text fields, notes and receipts contain only what the bookkeeping needs.

4.1 Inzenda ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.

4.2 Access to the personal data is given only to persons who need it to deliver, maintain and troubleshoot the Service or to answer the Customer's questions. Anyone given access is bound by confidentiality.

5.1 Inzenda takes the technical and organisational measures required by Article 32 GDPR. They are described in Appendix 3.

5.2 Inzenda may change the measures as long as the level of protection is not lowered.

6.1 The Customer gives Inzenda general prior authorisation to engage sub-processors. The sub-processors engaged when this agreement is entered into are listed in Appendix 2.

6.2 Inzenda informs the Customer of any intended addition or replacement of sub-processors at least 30 days before the change takes effect, by email to the account's email address and by updating the list at inzenda.se/legal/underbitraden. For an urgent change needed for the Service to work or stay secure the period may be shorter, but Inzenda always informs the Customer before the sub-processor starts processing the Customer's personal data, and the Customer's right under section 6.3 applies.

6.3 The Customer may object to a change on reasonable data protection grounds within 30 days of the notice. If the parties cannot resolve the objection, the Customer may terminate the Service before the change takes effect, and Inzenda refunds any prepaid fee for the period after termination.

6.4 Inzenda enters into a written agreement with each sub-processor imposing the same obligations as this agreement and remains fully liable to the Customer for the sub-processor's performance.

7.1 The database and file storage are within the EU/EEA. The exceptions are logs of sent emails (Resend, US) and support email (Google Workspace, EU and US), see Appendix 2. Transfer to, or access from, a country outside the EU/EEA happens only where there is a valid ground under Chapter V GDPR, for example an adequacy decision (such as the EU-US Data Privacy Framework for certified recipients) or the European Commission's standard contractual clauses. The ground for each sub-processor is stated in Appendix 2.

8.1 Inzenda helps the Customer respond to requests from data subjects, primarily through features in the Service: the Customer can view, correct and export data (for example the books as an SIE file and documents as PDF) and end a person's employment in payroll.

8.2 If a data subject contacts Inzenda directly with a request concerning the Customer's data, Inzenda forwards it to the Customer within five business days and does not answer it on the merits unless the Customer has asked it to.

8.3 The Customer is responsible for assessing whether a request for erasure can be granted. Accounting records that must be kept under the Swedish Bookkeeping Act cannot be erased during the retention period (GDPR Article 17(3)(b)).

9.1 Taking into account the nature of the processing and the information available to Inzenda, Inzenda helps the Customer meet its obligations on security (Art. 32), notification and communication of personal data breaches (Art. 33 and 34), data protection impact assessments (Art. 35) and prior consultation with the supervisory authority (Art. 36).

9.2 Inzenda may charge for assistance beyond what the Service normally includes, on a time-and-materials basis, after informing the Customer in advance.

10.1 Inzenda notifies the Customer without undue delay, and no later than 36 hours after becoming aware of a personal data breach affecting the Customer's data.

10.2 The notice is sent to the account's email address and contains, as far as available:

  • a description of the breach, the categories and approximate number of data subjects and personal data records concerned;
  • contact details of the person at Inzenda who can give more information;
  • the likely consequences;
  • the measures Inzenda has taken or proposes to address the breach and mitigate its effects.

10.3 Information not available at the first notice is provided as soon as it is, in phases if needed.

10.4 Inzenda documents all personal data breaches and does not notify the supervisory authority of breaches affecting the Customer's data on the Customer's behalf unless the Customer asks it to.

11.1 Before closing a company in the Service, the Customer can download the books and the documents produced (for example an SIE file, PDFs and receipts).

11.2 When the Customer closes the company in the Service, the Customer's account loses access at once, and the contact phone number and the reminder log are deleted. Other data, including data about employees in payroll (for example personal identity number, bank account, tax table and church membership), is kept as supporting records for the books and for the tax deductions and employer declarations (Bookkeeping Act chapter 7 section 2 and Tax Procedure Act chapter 39 section 3) under section 11.3.

11.3 Bookkeeping Act exception. Accounting records (vouchers, their history, transactions, receipts, payroll records, annual reports, tax returns, payroll runs and the system documentation in force for each year) must be kept until the end of the seventh year after the end of the calendar year in which the financial year ended (Swedish Bookkeeping Act, chapter 7, section 2). The Customer instructs Inzenda to keep storing the accounting records held in the Service on the Customer's behalf until 31 December of the seventh year after the last financial year ends, as a copy that the Customer, or whoever is to keep the Customer's accounting records, can request under section 12 of the terms of service. They are then deleted automatically, receipts and other files included. During storage the data is processed only for storage and for disclosure to the Customer, to whoever shows under section 12 of the terms of service that they represent the Customer or are to keep the Customer's accounting records, or to an authority entitled to it.

11.4 Backups containing the data are overwritten within 6 hours and are used only for restoration in the meantime.

11.5 Inzenda confirms the deletion in writing if the Customer asks.

12.1 Inzenda makes available to the Customer the information needed to demonstrate compliance with Article 28.

12.2 The Customer may audit Inzenda's compliance, itself or through an independent auditor bound by confidentiality. An audit is notified at least 30 days in advance, takes place at most once a year unless there has been a personal data breach or the supervisory authority requires it, happens during business hours, and must not disclose other customers' data or compromise security. Each party bears its own costs.

12.3 For sub-processors, Inzenda may meet this obligation by providing the sub-processor's own certifications and audit reports (for example SOC 2 or ISO 27001).

13.1 Towards data subjects, each party is liable under Article 82 GDPR. Between the parties, the limitation of liability in section 3 of the terms of service applies, including to loss under this agreement.

14.1 This agreement applies as long as Inzenda processes personal data on the Customer's behalf, including after the Customer has stopped using the Service, for as long as data is stored under section 11.

14.2 Inzenda may change this agreement where needed to comply with law or a decision of an authority, or when changing sub-processors under section 6. Other changes are notified, and may lead to termination, under section 10 of the terms of service.

15.1 This agreement is governed by Swedish law. Disputes are settled by the Swedish general courts, with Stockholm District Court as the court of first instance.

Purposes

The processing takes place so that the Customer can:

  • keep its books and store accounting records, with supporting documents such as receipts;
  • calculate salaries, tax deductions and employer contributions, produce payslips and pay salaries;
  • file the employer declaration at individual level (AGI), VAT returns, the income tax return (INK2) and the annual report digitally with Skatteverket and Bolagsverket;
  • fetch register data from Bolagsverket; fetch Skatteverket's decisions on the employees' preliminary tax (tax form, tax table, adjustment and validity period) through Skatteverket's 'Fråga om skatteavdrag' service, in the Customer's capacity as employer; and, where the Customer has authorised Inzenda as a read-only agent (läsombud), fetch data on the Customer's tax account, customer events and return status;
  • receive reminders about deadlines and status.

Nature of the processing

Collection through the Customer's input, file import and the authorities' APIs, storage, calculation, compilation, transmission to Bolagsverket and Skatteverket at the Customer's request, export to the Customer, storage during the retention period, and deletion.

Categories of data subjects

  • Board members, managing director and authorised signatories of the Customer's company.
  • The person who signs and files the annual report.
  • Employees and others who receive salary or fees (board fees, for example) from the Customer.
  • Shareholders, where they appear in the books (dividends, for example). Today shareholders are stored only as free text (the counterparty's name), never with a personal identity number.
  • The contact person for the employer declaration.
  • Natural persons who are counterparties in the Customer's transactions, for example sole traders, customers and suppliers.
  • Persons who appear in receipts, notes and minutes of general meetings.

Categories of personal data

  • Name and role in the company, with time period.
  • Personal identity number (personnummer), encrypted in the database and shown masked.
  • Salary, benefits, fees, tax deductions, employer contributions and other data in payslips and the AGI, including the specification number.
  • Tax table, tax column, adjustment (jämkning) and Skatteverket's answer on tax deduction (tax form, table, percentage decision and validity period).
  • Municipality of registration, parish and membership of the Church of Sweden, where it affects the tax deduction. Note: membership of a religious community may reveal religious belief and be a special category of personal data under Article 9 GDPR. The data is processed so that the employer can withhold the correct tax (Art. 9(2)(b) GDPR and chapter 3, section 2 of the Swedish Data Protection Act).
  • Bank account for salary payments, encrypted in the database and shown masked.
  • Start and end date of employment.
  • Contact person's phone number.
  • Counterparty, amount, date and note in transactions.
  • Receipts and other supporting documents as files, with whatever they contain.
  • Handwritten signatures as images, where the Customer uploads one.
  • Data from Skatteverket about the Customer's tax account and returns.

Duration

As long as the Customer uses the Service and thereafter during the retention period under section 11.3.

Location

Mainly within the EU/EEA; the exceptions and safeguards are set out in section 7 and Appendix 2.

Sub-processorServiceData processedStorage locationSafeguard for transfers outside the EU/EEA
Sub-processorVercel Inc., USServiceHosting of the application and server functions, file storage (Vercel Blob) for receipts and signatures, logs, protection against automated requestsData processedAll categories in Appendix 1 while processed; filesStorage locationFunctions: Frankfurt (fra1). File storage: Stockholm (arn1)Safeguard for transfers outside the EU/EEAEU-US DPF and standard contractual clauses
Sub-processorNeon (Databricks Inc.), USServiceDatabase (PostgreSQL) and backupsData processedAll categories in Appendix 1 except filesStorage locationFrankfurt (aws-eu-central-1)Safeguard for transfers outside the EU/EEAEU-US DPF and standard contractual clauses
Sub-processorResend (Plus Five Five Inc.), USServiceSending email, for example reminders and confirmationsData processedRecipient's email address, company name and period details in the message (no personal identity numbers or salary amounts)Storage locationSending via eu-west-1 (Ireland); logs in the USSafeguard for transfers outside the EU/EEAEU-US DPF and standard contractual clauses
Sub-processorFunctional Software Inc. (Sentry), USServiceError reportsData processedTechnical data about errors; personal identity numbers are masked before sending; occasional data in error messages may occurStorage locationEU (Germany, de.sentry.io)Safeguard for transfers outside the EU/EEAEU-US DPF and standard contractual clauses
Sub-processorGoogle Ireland Ltd (Google Workspace)ServiceSupport email, if the Customer sends personal data to supportData processedWhat the Customer sendsStorage locationEU and USSafeguard for transfers outside the EU/EEAStandard contractual clauses

Not sub-processors: Bolagsverket and Skatteverket (authorities that receive and provide data as controllers in their own right) and Stripe (processes only payment data about the account holder, not data about the Customer's employees or counterparties).

Encryption

  • All traffic is encrypted with TLS (HTTPS). Calls to Bolagsverket and Skatteverket are authenticated with Inzenda's organisation certificate (mutual TLS) where the authority requires it.
  • Personal identity numbers and salary bank accounts are encrypted in the application with AES-256-GCM, with a fresh random IV per value and the column name as additional authenticated data. The key is not in the database. Lookups use a keyed hash (HMAC-SHA256), never plaintext.
  • The database and file storage are encrypted at rest by the providers. (AES-256)

Access

  • Each account reaches only the companies it owns; every request is checked against the signed-in account on the server.
  • Full personal identity numbers are never sent to the browser; they are shown masked.
  • Data from Skatteverket is shown only to the account holding the authorisation for the company. Where it is unclear which account that is, the data is withheld until resolved manually.
  • Receipts and signatures are stored as private files and served only through the server after an ownership check.
  • Passwords are stored hashed.
  • Secrets and keys are kept as protected environment variables, never in source code.
  • The company lookup is protected against automated requests and rate-limited per IP address.
  • Inzenda's administrative accounts at Vercel, Neon, Google, Stripe, Resend, Sentry and GitHub are protected by two-factor sign-in or by sign-in through a Google account with 2-step verification.

Integrity and traceability

  • The books are append-only in the database: vouchers and history cannot be changed or deleted, only corrected with new entries.
  • Changes to transactions, the status of financial years and returns are kept with history.

Availability and recovery

  • The database has backups with point-in-time restore. The restore window is 6 hours.

Monitoring and incidents

  • Errors are reported to Sentry with alerts to Inzenda for errors in filing, payment and authority calls. Personal identity numbers are masked in error reports.
  • Inzenda's technical lead (CTO) assesses the incident and records it in an internal incident log. Where it affects the Customer's data, affected customers are notified by email within 36 hours (section 10). Where it affects data for which Inzenda is the controller, Inzenda reports it to IMY within 72 hours where required.

Development and testing

  • Tests run against separate databases and the authorities' test environments with test identity numbers. Copies of the production database are used only to rehearse migrations, are protected like production and are deleted the same day.

Organisation

  • Confidentiality undertakings for everyone with access, see section 4.
  • Access rights are reviewed once a year.