Data Processing Agreement — DPA
Standard Terms — ACS4M3 / Accure CloudSuite for M3. This DPA is incorporated by reference into each individual Agreement and governs Accure's processing of personal data on behalf of its customers.
Contents
1. Background and Applicability
1.1 The Customer and Accure have entered into an Agreement under which Accure shall provide certain services to the Customer. Within the scope and for the purpose of performing those services, Accure will Process Personal Data on behalf of the Customer.
1.2 This DPA fulfils the requirement of a written agreement under Applicable Data Protection Legislation. In addition to the Agreement, the following shall apply to Accure's Processing of Personal Data on behalf of the Customer.
1.3 In the event of a conflict between this DPA and the Agreement, this DPA shall prevail to the extent the Agreement does not meet the requirements of Applicable Data Protection Legislation. Section 8 of this DPA shall always prevail.
2. Definitions
The following terms shall have the meanings set out below:
- "Affiliate" — An entity controlling, controlled by, or under common control with a party.
- "Applicable Data Protection Legislation" — Any national or internationally binding data protection laws or regulations applicable during the term of this DPA, including GDPR (EU) 2016/679.
- "Controller" — The legal entity which determines the purposes and means of the Processing of Personal Data.
- "Data Subject" — The natural person to whom Personal Data relates.
- "Personal Data" — Any information relating to an identified or identifiable living natural person, as defined under Applicable Data Protection Legislation.
- "Personal Data Breach" — A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- "Processing" — Any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, combination, erasure or destruction.
- "Processor" — The legal entity processing Personal Data on behalf of the Controller.
- "Standard Contractual Clauses" — Standard clauses for third-country transfers pursuant to Regulation (EU) 2016/679, adopted by the European Commission on 4 June 2021 (C(2021) 3972).
- "Subcontractor" / "Subprocessor" — A legal entity engaged by Accure to carry out Processing on Accure's behalf.
- "Data Protection Authorities" — Any government or regulatory authority responsible for enforcing data privacy laws.
3. Processing of Personal Data
3.1 Accure shall only Process Personal Data in accordance with documented instructions from the Customer. Initial instructions regarding subject-matter, nature, purpose, data types and Data Subject categories are set out in Annex I to Appendix 1.
3.2 Accure shall assist the Customer in fulfilling its legal obligations, including responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, and objection), ensuring appropriate security, and performing data protection impact assessments.
3.3 Accure shall immediately inform the Customer if it lacks sufficient instructions for a particular Processing situation, or if an instruction appears to violate Applicable Data Protection Legislation.
3.4 If Data Subjects, authorities or third parties contact Accure regarding Personal Data, Accure shall refer such requests to the Customer. Accure may not act as the Customer's representative or disclose Personal Data to any third party without prior Customer instructions. If legally required to disclose, Accure shall promptly notify the Customer and request confidentiality.
4. Subcontractors
4.1 Accure will engage the Subcontractors set out in Annex I to Appendix 1. Accure ensures all Subcontractors are bound by written agreements imposing data processing obligations equivalent to those in this DPA.
4.2 If Accure wishes to engage a new Subcontractor, it shall notify the Customer in writing at least four (4) weeks in advance, including the identity, purpose and location of the Subcontractor. The Customer has two (2) weeks to object. No Personal Data may be transferred outside the EEA without Customer approval per section 5. Accure remains fully liable for Subcontractor performance.
5. Transfer to Third Countries
Processing locations are set out in Annex I to Appendix 1. Accure may not transfer Personal Data outside the European Economic Area unless approved in writing by the Customer and protected by Standard Contractual Clauses. The SCCs are incorporated herein by reference per Appendix 1, and deemed signed by both parties on the effective date of each individual Agreement.
6. Information Security and Confidentiality
6.1 Accure shall implement appropriate technical and organisational security measures proportionate to the risk, including:
- pseudonymisation and encryption of Personal Data;
- ongoing confidentiality, integrity, availability and resilience of Processing systems;
- ability to restore Personal Data availability in a timely manner following an incident; and
- a process for regularly testing, assessing and evaluating the effectiveness of security measures.
6.2 In assessing appropriate security levels, Accure shall account for risks including accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data.
6.3 Accure shall notify the Customer of a Personal Data Breach immediately and no later than 24 hours after becoming aware of it. The notification shall describe:
- the nature of the breach, including (where possible) categories and approximate numbers of Data Subjects and records affected;
- contact details of the data protection officer or relevant contact;
- likely consequences of the breach;
- measures taken or proposed to address the breach; and
- any other information required under Applicable Data Protection Legislation.
Accure will provide reasonable assistance to investigate the breach and support notifications to authorities and Data Subjects as required. Accure shall document the breach and shall not disclose it externally without the Customer's prior written approval.
6.4 Accure shall not disclose Personal Data to any third party without the Customer's prior written approval, except to listed or properly notified Subcontractors per section 4.
6.5 Access to Personal Data shall be restricted to personnel who require it to perform their obligations. Such personnel shall be bound by equivalent confidentiality obligations.
6.6 Confidentiality obligations under this section 6 survive the expiry or termination of the DPA.
7. Audit Rights
Accure shall make available all information and assistance necessary to demonstrate compliance with this DPA, and shall allow and contribute to audits and inspections, including by mandated auditors, in accordance with Swedish and European laws and regulations.
8. Liability and Indemnification
8.1 A Party shall be liable for all damages (including loss of reputation or data), fines, losses and costs incurred by the other Party or its Affiliates arising from non-compliance with this DPA or Applicable Data Protection Laws.
8.2 A Party shall indemnify the other Party against third-party claims, including from Data Subjects and Data Protection Authorities, and all associated damages and costs arising from non-compliance with this DPA.
8.3 Aggregate liability under clauses 8.1 and 8.2 is cumulatively limited to the charges payable under the Agreement in the calendar year in which the cause of action arose.
8.4 Clause 8.3 does not apply to liability or indemnification arising from wilful misconduct or gross negligence.
9. Term
These standard terms apply from 1 February 2026 and remain in effect for as long as Accure Processes Personal Data on behalf of any Customer under an active Agreement.
10. Notices
Any notice under this DPA shall be provided in accordance with the notices provision of the individual Agreement. For data protection matters, notices may also be sent to [email protected].
11. Measures Upon Completion of Processing
11.1 After services under the Agreement have ended, Accure shall delete or return all Personal Data (including copies) as instructed by the Customer, and shall ensure Subcontractors do the same.
11.2 Upon request, Accure shall provide written confirmation of deletion or return measures taken.
Appendix 1 — Standard Contractual Clauses
1. Incorporation and Interpretation
1.1 In relation to transfers by Customer of Personal Data subject to Data Protection Laws of Extended EEA Countries to Accure in Third Countries, Module Two (Transfer controller to processor) or Module 3 (Transfer processor to processor) of the Standard Contractual Clauses shall apply, as applicable.
1.2 The information required by the Standard Contractual Clauses, including appendices, is set out in Annex I and Annex II below.
1.3 If there is a conflict between this Agreement and the SCCs, the SCCs prevail — except to the extent prohibited by law, the SCCs shall be interpreted subject to this DPA and the Agreement, including provisions on liability, instructions, storage, erasure, audits and Subprocessors.
1.4 If any provision of this DPA renders the SCCs an invalid export mechanism, that provision shall be deemed deleted without affecting the rest of the Agreement. The parties shall negotiate a replacement in good faith.
1.5 Where requested by Accure, the Customer shall provide reasonable assistance including communications to Data Subjects and/or Controllers as required for Accure to comply with its SCC obligations.
1.6 Where the applicable Extended EEA Country is the UK, the UK Approved Addendum (ICO template B.1.0, 2 February 2022) shall amend the SCCs. Table 1: start date = effective date of the individual DPA; parties = Customer as exporter, Accure as importer. Table 2: modules/clauses per paragraphs 1.1–1.2. Table 3: per Annex I and Annex II. Table 4: Neither party may end the Addendum per its Section 19.
1.7 Where the applicable Extended EEA Country is not an EU Member State: (a) "Member States" refers to that country; (b) "the GDPR" refers to that country's data protection laws; (c) "supervisory authority" refers to that country's data protection authority per Annex I(C).
Annex I — List of Parties & Description of Processing
A. List of the Parties
Data exporter (Customer) and data importer (Accure AB)
Data Exporter (Customer)
Name and address: As set out in the individual Agreement
Contact details: As set out in the individual Agreement
Activities: Receipt of Services per the Agreement
Role: Controller
Data Importer (Accure AB)
Name: Accure AB | Org. No. 556667-0625
Address: Strandvägen 23D, SE-444 31 Stenungsund, Sweden
Contact: [email protected] | www.accure.eu
Activities: Provision of ACS4M3 / Accure CloudSuite services per the Agreement
Role: Processor
B. Details of Processing / Transfer
Subject matter, nature, purpose, data types, and data subject categories
| Categories of Data Subjects | Employees and partner staff accessing the Accure web portal. End-customers (consumers) of the Customer whose data is processed via the ERP system. |
| Categories of Personal Data | Business email addresses, contact and address information for consumers of customer products, used to generate invoices, order confirmations and similar business documents. |
| Special Categories of Data | Not applicable. |
| Frequency of Transfer | Continuously, as required to provide the services described in the Agreement. |
| Nature and Purpose of Processing | Storage and Processing of Personal Data required for service delivery. Portal user registration (work email address required). Processing of Customer-provided consumer data for document generation (Purchase Orders, Invoices, Shipping Labels, etc.). |
| Retention | Personal Data reviewed annually for deletion; exceptions apply for legal requirements. Customers notified 30 days before deletion. Default retention target: 30 days for transactional data. |
| Approved (Sub)Processors | Microsoft Corporation — Cloud hosting & infrastructure (Microsoft Azure, Western/North Europe, US) Creative Software Limited — Technical, Cloud Ops & Development support (Sri Lanka) |
| Location of Processing | Servers: Microsoft Azure data centres in Western Europe and Northern Europe (primary); US (secondary, as needed). Staff processing: Sweden and Sri Lanka. |
C. Competent Supervisory Authority
Determined per Clause 13 of the Standard Contractual Clauses: Integritetsskyddsmyndigheten (IMY), Sweden — www.imy.se.
D. Governing Law and Choice of Forum
Governing Law: Clause 17 — Option 1: the law of Sweden.
Choice of Forum: Clause 18 — the courts of Sweden.
E. Other
- Clause 7 (Docking Clause): optional provision applies.
- Clause 9(a): Option 2 (General Written Authorisation); notice period per section 4 of this DPA.
- Clause 11(a) (Redress): optional provision does not apply.
Annex II — Technical and Organisational Security Measures
Security Model
Accure Business Cloud (ABC) is deployed in three models: Public (Microsoft Azure — default), Private (higher-security or policy-restricted workloads in customer-operated or dedicated cloud), and Hybrid (on-premise services communicating with cloud environments). Across all models, Accure applies security-first design at the highest practicable level.
| Security Area | Measure |
|---|---|
| Cloud Environment | Built on Microsoft Azure (primary: Western Europe) with a multitenant architecture ensuring full customer data isolation per tenant. No cross-tenant data access is architecturally possible. |
| Strategy & Policy | Formal information security policy (ISMS) covering cloud security, risk ownership, business continuity, and a control framework aligned with ISO/IEC 27001 and NIS2. |
| Network Segmentation & Data Isolation | All cloud resources are segmented so that instances, containers, applications and systems are fully isolated. No customer data is accessible to another customer or user. |
| Identity & Access Management | Role-based access control (RBAC) for all resources. Multi-factor authentication (MFA) mandatory for all access paths — internal, external, and privileged. Privileged access is audited and session-monitored. All personnel undergo background screening and training before access is granted. Inactive accounts disabled after 45 days. |
| Password Control | Personal accounts only; shared passwords strictly prohibited. Passwords must meet complexity requirements and are never stored in clear text. |
| Vulnerability Management | Regular vulnerability scanning, security auditing, and patching by Accure cloud engineers and external security consultants. Annual penetration testing. |
| Encryption | All data encrypted at rest (AES-256) and in transit (TLS 1.2+). The Accure Transaction Client and API Gateway use HTTPS/TLS exclusively. |
| Backups & Disaster Recovery | All customer and system-critical data is backed up per agreed storage policies. Recovery procedures are regularly reviewed and tested. RTO and RPO commitments available under ESLA/USLA. |
| Monitoring & Logging | 24/7/365 continuous monitoring by automated systems and on-call staff. All activities are logged. Access logs retained for a minimum of 12 months and protected against tampering. Incident response procedures triggered immediately on detection. |
| Incident Response | Documented incident response plan. Personal Data Breach notification to Customer within 24 hours of becoming aware. Breaches documented and not disclosed externally without Customer approval. |
| GDPR & Regulatory Compliance | Personal data stored within EU/EEA (Sweden / Azure Western & Northern Europe) unless otherwise agreed in writing. All personnel and consultants undergo security screening and privacy training before accessing personal data. Regular technical audits by internal and external experts. Quarterly access reviews. |
| Certifications | SOC 2 Type II (Security, Availability, Confidentiality) — independently audited. NIS2 Directive (EU 2022/2555) compliant. ISO/IEC 27001 certification in progress. Azure infrastructure holds ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3 certifications. |