Last updated: April 2026
This Data Processing Agreement ("DPA") is entered into between the organisation subscribing to Formivera ("Data Controller", "you") and JLP Ventures AB, org. nr 559580-4948 ("Data Processor", "we", "us").
This DPA governs the processing of personal data that you, as a construction consultancy, submit to or generate through the Formivera platform in the course of managing projects, clients, inspections, and documents.
This DPA supplements and forms part of the Formivera Terms of Service.
"Personal Data" means any information relating to an identified or identifiable natural person as defined in Art. 4(1) GDPR.
"Processing" means any operation performed on Personal Data, as defined in Art. 4(2) GDPR.
"Sub-processor" means a third-party processor engaged by the Data Processor to process Personal Data on behalf of the Data Controller.
Contact data: names, email addresses, phone numbers, organisation numbers of project parties (clients, contractors, inspectors).
Project data: inspection findings, defect descriptions, contract details, property addresses, document contents.
Financial data: invoice amounts, price rows, payment references (no credit card data — handled by Stripe as independent controller).
Usage data: login timestamps, IP addresses, feature usage for platform operation and security.
We process Personal Data only on documented instructions from the Data Controller (i.e., through your use of the platform), unless required by EU or member state law.
We ensure that persons authorised to process Personal Data have committed to confidentiality.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: encryption at rest (AES-256) and in transit (TLS 1.3), access controls, audit logging, and regular security reviews.
We assist the Data Controller in fulfilling obligations to respond to data subject requests (access, rectification, erasure, portability) through platform features and support.
We delete or return all Personal Data upon termination of the service, at the Data Controller's choice, unless EU or member state law requires further storage.
The Data Controller grants general authorisation for the Data Processor to engage sub-processors. We will inform the Data Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Data Controller the opportunity to object.
Current sub-processors: Supabase Inc. (database, auth, storage — EU Frankfurt region), Vercel Inc. (hosting — EU region), Anthropic PBC (AI processing — no data retention for training), Resend Inc. (transactional email), Stripe Inc. (payment processing as independent controller), Sentry (error tracking — anonymised), ConvertAPI / Baltsoft (DOCX→PDF document conversion — EU/Lithuania), Upstash (rate limiting — Redis, processes IP addresses).
We ensure that each sub-processor is bound by data protection obligations no less protective than those in this DPA.
Primary data storage is in the EU (Supabase Frankfurt region). Where sub-processors process data outside the EU/EEA, transfers are safeguarded by Standard Contractual Clauses (SCCs) as approved by the European Commission, or by the sub-processor's participation in an approved certification mechanism.
We will notify the Data Controller without undue delay after becoming aware of a personal data breach, and no later than 72 hours where feasible. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach.
The Data Controller has the right to conduct audits, including inspections, to verify compliance with this DPA. Audits shall be conducted with reasonable notice (minimum 30 days) and during normal business hours. The Data Processor may satisfy audit requests by providing relevant certifications, audit reports, or third-party assessments.
This DPA is effective for the duration of the Data Controller's use of Formivera. Upon termination, we will delete all Personal Data within 90 days, unless retention is required by law. The Data Controller may at any time download a complete export of the organisation's data under Settings, Account (owner permission required).
This DPA is governed by the laws of Sweden and the EU General Data Protection Regulation (GDPR). Disputes arising from this DPA shall be resolved in Swedish general courts.
For questions about this DPA or to exercise data protection rights, contact us at: privacy@formivera.se
Data Protection matters are handled by: JLP Ventures AB, Sweden.