Legal
Data Processing Agreement
Última actualización
This Data Processing Agreement (DPA) forms part of the agreement under which Vantel AB, org.nr 559515-3205, Kungsgatan 54, 111 35 Stockholm, Sweden (Vantel) provides the Service to Customer — a signed agreement or the Terms of Use (the Agreement) — and applies whenever Vantel processes personal data on behalf of Customer. Customer is the controller and Vantel is the processor; terms defined in the GDPR have the same meaning here.
Processing
Subject matter, nature and purpose: hosting and analysis of documents uploaded to the Service in order to (a) provide the Service under the Agreement, (b) improve and develop the Service using aggregated and anonymized data, and (c) comply with applicable law.
Duration: the term of the Agreement plus up to 90 days.
Data subjects: Customer's clients, end users, policyholders, insured persons and other individuals appearing in uploaded documents.
Personal data: names, contact details, policy and premium information, and any other personal data (including health data) contained in uploaded documents.
Vantel shall
process personal data only on Customer's documented instructions, including as to transfers to third countries, and inform Customer if an instruction appears to infringe data protection law;
ensure persons processing the data are bound by confidentiality;
implement appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls with MFA, logging, and storage and processing exclusively within the EU/EEA, and not use Customer Data to train AI models;
engage only the sub-processors listed below, bound by written terms imposing substantially the same obligations, and give Customer 30 days' prior notice of changes, to which Customer may object on reasonable data protection grounds;
taking into account the nature of the processing, assist Customer with data subject requests under Articles 15–22 GDPR;
assist Customer with its obligations under Articles 32–36 GDPR, and notify Customer without undue delay, where feasible within 48 hours, after becoming aware of a personal data breach;
upon termination of the Agreement, delete or, at Customer's choice, return all personal data (deletion by default 30 days after termination absent instructions), unless law requires storage; and
make available to Customer the information necessary to demonstrate compliance with this DPA and allow and contribute to audits conducted by Customer or its mandated auditor, once per year on 30 days' notice at Customer's cost.
Sub-processors
Amazon Web Services (compute, storage, key management);
Microsoft Azure (document OCR);
Anthropic, Google and OpenAI (AI inference via EU endpoints with zero data retention);
Supabase (database, authentication, storage).
All sub-processors are located in the EEA or covered by EU Standard Contractual Clauses.
Liability
Liability under this DPA is subject to the limitations in the Agreement, except where prohibited by law; data subjects' rights under Article 82 GDPR are unaffected.

