Trust Center

Privacy & GDPR

Digital Plattform Sverige AB is a Swedish company operating under the GDPR. Your system is deployed to the AWS region nearest you, so an EU customer's data is held and processed in the EU.

This page sets out the roles, the rights, and what actually happens to personal data in a Digital Platform system.

Roles

Controller and processor

The division matters, because it decides who is answerable for what. It is not the same in both directions.

DataControllerProcessor
Personal data inside your systemYouDigital Plattform Sverige AB
Your users' account and login dataYouDigital Plattform Sverige AB
Your contact details as our customerDigital Plattform Sverige AB
Visitors to this websiteDigital Plattform Sverige AB
Are you a data controller or a data processor?

Both, for different data. For the personal data your organisation puts into its system, you are the controller and we are the processor: we act on your documented instructions and do not decide the purposes of that processing.

For your own contact details as our customer, and for visitors to this website, we are the controller.

Is a Data Processing Agreement available?

Yes, on request, and we will sign it before processing begins. It covers the subject matter and duration of processing, the categories of data subject and personal data, our obligations as processor, the subprocessors we use, and what happens to data when the agreement ends.

If your organisation has its own DPA template we will review it. We would rather negotiate a document you already trust than insist on ours.

What is your legal basis for processing?

As processor, we do not establish a legal basis for the personal data inside your system — you do, as controller, for the processing you instruct us to carry out.

For the data where we are controller, the basis is contract performance for customer relationship data, and legitimate interest for ordinary business communication and website operation.

Rights

Data subject rights

Requests from your users reach you, not us — you are their controller. What we owe you is the ability to answer them.

How do we handle a data subject access request?

A request from one of your users goes to you as controller. Your system gives you access to that person's data directly, so an ordinary access, rectification or erasure request is something you can complete yourself without waiting on us.

Where a request needs something the interface does not expose, we assist you as processor. Contact us and it is treated as a request with a deadline attached rather than as a support ticket.

Which rights are supported?

Access, rectification, erasure, restriction of processing, data portability and objection — the rights under GDPR Articles 15 to 21.

In practice: data is readable and correctable in the system, exportable in a machine-readable format for portability, and deletable on request. Restriction and objection are decisions you make as controller; we act on your instruction.

How quickly can data be exported?

Export is available on request and your system's data is held in a standard database rather than a proprietary format, so producing a complete machine-readable extract is a straightforward operation rather than a project.

Retention

How long data is kept

Live data is kept for as long as your system needs it — that is your decision as controller. What we set is how long copies survive after deletion.

Deleted data disappears from the live system immediately and ages out of the copies above as each reaches the end of its window.
CopyWhereRetention
Live system dataPlatform database, your regionUntil you delete it or the agreement ends
Daily server backupsEncrypted object storage, your region7 days
Daily machine imagesAWS Backup vault, your region3 days
Database operation logEncrypted object storage, your region7 days
How do customers request deletion?

Delete it in your system for ordinary record-level deletion. For deletion of a whole dataset, or of everything at the end of an agreement, email privacy@digitalplatform.ai and it is carried out as an instructed processing action.

We confirm in writing when it is done, and we tell you the date the last backup copy expires rather than claiming every copy vanished the moment the live record did.

What happens to our data if we leave?

You export it, then we delete it. Export first is the order deliberately: we do not delete anything until you have confirmed you have what you need.

After deletion, remaining copies expire on the retention windows in the table above. Nothing is retained beyond them as a commercial lever.

Is data really deleted, or just marked as deleted?

Deletion on request removes the data. Where the application uses a soft-delete flag for ordinary user actions — so a mistaken deletion is recoverable — a deletion instruction under this section is not that; it removes the underlying records.

Transfers

Cross-border transfers

Where personal data goes, and the only circumstances in which it leaves the region your system runs in.

Is personal data transferred outside the EU?

Not by the platform, for a system deployed in an EU region. Compute, the platform database, file storage, backups and outbound email all sit in the one region your system runs in — for an EU customer that is an EU region, and nothing in the ordinary running of the system moves data out of it.

One thing sits outside that boundary: an AI capability you enable reaches its model provider. Those providers are named, with their regions, on the Subprocessors page.

If your organisation requires that no personal data leaves the EU, say so: the region is a deployment decision we make with you, and the capabilities that would cross it can be left disabled with no effect on the rest of the platform.

How is our region decided?

From where you are. The default is the AWS region nearest your users, chosen when your system is provisioned, because a distant region charges every request a latency cost that no amount of application tuning recovers.

It is a default, not a constraint. Name the region your system must run in — for jurisdiction, for a contractual commitment, for anything — and it is deployed there instead.

What safeguards apply to transfers that do happen?

Standard Contractual Clauses with the relevant provider, together with that provider's own supplementary measures.

We list every subprocessor publicly, including its region, so a transfer is something you can see before you enable it rather than discover afterwards.

Do you use US cloud providers?

AWS — in the region your system is deployed to, which for an EU customer is an EU region. We are aware that a US-parent provider operating EU infrastructure is a point of debate in some procurement processes, and we would rather you raise it now than late.

The data itself is stored and processed in that one region, on infrastructure in our own AWS accounts.

Principles

How we approach privacy

Four commitments that govern the decisions this page describes. They are stated as constraints on us, not as reassurance.

Collect only what the system needs

The platform stores the data your system requires to do its job. We do not add collection of our own on top of it, and we do not instrument customer systems to gather usage data about your users.

Your data is not our product

Customer data is not sold, not shared with third parties for their own purposes, not used for advertising, and not used to train AI models. There is no version of our business model where it is.

Leaving is a decision, not a negotiation

Export is available at any time, in a machine-readable format, regardless of why you are asking. Data portability is a right under GDPR, and a vendor who makes it difficult is telling you something.

Say what is not in place

Where a control is planned rather than implemented, this Trust Center labels it as planned. A privacy page that reads as complete when it is not costs you more than an honest gap does.

Contact

Privacy enquiries

Data protection enquiries, DPA requests and data subject request assistance: privacy@digitalplatform.ai.

Digital Plattform Sverige AB, Industrigatan 14, 58255 Linköping, Sweden. VAT SE559221674001.

You also have the right to lodge a complaint with your national supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).

Need a DPA?

Ask and we will send one, or review yours. We will sign before processing begins rather than after go-live.