Data Processing Agreement

Last updated: 18 August 2026

This Data Processing Agreement (“DPA”) is made available by Lynora AB, org. nr. 559516-1190, Sweden (“Lynora”, “Verdix”, “we” or “us”) in connection with the Verdix service.

This DPA applies when it is incorporated into an agreement between Lynora AB and a customer or otherwise executed by the parties.

Where the customer acts as controller of Personal Data processed through Verdix, Lynora acts as processor. Where the customer acts as processor on behalf of another controller, Lynora acts as the customer’s subprocessor.

1. Scope and processing instructions

Lynora processes Customer Personal Data only to provide, secure, support and operate Verdix in accordance with the customer agreement, this DPA and the customer’s documented instructions, unless processing is required by applicable law.

The customer instructs Lynora to process Customer Personal Data as necessary to:

  • receive and store customer-provided agreements and related information;
  • extract and structure commercial terms;
  • identify and mask direct personal identifiers before AI model processing;
  • configure and apply commercial and billing rules;
  • retrieve or receive relevant operational and usage data;
  • calculate charges and billing instructions;
  • support human review and approval;
  • preserve clause-level source traceability;
  • transmit approved billing instructions to integrations enabled by the customer;
  • provide security, support, auditability and service administration.

2. Customer responsibilities

The customer is responsible for ensuring that:

  • Personal Data submitted to Verdix is processed lawfully;
  • the customer has the necessary lawful basis, notices, permissions and instructions for the processing;
  • the Personal Data submitted is appropriate for the customer’s use of Verdix.

Verdix does not require special-category Personal Data for normal use of the service. Customers should not intentionally submit special-category Personal Data unless separately agreed and supported by an appropriate lawful basis and safeguards.

3. Confidentiality

Lynora will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access the data only where required for their responsibilities.

4. Security

Lynora maintains appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature of the processing and the risks involved.

These measures include controls relating to:

  • data minimisation;
  • access control and organisation-level data isolation;
  • private handling of uploaded agreements;
  • encryption in transit and at rest across core application infrastructure;
  • masking of direct personal identifiers before AI model processing;
  • application and API security;
  • logging and traceability;
  • deletion and data lifecycle management.

A more detailed description of Verdix’s current Technical and Organisational Measures is available to customers and prospective customers on request.

Lynora may update its technical and organisational measures provided that the overall level of protection is not materially reduced.

5. Subprocessors

The customer gives Lynora general written authorisation to appoint subprocessors required to provide Verdix.

Lynora will:

  • maintain a current public list of its core subprocessors;
  • impose appropriate data-protection obligations on subprocessors;
  • remain responsible for its obligations under this DPA notwithstanding its use of subprocessors;
  • provide customers covered by this DPA at least 30 days’ notice before a material new subprocessor begins processing Customer Personal Data, except where an urgent change is required for security, availability or legal compliance.

Customers may raise legitimate data-protection concerns during the notice period. Lynora and the customer will work in good faith to address such concerns.

Customer-selected downstream integrations that the customer enables or instructs Verdix to send data to may have separate data-protection roles and are not automatically treated as Lynora’s core subprocessors.

Current subprocessors:

View the Verdix subprocessor list →

6. International data transfers

Where Personal Data is transferred from the European Economic Area to a country not covered by an applicable adequacy decision, Lynora will use an appropriate transfer mechanism where required by applicable data-protection law.

Where applicable, the relevant modules of the European Commission Standard Contractual Clauses may apply according to the roles of the parties, including controller-to-processor or processor-to-processor transfers.

7. Data-subject requests

Taking into account the nature of the processing, Lynora will provide reasonable assistance to the customer in responding to requests from data subjects exercising their rights under applicable data-protection law.

If Lynora receives a request relating to Customer Personal Data for which the customer is responsible, Lynora may direct the requester to the customer unless Lynora is legally required to respond directly.

8. Personal Data Breaches

Lynora will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification is required under applicable data-protection law.

Lynora will provide reasonably available information needed for the customer to assess the incident and meet applicable legal obligations and will take appropriate steps to contain and remediate the incident.

9. Data protection impact assessments

Taking into account the nature of the processing and the information available to Lynora, Lynora will provide reasonable assistance with data protection impact assessments and consultations with supervisory authorities where required in connection with the customer’s use of Verdix.

10. Data return and deletion

Verdix retains Customer Data while the customer’s account and relevant agreements remain active.

Customers may delete agreements and associated data through the service or request deletion.

Before termination, customers may request or use available functionality to obtain a copy of Customer Data where technically supported.

Following termination of the Verdix service, Customer Data will be deleted within 30 days, except where particular records must be retained for legal, accounting, security or compliance purposes.

Any records retained for such purposes remain protected and are used only for the applicable retention purpose.

Consent records may be retained for 7 years where required for legal compliance.

11. Compliance information and audits

Lynora will make available information reasonably necessary to demonstrate compliance with its applicable processor obligations, subject to appropriate confidentiality, security and proportionality requirements.

Customers should first use documentation and information made available by Lynora.

Where this is insufficient and an audit is reasonably required under applicable data-protection law, the parties will agree reasonable scope, timing, confidentiality and security arrangements. Any audit must avoid unnecessary disruption to Verdix and exposure of information relating to other customers.

12. Government and public-authority requests

Unless legally prohibited, Lynora will notify the customer of a legally binding request from a public authority requiring disclosure of Customer Personal Data where the request relates specifically to the customer’s data and such notification is permitted by law.

13. Duration

This DPA remains in effect for as long as Lynora processes Customer Personal Data on behalf of the customer.

14. Conflict

If this DPA conflicts with the customer agreement in relation to the processing of Personal Data, this DPA will prevail to the extent of that conflict.

Mandatory provisions of applicable data-protection law and any applicable Standard Contractual Clauses will prevail where required.

Annex 1 — Details of Processing

Subject matter

Processing of customer-provided agreements, operational and usage information, and related billing data in order to provide the Verdix agreement-to-billing service.

Nature and purpose of processing

Processing may include:

  • receipt and storage of agreements and supporting information;
  • extraction and structuring of commercial terms;
  • masking of direct personal identifiers;
  • AI-assisted interpretation of commercial terms;
  • configuration of billing and commercial logic;
  • retrieval, receipt and mapping of relevant usage data;
  • calculation of charges;
  • human review and approval;
  • clause and source traceability;
  • generation and transmission of approved billing instructions;
  • security, support and service administration.

Duration

For the duration of the Verdix customer relationship and relevant active agreements, followed by the deletion lifecycle described in this DPA.

Categories of data subjects

Depending on the information supplied by the customer, data subjects may include:

  • customer users and employees;
  • finance, billing, RevOps, legal and commercial contacts;
  • customer counterparties and their personnel;
  • individuals named in agreements;
  • individuals represented in relevant operational or billing data.

Categories of Personal Data

Depending on customer content, Personal Data may include:

  • names;
  • business email addresses;
  • telephone numbers;
  • job title, role and organisation;
  • account and organisation identifiers;
  • billing and contact information;
  • Personal Data contained in uploaded agreements;
  • operational or usage identifiers reasonably required for billing.

Special-category Personal Data

Verdix does not require special-category Personal Data for normal operation.

Customers should not intentionally submit such data unless separately agreed and supported by an appropriate lawful basis and safeguards.

Annex 2 — Technical and Organisational Measures

Lynora AB maintains technical and organisational measures designed to protect Customer Personal Data.

A detailed description of Verdix’s current Technical and Organisational Measures is available to customers and prospective customers on request.

Request security documentation →

Annex 3 — Subprocessors

Lynora AB maintains a current public list of the core subprocessors used to provide Verdix.

View subprocessors →

Need an executed DPA?

For procurement, legal or security review: