Data Processing Agreement

Last updated: 23 August 2026

This DPA applies automatically to all Customers via the Terms of Service. If your organisation's compliance programme requires an executed (signed) copy for your records, contact legal@organigram.se.

Parties

RoleParty
Data Controller ("Controller", "you")The Customer entity that has accepted the Organigram Terms of Service
Data Processor ("Processor", "we", "us")Szaloczi Brothers AB, Registered office: Lomma, Sweden, registration number 559596-6481

This Data Processing Agreement ("DPA") supplements the Terms of Service ("ToS") governing the Controller's use of the Organigram workforce-planning platform ("Services"). By accepting the ToS, the Controller agrees to the terms of this DPA. This DPA takes effect for each Controller on the date they accepted the ToS. In the event of any conflict between this DPA and the ToS regarding the processing of personal data, this DPA prevails.


1. Definitions

"Applicable Data Protection Law" means the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and any applicable national implementing legislation, as amended or replaced from time to time.

"Customer Data" means Personal Data contained within the Controller's workspaces on the Platform, including workforce and organisational data uploaded, imported, or generated by or on behalf of the Controller.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data transmitted, stored, or otherwise processed.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914.

"Sub-processor" means any third-party processor engaged by the Processor to carry out processing activities on Customer Data on behalf of the Processor.

"Technical and Organisational Measures" or "TOMs" means the security and organisational measures described in Annex II.

The terms "Controller", "Data Subject", "Personal Data", "Processing", "Processor", and "Supervisory Authority" have the meanings given in Article 4 GDPR.


2. Subject Matter and Duration

2.1 The Processor provides the Controller with access to the Platform for workforce planning, organisational modelling, and related activities.

2.2 This DPA applies for the duration of the Services agreement and terminates automatically when the Services agreement terminates, subject to Clause 10.


3. Nature and Purpose of Processing

3.1 The Processor processes Customer Data solely for the purpose of providing the Services to the Controller in accordance with this DPA and the ToS.

3.2 The Processing carried out by the Processor includes: storing Customer Data on the Platform; making it accessible to authorised workspace members; enabling editing, scenario planning, export, and reporting; maintaining audit and change logs for the Controller's operational and compliance benefit; and operating the technical infrastructure necessary to provide the Platform.

3.3 The Processor shall not:

3.4 If the Processor is required by EU or Member State law to process Customer Data beyond the Controller's instructions, the Processor shall, to the extent permitted by law, inform the Controller of that legal requirement before Processing.


4. Categories of Personal Data and Data Subjects

4.1 The categories of Personal Data processed and the categories of Data Subjects are set out in Annex I.

4.2 The Controller is responsible for ensuring it has an appropriate legal basis under Applicable Data Protection Law for uploading or otherwise providing Personal Data to the Platform, and for ensuring that Data Subjects have been adequately informed of the Processing where required.

4.3 The Controller shall not upload to the Platform special categories of Personal Data as defined in Article 9(1) GDPR — including data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation — unless the Controller has obtained prior written agreement from the Processor and can demonstrate an appropriate legal basis under Article 9(2) GDPR. The Processor makes no warranty as to the Platform's fitness for the processing of special-category data unless expressly agreed in writing.


5. Controller's Instructions

5.1 The Processor shall process Customer Data only on the Controller's documented instructions. The ToS and this DPA constitute the Controller's instructions as of the date this DPA takes effect.

5.2 The Controller may issue additional or amended instructions by written notice to legal@organigram.se. The Processor shall implement reasonable instructions within a reasonable timeframe and may charge additional fees for instructions requiring significant effort beyond the scope of the Services.

5.3 If the Processor reasonably considers that any instruction infringes Applicable Data Protection Law, the Processor shall notify the Controller in writing and may suspend performance of the relevant instruction until the Controller issues a revised or confirmed instruction. The Processor is not obliged to perform unlawful instructions.

5.4 The Processor does not make decisions regarding the purposes or essential means of Processing Customer Data. All such decisions remain the Controller's responsibility.


6. Confidentiality of Processing Personnel

6.1 The Processor shall ensure that persons authorised to process Customer Data are subject to a binding duty of confidentiality — whether by employment contract, professional obligation, or statutory requirement.

6.2 Access to Customer Data is limited to personnel who need such access to perform their duties in connection with providing the Services.


7. Sub-processors

7.1 The Controller grants the Processor general authorisation to engage the Sub-processors listed in Annex III for the purposes described therein.

7.2 Before adding or replacing a Sub-processor, the Processor shall:

(a) give the Controller at least 14 calendar days' prior written notice (by email to the address associated with the Controller's account, or by prominent in-app notice);

(b) carry out appropriate due diligence to confirm that the proposed Sub-processor meets the technical and organisational security standards required under this DPA; and

(c) impose data protection obligations on the Sub-processor that are substantially equivalent to those imposed on the Processor under this DPA, by written contract.

7.3 The Controller may object to a proposed change to the Sub-processor list on reasonable, documented data protection grounds by notifying the Processor in writing within 14 days of receiving the notice. The parties shall consult in good faith for up to 14 further days to resolve the objection. If the parties cannot agree, either party may terminate the Services agreement on 30 days' written notice, and the Controller shall receive a pro-rata refund of any prepaid fees for the unused portion of the then-current subscription period.

7.4 The Processor remains fully liable to the Controller for each Sub-processor's performance of their data protection obligations under this DPA, as if the Processor were performing those obligations itself.


8. Assistance with Data Subject Rights

8.1 Taking into account the nature of the Processing, the Processor shall assist the Controller in fulfilling obligations to respond to Data Subject rights requests under Articles 15–22 GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.

8.2 Such assistance includes:

(a) promptly forwarding to the Controller any Data Subject rights request received directly by the Processor relating to Customer Data;

(b) providing the Controller with access to the technical means available within the Platform to export, restrict access to, or delete Customer Data (such as workspace export and account deletion); and

(c) providing reasonable additional assistance upon written request to legal@organigram.se, subject to any agreed additional fees for requests requiring significant effort.

8.3 The Processor shall not respond directly to Data Subject rights requests relating to Customer Data without the Controller's prior authorisation, except to acknowledge receipt and direct the Data Subject to the Controller.


9. Security, Breach Notification, and Compliance Assistance

9.1 The Processor shall implement and maintain the Technical and Organisational Measures described in Annex II, designed to ensure a level of security appropriate to the risks of the Processing.

9.2 The Processor may update the TOMs from time to time to reflect improvements in security technology and practice, provided that any update does not materially reduce the overall level of protection afforded to Customer Data.

9.3 Breach notification. If the Processor becomes aware of a Personal Data Breach affecting Customer Data, the Processor shall:

(a) notify the Controller without undue delay after becoming aware of the breach;

(b) include in the notification, to the extent then known: the nature of the breach; the categories and approximate number of Data Subjects affected; the categories and approximate number of Personal Data records affected; the likely consequences; and the measures taken or proposed to address the breach and mitigate its adverse effects; and

(c) cooperate with the Controller and take reasonable steps to contain, investigate, and remediate the breach.

9.4 Notification under Clause 9.3 does not constitute an acknowledgement of fault or liability by the Processor.

9.5 Compliance assistance. Upon written request and at the Controller's reasonable cost, the Processor shall assist the Controller in:

(a) conducting Data Protection Impact Assessments (DPIAs) under Article 35 GDPR where the nature of the Processing requires one; and

(b) carrying out prior consultation with a Supervisory Authority under Article 36 GDPR.


10. Deletion and Return of Customer Data

10.1 Upon termination of the Services agreement, or upon the Controller's written instruction at any time, the Processor shall delete all Customer Data.

10.2 The Controller may delete Customer Data at any time through the Platform by deleting a workspace or deleting their account. Customer Data is deleted immediately from the Platform's operational systems upon such a request. Complete removal from all application-level storage and backup systems under the Processor's direct control is guaranteed without undue delay and no later than 30 days following the deletion request, including any cleanup and backup rotation processes.

10.3 Upon the Controller's written request, the Processor shall provide written confirmation that deletion has been completed.

10.4 The Processor may retain Customer Data beyond the periods set out in Clause 10.2 only to the extent required by applicable EU or Member State law. In such cases, the Processor shall (to the extent permitted by law) notify the Controller, limit Processing of the retained data strictly to the purposes required by that obligation, and delete the data as soon as the obligation expires.

10.5 For the avoidance of doubt, the 30-day commitment in Clause 10.2 applies to storage systems under the Processor's direct operational control. Records held by Sub-processors within their own infrastructure logging and backup systems are governed by those Sub-processors' respective data retention policies, as referenced in Annex III.


11. Audit and Information

11.1 The Processor shall make available to the Controller, upon written request to legal@organigram.se, all information reasonably necessary to demonstrate compliance with this DPA.

11.2 The Controller, or a qualified third-party auditor mandated by the Controller, may conduct an audit of the Processor's data processing practices, subject to the following conditions:

(a) the Controller provides at least 30 days' prior written notice, specifying the proposed scope;

(b) audits are conducted during normal business hours with minimal disruption to operations;

(c) audits may be conducted no more than once per rolling 12-month period, unless required by a Supervisory Authority or as a result of a Personal Data Breach;

(d) the Controller and any mandated auditor execute a confidentiality agreement covering all non-public information accessed during the audit; and

(e) the reasonable costs of the audit are borne by the Controller.

11.3 The Processor may satisfy the Controller's audit requirements by providing current audit reports, security certifications (such as ISO 27001 or SOC 2 Type II), or qualified third-party assessments where these sufficiently address the stated audit scope. The Controller shall accept such documentation in lieu of an on-site audit unless specific circumstances reasonably require a direct inspection.


12. International Data Transfers

12.1 Customer Data is stored in the European Economic Area. The Processor's database Sub-processor (Neon) operates the primary database in Frankfurt, Germany (EU). No transfer of Customer Data outside the EEA is required for the purpose of data storage.

12.2 Where Sub-processors outside the EEA process Customer Data — for example, in connection with application hosting or email delivery — such transfers are made under appropriate safeguards pursuant to Article 46 GDPR, including Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or, where applicable, other lawful mechanisms such as an adequacy decision or the EU–US Data Privacy Framework. The transfer mechanism applicable to each Sub-processor is specified in Annex III.

12.3 Where any new adequacy decision or transfer mechanism becomes available, the Processor may rely on it in addition to or in lieu of existing mechanisms, provided the level of protection afforded to Data Subjects is not diminished.


13. Liability

13.1 Each party's liability to the other under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where prohibited by applicable law.

13.2 Nothing in this DPA limits either party's liability to Data Subjects or Supervisory Authorities as provided under Applicable Data Protection Law.

13.3 Where both parties bear responsibility for damage caused by Processing in breach of the GDPR, each party shall be responsible for the damage attributable to its own infringement in accordance with Article 82 GDPR.


14. General Provisions

14.1 Governing law. This DPA is governed by the laws of Sweden. Each party submits to the non-exclusive jurisdiction of the courts of Sweden.

14.2 Order of precedence. In the event of conflict between this DPA and the ToS on matters relating to the Processing of Personal Data, this DPA prevails.

14.3 Amendments. The Processor may amend this DPA by giving at least 30 days' prior notice to Controllers (by email or in-app notice). Amendments that would materially reduce the level of data protection are subject to good-faith consultation with the Controller upon request.

14.4 Severability. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

14.5 Entire agreement. This DPA (including its Annexes) constitutes the entire agreement between the parties regarding the Processing of Customer Data and supersedes all prior agreements on that subject.


Annex I — Description of Processing Activities

A. Processor

Legal nameSzaloczi Brothers AB
Registration number559596-6481
Registered addressLomma, Sweden
Data protection contactlegal@organigram.se

B. Controller

The Controller is the Customer entity that has accepted the Terms of Service. Upon request for an executed copy of this DPA, the Controller's legal name, registration details, and contact address are recorded on the executed document.

C. Subject Matter and Nature of Processing

Provision of the Organigram workforce-planning platform as a cloud service. Processing includes storage, retrieval, display, editing, scenario planning, change tracking, export, and audit logging of workforce and organisational data on behalf of the Controller. Customer Data may also be imported from third-party services authorised by the Controller, such as Google Sheets.

D. Categories of Personal Data

CategoryExamplesRequired?
Employee identificationEmployee names, employee IDs, work email addressesYes
Professional informationJob titles, departments, areas, work locationsYes
Organisational structureReporting-line relationships, manager names, position referencesYes
Employment detailsSeniority level, full-time equivalent (FTE)Yes
Compensation dataSalary, salary level, cost centreOptional — only if uploaded by the Controller
Custom fieldsAny other workforce data defined and entered by the ControllerOptional — Controller-defined
Org chart snapshotsVisual representations of the organisational structureGenerated from the above data

Special categories of Personal Data as defined in Article 9(1) GDPR are not permitted on the Platform without prior written agreement between the parties.

E. Categories of Data Subjects

Employees, workers, contractors, and other personnel of the Controller's organisation whose personal data is included in the Controller's workforce planning data on the Platform.

F. Duration

Processing continues for the term of the Services agreement. Customer Data is deleted in accordance with Clause 10.


Annex II — Technical and Organisational Measures

1. Encryption

MeasureImplementation
Encryption in transitAll data transmitted between users and the Platform is encrypted using TLS/HTTPS
Encryption at restPersonal data stored within Neon databases is encrypted at rest using AES-256 encryption. Neon implements encryption at the storage layer for inactive data. Encryption keys are managed through cloud-provider key management services (AWS KMS or Azure Key Vault depending on infrastructure provider).

2. Access Control

MeasureImplementation
Role-based access controlWorkspace access is restricted to explicitly authorised members with defined roles (owner, editor, viewer), enforced server-side at the API layer
Granular field-level permissionsPer-member controls for hiding or marking specific fields as read-only; per-member scope restrictions (branch or department level)
Workspace isolationEach workspace is logically isolated; users can only access workspaces to which they have been explicitly added
Server-side enforcementAll access-control checks are performed server-side; client-side restrictions are for user experience only and cannot be bypassed to gain unauthorised access

3. Authentication Security

MeasureImplementation
Password hashingUser passwords are hashed using bcrypt before storage using an appropriate work factor; plain-text passwords are never stored or logged
Secure session tokensAuthentication tokens are stored in httpOnly cookies (inaccessible to JavaScript) with SameSite=lax policy to mitigate cross-site request risks
Email verificationNew accounts require email address verification before access is granted
Brute-force protectionAuthentication endpoints are rate-limited; repeated failed attempts result in temporary blocking
Secure password resetPassword reset uses time-limited (1-hour expiry), single-use, cryptographically random tokens delivered by email

4. Data Integrity and Availability

MeasureImplementation
Managed database infrastructureThe database is operated by Neon, a managed PostgreSQL provider, with built-in availability, automated failover, and backup capabilities
Concurrent edit protectionA workspace locking mechanism prevents simultaneous conflicting edits; stale locks are automatically detected and released after 5 minutes
Version-controlled schema managementAll database schema changes are applied through version-controlled Alembic migrations, ensuring consistency and rollback capability
Cascade deletionAll subordinate data is automatically and completely deleted when a parent record (workspace or user account) is deleted, ensuring the integrity of data erasure

5. Audit Trail and Accountability

MeasureImplementation
Operational audit logAll position-level create, update, delete, and lifecycle operations are recorded with user attribution, timestamp, and before/after state
Field-level change historyField-level changes are logged per position, recording the field changed, old and new values, timestamp, and the user responsible
Audit log lifecycleAudit and change log records are retained for the lifetime of the workspace and are permanently deleted when the workspace is deleted

6. Data Minimisation and Purpose Limitation

MeasureImplementation
No special-category dataThe Platform does not collect, prompt for, or have processes designed for Article 9 GDPR special-category data
Consent-gated product analyticsPostHog product analytics loads only after a user gives cookie consent. No advertising technologies or cross-site tracking pixels are used.
No independent use of Customer DataCustomer Data is not used for the Processor's own purposes, including advertising, product development, or AI model training

7. Sub-processor Management

MeasureImplementation
Contractual flow-downEach Sub-processor is required to enter into a data processing agreement imposing obligations substantially equivalent to those in this DPA
Security due diligenceSub-processors are assessed for their security capabilities before engagement
Change notificationControllers receive at least 14 days' advance notice of any intended change to the approved Sub-processor list

8. Organisational Measures

MeasureImplementation
Confidentiality obligationsAll personnel with access to Customer Data are bound by contractual or professional confidentiality duties
Need-to-know accessAccess to Customer Data is limited to personnel who require it to perform their specific duties
Breach responseThe Processor maintains procedures for identifying, containing, and notifying the Controller of Personal Data Breaches without undue delay

Annex III — Approved Sub-processors

Sub-processorRoleData categories processedLocationTransfer mechanism
Render (render.com)Backend application hosting; frontend delivery; CI/CD infrastructureAll data processed through the Service in transit during normal operationUnited StatesSCCs — Commission Implementing Decision (EU) 2021/914
Neon (neon.tech)Managed PostgreSQL databaseAll Customer Data stored in the PlatformFrankfurt, Germany (EU)EU-located storage — no international transfer required
Resend (resend.com)Transactional email delivery (account verification, password reset, workspace invitations)Recipient email addresses; inviter display name and workspace name (in invitation emails)United StatesSCCs — Commission Implementing Decision (EU) 2021/914
Stripe (stripe.com)Payment processing and subscription billingBilling contact name and email address. Payment card details are processed directly by Stripe and are not received or stored by Organigram.United States / EUSCCs — Commission Implementing Decision (EU) 2021/914; EU–US Data Privacy Framework where applicable

The Processor will give at least 14 calendar days' prior written notice before activating any new Sub-processor or making a material change to an existing Sub-processor arrangement.