Skip to main content

Data Processing Agreement (DPA)

The agreement applies to all paid plans and forms part of our terms. You accept it when you choose a paid plan; no separate signature is needed.

When you sign up for a paid CompliantHQ plan you become the data controller for the personal data we process on your behalf, and Style4 Solutions AB becomes your data processor under GDPR Article 28. This page is the full agreement text. If you need a copy for your records, printing the page is enough; the version date at the bottom states which wording applies.

1. Parties and validity

The agreement is between you as the customer (controller) and Style4 Solutions AB (processor) and forms part of our terms. It takes effect when you choose a paid plan and applies for as long as we process personal data on your behalf. In matters concerning personal data, this agreement takes precedence over the rest of the terms.

2. Subject matter, nature and purpose of the processing

We process personal data on your behalf in order to operate CompliantHQ: running scans of your websites, including the AI analysis that is part of every paid scan, generating action plans and the basis for your self-assessment, answering in the in-product chat, and sending product email. The processing consists of collection from your publicly reachable pages, storage, analysis and deletion.

3. Duration

For as long as you have an active account, plus the retention periods stated in our privacy policy.

4. Data subjects and personal data

  • Categories of data subjects: your users (team members with a CompliantHQ login) and, incidentally, people whose data appears on the publicly reachable pages you let us scan.
  • Categories of personal data: email addresses, names and billing details of your users, and whatever data happens to appear in the content of scanned pages, for example contact details of staff.
  • We do not intentionally process any special categories of personal data, and the scan never reads content behind a login.

5. Our obligations as processor

  • We process personal data only on your documented instructions. The instructions are this agreement, the terms and the settings you make in the service, for example which websites are scanned and how often. If the law requires us to process otherwise, we inform you in advance, where the law allows it.
  • The people at our end who process the data are bound by confidentiality.
  • We do not use the personal data for our own purposes, and neither we nor our sub-processors use it to train AI models.
  • We implement the technical and organisational security measures required by Article 32; they are described on our security page.
  • We assist you in meeting your obligations towards data subjects (Articles 12 to 22) and regarding security, breaches, impact assessments and prior consultation (Articles 32 to 36), to the extent the nature of the processing and the information we hold allow.
  • We notify you without undue delay, normally within 48 hours, after becoming aware of a personal data breach concerning your data, with the information you need for your own notification to the supervisory authority within 72 hours.
  • When the agreement ends we delete the personal data. If you want it returned, export your data in the service before the account is deleted. Exceptions apply where Union or Swedish law requires continued storage, for example the Swedish Bookkeeping Act.
  • We provide the information needed to demonstrate compliance with Article 28 and contribute to audits, primarily through documentation and written answers. An on-site audit takes place after agreement on timing and scope.
  • We inform you immediately if we consider an instruction to infringe data protection law.

6. Sub-processors

You give us general prior authorisation to engage sub-processors. The current list, with location and purpose, is on the sub-processors page, which is the channel we announce changes in. If you want changes by email, write to hello@complianthq.ai. A new or replaced sub-processor is put to use no earlier than 30 days after the change is published. If you have reasonable grounds to object, you may terminate the affected parts of the service before the change takes effect. Every sub-processor is bound by a written agreement with the same obligations as here, and we remain fully responsible for its processing.

7. Transfers to third countries

We process your data within the EU/EEA. The only exception today is the AI analysis at Anthropic PBC in the USA, which takes place under the European Commission's Standard Contractual Clauses pursuant to Article 46(2)(c). What is sent there, and what is never sent, is described in the privacy policy.

8. Liability and governing law

The limitations of liability in the terms also apply to this agreement, subject to the exceptions that follow from Article 82 GDPR. Swedish law applies.

9. Changes

We may update the agreement when the service or the law changes. Changes are published on this page with a new version date at least 30 days before they take effect, unless a change in law requires faster entry into force. Continued use after the effective date means the new wording applies.

Version

Version 2026-09-09. Questions about the agreement: hello@complianthq.ai.