Data Processing Agreement (“DPA”) regarding
Corvenia Software Solutions
Effective Date: 30th of September, 2026

1. Processor and controller roles and responsibilities

Corvenia AB (“the Supplier”) will, in order to provide the SaaS Services including any agreed Deliverables and Consultancy Services according to the agreed Order Form, which will constitute analytics and aggregated financial data collection and reporting of financial key figures and other operational data, process personal data as a processor.

The Customer defined in the Order Form will act as the controller when the Supplier processes personal data on the Customer’s behalf. Customer’s initial instructions and further processing details are set out below in section 4.

The Terms defined in Article 4 of the EU General Data Protection Regulation (“GDPR”) shall apply to this DPA.

This DPA forms an integral part of the Agreement and applies for as long as the Supplier processes personal data on behalf of the Customer, and is an integral part of the Order Form. This DPA does not apply to any processing of personal data which the Supplier carries out as an independent controller.

2. Warranty

Supplier warrants that it has implemented appropriate technical and organizational measures in such a manner that its processing of personal data under this DPA will meet the requirements of applicable data protection law and ensure the protection of the rights and freedoms of the data subjects.

Failure by the Supplier to fulfil its obligations under this DPA shall constitute a breach of the agreement.

3. Subsidiaries and Group Companies

Where the SaaS Services involve the retrieval or processing of personal data originating from a Subsidiary (as defined in the Terms of Use) or other group company of the Customer, the Customer warrants and represents that it has, as between the Customer and such Subsidiary or group company, a valid legal basis and any necessary internal authorization to instruct Supplier to process such personal data on the Customer's behalf, including where applicable a data sharing or intra-group processing arrangement between the Customer and the relevant Subsidiary or group company.

Supplier acts as processor solely on behalf of, and takes instructions solely from, the Customer named in the Order Form. Supplier does not enter into a separate controller-processor relationship with any Subsidiary or group company of the Customer under this DPA, and the Customer remains solely responsible for ensuring that its instructions to Supplier concerning personal data of any Subsidiary or group company comply with applicable data protection law.

The Parties may agree on a separate data processing arrangement naming a Subsidiary or group company as an independent controller party to this DPA, provided this is set out in writing and signed by the Supplier and the relevant Subsidiary or group company.

4. Processing details

Supplier warrants it will meet the requirements under Article 28 GDPR by:

a) Only processing personal data as instructed by the Customer in the DPA or later written instruction, without prejudice to any rights of the Supplier under the Terms of Use.

b) Notifying the Customer if Supplier believes that an instruction is in violation of applicable data protection laws.

c) Ensuring that individuals processing personal data are bound by a duty of confidentiality.

d) Implementing appropriate technical and organizational measures to ensure a level of security for personal data appropriate to the risk.

e) Assisting the Customer in its duty to respond to data subjects' requests to exercise their GDPR rights.

f) Fulfilling the requirement for data breach notification and assistance.

g) Assisting the Customer with data protection impact assessments and any cooperation with the relevant supervisory authority.

h) Immediately informing the Customer in writing of any legal obligation that requires Supplier to disclose personal data that Supplier processes on behalf of the Customer.

i) Demonstrating compliance with the obligations under Article 28 GDPR by making available necessary information on Customer’s request.

j) Allowing and contributing to any reasonable audits directed by the customer.

k) Deleting or returning personal data and copies at the Customer’s choice at the end of the service relating to the processing, without prejudice to any rights of the Supplier under the Terms of Use.

Due to the uncertain scope of points e, f, g and j above, these tasks may be subject to additional payment on a time-and-material basis in accordance with applicable rates.

5. Initial instructions of processing

Purposes

The purposes of the processing are the delivery of the SaaS Services including any agreed Deliverables and Consultancy Services according to the agreed Order Form, which may be described as follows:

Supplier has developed a cloud-based software platform intended to automate and improve financial data collection and reporting of financial key figures and other operational data, allowing customers to retrieve deep insights for decision-making and consolidated financial statements.

The system uses third-party machine learning systems and manual guidance and verification from the users (human-in-the-loop) in order to select and retrieve data directly from portfolio companies’ and subsidiaries’ accounting systems, project systems, Excel reports, and BI tools. The output from this software platform is structured and optimized by selected third-party machine learning systems and manual guiding from the users (human-in-the-loop). This verified output may be further analysed by selected third-party machine learning systems in order to present decision-making drafts of data and user-configurable automations (“Agents”) for customers’ personnel (human-in-the-loop) to solve various issues regarding data collection and reporting, analysis and decision-making, forecasting, etc. Customer will obtain access to the system by means of a web interface, through which Customer will have the functionality described for each software solution in the Order Form concluded between Supplier and Customer and covering the delivery of the system.

Categories of personal data and data subjects

The Supplier will process the personal data provided by the Customer through its use of the software in accordance with the Order Form. This data may include, but is not limited to, the following categories:

  • Employee Data: Names, job titles, email addresses, phone numbers, employment details and Financial Data to the extent included in the data retrieved from Customer's accounting or project systems.
  • Financial Data: Transactional information linked to identifiable individuals.
  • Platform User Data: Names of users, login credentials, usage logs, and related information.
  • Data from Integrated Systems: Personal data retrieved from accounting systems, project management tools, Excel reports, and BI tools.
  • System Monitoring Data: Information such as IP addresses and device details.
  • AI-Processed Data: To the extent Employee Data, Financial Data, Platform User Data, System Monitoring Data or Data from Integrated Systems is included in the output analysed by selected third-party machine learning systems or processed through Customer-configured Agents as described in the Terms of Use, such data will also be processed for these purposes.

Processing of other categories of data on the terms defined in this agreement may be specifically agreed between the Parties and listed in writing as an appendix to the Order Form.

Sub-Processors

The Customer authorizes the Supplier to engage third-party sub-processors for specific processing activities, including the use of third-party machine learning systems, provided that:

  1. The Supplier ensures that sub-processors are bound by equivalent data protection obligations.
  2. The Supplier provides prior notice to the Customer of any changes to the list of sub-processors.

The Supplier will be responsible for its own sub-processors.

Supplier will notify the Customer of any intended changes of sub-processors or locations of processing at least thirty (30) days in advance, offering the Customer the opportunity to object on reasonable grounds based on applicable data protection law. If the Customer objects, Supplier will use commercially reasonable efforts to address the objection, including by proposing an alternative sub-processor or adjusting the processing in question. If Supplier is unable to do so, Customer's sole and exclusive remedy is to terminate the Order Form(s) affected by the objection, without further liability for either Party for the terminated scope; any previously accrued rights and obligations shall survive such termination. If the Customer does not object within the notice period, the change shall be deemed accepted.

6. Measures to ensure the security of the personal data

The Supplier shall implement and maintain appropriate technical and organisational measures pursuant to GDPR Article 32, having regard to the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks for the rights and freedoms of data subjects. The measures shall include, as appropriate:

  • encryption of Personal Data in transit and at rest;
  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
  • access control measures, including personal user identification and role-based authorisation; and
  • a process for regularly testing, assessing and evaluating the effectiveness of the above measures.

The Supplier may update its security measures from time to time, provided that such updates do not materially decrease the overall level of protection afforded to Personal Data.

7. International data transfers

Supplier's primary hosting and AI-processing infrastructure (Microsoft Azure, including Azure OpenAI Service) is configured to store and process personal data within the EU/EEA region. The personal data required for processing does not require any additional basis for export as long as such EU/EEA configuration is maintained and processing occurs exclusively within the EEA.

If personal data is nonetheless transferred outside the EEA, including in connection with a sub-processor's provision of services, the Supplier shall ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) adopted by the European Commission or other mechanisms approved under the GDPR, and shall provide the Customer with relevant information on request.

8. Personal data breach

In the event of a Personal Data Breach involving Personal Data processed on behalf of the Customer, the Supplier shall notify the Customer without undue delay, and in any event no later than 48 hours after becoming aware of the breach. The notification shall describe, to the extent available:

  • the nature of the Personal Data Breach, including the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the breach; and
  • the measures taken or proposed to address the breach and mitigate its effects.

The Supplier shall cooperate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of the breach.

9. Term and termination

This DPA shall remain in effect for the duration of the Supplier’s provision of the platform to the Customer. Upon termination, Supplier shall retain Customer Data for a period of 30 days after the Termination Date in accordance with the Terms of Use, during which the Customer may request the return of personal data by written notice issued no later than five working days before the Termination Date. Following expiry of this period, or upon earlier written confirmation from the Customer that the data should not be transferred, the Supplier shall delete all remaining personal data, save to the extent retention is required by applicable law or permitted under the Terms of Use.

10. Liability

Any breach of this DPA shall be deemed a breach of the Terms of Use, and the limitations of liability and other remedies set out in the Terms of Use shall apply to any claims arising under or in connection with this DPA.

11. Governing law and disputes

This DPA shall be governed by and construed in accordance with Swedish law, without regard to its conflict-of-law principles. Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution mechanism set out in the Terms of Use.