Data Processing Agreement

Version 1.0 — 30 September 2026

Contracting processor: Ochno AB, Badhusgatan 8, 722 15 Västerås, Sweden.

Agreement and scope

This Data Processing Agreement (the DPA) forms part of the EULA governing the Customer's use of the Services and any service agreement, order form, subscription terms or other written agreement that identifies the Customer and the Ochno services it purchases (collectively, the Service Agreement). It applies only when, and to the extent that, Ochno processes Personal Data on behalf of the Customer in providing those services. The Service Agreement and this DPA together are the Agreement.

The Customer accepts the EULA, including the version of this DPA made available with and incorporated into that EULA, through the mandatory checkbox and acceptance button presented during account sign-up and any later re-acceptance required by Ochno. The DPA takes effect when the applicable EULA is accepted. The Customer is the legal entity identified during account sign-up, in the customer account or in the applicable Service Agreement. The individual accepting on the Customer's behalf represents that they are authorised to bind the Customer. Ochno records the accepting user's identity, affirmative acceptance, accepted EULA revision and content hash, and acceptance time. Publication of a web page alone does not create a contract.

For processing covered by this DPA, the Customer is the Controller and Ochno is the Processor, unless the Customer itself acts as a Processor for another Controller. If the Customer is a Processor, it warrants that the relevant Controller has authorised the appointment of Ochno and that the Customer's instructions reflect that Controller's instructions. References to the Controller in this DPA then include the Customer and, where relevant, that Controller.

The Customer determines the purposes and essential means of the processing and is responsible for its lawful basis, notices, permissions, instructions, and decisions about the Personal Data it submits or makes available through the services. Ochno processes that Personal Data only as described in this DPA and on the Customer's documented instructions.

This DPA does not govern Personal Data Ochno Processes for its own purposes, including its own business contacts, identity administration, service security, legal compliance and direct business communications. Ochno's Privacy Notice describes that processing. Personal Data Ochno Processes to administer Customer users, permissions and access to the Services on the Customer's behalf remains Customer Personal Data under this DPA. The parties' roles for each Processing activity follow its purposes and means.

If this DPA conflicts with the Service Agreement about the processing of Personal Data, this DPA controls. The Service Agreement controls commercial terms, service scope, fees, liability limits and dispute terms, except to the extent it would prevent either party from meeting a mandatory obligation under applicable Data Protection Law.

1. Definitions

Data Protection Law means the data protection and privacy laws applicable to the Processing under the Agreement, including the GDPR and applicable national laws supplementing it. GDPR means Regulation (EU) 2016/679. Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach and Supervisory Authority have the meanings given to them in applicable Data Protection Law. Services means the Ochno products or services identified in the Service Agreement. Customer Personal Data means Personal Data Processed by Ochno on the Customer's behalf in providing the Services. Subprocessor means another Processor engaged by Ochno to Process Customer Personal Data on behalf of the Customer.

2. Processing and instructions

2.1 The subject matter, duration, nature and purposes of the Processing, the categories of Data Subjects and Personal Data, and the relevant processing operations are set out in Annex 1. The Customer instructs Ochno to Process Personal Data to provide, secure, support and maintain the services described in the Service Agreement and to perform other documented instructions that are consistent with that Agreement and this DPA.

2.2 The Service Agreement, the Customer's service configuration and use of the services, and written instructions issued by the Customer's authorised representatives are documented instructions. Instructions must be lawful, sufficiently clear and within the agreed service scope. Ochno will notify the Customer if, in Ochno's reasonable opinion, an instruction infringes Data Protection Law. Ochno is not required to follow an instruction that is unlawful or would require an unagreed material change to the services. The parties will discuss a lawful alternative; Ochno may suspend only the affected Processing while the issue is resolved where necessary to comply with law or protect the services.

2.3 Ochno will Process Personal Data only on documented instructions, including instructions concerning a transfer to a country outside the European Economic Area (EEA), unless Union or Member State law requires otherwise. Where law requires Processing without the Customer's instruction, Ochno will inform the Customer of that requirement before Processing unless the law prohibits that notice on important grounds of public interest.

2.4 The Customer will not instruct Ochno to Process Personal Data in a way that violates Data Protection Law. The Customer will provide only Personal Data reasonably necessary for its use of the Services and will configure user and administrator access appropriately. The Services do not request, and are not designed or intended, to Process special-category Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions and offences under Article 10 GDPR. The Customer must not submit such data through the Services. If the Customer becomes aware that it has submitted such data, it will promptly notify Ochno so the parties can arrange its deletion or other lawful handling.

2.5 A Customer or authorised user may enable an integration only after separately accepting it and granting it access to Customer Personal Data. By enabling the integration, the Customer instructs Ochno to make the data available within the permissions selected by the Customer or user. An integration provider selected and separately authorised by the Customer is not an Ochno Subprocessor unless Ochno separately engages it to Process Customer Personal Data on Ochno's behalf. The Customer is responsible for selecting and authorising the integration and reviewing its terms and data practices. Ochno does not determine or control an integration provider's subsequent processing or the locations where the provider stores or uses data. This paragraph does not limit Ochno's obligations for Processing performed by Ochno or its Subprocessors.

3. Ochno's obligations

3.1 Ochno will:

  • Process Personal Data only as permitted by this DPA and on the Customer's documented instructions;

  • ensure that persons authorised to Process Personal Data are subject to an appropriate duty of confidentiality and receive access only as needed to perform their duties;

  • implement and maintain the technical and organisational measures described in Annex 2, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of Processing, and the risks to individuals;

  • provide reasonable assistance, taking account of the nature of the Processing, to enable the Customer to respond to Data Subject requests and meet its obligations under Articles 32 to 36 GDPR;

  • notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA, and provide the information reasonably available to Ochno to assist the Customer's assessment and response;

  • notify the Customer if Ochno receives a Data Subject request concerning Personal Data Processed on the Customer's behalf, and not respond to that request unless the Customer instructs Ochno to do so or the law requires it;

  • make available information reasonably necessary to demonstrate Ochno's compliance with this DPA and allow for and contribute to audits as described in section 7; and

  • keep records of Processing where and to the extent required by Data Protection Law.

3.2 A breach notice will describe the nature of the breach, the categories and approximate number of affected individuals and records where reasonably ascertainable, likely consequences, mitigation taken or proposed, and a contact point for follow-up. If all details are not initially available, Ochno may provide them in phases without undue further delay.

4. Subprocessors and international transfers

4.1 The Customer gives Ochno general written authorisation to engage the Subprocessors identified in the current Subprocessor Schedule incorporated into this DPA. Ochno will impose data protection obligations on each Subprocessor that provide at least the same level of protection as the applicable obligations in this DPA. Ochno remains responsible to the Customer for the performance of each Subprocessor's data protection obligations.

4.2 Ochno will notify the Customer in writing of an intended addition or replacement of a Subprocessor in advance, together with information reasonably needed to assess it, so the Customer has a meaningful opportunity to object on reasonable data protection grounds before the change takes effect. The notice will state a reasonable deadline for objections before the proposed change. The Customer must send an objection by that deadline and explain its grounds. The parties will work in good faith to address the objection. This DPA does not set a fixed notice period or a separate termination right; any such right in the Service Agreement continues to apply.

4.3 Ochno will not transfer Personal Data to a country outside the EEA, or permit a Subprocessor to do so, unless the transfer is covered by an applicable adequacy decision or another lawful transfer mechanism and any required supplementary measures. Before a restricted transfer begins, Ochno will provide the Customer with information about the destination, recipient and transfer mechanism. Where required, the parties will put in place the European Commission's Standard Contractual Clauses for a transfer from the Customer to Ochno, and Ochno will ensure that the appropriate clauses and safeguards are in place with a Subprocessor for a transfer from Ochno to that Subprocessor. Any UK or other jurisdiction-specific transfer instrument required by law will also be put in place before the relevant transfer.

5. Customer responsibilities

The Customer is responsible for:

  • ensuring that it has a lawful basis for the Processing and that its collection, use and instructions comply with Data Protection Law;

  • providing all required privacy information to Data Subjects and obtaining any required consents or authorisations;

  • ensuring its instructions are complete, accurate, lawful and within the services' capabilities;

  • deciding whether the Personal Data and service configuration are appropriate for its purposes, including whether a data protection impact assessment is required; and

  • responding to Data Subject requests and communications from Supervisory Authorities, with Ochno's assistance under this DPA where applicable.

6. Assistance and cooperation

6.1 Taking account of the nature of the Processing and the information available to Ochno, Ochno will reasonably assist the Customer with:

  • requests from Data Subjects to exercise their rights;

  • the Customer's obligations to secure Processing, notify Personal Data Breaches, conduct data protection impact assessments, and consult Supervisory Authorities; and

  • enquiries or investigations by a Supervisory Authority concerning Processing under this DPA.

6.2 If Ochno cannot itself fulfil a Data Subject request, it will provide reasonable technical and organisational assistance so the Customer can respond. Assistance beyond the standard functionality of the services may be subject to reasonable charges agreed in advance, except where charging is prohibited by law or the assistance is required because of Ochno's breach of this DPA.

7. Compliance information and audits

Ochno will make available to the Customer all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, as required by Data Protection Law.

8. Return and deletion

At the Customer's choice, following termination or expiry of the relevant services, Ochno will return or delete Personal Data Processed on the Customer's behalf and delete existing copies, unless Union or Member State law requires continued storage. The Customer must exercise its choice through the service's available export or deletion controls or by written instruction to Ochno. Ochno will protect any Personal Data that must be retained by law and will Process it only for that legal purpose. Personal Data remaining in backups will be protected and deleted or overwritten in accordance with the backup-retention period stated in Annex 1; it will not be restored or otherwise Processed except for disaster recovery or as required by law.

9. Term, liability and general terms

9.1 This DPA continues for as long as Ochno Processes Personal Data on behalf of the Customer under the Service Agreement. Sections that by their nature must continue after termination, including confidentiality, liability and deletion obligations, survive to the extent applicable.

9.2 Each party's liability under this DPA is subject to the liability provisions of the Service Agreement, if any, except to the extent that applicable law does not permit that limitation. Nothing in this DPA limits a Data Subject's rights or a party's liability under mandatory Data Protection Law. This DPA does not establish a separate liability cap.

9.3 Notices under this DPA must be sent to the privacy or legal contacts designated in the Service Agreement. If no such contact is designated, notices to Ochno must be sent to legal@ochno.com and notices to the Customer to the legal or security contact identified in its account or Service Agreement.

9.4 An amendment to this DPA must be agreed in writing by the parties, including by the Customer's authorised representative's affirmative acceptance of a replacement EULA incorporating a replacement version of this DPA, except for an update to the Subprocessor Schedule made in accordance with section 4.2. The version accepted by a Customer continues to apply unless the parties agree to a replacement version or the Service Agreement expressly permits the update. If any provision is unenforceable, the remaining provisions continue in effect.

9.5 Any governing-law and dispute-resolution provisions in the Service Agreement apply to this DPA. If it contains none, the governing law and forum are determined under applicable default rules.

Annex 1 — Processing details

Subject matter, duration and purpose

Ochno's provision of the authenticated customer and connected-product services identified in the Service Agreement, including management of Customer account and product information, Customer user identities and access permissions, hosting and displaying information the Customer supplies, registering and managing connected products, monitoring operational status and connectivity, providing usage information and analytics such as energy-consumption insights, troubleshooting, support, maintenance, and service security. This covers those activities only to the extent Ochno performs them on the Customer's documented instructions. Personal Data Ochno processes for its own identity-administration, security and legal purposes is outside this DPA as described below. Processing lasts for the term of the Service Agreement and the limited period needed to return or delete Customer Personal Data afterward.

Nature of the Processing

Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, display, combination, restriction, erasure and destruction, as necessary to provide the services and follow the Customer's documented instructions.

Categories of Data Subjects

  • The Customer's account administrators and authorised users;

  • the Customer's employees, contractors, business contacts and service providers whose information the Customer enters into or makes available through the services; and

  • the Customer's own customers, end users or other individuals whose information is submitted through the services or associated with connected products.

Categories of Personal Data

Depending on the Services selected and the Customer's configuration, Customer Personal Data may include names, business contact details, organisation and role, customer-account and user identifiers, access permissions and preferences, product identifiers and names, configuration, operational status, connectivity and usage information, timestamps, technical or security logs, Customer-uploaded images, and information the Customer chooses to submit. For media requests, this also includes the viewer's IP address and associated request, connection, browser or device metadata. Ochno's own identity-administration and security records Processed for Ochno's purposes are excluded. Product or usage information is covered only to the extent it relates to an identified or identifiable natural person. The Services are not designed or intended to Process special-category Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions and offences under Article 10 GDPR, and the Customer must not submit such data.

Processing frequency and locations

Processing occurs as the Customer and its authorised users use the Services, including ongoing or periodic processing of connected-product information where enabled. Ochno's AWS-hosted application servers, local caches and stored Customer Personal Data, including Customer-uploaded images, are in the eu-north-1 (Stockholm) region. MongoDB Atlas database clusters are hosted on AWS in eu-north-1. Support cases are handled in Atlassian Jira Service Management Cloud. The Jira Service Management app is not pinned and uses Atlassian's Global location: Atlassian dynamically hosts in-scope app data across its AWS regions. Atlassian account, operational and support data is processed globally. Ochno-owned video is delivered through Cloudflare Stream, which processes viewer IP addresses and media-request data through its global network. Applicable vendor transfer terms and safeguards are identified in Annex 3.

Retention

When a user is deleted, the user's information is removed from the active database. Copies in backups may remain until the backup expires, for no more than 12 months. Following the end of the Services, Customer Personal Data will be returned or deleted as described in section 8; backup copies are retained for no more than 12 months.

Roles outside this DPA

This Annex does not include Personal Data Ochno Processes as an independent Controller for its own business contacts, identity administration, service security, legal compliance or business communications. Those activities are addressed in Ochno's Privacy Notice. Account, identity, user and access information Processed to provide the Customer's Services on the Customer's behalf is included in this Annex.

Annex 2 — Technical and organisational measures

Ochno will maintain technical and organisational measures appropriate to the risks presented by the Processing, including measures to protect confidentiality, integrity, availability and resilience; restrict Personal Data access to authorised personnel; protect Personal Data against unauthorised access, alteration, disclosure, loss and destruction; restore availability following an incident; and regularly assess the effectiveness of security measures.

Ochno will maintain the following measures for the Services and will review them as appropriate to the risks, changes in the Services and applicable Data Protection Law.

Control area

Measures applicable to the Services

Personnel confidentiality and awareness

Personnel authorised to access Customer Personal Data are subject to confidentiality obligations and receive security and privacy guidance appropriate to their duties.

Identity, authentication and access management

Access is limited to authorised personnel with a business need, using individual accounts and role-based permissions. Privileged access is restricted, and access is removed when no longer required.

Customer or tenant separation

Logical access controls and service permissions are used to keep each Customer's data available only within the Customer's account and to personnel authorised to support the Services.

Encryption in transit and at rest

Database data and backups are encrypted at rest. Data transmitted to or from the database is encrypted in transit. Secure transport protections are used for service connections.

Security logging and monitoring

Relevant administrative and security events are logged and monitored to help identify unauthorised access and security incidents. Access to logs is restricted.

Vulnerability, patch and change management

Ochno applies risk-based vulnerability and patch handling. Changes to production systems are authorised and reviewed, and material changes are tested before release where practicable.

Backup, recovery and availability

Database backups are encrypted, protected against unauthorised access and retained for no more than 12 months. Recovery procedures are maintained to restore service and data after an incident.

Incident response and breach handling

Ochno maintains procedures to assess, contain and remediate security incidents and to notify Customers of Personal Data Breaches as stated in section 3.

Physical and environmental security

AWS and other hosting providers are responsible for physical security of their data centres under their security programmes. Ochno restricts physical access to its own work locations and equipment used to administer the Services.

Subprocessor security assurance

Ochno selects Subprocessors that provide services needed for the Services, requires appropriate written data protection and security commitments, and limits their access to what the service requires.

Review of measures

Ochno reviews these measures and relevant Subprocessor security information periodically and when material changes or risks warrant review.

Annex 3 — Subprocessor Schedule

The following providers are authorised Subprocessors for the services stated in this schedule. Their processing locations and categories of Customer Personal Data are stated below. The linked vendor terms and onward-subprocessor schedules identify each provider's safeguards and support entities. Ochno remains responsible under this DPA and will notify the Customer of changes to Ochno's authorised Subprocessors under section 4.2.

Subprocessor legal name

Service provided

Processing location(s)

Customer Personal Data accessed

Transfer mechanism or safeguards

Amazon Web Services EMEA SARL

Cloud hosting, servers, storage and infrastructure supporting the Services, including Ochno's customer-management service

AWS eu-north-1 (Stockholm) for Ochno's application servers, local caches, stored Customer Personal Data and backups. AWS's published processing schedule identifies locations for provider operations and support.

Customer Personal Data processed by the application infrastructure, including data in transit, locally cached data and Customer-uploaded images

AWS Data Processing Addendum and applicable transfer safeguards. AWS's published subprocessor schedule applies.

MongoDB Limited (Ireland)

MongoDB Atlas cloud database

Database cluster and stored Customer Personal Data hosted on AWS eu-north-1 (Stockholm). MongoDB operations and support are covered by its published global subprocessor and transfer terms.

Customer Personal Data stored in the Services' database

MongoDB DPA and applicable transfer safeguards. MongoDB's published subprocessor schedule applies.

Atlassian Pty. Ltd.

Jira Service Management Cloud support cases

Global. Atlassian dynamically hosts in-scope Jira data in AWS regions worldwide. Account, operational and support data are processed globally by Atlassian and its listed group support entities.

Support-case content and metadata submitted by the Customer or its users, including names, business contact details, correspondence and troubleshooting information

Atlassian DPA and applicable transfer safeguards. Atlassian's published subprocessor schedule applies.

Cloudflare, Inc.

Global delivery of Ochno-owned video through Cloudflare Stream in the Services

Cloudflare's global network and points of presence

Customer users' IP addresses, video identifiers, playback requests, timestamps, connection data and browser/device metadata generated when they request or view Ochno-owned video. The video assets themselves are Ochno content, not Customer Personal Data.

Cloudflare Customer DPA and applicable transfer safeguards. Cloudflare's published subprocessor schedule applies.

Customer-authorised integrations remain outside this Schedule unless Ochno separately engages the provider to Process Customer Personal Data on Ochno's behalf.

Current vendor terms and onward-subprocessor information: AWS Data Processing Addendum and subprocessor schedule; MongoDB DPA and subprocessor schedule; Atlassian DPA and subprocessor schedule; Cloudflare DPA and subprocessor schedule.