Skip to content
Takto o
Why Takto How it works Credibility Pricing Who it's for
Log in Run your numbers
Why Takto How it works Credibility Pricing Who it's for
Log in Run your numbers

Data protection

Data processing agreement

This standard data processing agreement ("DPA") governs Takto's processing of personal data on a customer's behalf under Article 28 of the EU General Data Protection Regulation (GDPR).

Version 1.1. Last updated 23 August 2026.

Public form only. This page is not an operative DPA and cannot be relied on for processing Customer Data. Before processing begins, the parties must complete the Customer identity, production Subprocessors, locations, transfer mechanisms, and security measures, then incorporate the completed DPA into an order or sign it separately. The security page explains which infrastructure decisions are still open. Contact hello@takto.se for an execution copy.

The parties

This DPA is between:

Processor Rinda Venture Studio AB, organisation number 559596-8800, operating Takto. Contact: hello@takto.se.
Controller The customer identified in the applicable order or other written agreement for the Takto service (the "Customer").

Each is a "party" and together they are the "parties".

1Background and scope

Takto is a decision-support service that analyses ERP and accounting data connected by the Customer. It may also analyse documents and contracts that the Customer chooses to upload. The service identifies possible leaks, risks, and opportunities and presents estimated impact in kronor. The terms of service and the applicable order are the "Main Agreement".

When the parties complete and incorporate this DPA into an order or sign it separately, it forms part of the Main Agreement. If the two conflict about that processing, the completed DPA takes priority. Any applicable completed and executed EU Standard Contractual Clauses take priority on international transfer matters.

2Definitions

"Personal data", "processing", "controller", "processor", "data subject", "personal data breach", "supervisory authority", and "special categories of personal data" have the meanings given in the GDPR (Regulation (EU) 2016/679). A "Subprocessor" is a third party that the Processor appoints to process personal data for the Customer. "Applicable Data Protection Law" means the GDPR and any Swedish law that supplements it.

3Roles of the parties

The Customer is the controller and determines why and how the personal data is processed. Takto is the processor and acts on the Customer's behalf. The Customer is responsible for having a lawful basis for the processing, sharing personal data lawfully, and giving lawful instructions.

This DPA does not cover personal data for which Rinda Venture Studio AB is the controller, such as business contact details collected for its own customer relationship. The privacy notice covers that processing.

4Details of the processing

Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects. Takto processes personal data only to provide the service and for the duration of the Main Agreement, unless the law requires a longer period.

5Instructions

Takto processes personal data only on the Customer's documented instructions, including instructions about transfers to a third country. The Main Agreement and the Customer's service configuration are those instructions. Additional instructions must be agreed in writing and may change the fees or scope if they require work beyond the service's standard operation.

If Union or Member State law requires other processing, Takto will tell the Customer before processing unless the law prohibits notice on important public-interest grounds. Takto will also tell the Customer if it believes an instruction breaches Applicable Data Protection Law. Takto does not provide legal advice and is not required to conduct a general legal review of the Customer's instructions.

6Confidentiality

Anyone authorised by Takto to process personal data must be bound by a contractual or statutory duty of confidentiality. Access is limited to people who need it to provide the service.

7Security of processing

Takto will maintain technical and organisational measures appropriate to the risk, taking account of the state of the art, implementation cost, and the nature, scope, context, and purpose of the processing, as required by Article 32 of the GDPR. Annex 3 sets the baseline. The execution copy will identify the measures that apply to the deployed production infrastructure before processing starts. Takto may update those measures without materially reducing security.

8Subprocessors

The Customer gives Takto general written authorisation to appoint Subprocessors for the service. The applicable Subprocessors must be identified in Annex 2 of the order or execution copy before they process Customer Data.

Takto will give reasonable prior notice of an intended addition or replacement. The Customer may object on reasonable data-protection grounds before the new Subprocessor begins processing. If the parties cannot resolve the objection, the Customer may terminate the affected part of the service.

Takto will require each Subprocessor by contract to meet the same data-protection duties that apply under this DPA. Takto remains fully liable to the Customer for the Subprocessor's performance of those duties.

9Assistance to the Customer

Taking account of the processing, Takto will use appropriate technical and organisational measures to help the Customer respond to data-subject requests under Chapter III of the GDPR where reasonably possible. If Takto receives a request directly, it will forward the request without undue delay and will not answer on the Customer's behalf unless the Customer instructs it to do so.

Takto will also provide reasonable assistance with the Customer's duties under Articles 32 to 36 of the GDPR, including security, breach notification, data protection impact assessments, and prior consultation. Takto may charge a reasonable fee for work beyond standard service functionality after notifying the Customer.

10Personal data breach

Takto will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data. It will provide the information reasonably available to help the Customer meet its notification duties. Takto will not notify a supervisory authority or data subject for the Customer unless instructed to do so.

11Return and deletion

When the service ends, Takto will return or delete personal data processed for the Customer, at the Customer's choice, and delete existing copies unless Union or Member State law requires storage. If the Customer does not choose within 30 days after termination, Takto may delete the data. This section does not apply to aggregated and de-identified information that no longer identifies an individual.

12Audits and information

Takto will provide information reasonably needed to demonstrate compliance with Article 28 of the GDPR and this DPA. It will allow and contribute to audits, including inspections, by the Customer or its appointed auditor.

An audit requires reasonable written notice and may take place no more than once a year, unless a supervisory authority requires it or it follows a personal data breach. Audits must take place during business hours and must not unreasonably disrupt operations or compromise another customer's confidentiality or security. Takto may meet a request by providing relevant certifications, reports, or control summaries when they reasonably address the request. Each party pays its own audit costs.

13Transfers outside the EU/EEA

Takto will not transfer personal data outside the EU/EEA unless a valid mechanism under Chapter V of the GDPR applies, such as an adequacy decision or the EU Standard Contractual Clauses, together with any required supplementary measures.

Annex 2 must identify any applicable international processing. Where the EU Standard Contractual Clauses are required, the parties will complete and incorporate the applicable module, annexes, and supplementary measures. The completed clauses take priority on transfer matters if they conflict with this DPA.

14Liability

The exclusions and liability limits in the Main Agreement apply to this DPA, including the limit based on fees paid during the three months before the event that caused the claim and the exclusion of indirect and consequential loss.

Those limits do not apply where mandatory law does not allow limitation or exclusion. They do not affect a data subject's right to compensation under Article 82 of the GDPR or liability for gross negligence or wilful misconduct. Between the parties, each party is responsible for fines and claims to the extent caused by its own breach of Applicable Data Protection Law.

15Term

This DPA takes effect only after the missing Customer, Subprocessor, transfer, and security details have been completed and the DPA has been incorporated into the Main Agreement or signed separately. It continues while Takto processes personal data for the Customer. The provisions on confidentiality, return and deletion, liability, and governing law survive termination where needed.

16Governing law and disputes

Swedish law governs this DPA. The Swedish general courts have jurisdiction, with Stockholm District Court (Stockholms tingsrätt) as the court of first instance.

17Acceptance

This public form does not bind either party. A completed DPA forms part of the Main Agreement when the applicable order incorporates it, or it takes effect when signed separately. The execution copy must identify the Customer and include the agreed execution details.

Annex 1: Details of the processing

Subject matter Personal data in ERP and accounting data connected by the Customer, and in documents or contracts the Customer uploads, as needed to provide Takto.
Duration The term of the Main Agreement and any period required by law, followed by return or deletion under section 11.
Nature and purpose Hosting, storage, structuring, analysis, and presentation of Customer Data to identify possible leaks, risks, opportunities, reminders, and findings for the Customer to review.
Data subjects The Customer's employees and personnel; the Customer's contact people and users; and people identified in customer, supplier, transaction, or contract records where such information is present in the connected data.
Personal data Names, roles, business contact details, system identifiers, and transaction, order, invoice, or contract data that may relate to an identifiable person, plus other personal data the Customer chooses to connect or upload.
Special-category data Not requested or intended. The Customer must avoid including special-category data unless the parties agree the processing and safeguards in writing.

Annex 2: Production subprocessors to be confirmed

The final production hosting and model-provider setup has not been chosen. No provider should be treated as approved to process production Customer Data solely because it supports the public website or pilot intake. The order or execution copy must list every applicable Subprocessor, its purpose, processing location, and transfer mechanism before processing begins.

For transparency, Google currently supports the public website and pilot intake operations, Cloudflare provides Turnstile where forms use it, and Slack may receive limited internal intake notifications. Their use is described on the security page and in the privacy notice. These current operations do not determine the future production Customer Data architecture.

Annex 3: Technical and organisational measures

The production execution copy must describe the controls that apply to the deployed service. At a minimum, Takto will address:

  • Access restricted to named, authorised personnel who need it, using individual accounts and appropriate authentication.
  • Encryption in transit and at rest using controls supported by the selected infrastructure.
  • Measures to protect confidentiality, integrity, and availability and to prevent accidental loss, destruction, or damage.
  • Data minimisation, including guidance not to place unnecessary personal data in free-text fields.
  • Logical separation of each customer's data.
  • Backup, restoration, resilience, vulnerability management, and timely patching.
  • Regular testing and evaluation of the effectiveness of security controls.
  • Written data-protection terms for every Subprocessor.
  • Confidentiality duties and appropriate guidance for personnel.
  • Procedures to detect, assess, contain, and report personal data breaches without undue delay.

← Back to Takto

TAKTO

Real data. Proven playbooks. Clear next steps.

Powered by Rinda Venture Studio

Quick links

Log in Privacy Terms Security DPA

Contact

hello@takto.se

Rinda Venture Studio
Org. no. 559596-8800

© 2026 Takto · Org. no. 559596-8800 · Privacy · Terms · Security · DPA