Parties
(1) The Customer (hereinafter referred to as the “Controller”), and
(2) Tandem Health AB incorporated and registered in Sweden with registration number 559444-6857 whose registered office is at Kungsgatan 14 111 35 Stockholm, Sweden (“Tandem” or the “Processor”),
each a party and together, the parties.
1. Background and purpose
1.1 This Data Processing Agreement (the “DPA”) forms part of the customer agreement entered into between the Controller and the Processor (the "Customer Agreement"), which is governed by and subject to the Processor's terms of service (the "Terms"). This DPA shall be read and interpreted in that context. This DPA governs the Processor's processing of Personal Data on behalf of the Controller in connection with the services provided under the Customer Agreement and the Terms and the level of data protection to be maintained.
1.2 This DPA is intended to ensure the rights and freedoms of data subjects where the Controller engages a Processor for the processing of Personal Data, and to satisfy the requirements of Article 28(3) of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), or where the Controller is subject to it, the UK General Data Protection Regulation (the “UK GDPR”), the Swiss Federal Act on Data Protection, and the associated Data Protection Ordinance, or Swiss cantonal data protection laws.
1.3 The following shall form part of the DPA:
(b) Technical and Organizational Measures
(c) Sub-Processors
1.4 If any provision of this DPA is inconsistent with any of the terms and conditions of the Terms, the provisions of this DPA shall prevail. Capitalized terms not defined herein (if any) have the meanings set forth in the Terms.
2. Definitions
The following definitions apply throughout this DPA, whether used in singular or plural form.
Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
Data Protection Law: All applicable privacy and personal data legislation, including: (i) Regulation (EU) 2016/679 (the “GDPR”) and applicable national implementing legislation within the EU/EEA; (ii) where applicable, the UK General Data Protection Regulation (the "UK GDPR") and UK Data Protection Act 2018, and any subsequent amendments, (iv) the Swiss Federal Act on Data Protection and the associated Data Protection Ordinance, and the Swiss cantonal data protection laws (v) any binding guidance, decision, order or requirement of a competent supervisory authority or court. Any references to the GDPR shall be interpreted as also referring to the corresponding provisions of the applicable Data Protection Law, including any equivalent or similar obligations, requirements, or defined terms under such legislation.
Data Subject: A natural person whose Personal Data is Processed (including Users, Participants, and Supporting Participants, as further defined in Description of Processing).
DPA: This Data Processing Agreement, including its Appendices (as may be included or incorporated by reference).
GDPR: The GDPR or UK GDPR (as defined above), as applicable to the Controller.
Instructions: The documented instructions issued by the Controller specifying the subject matter, duration, nature and purpose of the processing, the types of Personal Data and categories of data subjects, as set out in the DPA and the Terms.
Processor: The natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.
Sub-processor: Any data processor engaged by the Processor for the purpose of processing the Personal Data hereunder.
Personal Data: Any information relating to an identified or identifiable natural person.
Personal Data Breach: A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
Third Country: A state that is not a member of the European Union (“EU”) or the European Economic Area (“EEA”).
3. Processing of Personal Data
3.1 The Controller appoints the Processor to carry out processing on the Controller's behalf as set out in this DPA and the Terms. The Controller shall issue documented Instructions as set out in Description of Processing to the Processor, and what is set out in the Terms as regards the service provision shall by reference form part of the Instructions. The Processor shall only process Personal Data on the Controller’s behalf in accordance with those documented Instructions.
3.2 If the Processor considers that an Instruction infringes Data Protection Law, the Processor shall promptly notify the Controller. The Processor may suspend processing under the disputed Instruction until the Controller has confirmed in writing that the Instruction is lawful. The Processor shall not be liable for any delay arising from such suspension or for processing carried out in accordance with the Controller’s documented Instructions, provided that the Processor has informed the Controller if such Instructions appear to infringe applicable Data Protection Law.
3.3. The DPA (including its appendices) and the Terms together constitute the Controller’s entire Instructions to the Processor for the processing of Personal Data under the Terms.
4. Controller's obligations
4.1 The Controller takes full responsibility for ensuring that there is an appropriate lawful basis, Article 9 GDPR condition where applicable, and any other required authorization for all processing covered by this DPA, including any statutory healthcare or social care basis, permits, approvals, information notices, or consents where consent is legally required. and the Controller is responsible for providing Instructions that are lawful, clear and sufficient to enable the Processor to perform its obligations.
4.2 The Controller shall promptly notify the Processor in writing of any changes to the processing that affect the Processor's obligations under Data Protection Law. Any such changes shall be treated as amended Instructions and shall not take effect until agreed in writing by both parties.
4.3 The Controller is solely responsible for fulfilling its own obligations under Data Protection Law, including informing data subjects, handling data subject requests, and maintaining its own records of processing activities. Each party is responsible for its own compliance with applicable Data Protection Law.
5. Processor's obligations
5.1 The Processor shall process the Controller’s Personal Data only in accordance with this DPA and the Controller's Instructions, and shall comply with applicable Data Protection Law in relation to its obligations as a processor under the DPA.
5.2 The Processor shall implement reasonable and appropriate technical and organisational measures, as may be reasonably available within the Processor’s control, to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, to ensure a level of security appropriate to the risk.
5.3 The Processor shall, upon reasonable written request from the Controller and taking into account the nature of processing and information available to the Processor, provide reasonable assistance to the Controller in meeting its obligations under Articles 32–36 EU GDPR or UK GDPR, as applicable, and in responding to data subject requests under Chapter III of the same. Such assistance shall be limited to information and measures reasonably available to the Processor and shall not require the Processor to disclose source code, model weights, protected datasets, trade secrets, security-sensitive architecture, confidential information relating to other customers or other third-party confidential information, provided that the Processor shall make available sufficient alternative information to demonstrate compliance with this DPA. The Controller shall reimburse the Processor for all reasonable costs arising from assistance that goes beyond the ordinary scope of the services under this DPA.
6. Security
6.1 The Processor shall on an ongoing basis ensure that its security measures provide an appropriate level of confidentiality, integrity, availability and resilience, appropriate to the risk in accordance with Data Protection Law, and shall test and evaluate the effectiveness of those measures on a reasonable periodic basis. The Processor’s technical and organisational measures are further described here.
6.2 Access to Personal Data shall be limited to those personnel who require access to perform their duties under this DPA.
6.3 Any new or amended security requirements requested by the Controller after execution of this DPA shall be treated as amended Instructions and shall require written agreement between the parties before taking effect.
7. Confidentiality
7.1 The Processor and all personnel acting under its authority shall maintain confidentiality in respect of all Personal Data Processed under this DPA and shall not use or disclose such data for any purpose other than as set out in this DPA or the Instructions, unless the Controller has given prior written consent or disclosure is required by applicable law (including the laws of its member states), or decisions of authorities.
7.2 The Processor shall ensure that all employees, consultants and other persons acting under its authority who process Personal Data are bound by appropriate confidentiality obligations.
7.3 The Processor shall without undue delay notify the Controller in writing of any contact from a supervisory authority that relates to processing under this DPA. The Processor shall not represent or act on behalf of the Controller before any supervisory authority without prior written authorisation.
7.4 Where a data subject, supervisory authority or third party requests information from the Processor regarding processing under this DPA, the Processor shall refer the request to the Controller.
8. Audit and oversight
8.1 The Processor shall, upon reasonable prior written notice (no less than thirty (30) days, except in the case of a verified material breach or material regulatory requirement, in which case the Processor shall be given notice as reasonably possible), make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, provided that the scope of such information is proportionate and directly relevant to the Processor’s obligations under the DPA and the Terms. The Processor may satisfy this obligation by providing existing audit reports, certifications (e.g. ISO 27001) or equivalent documentation.
8.2 Where the Controller requires an on-site audit, such audit shall be conducted at the Controller's cost (including the Processor’s reasonable costs relating to such audit which shall be compensated to the Processor), during normal business hours, in a manner that minimises disruption to the Processor's operations, and by auditors who are bound by confidentiality. The Controller shall ensure that no competitor of the Processor is involved in conducting such an audit. As an alternative to on-site audits, the Processor may offer independent third-party audit reports or certifications. Audits shall be limited to information strictly necessary to verify compliance with this DPA and shall not require disclosure of source code, model weights, trade secrets, security-sensitive architecture, information, confidential information of other customers, third party confidential information or systems used by other customers, except to the limited extent strictly necessary to verify compliance with this DPA and subject to appropriate confidentiality, access and security controls. The Processor may provide such information through summaries, third-party reports, certifications, or controller review sessions.
8.3 The Processor shall permit access to supervisory authorities or other authorities with a lawful right of access, to the extent required by applicable law, even where such access would otherwise conflict with the provisions of this DPA. Where the Processor receives a legally binding request for disclosure of Personal Data from a public authority, the Processor shall, where legally permitted, notify the Controller before responding to such request.
8.4 The Controller, or any auditor mandated by the Controller, may conduct one (1) audit per calendar year. Additional audits may be conducted where required by Data Protection Law, a supervisory authority, or following a Personal Data Breach or material suspected non-compliance, provided that the scope remains proportionate and directly relevant to the Processor's obligations under this DPA.
9. Rectification and erasure
9.1 Upon written request from the Controller, the Processor shall rectify or erase Personal Data within thirty (30) calendar days of receipt of the request and the information required to fulfil it. The Controller shall reimburse the Processor for reasonable costs arising from rectification or erasure requests that go beyond the ordinary scope of the services. The Processor may retain personal data to the extent required by applicable law, in which case it shall notify the Controller accordingly and ensure that such retained data is only processed for the purpose required by applicable law.
10. Personal Data Breaches
10.1 The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours after becoming aware of a confirmed Personal Data Breach affecting Personal Data processed under this DPA. For the purposes of this clause, a breach shall be deemed confirmed when the Processor has verified that an incident affecting Personal Data has occurred.
10.2 The Processor shall take reasonable steps to investigate, contain and remediate any Personal Data Breach and shall maintain the ability to restore availability of and access to Personal Data in a reasonable timeframe following a physical or technical incident, in accordance with Article 32(1)(c) GDPR.
10.3 The Processor shall provide the Controller with the following information, to the extent available, either at the time of initial notification or thereafter without undue further delay:
the nature of the breach, including, where possible, the categories and approximate number of data subjects and Personal Data records affected;
the likely consequences of the breach; and
the measures taken or proposed to address the breach and mitigate its effects.
10.4 Where full information is not available at the time of initial notification, the Processor may provide information in phases as it becomes available.
11. Sub-processors
11.1 The Controller provides general written authorisation for the Processor to engage sub-processors. A current list of sub-processors is maintained and available here.
11.2 The Processor shall notify the Controller in writing of any intended addition or replacement of a sub-processor at least fourteen (14) days prior to the change taking effect, identifying the sub-processor and the nature of the processing. If no objection is raised within that period of fourteen (14) days, the change shall be deemed accepted. Where the Controller raises a reasonable objection, the parties shall discuss the matter in good faith.
11.3 The Processor shall impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and the Processor is liable to the Controller for sub-processor obligations.
12. International transfers
12.1 The Processor shall by default ensure that Personal Data is Processed within the EU/EEA. The Controller provides general authorisation for transfers to Third Countries provided that appropriate safeguards under Chapter V GDPR are implemented. Such appropriate safeguards may include the Processor entering into a contract with a sub-processor based upon the EU Commission’s standard contractual clauses for the transfer of Personal Data to a country outside the EU/EEA and appropriate supplementary measures. A transfer of personal data to a country outside of the EU/EEA may also be based upon a valid adequacy decision by the EU Commission.
13. Liability
13.1 To the extent permitted by applicable law, each party's total aggregate liability to the other party arising out of or in connection with this DPA (whether in contract, tort or otherwise) shall be subject to, and included within, the limitations and exclusions of liability set out in the Terms.
13.2 If either party becomes aware of circumstances that may give rise to loss or liability for the other party, it shall promptly inform that party and cooperate in good faith to prevent or minimise such loss.
13.3 Clauses 13.1 and 13.2 of this DPA shall prevail over any conflicting provisions in the Terms regarding the allocation of liability in connection with the processing.
14. Amendments
14.1 Any addition to or amendment of this DPA must be agreed in writing by both parties to be valid.
14.2 Notwithstanding clause 14.1, the Processor may amend this DPA or part thereof following thirty (30) days' prior written notice to the Controller where such amendment is required (i) for the parties to remain in compliance with Data Protection Law, or (ii) to reflect operational or security-related changes to the services or to the Processor 's technical and organisational measures, provided that any such amendment does not materially reduce the level of protection afforded to Personal Data under this DPA.
15. Term and termination
15.1 This DPA remains in force for as long as the Processor processes Personal Data on behalf of the Controller under the Terms. Upon termination of the DPA, for whatever reason, the Processor shall at the Controller's written request return all Personal Data in a mutually agreed format or delete the Personal Data at the Controller’s choice. Unless otherwise specified in the Instructions, the Processor shall securely delete all Personal Data Processed under this DPA within thirty (30) calendar days following termination, provided that it has first, if required, returned any Personal Data required by the Controller. The Processor may retain Personal Data to the extent required by applicable law, in which case it shall notify the Controller accordingly (unless prohibited to do so by applicable law).
15.2 This DPA shall terminate automatically upon termination or expiry of the Terms, provided that its provisions shall continue to apply to any Personal Data that the Processor continues to process after such termination or expiry, until such Personal Data has been returned or deleted in accordance with clause 15.1 (or, where retained under applicable law, for as long as it is so retained).
16. Governing law and dispute resolution
16.1 This DPA shall be governed by Swedish law, excluding its conflict of law rules.
16.2 Any dispute concerning the interpretation or application of the DPA shall be settled in accordance with the provisions on dispute resolution in the Terms.
16.3 This DPA may be made available in languages other than English. To the extent of any inconsistency or conflict between the English version of this DPA and any version in another language, the most current English version shall prevail. Any proceedings relating to a dispute under this DPA shall be conducted in the language specified in the Terms.