DPA

This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer and Oddcoll AB (“Main Agreement”) and governs Oddcoll’s processing of personal data on behalf of the Customer.

1. Parties

1.1 The “Customer” is the legal entity that has entered into the Main Agreement and uses Oddcoll’s services.

1.2 Oddcoll AB, company registration number 559047-7336, with registered address Stampgatan 15, 41664 Göteborg, Sweden (“Oddcoll”), acts as data processor for the processing activities covered by this DPA.

2. Roles and scope

2.1 The Customer is the data controller for the personal data it uploads to Oddcoll’s platform or otherwise makes available to Oddcoll in connection with the Services.

2.2 Oddcoll acts as the Customer’s data processor for the processing operations described in this DPA, within the meaning of Article 28 GDPR.

2.3 This DPA applies only to the processing of personal data where Oddcoll acts as processor on behalf of the Customer. For Oddcoll’s processing as an independent data controller (for example for its own billing, accounting and marketing), Oddcoll’s Privacy Policy applies.

3. Subject matter, nature and purpose of the processing

3.1 Subject matter: Personal data relating to debtors, contacts and customer representatives which the Customer uploads to, or otherwise processes through, Oddcoll’s platform in connection with cross-border B2B debt collection.

3.2 Nature and purpose: Oddcoll will process personal data to host and operate the platform, transmit case data to local debt collection agencies selected through the platform, administer user accounts, provide support and maintain logs, strictly for the purpose of enabling the Customer to manage its debt collection cases.

3.3 Duration: The processing will continue for as long as the Customer uses the Services and for the retention periods set out in clause 10 below.

4. Categories of data subjects and personal data

4.1 Data subjects may include:

(a) Representatives and contact persons of the Customer;

(b) Representatives and contact persons of debtor companies;

(c) Other individuals involved in or mentioned in a debt collection case.

4.2 Categories of personal data may include:

(a) Identification and contact details (name, position, email, phone number, address);

(b) Case data (invoice references, amounts, due dates, communications, notes);

(c) Technical data (IP addresses, log data and other online identifiers linked to the use of the platform).

5. Instructions

5.1 Oddcoll shall process personal data only on documented instructions from the Customer, unless required to do so by Union or Member State law to which Oddcoll is subject. In such a case, Oddcoll shall inform the Customer of that legal requirement before processing, unless the law prohibits such information.

5.2 The Main Agreement, this DPA and the Customer’s normal use of the platform together constitute the Customer’s documented instructions. The Customer may provide additional reasonable written instructions from time to time, provided they are compatible with the Main Agreement and this DPA.

5.3 Oddcoll shall inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

6. Confidentiality

6.1 Oddcoll shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7. Security

7.1 Oddcoll shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR, including, where appropriate, measures relating to:

(a) pseudonymisation and encryption of personal data;

(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;

(d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

8. Sub-processors

8.1 The Customer hereby gives general authorisation for Oddcoll to engage sub-processors for the processing activities covered by this DPA.

8.2 Sub-processors may include:

(a) Local debt collection agencies engaged through the platform to perform debt collection services for the Customer (“Debt Collectors”);

(b) IT and service providers such as hosting providers, email providers, CRM systems, analytics and monitoring tools.

8.3 Oddcoll shall enter into a written agreement with each sub-processor imposing data protection obligations that are no less protective than those set out in this DPA, as required by Article 28(4) GDPR.

8.4 Oddcoll shall remain fully liable to the Customer for the performance of its sub-processors’ obligations.

8.5 Oddcoll shall keep an up-to-date list of its sub-processors, which will be made available to the Customer upon request. Oddcoll shall notify the Customer of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Customer the opportunity to object on reasonable grounds. If the Customer reasonably objects and the parties cannot agree on a solution, the Customer may terminate the affected part of the Services.

9. Assistance to the Customer

9.1 Taking into account the nature of the processing, Oddcoll shall assist the Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Customer’s obligations to respond to requests for exercising data subject rights under Chapter III GDPR.

9.2 Oddcoll shall also assist the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to Oddcoll.

10. Retention and deletion

10.1 The Customer is responsible for determining the appropriate retention period for the personal data it uploads to the Service.

10.2 Unless otherwise instructed in writing by the Customer, Oddcoll will retain case-related personal data for up to ten (10) years after a case has been closed, to reflect applicable limitation periods and potential legal claims in cross-border B2B debt collection.

10.3 Upon termination of the Services, or upon the Customer’s written request, Oddcoll shall delete or return all personal data processed on behalf of the Customer and delete existing copies, unless applicable law requires storage of the personal data.

10.4 Where deletion is not possible (for example, in backup systems), Oddcoll shall ensure that the personal data is put beyond use and no longer actively processed.

11. Personal data breaches

11.1 Oddcoll shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer.

11.2 Such notification shall at least:

(a) describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

(b) communicate the name and contact details of a contact point where more information can be obtained;

(c) describe the likely consequences of the personal data breach;

(d) describe the measures taken or proposed to be taken by Oddcoll to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

12. International transfers

12.1 Where Oddcoll or a sub-processor processes personal data outside the EU/EEA in a country that does not benefit from an adequacy decision, Oddcoll shall ensure that such transfer is subject to appropriate safeguards under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses and, where necessary, additional technical and organisational measures.

13. Audits

13.1 The Customer or an auditor mandated by the Customer may, at the Customer’s cost, carry out audits, including inspections, of Oddcoll’s processing activities covered by this DPA, not more than once per year and with at least thirty (30) days’ prior written notice, unless there are reasonable grounds to suspect serious non-compliance.

13.2 Oddcoll may satisfy audit requests by providing up-to-date third-party audit reports, certifications or other appropriate documentation that adequately demonstrates Oddcoll’s compliance with this DPA.

14. Liability

14.1 The liability of each party under this DPA shall be governed by the liability provisions of the Main Agreement. Nothing in this DPA shall limit a data subject’s rights under GDPR.

15. Governing law and jurisdiction

15.1 This DPA shall be governed by and construed in accordance with the laws of Sweden.

15.2 Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the Swedish courts, with the Gothenburg District Court as the court of first instance.

By creating an account and using the Service, the Customer, as Data Controller, agrees to and enters into this Data Processing Agreement with Oddcoll AB, acting as Data Processor.

Get free consultation