---
title: Pickit® | Data Processing Agreement
description: Learn about our Data Processing Agreement between Pickit and the Customer. This is for non-US users.
image: https://www.pickit.com/hubfs/000_Pickit%C2%AE%20website%202022/Global%20Assets/logo-feature.png
---

[pickit-logo_fullcolor ](https://pickit.com)

# Data Processing Agreement

Between the Customer and Pickit

Last updated 21 April 2023

 

**Data Processing Agreement**

This** Data Processing Agreement **(the “**DPA**”) is entered into between:

**(1) Customer** (“**Controller**”); and 

**(2) PicHit.me AB**, reg. no. 556914-4156, a company organized under the laws of Sweden (“**Processor**” or “**Pickit**”).  

Each of Controller and Processor are referred to as a “**Party**” and jointly as the “**Parties**”.

**1. Background**

- 1.1 The Parties have entered into an enterprise agreement (the “**Agreement**”), where Controller has contracted Processor in order to use the Pickit Business service, in its business operations which forms the subject matter of the processing of personal data under this Agreement.
- 1.2 Terms such as “personal data”, “processing” and “data subject” and other expressions not defined in this DPA shall have the same meaning as set out in in the Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "**GDPR**"), as may be amended, updated, replaced or superseded from time to time, if not expressly stated otherwise.
- 1.3 Pickit’s service, is a SaaS solution providing content (images) in MS Office 365 through an Add-in (the (the “**Pickit Business Service**”), rendering Controller the data controller, whilst Pickit qualifies as data processor under the applicable data protection laws. In light of the above, Processor and Controller have agreed on the following terms and conditions set out in this DPA (including the Schedules) concerning the Processing of personal data under this DPA.
- 1.4 This DPA shall supersede any prior agreements, arrangements and understandings between the parties and constitutes the entire agreement between the parties relating to the subject matter hereof. In case of conflict between the Agreement and the DPA including the Schedules, this DPA shall take precedence.

**2. Processor’s obligations**

- 2.1 Processor shall to the extent any personal data is processed by Processor on behalf of Controller under the Agreement:

**3. Limitation of liability and Indemnification**

- 3.1 The Processor’s aggregate liability for breach of personal data obligations set forth in the Agreement, DPA or applicable data protection law shall be governed by the limitation of liability in the Agreement. This includes, for example, claims from data subjects and administrative penalties or fines imposed on the Processor by relevant courts or data protections authorities. 
- 3.2 Notwithstanding what is stated in the Agreement, DPA or applicable data protections law the Controller shall hold harmless the Processor from all liability, if such liability arises as a result of the Controller’s breach of the Agreement, DPA or applicable data protection law or if the Controller’s instructions is in breach of the Agreement, DPA or applicable data protection law. 

**4. Governing Law and Disputes**

- 4.1 This DPA shall be governed in accordance with the laws of Sweden, with the exclusion of its conflict of laws rules.
- 4.2 Any dispute, controversy or claim arising out of or in connection with this Agreement, or the breach, termination or invalidity thereof, shall be finally settled by arbitration administered by the Arbitration Institute of the Stockholm Chamber of Commerce (the SCC Institute). The place of arbitration shall be Stockholm, Sweden. The language to be used in the arbitral proceedings shall be English, unless otherwise agreed.
- 4.3 The Rules for Expedited Arbitrations of the Arbitration Institute of the Stockholm Chamber of Commerce shall apply, unless the SCC Institute, taking into account the complexity of the case, the amount in dispute and other circumstances, determines, in its discretion, that the Rules of the Arbitration Institute of the Stockholm Chamber of Commerce shall apply. In the latter case, the SCC Institute shall also decide whether the arbitral tribunal shall be composed of one or three arbitrators. 
- 4.4 The Parties undertake and agree that all arbitral proceedings conducted with reference to this arbitration clause will be kept strictly confidential. This confidentiality undertaking shall cover all information disclosed in the course of such arbitral proceedings, as well as any decision or award that is made or declared during the proceedings. Information covered by this confidentiality undertaking may not, in any form, be disclosed to a third party without the written consent of the other Party. This notwithstanding, a Party shall not be prevented from disclosing such information in order to safeguard in the best possible way his rights vis-à-vis the other Party in connection with the dispute, or if the Party is obliged to so disclose pursuant to statute, regulation, a decision by an authority or similar.

 

 

**Schedule 1 – Controller’s instructions **

The following are instructions from the Controller to the Processor for the processing of personal data which covers this DPA. 

 

| PROCESSING ACTIVITIES | Collecting, registering and storing |
| --- | --- |
| CATEGORIES OF PERSONAL DATA | • username • password • email address • company postal & invoicing address • invoicing e-mail • postal code • country   |
| CATEGORIES OF DATA SUBJECTS   | Image Bank Owner Image Bank Admin Image Bank Users |
| RETENTION PERIODS | Within the Pickit Business service, personal data is being registered and stored for each user in order to secure eligibility rules per user managed by the customers Office 365 admin.   |
| DATA PROTECTION OFFICER | The data privacy officer can be reached at [privacy@pickit.com](mailto:privacy@pickit.com)   |

 

**Schedule 2 – sub-processors**

 

| **Sub-processors** | **Third country** | **Security measures** |
| --- | --- | --- |
| Application Insights | Ireland | GDPR |
| Fortnox | Sweden | GDPR |
| Sendgrid (System email sendouts) | USA | SCC |
| Hubspot (Customer support & information) | USA | SCC |

 

 

**Schedule 3 technical and organisational measures**

 

**Physical security**

The premises used by Processor shall be protected with adequate physical security measures, such as alarms for fires, water damage, burglary, etc. In addition, there should be procedures and equipment for example in the form of alarms, barriers, locks, etc. which control access to the premises. Processor shall introduce necessary safety routines, such as (i) lock devices on computers and other equipment; (ii) entry control system; (iii) protection gear for power breaks as well as smoke and water damages; (iv) fire extinguishers; (v) safety locks; and (vi) marking of equipment etc.

 

**Organisational security measures**

Processor should possess an updated and implemented security policy which states for example the manner in which the personal data shall be processed, to whom Processor’s personnel shall turn in the event of a burglary or other incident, which personnel are authorized as regards which type of information, back-up procedures, contingency plans, etc.

 

**Technical security measures**

Processor should create a safe IT-environment, which includes, but is not limited to (i) necessary safety routines for avoiding virus attacks or other threats that could be harmful to the IT-environment; (ii) an encryption system and/or other security measures with the purpose of avoiding tapping or revealing signals; (iii) necessary security routines for IT-equipment; (iv) a control system based on user authorization, which enables identification of user identity (through the usage of passwords or such) and prevents unauthorized use of or access to the processed personal data; (v) storage of processing history (log data), which shall be sorted out in accordance with Controller’s instructions; (vi) automatic back-up routines, including storage of back-up copies, which shall be sorted out in accordance with Controller’s instructions; as well as (vii) destruction or other means of eradication of all media that has contained personal data that no longer is used.

 