Skip to content

Legal

Data Processing Agreement

How INTYGA processes personal data on your behalf.

1. Parties and scope

This Data Processing Agreement (DPA), version 2026-09-24.2, forms part of the INTYGA Terms of Service between the customer accepting those Terms (Customer) and Janbjer Technologies AB, org. no. 559602-1757, Sweden (INTYGA). It applies whenever INTYGA processes personal data on the Customer’s behalf. The Customer is the controller, or an authorised processor acting for its controller; INTYGA is respectively the processor or subprocessor. GDPR terms have their GDPR meanings.

This DPA prevails over conflicting Terms on the protection of that data. A separately agreed DPA may replace it for the processing it covers. INTYGA’s processing for its own business administration, billing and website purposes is described in the privacy notice.

2. Processing and duration

INTYGA collects, stores, retrieves, transmits and deletes data to authenticate users, present approval requests, verify and record signed approvals, send notifications, and provide the console, APIs, exports and related support. Processing lasts for the provision of these services and the agreed return/deletion period. During service, approval records follow the retention period of the Customer’s plan or other documented agreement.

Data subjects are the Customer’s administrators, users and approvers, its platform end users, and people identified in submitted request or support content. Data comprises names, contact details, memberships, customer-assigned identifiers, public keys and credential identifiers, request content, approval records, signatures, pseudonymous identifiers, IP addresses and technical or delivery metadata. INTYGA receives no signing private keys or biometric data. Special-category and criminal-offence data are excluded unless separately agreed with appropriate safeguards.

3. Instructions and Customer responsibilities

INTYGA processes data only on documented Customer instructions, including this DPA, the Terms, service configuration and further written instructions. This also applies to international transfers. If Union or Member State law requires other processing, INTYGA informs the Customer beforehand unless that law prohibits notification on important public-interest grounds. INTYGA immediately informs the Customer if it considers an instruction contrary to GDPR or other Union or Member State data protection law.

The Customer determines the purposes of processing, provides lawful instructions and required notices, ensures a lawful basis and limits submitted data to what is necessary. If acting as a processor, it ensures authority from its controller to instruct INTYGA and authorise subprocessors. The Customer may exercise the instruction, information, audit, objection and return/deletion rights set out here.

4. Confidentiality and security

INTYGA ensures that authorised personnel are bound by confidentiality commitments or an appropriate statutory duty. It implements the technical and organisational measures required by GDPR Article 32, appropriate to the processing and risks: restricted access, passkey-based human authentication, customer isolation, encryption in transit and protection of stored data, tamper-evident records, incident handling, retention controls, and backup and recovery procedures. INTYGA regularly tests and evaluates the effectiveness of its security measures.

5. Subprocessors and transfers

The Customer gives general written authorisation for the providers on INTYGA’s subprocessor list. INTYGA informs the Customer’s designated contact, or its account administrator, of intended additions or replacements in advance, allowing a meaningful opportunity to object before the change. INTYGA resolves an objection before using the disputed provider for that Customer’s data; if it cannot, the affected processing must stop.

INTYGA binds each subprocessor by written agreement to the same data protection obligations and remains fully liable to the Customer for their performance. Transfers outside the EEA take place only on documented instructions and in compliance with GDPR Chapter V, using an applicable adequacy decision or appropriate safeguards, including standard contractual clauses and supplementary measures where required.

6. Assistance and incidents

Taking account of the nature of processing, INTYGA assists the Customer through appropriate technical and organisational measures, insofar as possible, in fulfilling requests to exercise data subject rights. It forwards requests received directly and acts on the Customer’s instructions unless law requires otherwise. Taking account of the nature of processing and information available, INTYGA also assists with obligations under Articles 32–36, including security, breach notifications, impact assessments and prior consultation.

INTYGA notifies the Customer without undue delay after becoming aware of a personal data breach affecting its data, provides the available information needed for the Customer’s response and statutory notifications, and supplements it as further information becomes available.

7. Return and deletion

At the Customer’s choice, INTYGA returns or deletes all personal data after the processing services end and deletes existing copies, including backups, unless Union or Member State law requires storage. The export period in the Terms applies unless the Customer requests earlier deletion; deletion then follows without undue delay. Requested data outside the service’s evidence export is returned securely. Any legally required storage is limited to the required data, purpose and duration. Remaining personal identifiers are subject to these obligations, even in audit records. Restoring a backup must not reintroduce data already instructed to be deleted.

8. Information and audits

INTYGA provides all information necessary to demonstrate compliance with Article 28 and allows and contributes to audits, including inspections, by the Customer or its appointed auditor. Practical arrangements protect confidentiality and other customers’ data without preventing these rights. This DPA continues until processing of the Customer’s personal data ends. Mandatory law and applicable standard contractual clauses retain their required precedence.

Contact: privacy@intyga.com. Terms of Service · Privacy notice