Data Processing Agreement
Version 1.1, last updated 27 August 2026
1. Scope and acceptance
1.1 This Data Processing Agreement ("DPA") forms part of the Skeptiva Terms of Service (the "Agreement") between Skeptiva and the customer ("Customer"). It applies where Skeptiva processes Personal Data on the Customer's behalf in providing the Skeptiva email security software and Admin Portal (the "Services").
1.2 No signature is required. This DPA is accepted, and becomes binding on both parties, when the Customer accepts the Agreement or begins using the Services. It terminates automatically when the Agreement terminates.
1.3 Any deletion or revision made by the Customer to the text of this DPA is rejected and of no effect. Variations are agreed only in an Order Form that expressly identifies the provision varied.
1.4 In the event of conflict, this DPA prevails over the Agreement in respect of the processing of Personal Data.
2. Definitions
2.1 Terms used but not defined here have the meaning given first in the GDPR (Regulation (EU) 2016/679) and second in the Agreement.
2.2 The description of the data transmitted from the Customer's environment to Skeptiva, published at skeptiva.com/data (the "Data Schedule"), is incorporated into this DPA. "Customer Personal Data" means the categories identified in the Data Schedule as processed by Skeptiva as processor on the Customer's behalf. The categories identified there as processed by Skeptiva as an independent controller are not Customer Personal Data and are governed by Section 13.
3. Roles of the parties
3.1 In respect of Customer Personal Data, the Customer is Controller and Skeptiva is Processor.
3.2 The Customer is responsible for the lawfulness of the Personal Data it and its users transmit, for having a lawful basis for the processing it instructs, and for informing its users in accordance with Articles 13 and 14 GDPR.
3.3 The Software analyses email locally on the Customer's devices. Email content that is analysed locally and not transmitted to Skeptiva in accordance with the Data Schedule is not processed by Skeptiva and remains solely under the Customer's control.
4. Processing of Customer Personal Data
4.1 Skeptiva shall process Customer Personal Data only on the Customer's documented instructions, including as to transfers, and shall comply with applicable Data Protection Law in doing so.
4.2 The Agreement, this DPA and the Data Schedule, the Customer's settings in the Admin Portal, and a user's use of the Report function together constitute the Customer's complete documented instructions. The Customer instructs Skeptiva to process Customer Personal Data in order to:
- (a) provide, maintain and support the Services;
- (b) detect, investigate and respond to security threats affecting the Customer;
- (c) comply with legal obligations and establish or defend legal claims.
4.3 Skeptiva shall inform the Customer without undue delay if an instruction appears to infringe Data Protection Law, and may suspend performance of it pending resolution. Where law requires Skeptiva to process otherwise than on instruction, it shall inform the Customer beforehand unless that law prohibits it.
5. Confidentiality and personnel
5.1 Skeptiva shall ensure that persons authorised to process Customer Personal Data are bound by an obligation of confidentiality that survives the end of their engagement, and that access is limited to those who require it to perform their duties.
6. Security
6.1 Skeptiva shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures in force are published at skeptiva.com/security and are incorporated into this DPA.
6.2 Skeptiva may update those measures provided the overall level of security is not reduced. Skeptiva shall give thirty days' notice of any material reduction, and the Customer may terminate the affected subscription if it reasonably objects.
7. Subprocessors
7.1 The Customer gives Skeptiva general authorisation to engage subprocessors. The current list is published at skeptiva.com/subprocessors.
7.2 Skeptiva shall impose on each subprocessor, by written contract, data protection obligations no less protective than those in this DPA, and remains liable to the Customer for each subprocessor's performance.
7.3 Skeptiva shall give at least thirty days' notice before adding or replacing a subprocessor. The Customer may object within that period on reasonable, documented data protection grounds. If the parties cannot resolve the objection within thirty days, the Customer may terminate the affected subscription and receive a pro rata refund of prepaid fees for the unexpired term. This is the Customer's sole remedy.
8. Data location and international transfers
8.1 Personal Data received from the Customer's environment, whether processed by Skeptiva as processor or under Section 13 as an independent controller, is stored exclusively within the European Union or European Economic Area, and is not accessed from outside it.
8.2 Should this change, Skeptiva shall give at least thirty days' prior notice, update the subprocessor list, and put in place the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with a documented transfer assessment. The Customer may object under Section 7.3.
8.3 Customer billing and payment data is processed by Stripe as an independent controller and may be processed outside the EU/EEA. This is the only exception to Section 8.1.
9. Data subject rights
9.1 The Admin Portal enables the Customer to search, export and delete reported messages and Admin Portal data relating to an identified data subject without Skeptiva's involvement. Where the Customer can satisfy a request through the Admin Portal, it shall do so.
9.2 Skeptiva shall otherwise provide reasonable assistance, taking into account the nature of the processing, in enabling the Customer to respond to data subject requests and to comply with Articles 32 to 36 GDPR. Where Skeptiva receives a request directly, it shall refer the data subject to the Customer and notify the Customer within five business days.
10. Personal data breach
10.1 Skeptiva shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide the information described in Article 33(3) GDPR to the extent known. Where complete information is not available, Skeptiva shall provide what is known and supply the remainder in phases.
10.2 Skeptiva shall take reasonable steps to mitigate the breach and shall cooperate with the Customer in its investigation. Notification is not an acknowledgement of fault.
11. Audit
11.1 Skeptiva shall make available to the Customer, on request and no more than once in any twelve-month period, the information necessary to demonstrate compliance with Article 28 GDPR, including its published security measures and a completed standard security questionnaire.
11.2 Where that information is not sufficient, the Customer may audit Skeptiva on thirty days' notice, no more than once in any twelve-month period, during business hours, at the Customer's cost, and through an auditor who is not a competitor of Skeptiva and who accepts confidentiality obligations. An audit shall not extend to other customers' data, source code or model weights. The frequency limit does not apply following a Personal Data Breach affecting the Customer.
12. Retention, deletion and return
12.1 Skeptiva retains Customer Personal Data for the retention periods stated in the Data Schedule, save where a different period is required by law. Skeptiva shall give at least thirty days' notice before extending a retention period, and the Customer may object under Section 7.3.
12.2 On termination of the Agreement, Skeptiva shall delete or, at the Customer's election, return Customer Personal Data within ninety days, and shall confirm deletion in writing on request.
12.3 Skeptiva may retain Personal Data where required by Union or Member State law, including the Swedish Bookkeeping Act. Data present in backup media is deleted on the ordinary backup rotation cycle and is not restored to production save for disaster recovery.
13. Skeptiva's own processing
13.1 Skeptiva also processes certain data as an independent controller for its own purposes, namely securing and licensing the Services, diagnosing faults, and maintaining and improving its threat detection. The categories concerned are identified as such in the Data Schedule, and the purposes and legal basis are described in the Skeptiva Privacy Policy at skeptiva.com/privacy-policy. The parties are not joint controllers in respect of it.
13.2 Skeptiva shall not use data processed under Section 13.1 to profile, evaluate or report on any individual user, and shall not disclose it to any third party in a form from which an individual or the Customer can be identified.
13.3 Sections 9 and 11 do not apply to data processed under Section 13.1, and Section 12 applies to it only to the extent of the retention and deletion periods stated in the Data Schedule.
14. De-identified and aggregated data
14.1 Skeptiva may create de-identified and aggregated data derived from data it receives, provided it is rendered permanently non-attributable to the Customer, any individual or any identifiable person. Skeptiva may process such data for its own purposes without restriction and without time limit, consistent with applicable law. Section 12 does not apply to it.
15. Liability
15.1 The limitations and exclusions of liability in the Agreement apply to this DPA, and liability under the Agreement and this DPA is subject to a single aggregate cap as provided in the Agreement.
16. General
16.1 Skeptiva may amend this DPA on thirty days' notice. Amendments required by law or by a decision of a supervisory authority take effect on notice. Amendments do not apply retrospectively.
16.2 This DPA is governed by Swedish law and subject to the venue stated in the Agreement.
16.3 Sections 5, 10, 12, 14 and 15 survive termination.
16.4 Data protection enquiries: info@skeptiva.com.
17. Annex: US state privacy laws
17.1 This Annex applies only where the Customer is subject to the California Consumer Privacy Act as amended, or a comparable US state privacy law, and only to personal information governed by that law.
17.2 Where Skeptiva acts as Processor under this DPA it acts as a "service provider" or "processor", and the Customer as a "business" or "controller". In that capacity Skeptiva shall not sell or share personal information, shall not retain, use or disclose it for any purpose other than performing the Services or as permitted by law, and shall not retain, use or disclose it outside the direct business relationship between the parties. Skeptiva certifies that it understands and will comply with these restrictions.
17.3 Processing described in Section 13 is carried out by Skeptiva as an independent controller and is outside that relationship. Skeptiva does not sell or share that data.
Data Processing Agreement Data We Process Security Measures Subprocessors Privacy Policy