Version 2026.09 · Effective 25 September 2026

Data Processing Agreement

Processor
Sidcom AB, a Swedish limited liability company. Reg. no. 559504-0840 · VAT SE559504084001 · Sweden
Contact
hello@sidcom.ai
Terms of Service
sidcom.ai/terms
Privacy Policy
sidcom.ai/privacy — a single policy covering the connectors, the account portal, Sidcom’s products and the sidcom.ai website, for data where Sidcom is an independent controller (Clause 2.3)
Sub-processors
sidcom.ai/subprocessors (Clause 6.1)
Version
2026.09

1.1 In this DPA, unless the context otherwise requires:

(a) “Business Data” means the Customer Personal Data that passes through the Services in transit between the Customer’s AI assistant and the connected business system, as further described in Annex 3.

(b) “Customer Personal Data” means the personal data that Sidcom processes on the Customer’s behalf in connection with the Services, as described in Annex 1 and, for the specific Service, in the service annex.

(c) “Data Protection Law” means the GDPR, the Swedish Data Protection Act (lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning) and any other applicable data protection or privacy legislation, in each case as amended or replaced from time to time.

(d) “GDPR” means Regulation (EU) 2016/679.

(e) “Services” means the Sidcom services that the Customer uses under the Terms of Service, as further described in the service annex.

(f) “Sub-processor” means another processor engaged by Sidcom to process Customer Personal Data on the Customer’s behalf in connection with the Services.

(g) “Terms of Service” means the Sidcom Terms of Service available at sidcom.ai/terms, as amended from time to time.

(h) the terms “controller”, “processor”, “data subject”, “personal data”, “personal data breach”, “processing” and “supervisory authority” have the meanings given to them in the GDPR.

1.2 Sidcom and the Customer are each a “Party” and together the “Parties”. Capitalised terms used but not defined in this DPA have the meanings given in the Terms of Service. References to Clauses are to Clauses of this DPA unless otherwise stated. Headings are for convenience only.

1.3 Structure. This DPA implements Article 28(3) of the GDPR in respect of personal data that Sidcom processes on the Customer’s behalf when providing the Services. It supplements the Terms of Service and does not replace them. It consists of Clauses 1–19 and Annexes 1–2, which are Sidcom’s standard terms and apply to every Service, together with a service annex for each Service the Customer uses. The service annex for the AI Connectors for Fortnox is Annex 3.

2.1 Sidcom as processor. For Customer Personal Data, the Customer is the controller and Sidcom is the processor. This DPA applies to that processing. The processing is described in Annex 1 and, for the specific Service, in the service annex.

2.2 Customer responsibilities. The Customer is responsible for ensuring that there is a lawful basis for the processing and that the Customer’s instructions to Sidcom comply with Data Protection Law.

2.3 Sidcom as independent controller. For the categories of data identified in the service annex as processed for Sidcom’s own purposes — typically account details and technical operational data relating to the Customer’s own use of the Services — Sidcom is an independent controller, because that processing takes place within Sidcom’s own customer relationship. Such processing falls outside the scope of this DPA and is described in the Sidcom Privacy Policy at sidcom.ai/privacy.

2.4 Third-party platforms. The business systems that the Services connect to and the provider of the Customer’s AI assistant are not Sidcom’s Sub-processors. They act as independent controllers or processors in their own right, under the agreements the Customer has entered into directly with them. The Customer is responsible for ensuring that those agreements permit the data flows the Services entail. Sidcom is not responsible for the processing of personal data by such third-party platforms in their respective capacities.

3.1 Sidcom shall process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which Sidcom is subject. In such a case, Sidcom shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.2 The Customer’s documented instructions consist of the Terms of Service, this DPA including its Annexes, and the individual operations that the Customer (or a system acting on the Customer’s behalf, such as the Customer’s AI assistant) initiates through the Services. Each such operation constitutes an instruction to perform it.

3.3 Sidcom shall immediately inform the Customer if, in Sidcom’s opinion, an instruction infringes Data Protection Law.

3.4 Sidcom does not process Customer Personal Data for its own purposes and does not use Customer Personal Data for model training, profiling or analytics. This applies without exception.

4.1 Sidcom shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is granted only to those who need it in order to provide the Services.

5.1 Sidcom shall implement the technical and organisational measures required pursuant to Article 32 GDPR to ensure a level of security appropriate to the risk. Those measures consist of the standard measures set out in Annex 2 and the service-specific measures set out in the service annex.

5.2 Sidcom may update those measures from time to time, provided that no update materially reduces the overall level of security.

6.1 General authorisation. The Customer provides general written authorisation for Sidcom to engage Sub-processors. The current list of authorised Sub-processors, including the processing activity performed by each and its processing locations, is published at sidcom.ai/subprocessors and forms part of this DPA.

6.2 Notice of changes. Sidcom shall notify the Customer by email at least fourteen (14) days before an intended addition or replacement of a Sub-processor takes effect, and shall update the list at sidcom.ai/subprocessors when the change takes effect. Notices are sent in accordance with Clause 17.1.

6.3 Right to object. The Customer may object to an intended addition or replacement on reasonable grounds relating to data protection by notifying Sidcom in writing before the change takes effect. The Parties shall discuss the objection in good faith. If the Parties cannot agree on a solution within a reasonable time, the Customer may terminate the affected Service and this DPA with immediate effect. Termination is effected under the Terms of Service or, where the Service was obtained through a marketplace, under that marketplace’s terms. Sidcom shall refund fees paid to Sidcom for the unused remainder of the current period; fees paid to a marketplace are refunded under that marketplace’s terms.

6.4 Flow-down and liability. Sidcom shall impose on each Sub-processor, by way of a written contract, data protection obligations equivalent to those set out in this DPA. Where a Sub-processor fails to fulfil its data protection obligations, Sidcom remains fully liable to the Customer for the performance of that Sub-processor’s obligations.

6.5 Other providers. Providers that Sidcom engages only in processing for which Sidcom is an independent controller under Clause 2.3 are not Sub-processors under this DPA, and the right to object under Clause 6.3 does not apply to them. They are described in the Privacy Policy at sidcom.ai/privacy. Sidcom has a written data processing agreement in place with each.

7.1 To the extent that Customer Personal Data is transferred to a country outside the EU/EEA, Sidcom shall ensure that the transfer is covered by a valid transfer mechanism under Chapter V of the GDPR, such as an adequacy decision of the European Commission (including the EU–U.S. Data Privacy Framework in respect of certified recipients) or the European Commission’s Standard Contractual Clauses, together with any supplementary measures required.

7.2 The processing locations and the Chapter V transfer mechanism relied on for each Sub-processor are stated at sidcom.ai/subprocessors. Sidcom does not represent that the Services store data exclusively within the EU/EEA.

7.3 Where a transfer mechanism relied on ceases to be valid, Sidcom shall without undue delay implement an alternative valid mechanism under Chapter V of the GDPR or cease the transfer concerned.

8.1 Taking into account the nature of the processing, Sidcom shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests for exercising the data subject rights laid down in Chapter III of the GDPR (Articles 15–22).

8.2 If Sidcom receives a request directly from a data subject relating to Customer Personal Data, Sidcom shall forward it to the Customer without undue delay and shall not respond to it on the merits.

8.3 Where the service annex states that Sidcom does not store a category of Customer Personal Data, Sidcom’s ability to assist in respect of that category is correspondingly limited in practice: erasure, rectification and disclosure take place in the source systems identified in the service annex.

9.1 Taking into account the nature of the processing and the information available to Sidcom, Sidcom shall assist the Customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR, including security of processing, notification of personal data breaches, data protection impact assessments and prior consultation.

10.1 Sidcom shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and shall provide the information that the Customer reasonably needs in order to meet any obligation to notify the competent supervisory authority within 72 hours under Article 33 GDPR and to inform data subjects under Article 34 GDPR.

10.2 The notification shall, to the extent the information is available to Sidcom, describe the nature of the breach, the categories and approximate number of data subjects and personal data records concerned, the likely consequences, and the measures taken or proposed to address the breach. Information may be provided in phases as it becomes available. A notification is not an acknowledgement of fault or liability.

11.1 Upon termination or expiry of the Terms of Service, or earlier upon the Customer’s written request, Sidcom shall, at the choice of the Customer, delete or return the categories of Customer Personal Data identified as stored in the service annex, within the periods stated there, unless Union or Member State law requires storage of the personal data. In such a case, Sidcom shall protect the retained data in accordance with this DPA and process it only for the purpose required by that law. Return is available only for categories capable of being returned in a usable form. Access tokens and connection credentials cannot be returned and are therefore deleted; the Customer may in addition revoke the Service’s access at source at any time.

11.2 Where the service annex states that a category of Customer Personal Data is not stored by Sidcom, no return or deletion action is required for that category. The same applies to a short-lived operational cache identified in the service annex, which requires no action beyond its automatic expiry.

11.3 Upon the Customer’s written request, Sidcom shall confirm in writing that deletion under this Clause 11 has been completed.

12.1 Sidcom shall make available to the Customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR. In the first instance this is done through documentation: descriptions of technical and organisational measures, responses to written questions and, where available, third-party attestations and certifications relating to Sidcom’s Sub-processors.

12.2 Where such documentation is not reasonably sufficient, the Customer, or an independent auditor mandated by the Customer that is not a competitor of Sidcom, may as a last resort conduct an on-site audit — no more than once in any twelve (12) month period unless required by a supervisory authority or following a personal data breach, on at least fourteen (14) days’ prior written notice, during business hours and subject to reasonable confidentiality and security requirements. Each Party bears its own costs of an audit, without prejudice to Clause 13.1.

13.1 Assistance and cooperation of a scope that is customary and reasonable for the Services is included in the fees for the Services. Where assistance is manifestly excessive or is attributable to the Customer’s own failure to comply with Data Protection Law, Sidcom may charge reasonable compensation at its then-current rates, having notified the Customer in advance.

14.1 Entry into force. This DPA takes effect when the Customer accepts the Terms of Service. No signature is required. It applies in full irrespective of the channel through which the Customer obtained the Services.

14.2 Term. This DPA remains in force for as long as Sidcom processes Customer Personal Data under the Terms of Service, and thereafter until deletion or return under Clause 11 has been completed.

14.3 Termination of the Terms of Service automatically terminates this DPA. This DPA cannot be terminated separately while Sidcom processes Customer Personal Data on the Customer’s behalf, except as expressly provided in Clauses 6.3 and 16.2.

15.1 Each Party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, which apply in aggregate across the Terms of Service and this DPA together. This limitation applies to the extent it is not precluded by mandatory law, including Article 82 GDPR in relation to data subjects.

16.1 Amendments with notice. Sidcom may amend this DPA unilaterally. Except for amendments described in Clauses 16.3 and 16.4, Sidcom shall notify the Customer by email and publish the amended version, together with its version identifier and the date on which it takes effect, at least fourteen (14) days before that date. Changes to the list of Sub-processors are governed by Clause 6.2.

16.2 Right to object. Where an amendment materially affects the Customer’s rights or the protection of Customer Personal Data, the Customer may object on reasonable grounds relating to data protection by notifying Sidcom in writing before the amendment takes effect. The Parties shall discuss the objection in good faith. If the Parties cannot agree on a solution within a reasonable time, the Customer may terminate the affected Service and this DPA with immediate effect, whether or not the amendment has already taken effect. Termination is effected under the Terms of Service or, where the Service was obtained through a marketplace, under that marketplace’s terms. Sidcom shall refund fees paid to Sidcom for the unused remainder of the current period; fees paid to a marketplace are refunded under that marketplace’s terms.

16.3 Amendments required by law. Sidcom may implement with immediate effect any amendment that is required by Data Protection Law, by a supervisory authority or by a court. Sidcom shall inform the Customer of such an amendment without undue delay.

16.4 Minor amendments. Sidcom may make minor amendments to this DPA without prior notice to the Customer. A minor amendment is one that neither reduces the protection afforded to Customer Personal Data nor adversely affects the Customer’s rights or Sidcom’s obligations under this DPA, and is limited to:

(a) correction of typographical, grammatical, formatting, numbering or cross-referencing errors;

(b) clarification of existing wording that does not change its meaning or effect;

(c) updates to Sidcom’s contact details or corporate information;

(d) updates to the addresses at which documents referred to in this DPA are published, where the content of those documents is unchanged; and

(e) the addition of a service annex for a Service that the Customer does not use.

16.5 Publication and versioning. Every version of this DPA, however amended, is published with a version identifier and the date from which it applies. Sidcom shall retain previous versions and provide them to the Customer on request, so that the Customer can establish which version applied at any given time. An amendment under Clause 16.4 takes effect on publication.

16.6 Continued use of the Services after an amendment has taken effect constitutes acceptance of the amended DPA. This does not apply to an amendment to which the Customer has objected under Clause 16.2 while that objection remains unresolved; continued use of the Services during the discussion of an objection is not acceptance of the amendment objected to.

17.1 Notices from Sidcom to the Customer under this DPA — including notice of changes to the list of Sub- processors under Clause 6.2 and of amendments to this DPA under Clause 16.1 — are sent by email to the address registered on the Customer’s account. The Customer is responsible for keeping that address current and for ensuring that it is monitored.

17.2 Notices from the Customer to Sidcom under this DPA — including objections under Clauses 6.3 and 16.2 and requests under Clause 11 — may be sent to hello@sidcom.ai.

18.1 In the event of any conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails. Within this DPA, the Annexes prevail over Clauses 1–19 in respect of the description of the Services, the data processed and storage. In all other respects, the Terms of Service prevail.

19.1 This DPA is governed by, and disputes arising out of or in connection with it shall be settled in accordance with, the governing law and dispute resolution provisions of the Terms of Service.

This Annex sets out the information required by Article 28(3) GDPR and supports the Customer’s record of processing activities under Article 30 GDPR. Service-specific detail is set out in the service annex.

Access tokens and connection credentials are Customer Personal Data and are covered by this Annex: Sidcom processes them on the Customer’s behalf as processor, and the storage, retention and deletion arrangements for them are set out in the service annex.

ItemDescription
ControllerThe Customer.
ProcessorSidcom AB, reg. no. 559504-0840, Sweden.
Subject matterPerforming, on the Customer’s instruction, the operations against the Customer’s connected business system that the Customer’s AI assistant initiates through the Services — including retrieving files from locations the Customer designates and delivering them, together with files uploaded via the Services’ upload endpoint, to that business system.
Nature of the processingReal-time pass-through transmission. Business Data is processed in memory only, for the duration of the individual API call — never archived, never used for model training or analytics — subject only to the short-lived operational caches identified in the service annex. Access tokens and connection credentials are stored in encrypted form for the sole purpose of maintaining the connection the Customer has authorised, as set out in the service annex.
PurposeEnabling the connection between the Customer’s AI assistant and the Customer’s account in the connected business system.
Categories of data subjectsThe Customer’s customers, suppliers and employees, and other persons whose personal data appears in the Customer’s data in the connected business system. In addition, for access tokens and connection credentials: the members of the Customer’s organisation who authorise a connection.
Categories of personal dataNames, contact details, addresses, company and personal identity numbers, and financial data such as invoices, payments and payroll materials — in principle anything that may appear in the connected business system. In addition: the access tokens and connection credentials by which the Services access the Customer’s connected business system.
Special categoriesNot intended. To the extent such data exceptionally appears in the Customer’s data in the connected business system, it is processed in transit only, under this DPA.
FrequencyContinuous, on demand — each operation initiated by the Customer or the Customer’s AI assistant.
DurationMilliseconds per API call for Business Data; operational caches as stated in the service annex; access tokens and connection credentials for the periods stated in the service annex. This DPA remains in force for as long as the Customer uses the Services (Clause 14).
Storage and retentionPer category, as set out in the service annex.
Source systemsPer Service, as identified in the service annex (Clause 8.3).
Sub-processorsAs published at sidcom.ai/subprocessors (Clause 6.1).
TransfersPer Sub-processor, as published at sidcom.ai/subprocessors. Each transfer outside the EU/EEA is covered by a valid mechanism under Chapter V GDPR (Clause 7).

Sidcom applies the following standard measures across its services pursuant to Article 32 GDPR. Service- specific measures — storage and retention — are set out in the service annex and apply in addition to these.

MeasureGDPR ref.Description
EncryptionArt. 32(1)(a)All traffic to and from Sidcom services is encrypted in transit using TLS. Data stored by Sidcom or its Sub-processors is encrypted at rest. Tokens and connection credentials for the Customer’s business systems are additionally encrypted by Sidcom at the application layer before being written. Sidcom requires encryption at rest of its Sub-processors by contract and verifies it against each Sub-processor’s published documentation and, where available, third-party attestations; Sidcom does not warrant the technical implementation of a Sub-processor beyond what that Sub- processor undertakes.
Pseudonymisation and minimisationArt. 32(1)(a); Art. 25Services are designed to process and retain the minimum personal data needed to perform their function. Request and response content is not logged; operational logs contain metadata only. Storage and retention specifics are stated per service in the service annex.
Access controlArt. 32(1)(b)Access to production environments and administrative systems is restricted to authorised personnel and protected by personal accounts and multi-factor authentication. Access is granted on a least-privilege basis and reviewed at least annually.
Confidentiality of personnelArt. 28(3)(b); Art. 32(1)(b)Personnel with access to personal data are bound by written confidentiality undertakings and instructed in secure data handling.
IntegrityArt. 32(1)(b)Authentication and authorisation are enforced on every request, and the token presented is verified on each call. Tokens are scoped to the individual Customer connection and are not reusable across Customers.
Availability and resilienceArt. 32(1)(b)– (c)The Services run on a distributed, redundant platform. Because Business Data is not persisted by Sidcom beyond the short-lived operational caches identified in the service annex, restoration of Business Data is not applicable; availability of the connection is restored by the platform’s own redundancy.
Testing and evaluationArt. 32(1)(d)Security measures are reviewed at least annually and reassessed when the architecture, the Sub-processors or the threat landscape change materially.
Incident managementArts. 33–34Suspected security incidents are triaged promptly. Incidents affecting Customer Personal Data are escalated and notified in accordance with Clause 10.
Sub-processor managementArt. 28(4)Written data processing agreements imposing equivalent obligations are in place with all Sub-processors published at sidcom.ai/subprocessors, and with each of the other providers Sidcom engages.

This Annex is the service annex for the AI Connectors for Fortnox. It describes the Service, the allocation of roles for the data it involves, and its storage, retention and deletion, and forms part of this DPA as set out in Clause 1.3.

A3.1 The Service

Service
The Sidcom AI Connector services for Fortnox — MCP servers that connect the Customer’s AI assistant to the Customer’s Fortnox account. Currently published as ChatGPT Connector, Claude Connector and Microsoft Copilot Connector. The connectors are technically identical and differ only in the AI assistant they serve, their branding and their endpoint address; this Annex covers each connector the Customer uses. Where the Customer has entered into an agreement directly with Sidcom, the Service also includes the Sidcom account portal at business.sidcom.ai, through which the Customer’s organisation, its members and their roles are administered and through which account-linked connections to Fortnox are established; the portal is not used where the Customer obtained the Service through a marketplace. Jointly and severally, the “Service”.
Distribution
The Service is made available through one or more of the following channels: (i) the Fortnox App-market or another marketplace, where the marketplace sets the price, invoices the Customer and handles payment under the marketplace’s own terms; (ii) directly from Sidcom against card payment or subscription billing, processed by Sidcom’s payment provider; or (iii) directly from Sidcom against invoice. This DPA applies in full irrespective of the channel through which the Customer obtained the Service. Endpoint addresses (under the sidcom.app domain) are stated in the relevant marketplace listing or provided by Sidcom.
Terms of Service
The Sidcom Terms of Service at sidcom.ai/terms
Privacy Policy
sidcom.ai/privacy — a single policy covering the connectors, the account portal, Sidcom’s products and the sidcom.ai website. For data where Sidcom is an independent controller, see Clause 2.3 and A3.2(c).
Sub-processors
sidcom.ai/subprocessors — see Clause 6 and A3.4.
Source systems (Clause 8.3)
The Customer’s Fortnox account and, where relevant, the provider of the Customer’s AI assistant.
Annex version
2026.09

A3.2 Allocation of Roles for this Service

(a) Business Data — Customer Personal Data: The data passing through the Service in API calls between the Customer’s AI assistant and Fortnox — such as invoices, customer and supplier records, vouchers and payroll materials — including files that the Service retrieves from locations the Customer designates or receives through the Service’s one-time upload endpoint, in each case for immediate delivery to Fortnox. The Customer is controller and Sidcom is processor (Clause 2.1).

(b) Access tokens (OAuth and credential-flow) — Customer Personal Data: The access tokens and connection credentials by which the Service accesses the Customer’s Fortnox account. They exist solely to execute the operations the Customer authorises through the Services; the Customer determines their scope through the provider’s own authorisation flow and may revoke them at any time; and Sidcom may not use them for any other purpose. The Customer is controller and Sidcom is processor (Clause 2.1). Storage, retention and deletion are set out in A3.3(b).

(c) Other independent-controller data (outside this DPA, Clause 2.3): Account records, the activity log for the Customer’s organisation, payment and billing details, and the metadata logs and monitoring used for operations, billing and statistics concerning only the Customer itself. These are described in the Privacy Policy identified in A3.1 and are not further specified in this DPA. For the avoidance of doubt, Clause 3.4 (no processing for Sidcom’s own purposes, no model training, no analytics) applies to Business Data without exception; the billing and statistics referred to here are performed only on the metadata logs in A3.3(c), which contain no content of requests or responses.

(d) Third-party platforms (Clause 2.4): Fortnox AB and the provider of the Customer’s AI assistant — OpenAI, Anthropic or Microsoft, depending on which connector(s) the Customer uses — are independent actors and not Sidcom’s Sub-processors.

A3.3 Storage, Retention and Deletion (Clauses 8.3 and 11)

(a) Business Data: not stored. Processed in memory only during the individual API call; never written to disk or database, with two limited exceptions, both held in a key-value store with automatic expiry and used for no other purpose: (i) to make retried write operations safe

(idempotency) , the Fortnox API response of a create/action call may be cached, keyed by a hash of the request payload, for up to sixty (60) seconds; (ii) where the Customer has configured dashboards in the account portal, the computed panel values (aggregated figures derived from the Customer’s Fortnox data) are cached for between fifteen (15) minutes and six (6) hours, so that a dashboard can be displayed without re-querying Fortnox on every view. Neither cache requires a return or deletion action beyond its automatic expiry (Clause 11.2).

(b) Access tokens (Customer Personal Data under A3.2(b)): (i) connector OAuth tokens are stored in a key-value store, encrypted at rest, with a lifetime bounded by the third-party refresh cycle (at most approximately 44 days for Fortnox refresh tokens); sign-in-based tokens are stored for up to 365 days, with automatic re-authentication. (ii) Account-linked company tokens, established through the account portal, are encrypted by Sidcom before being written and are stored in a database created with EU jurisdiction. (iii) Tokens are verified on every call. When a company connection is removed in the account portal, the connection is immediately marked as revoked and the Service no longer uses the token; the encrypted token record is deleted when the member leaves the Customer’s organisation, when the Customer’s organisation is deleted, or earlier upon the Customer’s written request, with written confirmation. Where the Customer revokes the Service’s access at Fortnox, Fortnox invalidates the token at source and any copy held by Sidcom becomes unusable. Tokens that are neither revoked nor deleted expire under Fortnox’s own token lifecycle (A3.3(b)(i)). Once a token has been revoked, invalidated or deleted, Sidcom can no longer use it to access the Customer’s Fortnox data.

(c) Logs: metadata only — timestamp, tool name, response time, status code and company ID. The content of requests and responses is never logged. Operational logs are automatically purged after three (3) days.

(d) Upload URLs and tickets: upload URLs are single-use and expire after ten (10) minutes. Each URL embeds an AES-256-GCM-encrypted ticket containing the session identifier and the file name; because file names may contain personal data, the Customer should treat upload URLs as confidential and should not rely on file names as a safe place for personal data. To prevent reuse, a SHA-256 fingerprint of each used ticket (metadata only, no content) is retained for up to fifteen (15) minutes before automatic expiry.

(e) What remains after deletion: when an organisation is deleted, Sidcom deletes the account records, the activity log and all tokens for that organisation. Sidcom retains only the contract and accounting record required by mandatory law — the Customer’s legal name and registration number and the dates on which the Customer’s subscription began and ended — for the period prescribed by the Swedish Bookkeeping Act (bokföringslagen (1999:1078)), and processes it only for that purpose (Clause 11.1). No tokens, no logs and no Business Data are retained on that basis.

A3.4 Providers (Clause 6)

The Sub-processors Sidcom engages for this Service, the personal data each processes, the processing locations and the Chapter V transfer mechanism relied on for each are published at sidcom.ai/subprocessors. Sidcom keeps that list current, publishes changes under Clause 6.2 and provides the list to the Customer on request (Clauses 6.1 and 7.2).

Providers that Sidcom engages only in processing for which Sidcom is an independent controller are not Sub- processors, are not listed here and are described in the Privacy Policy identified in A3.1 (Clause 6.5).

For the avoidance of doubt: Fortnox AB and the provider of the Customer’s AI assistant are not Sidcom’s Sub- processors (see A3.2(d)). Where the same company appears in more than one capacity — for example as the provider of the connected business system under A3.2(d) and as the operator of a marketplace under A3.1 — each capacity is separate, and the rights and obligations stated for one capacity do not extend to another.