Data Processing Agreement
Last updated 16 August 2026
This DPA governs how FirmoryX processes personal data on your behalf under Article 28 of the GDPR. It forms part of, and is subject to, our Terms of Service.
1. Roles
For personal data you upload to run the service ("Customer Data"), you are the controller and FirmoryX is the processor. FirmoryX processes Customer Data only on your documented instructions, which the service's features and these terms constitute, unless required otherwise by law.
2. Scope of processing
- Subject matter: providing firmware-vulnerability monitoring and compliance evidence.
- Duration: for the term of your subscription, plus the deletion window below.
- Nature & purpose: storage, matching, alerting, and report generation.
- Data subjects: your personnel and, incidentally, individuals identifiable from the device or client records you enter.
- Categories of data: account contact details; client and device inventory data. No special-category data is required or expected.
3. Our obligations
- Process Customer Data only on your instructions.
- Ensure persons authorized to process it are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see our security page).
- Assist you, as far as reasonably possible, with data-subject requests and your own security, breach-notification, and impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data.
4. Sub-processors
You authorize FirmoryX to engage the sub-processors listed at firmoryx.se/legal/subprocessors. Each is bound by data-protection obligations no less protective than this DPA. We will give you a way to learn of intended changes so you may object on reasonable grounds.
5. International transfers
Where a sub-processor processes Customer Data outside the EU/EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent Article 46 safeguard.
6. Return & deletion
You can export Customer Data at any time from Settings → Account & data. On termination, or on your request, we delete Customer Data from production systems, and it is purged from routine backups within 30 days, save where retention is legally required.
7. Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will make available the information necessary to demonstrate compliance with Article 28.
8. Acceptance
This DPA is incorporated into the agreement by your acceptance of the Terms of Service. If your organization requires a countersigned copy, contact privacy@firmoryx.se.