Mandraki Mandraki
Începeți acum
This document is available in English only.

Mandraki Data Processing Agreement

Version: 1.0 · Effective: 11 October 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Mandraki AB, org. nr 559575-7328, Banvägen 70, 435 43 Pixbo, Sweden ("Mandraki", the "Processor") and the Customer (as defined in the Mandraki Terms of Service, the "Controller") governing the Customer's use of the Mandraki services (the "Services"). It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (the "GDPR").

This DPA consists of these main terms and the deployment schedule that applies to the Customer's Services. Schedule 1 covers the hosted service operated by Mandraki at app.mandraki.cloud and contains Annex A (details of processing), Annex B (technical and organisational measures) and Annex C (sub-processors). Schedules for other deployment models will be added only when their allocation of responsibilities has been confirmed.

Where the Terms of Service and this DPA conflict, this DPA prevails for matters concerning the processing of personal data.

1. Definitions

Terms not defined here have the meaning given in the GDPR ("personal data", "processing", "data subject", "supervisory authority", "personal data breach") or in the Terms of Service ("Customer Content", "Services", "User").

  • "Customer Personal Data" means personal data that Mandraki processes on the Customer's behalf in providing the Services, including personal data in Customer Content and in the Customer's organisation audit log.
  • "Exit Period" means the 30 days following termination or expiry of the Services, described in Section 11.
  • "Instructions" means the Customer's documented instructions described in Section 4.

2. Roles and scope

2.1. For Customer Personal Data, the Customer is the controller and Mandraki is the processor. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex A.

2.2. Customer acting as processor. Where the Customer processes Customer Personal Data as a processor on behalf of a third-party controller, Mandraki acts as the Customer's sub-processor. In that case: (a) the Customer confirms that its Instructions, including its authorisation of the sub-processors in Annex C, are consistent with the instructions and authorisations it has received from that controller; (b) the Customer remains Mandraki's sole point of contact and passes on information and notices under this DPA to that controller; and (c) Mandraki's obligations under this DPA are owed to the Customer, without prejudice to any rights the third-party controller has directly under the GDPR.

2.3. Processing for Mandraki's own purposes. Mandraki determines the purposes and means of, and is an independent controller for, only the following processing, which is governed by the Mandraki Privacy Policy and not by this DPA:

  • (a) administering the Customer's account, subscription, billing and payments;
  • (b) protecting the security and integrity of the Services as a whole — platform-wide abuse prevention, fraud prevention and service-level security monitoring — limited to the data necessary for that purpose;
  • (c) aggregated service telemetry used to operate and improve the Services, from which individual Users are not identified; and
  • (d) the advertising-conversion measurement described in the Privacy Policy.

2.4. Processing performed for the Customer. The following remains processing on the Customer's behalf under this DPA, whatever its technical form: the Customer's organisation audit log; access, sign-in and session records of the Customer's Users; security alerts, investigations and incident handling relating to the Customer's organisation; backups of Customer Content; and support access to Customer Content made at the Customer's request.

2.5. Mandraki does not use Customer Personal Data for any purpose other than providing the Services under this DPA and the purposes in Section 2.3. In particular, Mandraki does not use Customer Personal Data to train AI models or for advertising.

3. Duration

This DPA applies for as long as Mandraki processes Customer Personal Data, including during the Exit Period and until deletion under Section 11 is complete. Sections 6 (confidentiality), 11 (return and deletion) and 12 (audit log) survive termination to the extent stated there.

4. Processing on documented instructions (Art. 28(3)(a))

4.1. Mandraki processes Customer Personal Data only on the Customer's Instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which Mandraki is subject. In that case Mandraki informs the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.

4.2. The Customer's Instructions at the date of this DPA are: (a) processing necessary to provide the Services as described in the Agreement and the product documentation; (b) processing configured by the Customer and its Users through the Services, including organisation settings, retention settings, feature enablement and sharing and access decisions; and (c) any further written instructions agreed between the parties.

4.3. If Mandraki considers that an Instruction infringes the GDPR or other Union or Member State data protection provisions, it informs the Customer without undue delay. Mandraki is not obliged to carry out an Instruction it reasonably considers unlawful, and the Customer's confirmation of such an Instruction does not oblige Mandraki to carry it out. Mandraki may suspend the affected processing until the Instruction is withdrawn or modified so that it is lawful. If the parties cannot agree, either party may terminate the affected Services.

5. Obligations of the Customer

5.1. The Customer determines the purposes and means of processing Customer Personal Data and is responsible for:

  • (a) having a lawful basis for the processing it instructs, including for content its Users submit;
  • (b) informing data subjects as required by Articles 13 and 14 GDPR;
  • (c) the lawfulness of its Instructions;
  • (d) configuring the Services appropriately for its risk, including retention periods, external sharing, guest access, AI features, notification detail, administrator roles and multi-factor authentication;
  • (e) managing its Users' accounts and credentials;
  • (f) responding to data subject requests, with Mandraki's assistance under Section 9;
  • (g) notifying supervisory authorities and data subjects of personal data breaches where required, with Mandraki's assistance under Section 10; and
  • (h) carrying out any data protection impact assessment its processing requires.

5.2. The Customer informs Mandraki without undue delay if it becomes aware of a breach of this DPA by Mandraki or of a security incident affecting its organisation in the Services.

5.3. The Customer's rights under this DPA include giving Instructions (Section 4), objecting to new sub-processors (Section 8), receiving notice of personal data breaches (Section 10), choosing return or deletion (Section 11) and obtaining information and conducting audits (Section 13).

5.4. Nothing in this Section 5 limits or transfers Mandraki's own obligations under this DPA or the GDPR.

6. Confidentiality (Art. 28(3)(b))

Mandraki ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process it only for the purposes of providing the Services. This obligation survives the end of their engagement and of this DPA.

7. Security (Art. 28(3)(c), Art. 32)

7.1. Mandraki implements and maintains the technical and organisational measures in Annex B, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.

7.2. Mandraki may update Annex B, provided the updates do not reduce the overall level of protection.

8. Sub-processors (Art. 28(3)(d))

8.1. The Customer grants Mandraki general written authorisation to engage the sub-processors listed in Annex C, and to add or replace sub-processors in accordance with this Section. The current list is Annex C of this DPA as published at mandraki.cloud/legal/dpa, updated in accordance with this Section.

8.2. Mandraki gives the Customer at least 30 days' prior notice of any intended addition or replacement of a sub-processor, by email to the organisation's owners and administrators and by in-product notice. The notice states the sub-processor's name, the processing it will perform, the categories of Customer Personal Data concerned, the location of processing and, where relevant, the transfer mechanism.

8.3. The Customer may object on reasonable data protection grounds by written notice within 21 days of the notice. The parties then discuss the objection in good faith, and Mandraki may propose an alternative, such as a configuration that avoids the new sub-processor for the Customer.

8.4. If an objection is not resolved before the change date, Mandraki does not use the new sub-processor to process the Customer's Customer Personal Data until the objection is resolved or the Customer's termination takes effect. If Mandraki cannot reasonably provide the Services without the change, the Customer may terminate the affected Services with effect before the change date and receives a pro-rata refund of prepaid fees for the period after termination.

8.5. Where a sub-processor must be replaced urgently to prevent or remedy a security incident or to comply with law, Mandraki may do so on shorter notice and informs the Customer as soon as possible. The Customer's objection right under Sections 8.3 and 8.4 then applies from that notice.

8.6. Mandraki imposes on each sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to the Customer for each sub-processor's performance of those obligations.

9. Assistance with data subject rights (Art. 28(3)(e))

9.1. Taking into account the nature of the processing, Mandraki assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

9.2. The Services provide capabilities for access, export in a machine-readable format, rectification and erasure of User data. Where a request cannot be fulfilled through the Services, Mandraki provides reasonable assistance on request via privacy@mandraki.cloud.

9.3. If a data subject contacts Mandraki directly about Customer Personal Data, Mandraki refers the data subject to the Customer where the Customer is identifiable, and informs the Customer of the request without undue delay. Mandraki does not respond to the request itself unless the Customer instructs it to.

10. Personal data breach (Art. 28(3)(f), Art. 33)

10.1. Mandraki notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event no later than 48 hours after becoming aware of it. The 48-hour limit is an outer limit and does not permit delay where earlier notification is possible.

10.2. Where not all information is available at once, Mandraki provides it in phases. The first notification includes what is then known of: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point. Mandraki provides updates without undue delay as further information becomes available.

10.3. Mandraki sends notifications to the security contact the Customer designates in the Services or, if none is designated, by email to the organisation's owners.

10.4. Mandraki takes reasonable steps to contain, investigate and mitigate the breach, and documents it. Notification is not an acknowledgement of fault or liability.

10.5. Taking into account the nature of the processing and the information available to it, Mandraki assists the Customer in meeting its obligations under Articles 32 to 36 GDPR.

11. Return and deletion (Art. 28(3)(g))

11.1. Choice. The Customer may choose whether Customer Personal Data is returned or deleted at the end of the Services. Return means export as described in Section 11.3. The Customer may make this choice at any time before the end of the Exit Period, through the Services or by written notice to legal@mandraki.cloud. If the Customer makes no choice, Customer Personal Data is deleted at the end of the Exit Period.

11.2. Exit Period. For 30 days after termination or expiry of the Services, the Customer's owners keep access to the export functions of the Services. During the Exit Period, Mandraki processes Customer Personal Data only to store, export and delete it, and continues to protect it under this DPA.

11.3. Format and assistance. Exports are provided in structured, commonly used and machine-readable formats, as described in the product documentation: email as .eml files, calendars as .ics files, files in their original format, and messages and other records as JSON or CSV, together with the signed audit log. Exports are delivered as an encrypted archive by download or to storage the Customer designates. On request, Mandraki provides reasonable further assistance with return.

11.4. Deletion. Deletion starts at the end of the Exit Period, or earlier if the Customer requests it in writing, and is completed in Mandraki's production systems within 30 days. Deletion includes destroying the Customer's organisation encryption keys, which makes any remaining encrypted copies unreadable.

11.5. Backups. Copies of Customer Personal Data in backups remain protected under this DPA, are not restored for any purpose other than disaster recovery, and are deleted or made unreadable as the backups expire, no later than 60 days after deletion from production systems.

11.6. Legal retention. Where Union or Member State law requires Mandraki to retain Customer Personal Data, Mandraki retains only what is required, for as long as required, protects it under this DPA and does not otherwise process it.

11.7. Confirmation. On request, Mandraki confirms in writing that deletion is complete.

11.8. During the term. Deletion performed by the Customer or its Users through the Services, including under organisation retention settings, takes effect as described in the product documentation. Copies in backups are handled as in Section 11.5.

12. Audit log

12.1. During the term, Mandraki retains the Customer's organisation audit log for the period the Customer sets in the Services: by default 365 days, at least 90 days, and up to 2,555 days (seven years) where the Compliance pack is subscribed. Entries older than that period are deleted, and each deletion run is itself recorded in the log.

12.2. The Services can deliver a cryptographically signed, independently verifiable copy of the audit log to storage the Customer designates, nightly where configured and on demand through the export function. Long-term retention beyond the configured period is the Customer's responsibility.

12.3. The retention period in Section 12.1 applies during the term only. On termination, the audit log is part of Customer Personal Data: it is included in exports during the Exit Period and deleted under Section 11.

13. Information and audits (Art. 28(3)(h))

13.1. Mandraki makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including its security documentation, the sub-processor list, the software bill of materials published at mandraki.cloud/.well-known/sbom.json and, where available, third-party audit reports.

13.2. The Customer first requests the information it needs under Section 13.1. Mandraki responds within 30 days.

13.3. The Customer, or an independent auditor it mandates, may conduct an audit, including an inspection, where: (a) the information provided under Section 13.2 does not reasonably demonstrate compliance; (b) there are indications of non-compliance with this DPA; (c) a personal data breach has occurred; or (d) a supervisory authority or applicable law requires it.

13.4. Audits are conducted: on at least 30 days' written notice, or on shorter reasonable notice in the cases in Section 13.3(b) to (d); for inspections, normally not more than once in any 12-month period, except in those cases; during business hours and without unreasonable disruption; under confidentiality obligations; by an auditor who is not a competitor of Mandraki; and without access to other customers' data. Each party bears its own costs, unless the audit reveals material non-compliance by Mandraki, in which case Mandraki bears the reasonable costs of the audit.

13.5. Mandraki remedies any non-compliance found without undue delay.

14. International transfers (Chapter V)

14.1. Subject only to Section 14.2, Mandraki stores and processes Customer Personal Data exclusively within the European Union, on infrastructure operated by the sub-processors in Annex C, and does not transfer Customer Personal Data outside the EU/EEA.

14.2. Push notifications are delivered through the push gateway operated by the platform of the User's own device or browser (Apple APNs, Google FCM, Microsoft WNS, Mozilla autopush). These gateways are chosen by the device platform, not by Mandraki, and may see the notification in transit. By default, a notification carries only a generic label, such as "New message", and no sender name or message content. Each User may choose in their notification settings to include further detail, and Users and administrators can turn push notifications off entirely. No Customer Content is stored with these gateways. The Customer instructs Mandraki to deliver push notifications on these terms to the extent its Users enable them.

14.3. If any transfer of Customer Personal Data to a third country becomes necessary, the parties will put in place a valid transfer mechanism under Chapter V GDPR before the transfer takes place.

15. Liability

15.1. Each party's liability under this DPA is subject to the limitations of liability in Section 16 of the Terms of Service, except where such limitation is prohibited by applicable law.

15.2. Nothing in this DPA limits either party's liability to data subjects under Article 82 GDPR, or the powers of supervisory authorities under Article 83 GDPR.

16. Precedence

This DPA prevails over the Terms of Service for matters concerning the processing of personal data. Within this DPA, a deployment schedule prevails over these main terms only where it expressly says so.

17. Governing law and language

17.1. This DPA is governed by the laws of Sweden, and disputes are resolved by the courts of Stockholm, Sweden, as in the Terms of Service, without prejudice to mandatory provisions of the GDPR.

17.2. This DPA is made in English. Any translation is provided for convenience only, and the English text governs.

Schedule 1 — Hosted service

This Schedule applies to the Services hosted and operated by Mandraki at app.mandraki.cloud.

Annex A — Details of processing

Subject matter: Provision of the Mandraki collaboration services (video calls, chat, email, file storage and collaborative documents, calendar, tasks and related features) to the Customer's organisation.

Duration: The term of the Agreement, plus the Exit Period and the deletion periods in Section 11.

Nature and purpose: Hosting, storage, transmission, display, indexing for in-product search, backup and, where enabled by the Customer, recording, transcription and AI-assisted processing of Customer Content, in order to provide the Services; and keeping the Customer's organisation audit log.

Categories of data subjects: The Customer's Users (employees, contractors), guests invited to calls or shared content, communication counterparties such as email correspondents, and other individuals appearing in Customer Content.

Types of personal data: Identification and contact data (names, email addresses, profile images); communication content (messages, email, files, documents, comments, tasks, calendar entries); audio and video streams and, if enabled, recordings and transcripts; usage and security records of the Customer's Users (participation, timestamps, presence, sign-ins, audit log entries); and any personal data the Customer's Users include in Customer Content.

Special categories of personal data (Art. 9) and data relating to criminal convictions and offences (Art. 10): The Customer may use the Services to process special categories of personal data, provided that it has a lawful basis and a condition under Article 9(2) GDPR, has carried out any data protection impact assessment the processing requires, and configures the Services with appropriate safeguards, including requiring multi-factor authentication for all Users, restricting external sharing and enabling AI features only after assessing them. The Customer may process personal data relating to criminal convictions and offences only where Union or Member State law permits it to do so under Article 10 GDPR, subject to the same safeguards.

Annex B — Technical and organisational measures

  • EU-only infrastructure. Production systems run in data centres in the European Union, subject only to the push-notification delivery described in Section 14.2.
  • Encryption in transit. TLS 1.2 or higher for all traffic to the Services; HSTS; WebRTC media encrypted with DTLS-SRTP; time-limited credentials for TURN relay. Traffic between Mandraki's servers runs on private networks isolated from the internet.
  • Encryption at rest. Message content, email bodies, files and recordings are encrypted at the application level with AES-256-GCM under a three-tier key hierarchy (master key, per-organisation keys, data-encryption keys). The master key is not stored in the databases or their backups. Encryption coverage is extended continuously, and a build-time gate prevents regressions.
  • Access control. Role-based access control enforced on every organisation-scoped request; per-organisation data isolation; short-lived access tokens; session tokens stored only as hashes and revocable by administrators; multi-factor authentication that administrators can require for their organisation; additional authentication for sensitive operations.
  • No direct storage exposure. Clients never receive storage URLs; all file access is streamed through authenticated, organisation-scoped endpoints.
  • Network security. Private network isolation between application, data and coordination tiers; firewall rules restricting traffic between tiers; rate limiting at several layers.
  • Availability and resilience. Redundant load balancers and application servers in separate availability zones; database replicas; backups that are encrypted, stored separately from production systems and expire as described in Section 11.5; documented restore procedures that are tested regularly.
  • Secure development. Code review and automated security checks before changes are merged; a published software bill of materials (CycloneDX); a vulnerability disclosure channel through security.txt.
  • Incident management. A documented incident response procedure; incident tracking with monitoring of the 72-hour notification deadline; confidentiality obligations for personnel; least-privilege operational access.
  • Data subject tooling. Export in a machine-readable format and erasure of User accounts; organisation-level retention settings.
  • Audit log. A tamper-evident (hash-chained) organisation audit log with details encrypted under the organisation key, retained and exported as described in Section 12. Changes to the retention period require additional authentication and, where enabled, approval by a second administrator.

Annex C — Authorised sub-processors

Sub-processorProcessingLocation of processing
evroc ABCloud infrastructure (compute, storage, networking) for the hosted ServicesEuropean Union (Sweden)
Scaleway SASOutbound email relay; auxiliary infrastructureEuropean Union (France)
evroc AB (Think Models)AI-assisted features (transcription, assistant), engaged only where the Customer enables AI features; prompts and results are not used to train modelsEuropean Union

Push-notification gateways (Apple APNs, Google FCM, Microsoft WNS, Mozilla autopush) are engaged by the User's own device or browser platform as described in Section 14.2. They are listed here for transparency and do not store Customer Content.

The following are not sub-processors, because they receive only data for which Mandraki is the controller under Section 2.3 and never Customer Personal Data: Mollie B.V. (payment processing) and any advertising-measurement recipient named in the Privacy Policy.