
Data Processing Agreement (DPA) – FutureCalc.ai

**Effective:** 2026-10-01

This Data Processing Agreement (the "**DPA**") is entered into between the company that has accepted the Terms of Use for FutureCalc.ai (the "**Customer**") and FutureCalc AB, reg. no. 559536-7847, c/o Kivra: 559536-7847, 106 31 Stockholm, Sweden ("**FutureCalc**"). The DPA forms part of the Terms of Use and applies automatically from the moment the Customer accepts them, without separate signature. Capitalized terms have the meaning given in the Terms of Use. In case of any discrepancy between the Swedish and English versions, the Swedish version prevails.

1\. Background and scope

1.1 The Customer uploads drawings and other Customer Content to the Service. Such material may contain personal data, typically names, roles and contact details of designers, handläggare and clients in title blocks, annotations and comments. When FutureCalc provides the Service, FutureCalc processes this personal data on the Customer's behalf. The Customer is the controller and FutureCalc the processor. The DPA governs that processing in accordance with Article 28 GDPR.

1.2 The DPA does **not** cover (a) processing for which FutureCalc is the controller under the Privacy Policy, i.e. account data, authentication and security data, usage analytics, communications, billing and marketing, and (b) FutureCalc's use of Customer Content, Output, Corrections and Derived Data for development purposes under section 6.2 (b) and (c) of the Terms of Use. For the processing under (b), FutureCalc is the controller; by accepting the Terms of Use the Customer confirms that it is aware of this use and of the safeguards set out in section 6.6 of the Terms of Use and section 4 of the Privacy Policy.

1.3 In case of conflict between the DPA and the Terms of Use, the DPA prevails in matters concerning the processing of personal data under section 1.1. In all other matters, including limitation of liability, the Terms of Use apply.

2\. Subject matter, nature, purpose and duration of processing

2.1 **Subject matter:** personal data contained in Customer Content.

2.2 **Nature:** storage, copying, display, machine interpretation, aggregation, export, backup and deletion.

2.3 **Purpose:** providing the Service to the Customer under the Terms of Use.

2.4 **Categories of data subjects:** the Customer's employees and contractors, and persons appearing in drawings and project documents (designers, consultants, clients, contractors and their contact persons).

2.5 **Categories of personal data:** name, job title, company, email address, phone number, signatures and other data the Customer chooses to include in Customer Content. Special categories of personal data (Article 9) must not be uploaded to the Service.

2.6 **Duration:** the term of the agreement and the export window set out in section 14.3 of the Terms of Use.

3\. Customer obligations

3.1 The Customer is responsible for having a legal basis for the processing, for having fulfilled its information duties toward data subjects and for ensuring that Customer Content contains no more personal data than necessary for the Customer's purposes.

3.2 The Customer is responsible for the lawfulness of its instructions to FutureCalc. The Customer's instructions consist of the Terms of Use, this DPA and the choices the Customer makes in the Service. Additional instructions require written agreement and may be charged at FutureCalc's current hourly rate.

3.3 The Customer is responsible for configuring permissions in the Service correctly and for disabling Users who should no longer have access.

4\. FutureCalc obligations

4.1 **Instructions.** FutureCalc processes personal data under section 1.1 only on the Customer's documented instructions, unless required to do so by EU or Swedish law. In that case FutureCalc informs the Customer of the legal requirement before processing, unless the law prohibits this. FutureCalc will inform the Customer if it considers an instruction to infringe the GDPR or other data protection law, and may suspend the processing until the instruction is confirmed or amended.

4.2 **Confidentiality.** FutureCalc ensures that persons processing personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and that access is limited to what each role requires.

4.3 **Security.** FutureCalc implements the technical and organizational measures set out in Annex 2 and in section 9 of the Privacy Policy, and may replace them over time with measures providing equivalent or better protection.

4.4 **Assistance.** Taking into account the nature of the processing and the information available to FutureCalc, FutureCalc assists the Customer with (a) responding to data subject requests concerning Customer Content, and (b) the Customer's obligations under Articles 32 to 36 (security, breach handling, impact assessments and prior consultation). Assistance beyond the self-service features available in the Service is charged at FutureCalc's current hourly rate.

4.5 **Requests made directly to FutureCalc.** If a data subject contacts FutureCalc directly with a request concerning Customer Content, FutureCalc forwards the request to the Customer without undue delay and does not respond to it itself, other than to refer the data subject to the Customer.

4.6 **Personal data breaches.** FutureCalc notifies the Customer without undue delay after FutureCalc has confirmed a personal data breach affecting Customer Content. Notification is sent to the email address on the Customer's Administrator account and contains the information then available to FutureCalc under Article 33(3); further information is provided as it becomes available. FutureCalc's notification does not constitute an admission of fault or liability.

4.7 **Deletion and return.** Upon termination, the Customer may export Customer Content during the window set out in section 14.3 of the Terms of Use. FutureCalc then deletes personal data under section 1.1 from the production environment, except for (a) backups, which are deleted under ordinary rotation (max 90 days), (b) data that must be retained by law, and (c) pseudonymized development data under section 1.2 (b), which FutureCalc processes as controller.

4.8 **Records and information.** FutureCalc maintains records of processing under Article 30(2) and makes available to the Customer the information necessary to demonstrate compliance with Article 28.

5\. Sub-processors

5.1 The Customer grants FutureCalc a **general prior authorization** to engage sub-processors within the categories set out in section 5 of the Privacy Policy. The named list of current sub-processors is provided to the Customer on request via privacy@futurecalc.ai and is available in the Service where such a feature is offered.

5.2 FutureCalc notifies the Customer at least thirty (30) days before a new sub-processor is given access to personal data under section 1.1. The Customer may object in writing within that period on reasonable data protection grounds. If the parties do not reach a solution within thirty (30) days of the objection, the Customer may terminate the subscription as of the date the sub-processor is put into use, in which case unused pre-paid fees are refunded pro rata. This is the Customer's sole remedy in case of objection.

5.3 FutureCalc enters into a written agreement with each sub-processor imposing data protection obligations substantially equivalent to those in the DPA. FutureCalc remains responsible to the Customer for the sub-processor's performance of those obligations, within the limits of liability under section 8.

6\. Transfers to third countries

6.1 Personal data under section 1.1 is stored and processed primarily within the EEA. Where a sub-processor processes personal data outside the EEA, FutureCalc ensures that the transfer is based on a valid transfer mechanism under Chapter V GDPR, primarily the European Commission's Standard Contractual Clauses (Decision 2021/914) or an adequacy decision, supplemented by the safeguards set out in Annex 2.

6.2 The Customer authorizes FutureCalc to enter into Standard Contractual Clauses with sub-processors on the Customer's behalf where required.

7\. Audits

7.1 FutureCalc makes available to the Customer the information necessary to demonstrate compliance with the DPA, primarily through documentation, security descriptions, summaries of third-party reviews and answers to written questions.

7.2 If such documentation is not reasonably sufficient for the Customer to meet its obligations under the GDPR, the Customer or an independent auditor engaged by the Customer, accepted by FutureCalc and bound by confidentiality, may conduct an on-site or remote audit no more than once per twelve-month period, upon written request with at least thirty (30) days' notice, during business hours, in a manner that does not disrupt operations and without access to other customers' data or FutureCalc's trade secrets. The Customer bears its own costs and reimburses FutureCalc's reasonable costs of participation at the current hourly rate.

7.3 Audits required by a supervisory authority take place on the terms set by that authority.

8\. Liability

8.1 Each party's liability under or in connection with the DPA is subject to the limitation of liability in section 9 of the Terms of Use, which applies to the parties' aggregate liability under the Terms of Use and the DPA together, not to each separately.

8.2 The Customer shall indemnify FutureCalc for claims, administrative fines and costs resulting from the Customer lacking a legal basis for the processing, giving unlawful instructions, uploading more personal data than necessary or otherwise breaching the DPA or data protection law.

8.3 Nothing in the DPA limits the rights of data subjects or liability that cannot be limited under Article 82 GDPR.

9\. Term and amendments

9.1 The DPA applies for as long as FutureCalc processes personal data under section 1.1 on the Customer's behalf.

9.2 FutureCalc may update the DPA in the same manner and with the same notice as the Terms of Use, and without notice where the change is required by law, a supervisory decision or new Standard Contractual Clauses.

9.3 The DPA is governed by Swedish law and disputes are resolved in accordance with section 16 of the Terms of Use.

Annex 1 – Description of processing

See section 2 above. Location of processing: the EEA, subject to the exceptions in section 6. Frequency: continuous during the term.

Annex 2 – Technical and organizational measures

FutureCalc maintains at least the following measures:

- Logical data isolation between Customer organizations at the database layer.

- Role-based access control on the principle of least privilege at the application and database layers.

- Passwords stored only in hashed form; support for strong authentication where the Service offers it.

- Encryption of data in transit and at rest using modern protocols.

- Time-limited download links for files in storage.

- Logging of administrator actions and user activity; logs retained in accordance with section 7 of the Privacy Policy.

- Forced session termination and account blocking on security events.

- Protection against automated attacks and credential stuffing at sign-in.

- Backups with defined recovery time and recovery point objectives; regular restore tests.

- Pseudonymization of development data and separate access control for such data.

- Confidentiality undertakings and data protection training for all personnel with access to personal data.

- Documented incident response process.

- Annual review of access rights, sub-processors and security measures.

Annex 3 – Categories of sub-processors

Cloud infrastructure (database, authentication, storage, hosting), compute platform, network and security services, transactional email, development and operations tools, and external interpretation service for individual interpretation steps under "no training" terms. Regions and transfer mechanisms per category are set out in section 5 of the Privacy Policy. A named list is provided on request.

Data protection contact: privacy@futurecalc.ai
