Data Processing Agreement

Last updated: September 25, 2026

This Data Processing Agreement (the "DPA") forms part of Briefer's Terms of Service. It applies between Briefer Technologies AB, Swedish reg. no. 559540-9144, Herkulesgatan 12, 111 52 Stockholm, Sweden (the "Processor"), and each customer that has accepted the Terms of Service or another written agreement with Briefer (the "Controller"), whenever Briefer processes personal data on the Controller's behalf. No separate signature is needed. Customers who want a countersigned copy can request one from [email protected].

1. Background and scope

1.1 The Processor provides an investor relations platform to the Controller under Briefer's Terms of Service or another written agreement between the Parties (the "Main Agreement"). In doing so, the Processor processes personal data on behalf of the Controller.

1.2 This DPA sets out the Parties' obligations under Article 28 of Regulation (EU) 2016/679 ("GDPR") and supplementary Swedish data protection law. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the GDPR.

1.3 If this DPA conflicts with the Main Agreement, this DPA prevails for the processing of personal data.

2. Roles

2.1 The Controller determines the purposes and means of the processing and is responsible for having a lawful basis for it, including for any national identity numbers it uploads. The Processor processes personal data only on behalf of the Controller.

2.2 The subject matter, duration, nature and purpose of the processing, and the categories of personal data and data subjects, are described in Annex 1.

2.3 The Processor processes data about the Controller's own users (for example account details and product usage) as a controller for the purposes of running, securing and billing the service. That processing is described in Briefer's Privacy Policy and is outside this DPA.

3. Instructions

3.1 The Processor processes personal data only on the Controller's documented instructions. This DPA, the Main Agreement and the Controller's use and configuration of the service (for example uploading a share register or approving an investor communication) are the Controller's complete instructions at the date this DPA takes effect. Additional instructions must be in writing.

3.2 The Processor shall inform the Controller without delay if it considers that an instruction infringes the GDPR or other data protection law.

3.3 If Union or Member State law requires the Processor to process personal data other than on instructions, the Processor shall inform the Controller before processing, unless that law prohibits it.

3.4 The Processor shall not use the Controller's personal data to train or fine-tune any AI model, or to improve the service for other customers, and shall not sell it or use it for its own marketing.

4. Confidentiality

The Processor ensures that everyone authorised to process the personal data has committed to confidentiality or is under a statutory duty of confidentiality, and has access only to the extent needed to perform the service.

5. Security

5.1 The Processor implements the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.

5.2 The Processor may update those measures, provided the overall level of security is not reduced.

6. Sub-processors

6.1 The Controller gives general authorisation for the Processor to engage sub-processors. The sub-processors approved at the date of this DPA are listed in Annex 3.

6.2 The Processor shall notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If the Parties cannot resolve the objection, the Controller may terminate the affected service without penalty.

6.3 The Processor shall impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Controller for its sub-processors' performance.

7. Transfers outside the EU/EEA

7.1 The Processor stores the Controller's personal data within the EU/EEA. Some sub-processors in Annex 3 may process personal data in, or access it from, countries outside the EU/EEA.

7.2 The Processor shall transfer personal data to a third country only where a transfer mechanism under Chapter V GDPR applies, such as an adequacy decision (including the EU-US Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses, together with any supplementary measures required.

8. Assistance to the Controller

8.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). If the Processor receives such a request directly, it shall forward it to the Controller without undue delay and not respond itself unless instructed.

8.2 The Processor shall assist the Controller with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to the Processor.

9. Personal data breaches

9.1 The Processor shall notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data.

9.2 The notification shall, as far as then known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available at first notification shall be provided as it becomes available.

9.3 The Processor shall take reasonable steps to contain the breach and mitigate its effects, and shall not notify supervisory authorities or data subjects on the Controller's behalf unless instructed.

10. Audits and information

10.1 The Processor shall make available to the Controller the information necessary to demonstrate compliance with this DPA, including answers to reasonable security questionnaires and the current sub-processor certifications.

10.2 The Controller shall first request information under section 10.1. If that information is insufficient to demonstrate compliance, the Controller, or an independent auditor bound by confidentiality, may audit the Processor's compliance with this DPA once per year. Audits following a personal data breach or at the request of a supervisory authority are not limited to once per year. Audits require at least 30 days' written notice, or a shorter period if the authority requires it, take place during normal business hours without unreasonable disruption, and are at the Controller's cost.

11. Deletion and return

11.1 When the Main Agreement ends, or on the Controller's written request, the Processor shall at the Controller's choice return the personal data in a common machine-readable format and/or delete it within 30 days, unless Union or Member State law requires storage.

11.2 Copies in backups are deleted as backups are overwritten, within 7 days, and remain subject to this DPA until then. On request, the Processor shall confirm deletion in writing.

11.3 As an exception, the Processor's security audit log (records of which user performed which action, and when) may be retained for 12 months after termination to evidence security and compliance, and is then deleted. Personal data in retained entries is limited to what is needed to identify the user and the affected record. Access is restricted and the log is used for no other purpose. Business records such as share register history are Controller data and are returned or deleted under section 11.1.

12. Liability

Each Party is liable towards data subjects as set out in Article 82 GDPR. Between the Parties, liability under this DPA follows the limitations in the Main Agreement, except that no limitation applies to a Party's liability for processing in breach of the GDPR caused by its wilful misconduct or gross negligence.

13. Term

This DPA applies for as long as the Processor processes personal data on behalf of the Controller, and ends automatically when deletion or return under section 11 is complete.

14. Governing law and disputes

This DPA is governed by Swedish law. Disputes shall be settled by Swedish courts, with Stockholm District Court (Stockholms tingsrätt) as the court of first instance.

Annex 1: Description of processing

ItemDescription
Subject matterProvision of Briefer's investor relations platform to the Controller, including share register and cap table management, investor CRM, investor communications, fundraising pipeline, data room and portfolio and vehicle administration.
DurationFor the term of the Main Agreement, plus the deletion period in section 11 of the DPA.
Nature of processingCollection by upload or connected systems, storage, structuring, organisation, search and retrieval, AI-assisted analysis and drafting, transmission of communications approved by the Controller, and deletion.
PurposeTo let the Controller manage its shareholders, investors and related governance and communications through the service.
Data subjectsShareholders and holders of other securities; investors, prospective investors and members of investor networks; board members, officers and contact persons at the Controller, its portfolio companies and vehicles; other persons whose data the Controller chooses to upload.
Categories of personal dataName; contact details (email, phone, postal address); personal identity number (personnummer) or date of birth where included in a share register; company affiliation and role; shareholdings, share numbers, classes and transaction history; investment amounts and commitments; bank or payment references where included by the Controller; communications and meeting notes relating to the investor relationship.
Special categories (Art. 9 GDPR)None. The Controller shall not upload special categories of personal data or data about criminal offences.
FrequencyContinuous for the term of the Main Agreement.
Location of storageEU/EEA: Sweden (database) and the Netherlands (application hosting and knowledge graph).

Annex 2: Technical and organisational measures

Briefer holds no security certification of its own. It runs on SOC 2 Type II and/or ISO 27001 certified providers and applies the following measures.

AreaMeasures
Hosting and locationApplication services and the knowledge graph (FalkorDB) run on Railway in EU West (Amsterdam, Netherlands). The database and file storage run on Supabase in EU North (Stockholm, Sweden). Cloudflare provides CDN and DDoS protection in the EU.
EncryptionData encrypted in transit (TLS 1.2 or higher, TLS 1.3 to the database) and at rest (AES-256). Secrets stored encrypted with KMS.
Tenant isolationEvery database table enforces row-level security, so each customer's data is isolated by the database itself and not only by application code. Knowledge graph data is partitioned per customer.
Access controlProduction access limited to named individuals, each using an individual account with multi-factor authentication (no shared credentials). Access granted on a need-to-know basis and revoked when no longer needed. Customer users authenticate through Supabase Auth.
Audit loggingAppend-only audit log, tamper-resistant at the database privilege level.
Third-party connectionsConnections to the customer's other systems use OAuth through Composio's managed token store with scoped permissions. Briefer never stores third-party passwords.
AI processingAI providers (Anthropic, Cohere, OpenAI) do not use customer data for training. Anthropic and Cohere are called under zero-data-retention agreements. OpenAI, used for knowledge graph embeddings, retains API inputs for up to 30 days for abuse monitoring and then deletes them. Swedish personal identity numbers are processed only where needed to maintain statutory share registers.
Human approvalNo communication is sent to investors or other third parties without a human at the customer approving it.
EmailOutgoing email is sent through Resend in the EU with TLS, and every sending domain uses DKIM, SPF and DMARC. Open and click tracking data is retained for 24 months from send, or until deleted under section 11 of the DPA if earlier.
AnalyticsProduct analytics (Mixpanel, EU servers) receives usage events with pseudonymous user IDs only. No names, email addresses, or shareholder or investor data are sent to analytics.
PaymentsCard data goes directly to Stripe and never reaches Briefer's servers.
Backups and recoveryDaily database snapshots by Supabase, retained for 7 days and encrypted at rest. Restore testing performed quarterly.
Incident responseDocumented process to contain, assess and notify. Customers notified without undue delay, and no later than 48 hours, after Briefer becomes aware of a personal data breach.
PersonnelAll staff and contractors bound by written confidentiality obligations.
DeletionWorkspace data (investor updates, attachments, data room files, engagement events) deleted on workspace deletion, and in any case within 30 days of termination or request. Backups overwritten within 7 days. Export and deletion requests: [email protected].

Annex 3: Approved sub-processors

Customer personal data is stored in the EU. Four sub-processors process data in the United States; transfers to them rely on the EU Standard Contractual Clauses included in each provider's DPA. Providers with an EU region may still access data from outside the EU for support and operations; any such access is covered by the same clauses in their DPAs.

Sub-processorPurposeRegionData categoriesTransfer mechanism
SupabasePrimary database, authentication, file storageEU (Stockholm, Sweden)Account data, stakeholder records, files, engagement, audit logsEU region; SCCs in the provider's DPA for any access from outside the EU
RailwayApplication hosting (API, frontend, AI worker) and knowledge graph (FalkorDB)EU (Amsterdam, Netherlands)Server logs, runtime environment, stakeholder relationship graph, agent observationsEU region; SCCs in the provider's DPA for any access from outside the EU
CloudflareCDN, DDoS protection, edge cacheEURequest metadata and IP addresses (transient)EU region; SCCs in the provider's DPA for any access from outside the EU
ResendEmail delivery and open/click trackingEURecipient email, message body, open/click eventsEU region; SCCs in the provider's DPA for any access from outside the EU
MixpanelProduct analyticsEUPage views, feature usage, pseudonymous user IDsEU region; SCCs in the provider's DPA for any access from outside the EU
AnthropicAI inference for the Briefer agentUnited StatesUpdate drafts, agent prompts, retrieved context; zero retention, no trainingSCCs (Module 3) in Anthropic's DPA
CohereEmbeddings and reranking for document searchUnited StatesDocument text snippets; zero retention, no trainingSCCs in Cohere's DPA
OpenAIEmbeddings for the knowledge graphUnited StatesStakeholder relationship graph text, agent observations; up to 30 days retention, no trainingSCCs in OpenAI's DPA
ComposioConnector broker for external sources (Slack, Gmail, Drive and similar)United StatesOAuth tokens for connected accountsSCCs (Module 3) in Composio's DPA