> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.pinmeto.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Data Processing Agreement (DPA)

# Data Processing Agreement


### Where can I find my latest approved Data Processing Agreement?

* You can always find this under **Legal Agreements** in your **Account Settings**. 
* If you have a **custom DPA agreement** it is available there too.

### Latest Agreement 2026-09-04

* Latest [Data Processing Agreement](https://places.pinmeto.com/listings/public/legal/dataprocessingagreement/)

## What changed in version 2.0 (4 September 2026)

Version 2.0 replaces the Data Processing Agreement published on 16 April 2024. It does not change what data PinMeTo processes, where it is processed, or which third-party sub-processors are used. All processing stays within the EEA. The changes concern how the agreement is written and who it names.

**Your processor is the PinMeTo company on your contract.** The 2024 version named PinMeTo AB as the processor for every customer, including customers whose agreement is with PinMeTo Polska sp. z o.o. Version 2.0 defines the processor as the PinMeTo company that is party to your main contract. Both companies are listed in Annex I. Where the other company's team works on your account, for example in onboarding or support, it does so as a sub-processor of your contracting company under an intra-group agreement with the same obligations.

**The European Commission's standard clauses, unmodified.** The agreement uses the standard contractual clauses for processors adopted by the European Commission (Decision 2021/915). The 2024 version had adapted the text, with renumbered clauses and some changed wording. Version 2.0 reproduces the official clauses word for word, with their official numbering. PinMeTo's own commitments sit in a separate Part B so the standard clauses remain as approved.

**Part B additional terms.** Three commitments that were not spelled out before:

* What happens if you object to a new sub-processor within the 30-day notice period. We discuss it with you. Where the change can be held back for your account alone, we do not engage the new sub-processor for your data while the objection is unresolved. Where the change concerns infrastructure shared by all customers, you may terminate the affected part of the service without penalty before the change applies.
* How optional AI services work. Services marked optional on the sub-processor list are either activated by you or, depending on your contract, on from the start with a right to switch them off. A new optional service is never switched on by default for existing customers.
* Where notices go. You reach us at privacy@pinmeto.com. We send sub-processor notices by email to the users holding the Owner role on your account, at least 30 days before a change takes effect.

**One sub-processor list.** Annex IV no longer repeats the list inside the agreement. It points to the sub-processor list on this help centre, which is dated, carries a change history, and keeps earlier versions available. The list now includes the two PinMeTo group companies. The third-party sub-processors are unchanged: Amazon Web Services, Planhat, Brevo, and Crisp, plus the optional Amazon Comprehend and Amazon Bedrock services.

**A complete Annex II.** The description of the processing now lists the categories of data subjects (left blank in 2024), states that sensitive data is never requested but may appear incidentally in reviews and messages, and describes the safeguards that apply. Retention after termination is stated as it works in practice: you can export your data before or within 30 days after termination, production data is deleted within 30 days, and encrypted backups are overwritten within a rolling 90-day cycle.

**Concrete security measures in Annex III.** The 2024 annex described security in general terms. Version 2.0 sets out the actual controls: encryption in transit and at rest, hosting in the AWS Ireland region across three availability zones, daily backups with automated restore testing, mandatory multi-factor authentication for PinMeTo personnel, regular access reviews, logs retained for at least 12 months, defined remediation deadlines for vulnerabilities, annual third-party penetration testing, and the supplier assessment process. It cites PinMeTo's ISO/IEC 27001:2022 certificate (DNV, no. C849231, covering Malmö and Gdańsk) with a public verification link, and describes how PinMeTo assists you with data subject requests, impact assessments, and breach notifications.

**A recorded acceptance.** Annex I states what PinMeTo records when the Owner user on your account approves the agreement: the version, the date and time, the approving user, your legal entity, and your contracting PinMeTo company. You can request this record at any time.

**Contact.** PinMeTo's Information Security and Data Privacy Officer, Maciej Nebelski, is named in Annex I. All data protection matters go to privacy@pinmeto.com.

**Removed.** The 2024 version inserted a "max 24 hours" deadline into the breach notification clause; version 2.0 uses the Commission's wording, "without undue delay", and describes the incident-response process and notification contents in Annex III. The 2024 version also added Data Privacy Framework language to the transfer clause. No sub-processor transfers your data outside the EEA, so that language has been removed.

## Previously Data Processing Agreement

* [Data Processing Agreement 2024-04-16](https://places.pinmeto.com/listings/public/legal/dataprocessingagreement/655b319b01bcb9f4181f7c76)
* [Data Processing Agreement 2022-02-15](https://places.pinmeto.com/listings/public/legal/dataprocessingagreement/61c05ec94661b26e7db3a905)
* [Data Processing Agreement 2020-12-17](https://places.pinmeto.com/listings/public/legal/dataprocessingagreement/5f8ec70adbed1e61b91395d1)

## Change history

| Date | Change |
| ---- |
| 4 September 2026 | Version 2.0. Processor defined as the PinMeTo company on your main contract (PinMeTo AB or PinMeTo Polska sp. z o.o.); Commission standard clauses restored unmodified with official numbering; Part B additional terms added (objection handling, optional services, notices); Annex IV replaced by a reference to the sub-processor list on the help centre; Annex II completed (data subjects, sensitive data, retention terms); Annex III rewritten with concrete security measures and the ISO/IEC 27001:2022 certificate; acceptance record described in Annex I; 24-hour breach deadline and Data Privacy Framework language removed. |
| 16 April 2024 | Previous version. |
| 15 February 2022 | Previous version. |
| 17 December 2020 | Previous version. |