Data Processing Agreement

Compose Group International AB  ·  glowcode.io  ·  Version 1.2  ·  Aug 2026

1. Parties of the Agreement

1.1 Data Controller

The entity (e.g., company, organization) that has entered into the Service Agreement ("Customer"). The person who has entered into the Service Agreement on behalf of the Customer is considered the contact person.

1.2 Data Processor

Compose Group International AB, Address: Tykövägen 28, 181 61 Lidingö, Sweden, Organization number: 559556-7875
Contact person: Frode Preber Ettesvoll, Title: CEO, E-mail: legal@usecompose.com
The Data Controller and Data Processor are individually referred to as "Party" and collectively as "Parties".

2. Background and Purpose of the Agreement

The Data Processor has committed to delivering the services described in the Terms of Service (https://glow.usecompose.com/legal/terms-of-service) ("Service Agreement"). The execution of this work involves the Data Processor Processing Personal Data on behalf of the Data Controller.

As the customer, the Data Controller determines the purpose of the Processing of Personal Data and the means to be used.
This Data Processing Agreement governs the Processing of Personal Data contained in Customer Content, as defined in Section 3. Personal Data that Compose processes for its own purposes and under its own responsibility (Operational Data, such as account data about Authorized Users, usage and telemetry data, error and security logs, and billing data) is processed by Compose as an independent data controller. Such processing is described in Compose's privacy policy and falls outside the scope of this Data Processing Agreement.

This data processing agreement ("Data Processing Agreement") sets out the framework for the Data Processor's Processing of Personal Data on behalf of the Data Controller.

The purpose of this Data Processing Agreement is to:

  • regulate the Parties' rights and obligations when Processing Personal Data;
  • ensure that the requirements of the Swedish Data Protection Act and GDPR are complied with in the implementation of the Service Agreement; and
  • ensure that Personal Data is not used for purposes other than those specified in this Data Processing Agreement or used without a lawful basis.

In the event of a conflict between the provisions of this Data Processing Agreement and other agreements between the Parties, including the Service Agreement, the provisions of the Data Processing Agreement shall prevail.

3. Definitions

The following definitions apply to this Data Processing Agreement:

"Data Processing Agreement" means the provisions set out in this data processing agreement with appendices.

"Personal Data" means any type of data or information that is considered personal data under the Swedish Data Protection Act and GDPR. This includes, but is not limited to, the information set out in Appendix 1.

"Processing" (of Personal Data) means any use of Personal Data, such as collection, storage, organization, alteration or adaptation, disclosure, and/or transfer.

"GDPR" means EU Regulation 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (as implemented in Swedish law).

"Personal Data Legislation" means the Swedish Data Protection Act (lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning) with supplementary regulations implementing GDPR and all other relevant legislation regulating the Parties' processing of Personal Data.

"Law" means any other applicable legislation to which the Parties are subject.

"Sub-processor" means other data processors used by the Data Processor to process the Personal Data.

"Data Subjects" means any identified or identifiable person to whom the Personal Data relates.

"System" means the Compose Glow software-as-a-service product described in the Service Agreement, a low-code platform for form building, data gathering, and workflow and process automation (currently accessible at glow.usecompose.com).

"Customer" means the company purchasing services from Compose under the Service Agreement, and is the same Party as Data Controller.

"Customer Content" means the data that the Customer or its Authorized Users upload to or register in the System (as defined in the Service Agreement), including form definitions, form submissions and responses ("Respondent Data"), workflow and process data, uploaded documents, and other free-text entries, as well as any Personal Data relating to persons who are named or otherwise identifiable in such data.

"Operational Data" means data related to the operation and use of the System that Compose processes for its own purposes as an independent data controller, including account data about the Customer's Authorized Users (such as name, e-mail address, role, and authentication data), usage and telemetry data, error and security logs, and billing data. Operational Data is not Customer Content. Compose's processing of Operational Data is described in Compose's privacy policy and is not governed by this Data Processing Agreement.

4. General

The Parties shall Process Personal Data in accordance with the Personal Data Legislation, GDPR, and this Data Processing Agreement.
The Data Processor shall only collect, record, compile, store, and otherwise Process Personal Data to the extent necessary to fulfill the Service Agreement and the Data Processing Agreement.
The Data Controller must ensure that there is a legal basis for the Processing of Personal Data.

5. Data Controller's Authority to Issue Instructions

The Data Processor shall only Process Personal Data according to documented instructions from the Data Controller.
The Data Processor may also Process Personal Data if required by Law to which the Data Processor is subject. In such a case, the Data Processor shall notify the Data Controller of the legal obligation prior to the Processing, unless the relevant Law prohibits such information from being provided for reasons of public interest.
The Data Controller's instructions to the Data Processor are set out in this Data Processing Agreement with appendices.
Appendix 1 to the Data Processing Agreement describes the categories of Personal Data the Data Processor may Process and the purpose of the Processing. The Data Processor shall not Process Personal Data for purposes other than those stated herein.
The Parties shall immediately notify each other if one Party believes that instructions or requirements from the other Party are contrary to the Personal Data Legislation or GDPR.

6. Data Processor's Duty to Assist the Data Controller

Taking into account the nature of the Processing and the information available to the Data Processor, the Data Processor shall assist the Data Controller in ensuring compliance with the Data Controller's obligations under GDPR Articles 32 – 36.

7. Personal Data Security

The Data Processor shall comply with the information security requirements of the Personal Data Legislation and GDPR, including implementing appropriate technical and organizational security measures to achieve a level of security appropriate to the risk, in accordance with GDPR Article 32.
The technical and organizational measures to be implemented are described in Appendix 2.
The Data Processor shall also assist the Data Controller in ensuring compliance with the Data Controller's obligations regarding sufficient information security in accordance with GDPR Article 32.

8. Data Processor's Use of Sub-processors

If the Data Processor engages a Sub-processor to perform specific processing activities on behalf of the Data Controller, the relevant Sub-processor shall be subject to the same obligations for the protection of personal data as set out in this Data Processing Agreement through an agreement or other legal document.
The Data Processor shall be fully liable to the Data Controller for the Sub-processor's compliance with its obligations for the protection of personal data.
The Sub-processors used by the Data Processor in connection with the Service Agreement ("List") are available to the Data Controller at https://glow.usecompose.com/legal/sub-processors. The List identifies the Sub-processors used to Process Personal Data contained in Customer Content. The Data Controller accepts that the Data Processor uses these Sub-processors.
The Data Controller accepts that the Data Processor uses Sub-processors other than those described in the current List. The Data Processor will provide the Data Controller a mechanism to subscribe to notifications about new Sub-processors and the Data Controller, if it wishes, will subscribe to such notifications where available. If the Data Controller does not subscribe to such notifications, the Data Controller waives any right it may have to receive prior notice of changes in Sub-processors. At least twenty (20) days before the Data Processor grants a third party other than existing Sub-processors access to perform specific processing activities on Personal Data, the Data Processor will add such third party to the List and notify subscribers, including the Data Controller, via the aforementioned notifications. The Data Controller may object to such an agreement by informing the Data Processor in writing and based on objective grounds related to data protection. The Data Controller acknowledges that certain Sub-processors are necessary to provide the Service, and that objection to the use of a Sub-processor may prevent the Data Processor from providing the Service to the Data Controller.
If the Data Controller reasonably objects to an engagement in accordance with this Section 8, and the Data Processor cannot offer a commercially satisfactory alternative within a reasonable time, the Data Controller may discontinue the use of the Service by giving written notice to the Data Processor. The discontinuation shall not relieve the Data Controller of any fees owed to the Data Processor under the Service Agreement.
If the Data Controller does not object to the use of the new Sub-processor in accordance with this Section 8 within twenty (20) days of notification from the Data Processor, the relevant third party will be considered a Sub-processor in connection with this Data Processing Agreement.

9. Data Processor's Transfer of Personal Data Abroad

The Data Processor shall not transfer Personal Data contained in Customer Content to countries outside the EU/EEA area or to an international organization without the prior written consent of the Data Controller, unless the European Commission has determined that the country or international organization ensures an adequate level of protection.
If the Data Controller accepts such a transfer of Personal Data to a country outside the EU/EEA area or to an international organization, the Data Processor shall ensure that the transfer takes place in accordance with the rules in GDPR Chapter V, including assessing the level of protection in the third country or third countries to which personal data is to be transferred, and to ensure that supplementary measures of a technical, organizational, or contractual nature are implemented to ensure a level of protection essentially equivalent to that in the EU/EEA.
Note: The System hosts Customer Content within the EU/EEA, in Microsoft Azure (Norway East region) and Google Cloud. Sub-processors and hosting locations are set out in the List referenced in Section 8.

10. Handling of Data Subjects' Rights

The Data Controller shall be the point of contact for Data Subjects and provide necessary information about the Processing.
The Data Controller is responsible for handling Data Subjects' requests for access, rectification, erasure, restriction, data portability, etc., and for ensuring that such requests are met.
The Data Processor shall, taking into account the nature of the Processing and to the extent possible by means of appropriate technical and organizational measures, assist the Data Controller in fulfilling the Data Controller's obligation to respond to requests that Data Subjects submit with a view to exercising their rights set out in GDPR Chapter III.
If the Data Processor receives a request from the Data Subject, the Data Processor shall notify the Data Controller as soon as possible.

11. Incident Management and Notification

Any use of information systems in violation of the Data Processor's established procedures, the Data Controller's instructions, the Personal Data Legislation, or GDPR, as well as any other security breach, shall be handled as an incident.
The Parties shall establish and maintain procedures and systematic measures for following up on incidents, including measures for restoring normal conditions, removing the cause of the incident, and preventing recurrence.
The Parties shall, as soon as they become aware of an incident, without undue delay and no later than within 36 hours, inform each other of any security breaches and immediately implement all necessary and appropriate measures to restore normal conditions.
The Data Controller is responsible for sending a breach notification to the Data Protection Authority and Data Subjects in accordance with GDPR Articles 33 and 34. The Data Processor shall, if necessary, assist the Data Controller in ensuring that GDPR Articles 33 and 34 are complied with.

12. Audit and Inspection

The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the Data Processor's obligations under the Personal Data Legislation, GDPR, and this Data Processing Agreement.
The Data Processor shall enable and contribute to audits, including inspections, conducted by the Data Controller or another inspector authorized by the Data Controller, of the Data Processor's compliance with GDPR, the Personal Data Legislation, and this Data Processing Agreement. The Data Controller has the right to conduct such audits at its own expense, up to once a year with four weeks' prior notice.

13. Confidentiality and Duty of Secrecy

The Data Processor has a duty of confidentiality regarding the Personal Data and the documentation that the Data Processor gains access to through the Data Processing Agreement. The duty of confidentiality also applies after the termination of the Data Processing Agreement.
The Data Processor shall not disclose or provide access to the Personal Data to anyone other than its own employees, Sub-processors, or employees of the Data Controller, unless this has been agreed in writing with the Data Controller or follows from law, regulation, or decision of a public authority.
The Data Processor shall ensure that persons authorized to Process the Personal Data have committed themselves to treating the information confidentially in the form of a confidentiality agreement or are subject to an appropriate statutory duty of confidentiality.

14. Duration of the Agreement

The Agreement applies as long as the Data Processor processes Personal Data on behalf of the Data Controller.

15. Termination

When the Data Processing Agreement terminates, the Data Processor shall return all Personal Data covered by the Data Processing Agreement in a format suitable for further Processing by the Data Controller or a third party designated by the Data Controller.
The Data Controller may alternatively require that the Personal Data be deleted and/or destroyed in accordance with the Data Controller's written instructions.
The Parties shall agree on how the transfer, or deletion and/or destruction, shall specifically take place.
The Data Processor shall document in writing that deletion and/or destruction has been carried out in accordance with the agreement within a reasonable time after the Data Processing Agreement terminates.
Exceptions apply if the Personal Data Legislation, GDPR, or Law requires that the Personal Data be stored further.

16. Amendments

The Data Processor may update this Data Processing Agreement from time to time, for example to reflect changes in law, in Sub-processors, or in the System. The current version is always available at this page.
In the event of material changes that reduce the Data Controller's rights or the level of protection under this Data Processing Agreement, the Data Processor shall notify the Data Controller at least thirty (30) days before the changes take effect, for example by e-mail to the Customer's registered contact persons or by notice in the System. If the Data Controller does not object in writing before the changes take effect and continues to use the System after that date, the updated version applies between the Parties. If the Data Controller objects on reasonable grounds related to data protection and the Parties do not reach agreement, the Data Controller may terminate the Service Agreement in accordance with its termination provisions.
Upon acceptance, the most recent version of the Data Processing Agreement replaces all previous versions, including previously signed copies of earlier versions.

17. Choice of Law and Venue

The Agreement is governed by Swedish law. The Parties agree on Stockholm District Court (Stockholms tingsrätt) as the legal venue.

Appendices to the Agreement

  • Appendix 1: Description of the personal data and the purpose of the processing
  • Appendix 2: Technical and organizational measures for information security

Appendix 1: Description of the Personal Data and the Purpose of the Processing

Type of personal data

  • Personal Data contained in Customer Content: information about persons that the Customer or its Authorized Users enter into, or upload to, forms, fields, workflows, or documents where free text can be entered — such as form respondents, contact persons, references, and other persons named or otherwise identifiable in form submissions, workflow data, and uploaded documentation.
  • Account data about the Customer's Authorized Users (such as name, e-mail address, role, and authentication data) and technical data related to the use of the System (such as security logs, IP address, and registration of activities and use) are Operational Data that Compose processes as an independent data controller in order to provide, secure, and improve the System. Such processing is described in Compose's privacy policy and is not part of the Processing governed by this Data Processing Agreement.

Category of data subjects

  • The Customer's employees, partners, and consultants, to the extent they are named in Customer Content.
  • Respondents and other persons who submit data through forms created by the Customer using the System.
  • Other persons who can be identified in information or documentation entered into the System.

Purpose of processing

To deliver the System Compose Glow as described in the Service Agreement, a Software as a Service (SaaS) product for form building, data gathering, and workflow and process automation, including relevant services such as customer support. The Data Controller will use the System to design forms, collect and manage responses, build and automate workflows, and integrate with other systems in accordance with the Service Agreement.

Appendix 2: Technical and Organizational Security Measures

To protect Personal Data, Compose has implemented the following security measures:

Data Protection

  • Encryption: Compose encrypts Personal Data both when it is stored and when it is transmitted over networks, using only recommended secure cipher suites and protocols. This ensures that the information is unreadable to unauthorized persons.
  • Access Control: Compose uses strict access controls to ensure that only authorized persons have access to the data. This includes multi-factor authentication and Single Sign-On (SSO), and supported authentication providers such as ID-porten, BankID, and Azure AD.
  • Backup: Compose takes regular backups of data to ensure that it can be restored in the event of an incident. Backups are periodically tested in accordance with information security and data management policies.
  • Logging: Compose monitors access to applications, tools, and resources that process or store Personal Data, including cloud services. Log activities are investigated when necessary and escalated appropriately.
  • Monitoring: Compose continuously monitors its systems to detect and respond to potential security threats.
  • Hosting: Customer Content is hosted within the EU/EEA in Microsoft Azure (Norway East region) and Google Cloud.

Organizational Security

  • Confidentiality: Compose has strict confidentiality agreements with all its employees.
  • Risk Management: Compose has a comprehensive risk management program to identify and manage potential security risks.
  • Data Minimization: Compose only collects and stores the data that is necessary to deliver its services.
  • Data Quality: Compose has implemented measures to ensure that data is accurate and up-to-date.
  • Limited Data Storage: Compose only stores data for as long as it is necessary.
  • Security Training: All employees go through security training yearly and at the beginning of their employment.
  • Change Management: Compose adheres to a change management process to administer changes to the production environment for the Services, including changes to its underlying software, applications, and systems. All production changes are automated through CI/CD tools to ensure consistent configurations.
  • Accountability: Compose has adopted measures for ensuring accountability, such as implementing data protection and information security policies across the business, recording and reporting Personal Data Breaches, and formally assigning roles and responsibilities for information security and data privacy functions.

Sub-processors

  • Data Processing Agreements: Compose enters into data processing agreements with all its sub-processors, which impose on them similarly strict or stricter security obligations than Compose.

Data Portability and Deletion

The Customer can request to have its data exported or deleted at any time.
Compose is committed to protecting Personal Data and takes security seriously. Compose is constantly working to improve its security measures to ensure that the data is safe.

Related documents: Terms of Service | Privacy Policy