Gridheart Data Processing Terms

    Version 2026-10, effective 9 October 2026. Replaces the Gridheart Data Processing Terms, version 2026-03, including Appendix 1.

    1. Scope, roles and order of precedence

    1.1 Parties. These Data Processing Terms are entered into between Gridheart AB, reg. no. 556779-9209 ("Gridheart"), and the partner that has accepted the Gridheart Partner Terms ("You"). They form part of the Partner Terms and fulfil the requirements of Article 28(3) GDPR and the equivalent provisions of the UK GDPR. Capitalised terms not defined here have the meaning given in the Partner Terms.

    1.2 Scope. These Data Processing Terms apply only to Personal Data that Gridheart processes on Your behalf when providing the Gridheart Services, as described in Appendix 1 ("Partner Personal Data").

    1.3 Roles. For Partner Personal Data, You are the controller, or a processor acting on behalf of Your Customer, and Gridheart is Your processor or sub-processor. If You act as processor, You warrant that Your instructions, including the appointment of Gridheart, are authorised by the relevant controller, and You are the only party that may give Gridheart instructions.

    1.4 Outside the scope. These Data Processing Terms do not apply to:

    1. Personal Data that Gridheart processes as controller for its own purposes, such as managing the partner relationship, invoicing, credit, sanctions and fraud checks, marketing, analysing, developing and improving the Platform and Gridheart's services under Section 10.1 of the Partner Terms, and complying with law, which is governed by Section 10.5 of the Partner Terms and Gridheart's privacy notice; and
    2. processing by Vendors in or through Third-party Products. Vendors process such data under their own data processing terms with You or Your Customer. Gridheart is not a party to, and not responsible for, that processing.

    1.5 Precedence. For the processing of Partner Personal Data, these Data Processing Terms prevail over the rest of the Partner Terms. Liability is always governed by Section 15 of the Partner Terms.

    2. Definitions

    "Data Protection Law" means the GDPR (Regulation (EU) 2016/679), the Swedish Data Protection Act (2018:218), the UK GDPR and the UK Data Protection Act 2018, and any other data protection law that applies to the processing of Partner Personal Data.

    "Data Incident" means a breach of Gridheart's security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Partner Personal Data on systems managed or controlled by Gridheart. Unsuccessful attempts that do not compromise Partner Personal Data, such as failed login attempts, pings, port scans and denial-of-service attacks, are not Data Incidents.

    "Personal Data", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR.

    "Restricted Transfer" means a transfer of Partner Personal Data to a country outside the EEA, or for UK data outside the UK, that is not covered by an adequacy decision or adequacy regulations.

    "Standard Contractual Clauses" means the clauses adopted by the European Commission in Decision (EU) 2021/914 and, for UK data, the UK International Data Transfer Addendum, in each case as amended or replaced.

    "Sub-processor" means a third party engaged by Gridheart to process Partner Personal Data.

    3. Instructions and processing

    3.1 Your instructions. Gridheart processes Partner Personal Data only on Your documented instructions. The Partner Terms, these Data Processing Terms, Appendix 1 and Your use and configuration of the Platform are Your complete instructions. Further instructions must be agreed in writing, and Gridheart may charge for implementing them.

    3.2 Processing required by law. Gridheart may process Partner Personal Data where required by EU or Member State law, or UK law for UK data. Gridheart will inform You before such processing unless the law prohibits it.

    3.3 Infringing instructions. Gridheart will inform You without undue delay if, in its opinion, an instruction infringes Data Protection Law. Gridheart may suspend the processing concerned until You confirm or change the instruction. Gridheart is not obliged to check whether Your instructions are lawful.

    3.4 Your responsibilities. You are responsible for the lawfulness of the processing, including having a legal basis, informing data subjects and ensuring that Partner Personal Data is accurate. You must not provide special categories of Personal Data, or Personal Data relating to criminal convictions, to Gridheart unless Gridheart has agreed to this in writing.

    3.5 Records. Each party keeps the records of processing that Article 30 GDPR requires of it. You must provide Gridheart with the information it reasonably needs for its records.

    4. Confidentiality and security

    4.1 Confidentiality. Gridheart ensures that everyone it authorises to process Partner Personal Data is bound by a duty of confidentiality, by contract or by law, and only has access to the extent needed for their tasks.

    4.2 Security measures. Gridheart implements the technical and organisational measures described in Appendix 2, which are designed to provide a level of security appropriate to the risk, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing. Gridheart may update the measures, provided the overall level of security is not reduced.

    4.3 Your security. You are responsible for the security of Your own systems, accounts and devices used to access the Platform, including keeping credentials secure, using multi-factor authentication and managing Your Users' access rights. You acknowledge that the measures in Appendix 2 provide a level of security appropriate to the risk for Partner Personal Data.

    5. Data Incidents

    5.1 Notification. Gridheart will notify You without undue delay after becoming aware of a Data Incident, and where feasible within forty-eight (48) hours. Gridheart will take reasonable steps to contain the Data Incident and limit its effects.

    5.2 Content. The notification will describe, as far as the information is available, the nature of the Data Incident, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Gridheart may provide the information in stages.

    5.3 Delivery. Notifications are sent to the administrators of Your account or the security contact You have registered in the Platform. You must keep these contacts up to date.

    5.4 Your obligations. You are responsible for assessing whether to notify supervisory authorities, data subjects or Customers, and for making any such notification. Gridheart's notification of a Data Incident is not an acknowledgement of fault or liability.

    6. Sub-processors

    6.1 General authorisation. You give Gridheart general written authorisation to engage Sub-processors. This includes Gridheart's Affiliates and the Sub-processors listed at gridheart.com/sub-processors on the date You accept these Data Processing Terms.

    6.2 Requirements. Gridheart will impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as these Data Processing Terms, as required by Article 28(4) GDPR. Gridheart remains responsible to You for the performance of its Sub-processors' obligations, subject to Section 11.

    6.3 Changes. Gridheart will inform You of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance, by updating the sub-processor list and notifying You in the Platform or by email. Where a change is needed urgently to maintain the service or security, Gridheart may give shorter notice.

    6.4 Objection. You may object to a new Sub-processor within five (5) calendar days of the notice, on reasonable grounds relating to data protection, by notice to legal@gridheart.com. The parties will discuss the objection in good faith. If no solution is found within thirty (30) days, You may, as Your sole remedy, stop using the Gridheart Service concerned by notice to Gridheart. Commitments and Fees already incurred remain payable. If You do not object in time, the new Sub-processor is approved.

    7. International transfers

    7.1 Location. Gridheart aims to process Partner Personal Data within the EU/EEA. The locations of Sub-processors are shown in the sub-processor list.

    7.2 Safeguards. Gridheart will not make a Restricted Transfer unless an appropriate safeguard under Data Protection Law is in place, such as the Standard Contractual Clauses, supplemented where required by a transfer impact assessment and additional measures, or the transfer is covered by an adequacy decision, including the EU-US Data Privacy Framework for certified recipients.

    7.3 Your authorisation. You authorise Gridheart to enter into Standard Contractual Clauses with Sub-processors on Your behalf, or on behalf of Your Customers where You act as processor, where this is needed for a Restricted Transfer. Where a transfer from You to Gridheart is itself a Restricted Transfer, the parties will enter into the applicable Standard Contractual Clauses on request.

    8. Assistance, data subject requests and impact assessments

    8.1 Data subject requests. Taking into account the nature of the processing, Gridheart will assist You by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects to exercise their rights under Chapter III GDPR. Where available, You must use the functions in the Platform to do so. If Gridheart receives a request directly, it will refer the data subject to You and will not respond itself, except to confirm the referral.

    8.2 Other assistance. Taking into account the nature of the processing and the information available to it, Gridheart will assist You in ensuring compliance with Articles 32 to 36 GDPR, including security, Data Incidents, data protection impact assessments and prior consultation with supervisory authorities.

    8.3 Fees. Gridheart may charge for assistance under this Section at its current hourly rates, unless the assistance is needed because of Gridheart's own breach of these Data Processing Terms or is available through standard functions of the Platform.

    8.4 Requests from authorities. If Gridheart receives a request from a supervisory authority or other public authority concerning Partner Personal Data, it will inform You without undue delay, unless prohibited by law.

    9. Audits and information

    9.1 Information. Gridheart will make available to You the information reasonably necessary to demonstrate compliance with Article 28 GDPR, primarily through these Data Processing Terms, Appendix 2, its sub-processor list and, where available, certifications, audit reports and completed security questionnaires.

    9.2 Audits. If that information is not sufficient, or a supervisory authority requires it, You may audit Gridheart's compliance, by Yourself or through an independent auditor that is bound by confidentiality and is not a competitor of Gridheart, on the following conditions:

    1. no more than once in any twelve (12) month period, unless a supervisory authority requires it or after a Data Incident;
    2. on at least thirty (30) days' written notice, with scope, timing and duration agreed in advance;
    3. during Business Hours and without unreasonable disruption of Gridheart's operations;
    4. without access to other partners' data, Gridheart's internal financial information, trade secrets or information that could compromise security; and
    5. at Your cost, including reimbursement of Gridheart's time at its current hourly rates.

    9.3 Sub-processors. Audits of Sub-processors are carried out by relying on the Sub-processors' own certifications and audit reports, which Gridheart will make available on request where it is permitted to do so.

    10. Return and deletion

    10.1 During the term. You can export and delete Partner Personal Data through the functions of the Platform. Gridheart will assist with other reasonable deletion requests under Section 8.3.

    10.2 At the end of the term. On termination of the Partner Terms, You may within thirty (30) days request a copy of Partner Personal Data in a standard export format. After that, Gridheart will delete or anonymise Partner Personal Data within ninety (90) days.

    10.3 Exceptions. Gridheart may keep Partner Personal Data to the extent required by law, for example accounting records that must be kept for seven (7) years under the Swedish Bookkeeping Act, and copies in backups until they are overwritten in the normal backup cycle. Retained data remains subject to these Data Processing Terms and is processed only for the purpose for which it is retained.

    11. Liability, term and changes

    11.1 Liability. Liability under these Data Processing Terms is governed by Section 15 of the Partner Terms, including Gridheart's cap and the excluded losses. This does not affect data subjects' rights against either party under Article 82 GDPR. If Gridheart pays compensation to a data subject, or a fine, for damage that is wholly or partly due to You, You must reimburse Gridheart for Your share in accordance with Article 82(5) GDPR.

    11.2 Term. These Data Processing Terms apply for as long as Gridheart processes Partner Personal Data on Your behalf, including after termination of the Partner Terms until the data has been deleted under Section 10.

    11.3 Changes. Gridheart may change these Data Processing Terms in accordance with Section 16 of the Partner Terms. Gridheart will not make a change that reduces the overall protection of Partner Personal Data, unless the change is required by Data Protection Law or a supervisory authority.

    11.4 Governing law. These Data Processing Terms are governed by Swedish law, and disputes are resolved in accordance with Section 17 of the Partner Terms, except where Data Protection Law or the Standard Contractual Clauses require otherwise.

    Appendix 1: Details of processing

    ItemDescription
    Subject matterProvision of the Platform and other Gridheart Services to You under the Partner Terms
    DurationThe term of the Partner Terms and the deletion period in Section 10
    Nature of processingCollection, recording, storage, organisation, retrieval, use, transmission to Vendors and connected systems, and deletion
    PurposesOrdering, provisioning and administering Products for You and Your Customers; calculating usage and Fees; billing and invoicing support, including through Your connected accounting systems; the customer portal; support; reporting to Vendors as required to provide, bill and report the Products; and security and fraud prevention for the Platform
    Data subjectsYour employees and contractors who use the Platform; contact persons and users at Your Customers; end users whose identifiers appear in Vendor Usage Data or licence assignments
    Personal DataNames, business email addresses, phone numbers, job titles, user and account identifiers, login and audit logs, IP addresses, licence assignments, usage records linked to users or devices, and the content of support tickets
    Special categoriesNone. You must not provide special categories of Personal Data under Section 3.4
    Sub-processorsAs listed at gridheart.com/sub-processors
    RetentionAs set out in Section 10

    Appendix 2: Security measures

    Gridheart has the following measures in place for the Platform. Gridheart reviews them periodically and when the Platform or the risks change, and may update them under Section 4.2.

    1. User access. Each User has an individual account. Sign-in to the Platform uses multi-factor authentication. Access rights are role-based, and administrative functions are limited to authorised Gridheart personnel.

    2. Separation of partner data. Database-level access rules restrict each partner's Users to the data of their own organisation.

    3. Credentials. Partner API keys are stored only in hashed form. Credentials for connected Vendor and accounting systems are stored encrypted in a dedicated secrets store and are not exposed to the browser.

    4. Encryption. Partner Personal Data is encrypted in transit using TLS and encrypted at rest by the hosting provider.

    5. Hosting and backup. The Platform is hosted on cloud infrastructure provided by the Sub-processors listed at gridheart.com/sub-processors, which are responsible for the physical security of their data centres and take regular backups of the Platform database.

    6. Audit trail. Administrative actions and changes to billing-relevant data are recorded in an audit log that is accessible only to authorised personnel.

    7. Change control. Changes to the Platform's code are version-controlled, so that each change can be traced and rolled back.

    8. Personnel. Only Gridheart personnel who need access to Partner Personal Data for their tasks are given it, and they are bound by confidentiality under Section 4.1.

    9. Incidents. Security incidents are handled and notified in accordance with Section 5.

    10. Sub-processors. Sub-processors are engaged under written data protection terms in accordance with Section 6.