GDPR and data protection
Practical information about roles, responsibilities, data location, and security measures when Cygrids delivers infrastructure and operations services.
This is a summary - contact us for the complete agreement documents.
Who is responsible for personal data
The division of responsibility depends on which service is used, what data is processed, and what the parties have agreed.
Cygrids as data processor
When Cygrids processes personal data on behalf of a customer, it is normally done as a data processor under the customer's instructions and the applicable agreement.
Cygrids as data controller
In some administrative contexts, such as customer dialogue, agreement management, and Cygrids own support, Cygrids may be the data controller for processing where Cygrids determines the purposes and means.
Customer responsibilities
The customer is normally responsible for content, user accounts, instructions, and the personal data the customer stores or processes in the service.
Swedish operations and EU/EEA
Cygrids services are designed for Swedish operations and processing within the EU/EEA, unless otherwise explicitly agreed.
Swedish infrastructure
Production and operations use Swedish infrastructure as the starting point. Location and any specific requirements should be documented in the customer agreement or an appendix.
EU/EEA
Personal data must be processed within the EU/EEA or otherwise in a way that complies with data protection rules and the agreed setup.
Technical and organizational safeguards
Security is adapted to the service, customer environment, and agreed requirements.
Access control
Access to systems and customer environments is limited by role and need. Permissions must be manageable, reviewable, and removable when no longer needed.
Encryption and data protection
Encryption, segmentation, and other safeguards are used where relevant for the service, infrastructure, and risk level agreed by the parties.
Logging and traceability
Logging is used for operations, troubleshooting, security follow-up, and incident handling. The exact scope depends on the service and agreement.
Physical security
Data center operations include physical security, controlled access, and protection for power, cooling, and networks according to the requirements for the relevant environment.
Documentation for review
A Data Processing Agreement (DPA) is available on request and supplemented with relevant appendices when needed.
Request a DPA
Contact us via kontaktsidan if you need a Data Processing Agreement, security documentation, or other material for your review.
Document hub
Overviews, terms, and references to available documents are collected under Documents.
Company details and cookies
Registration number, VAT-ID and bankuppgifter is available during Company information. Read about how we use cookies.
Do you need GDPR documentation?
Describe which service, review, or procurement the request concerns, and we will get back to you with the right documents and contact path.