GDPR and data protection
Practical information about roles, responsibilities, data location, and security measures when Cygrids delivers infrastructure and operations services.
This is a summary. Contact us for the full contractual documentation.
Responsibility for personal data
The division of responsibility depends on which service is used, what data is processed, and what the parties have agreed.
Cygrids as data processor
When processing personal data on a customer’s behalf, Cygrids normally acts as a data processor under the customer’s instructions and the applicable agreement.
Cygrids as data controller
In certain administrative contexts, such as customer communications, contract administration, and Cygrids’ own support services, Cygrids may act as the data controller when it determines the purposes and means of processing.
Customer responsibilities
The customer is normally responsible for content, user accounts, instructions, and the personal data the customer stores or processes in the service.
Swedish operations and EU/EEA
Cygrids services are designed to operate in Sweden and process data within the EU/EEA, unless expressly agreed otherwise.
Swedish infrastructure
Production services run on infrastructure in Sweden and are operated from Sweden by default. The location and any specific requirements should be documented in the customer agreement or an appendix.
EU/EEA
Personal data must be processed within the EU/EEA or in another manner that complies with applicable data protection law and the agreed service configuration.
Technical and organizational safeguards
Security is adapted to the service, customer environment, and agreed requirements.
Access control
Access to systems and customer environments is restricted according to role and operational need. Permissions must be managed, reviewed, and revoked when they are no longer required.
Encryption and data protection
Encryption, segmentation, and other safeguards are used where relevant for the service, infrastructure, and risk level agreed by the parties.
Logging and traceability
Logging supports operations, troubleshooting, security reviews, and incident response. The precise scope depends on the service and the agreement.
Physical security
Data center operations include physical security, controlled access, resilient power and cooling, and multiple network paths suited to the requirements of the relevant environment.
Documentation for review
A Data Processing Agreement (DPA) is available on request and supplemented with relevant appendices when needed.
Request a DPA
Contact us via the contact page if you need a Data Processing Agreement, security documentation, or other material for your review.
Document hub
Overviews, terms, and links to available documents are provided under Documents.
Company details and cookies
Registration number, VAT ID, and bank details are available under Company information. Read about how we use cookies.
Do you need GDPR documentation?
Tell us which service, audit, or procurement process your request relates to, and we will provide the appropriate documents and point of contact.