This Data Processing Agreement (the "DPA") forms part of the Agreement between Limitless Design Sweden AB, Swedish company registration number 559251-7683 ("Seller" or "Processor"), and the business customer using Limitless Plant ("Customer" or "Controller"). It applies only to the extent Seller processes Personal Data on Customer's behalf as a processor under the GDPR.
Capitalized terms not defined in this DPA have the meanings given in the General Terms and Conditions. "Personal Data", "Controller", "Processor", "Personal Data Breach" and "Subprocessor" have the meanings given in applicable data protection law.
1. Roles, instructions and scope
Customer is the Controller for Personal Data processed by Seller on Customer's behalf and is responsible for the lawfulness of the processing, its legal basis, required information to data subjects and the lawfulness of its instructions.
Seller shall process Personal Data only to provide, operate, secure and support Limitless Plant, in accordance with the Agreement, this DPA and Customer's documented lawful instructions, or as otherwise required by applicable EU or Member State law. The Agreement and the Customer's ordinary use and configuration of the Services constitute documented instructions.
If Seller is required by law to process Personal Data outside Customer's instructions, Seller shall inform Customer before doing so unless prohibited by law. Seller shall inform Customer if, in Seller's reasonable opinion, an instruction infringes applicable data protection law and may suspend the affected processing until the issue is resolved.
This DPA does not apply to processing for which Seller independently determines the purposes and means and therefore acts as a Controller. Such processing is described in Seller's Privacy Policy.
2. Details of processing
The subject matter, duration, purposes, types of Personal Data and categories of data subjects are described in Schedule 1. Processing continues for the period necessary to provide the Services and for any limited period required for support, return, deletion, backups or legal retention.
3. Confidentiality, security and Personal Data Breaches
Seller shall ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations and process Personal Data only as permitted by this DPA.
Seller shall maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risks of the processing, taking account of the nature of the processing, reasonably foreseeable risks, state of the art and implementation costs. General categories of measures are described in Schedule 2. Seller may update its measures provided the overall level of protection is not materially reduced.
Seller shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA and shall provide information reasonably available to Seller that Customer needs to meet its applicable breach-notification obligations. Information may be provided in stages. A notification is not an admission of fault or liability.
4. Subprocessors and international transfers
4.1 Subprocessors
Customer gives Seller general authorization to engage Subprocessors reasonably necessary to provide, operate, secure or support the Services. Seller shall require each Subprocessor to be bound by data protection obligations appropriate to the processing and remains responsible for its Subprocessors to the extent required by applicable law.
Seller shall make a current Subprocessor list available through the Services, Seller's website or on reasonable request and shall provide reasonable prior notice of intended additions or replacements. Customer may object within ten (10) Business Days on reasonable and documented data protection grounds. If the parties cannot reasonably resolve the objection, Seller may provide an alternative where reasonably practicable or terminate the affected Service and provide a pro-rata credit or refund for the unused part of the affected Access Period.
4.2 International transfers
Seller shall not transfer Personal Data outside the European Economic Area except in accordance with applicable data protection law. Where required, Seller shall use a lawful transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses together with any additional safeguards required in the circumstances.
5. Assistance and data subject requests
Taking into account the nature of the processing and information available to Seller, Seller shall provide reasonable assistance required under Article 28 GDPR in relation to data subject requests, security of processing, Personal Data Breaches, data protection impact assessments and prior consultations with supervisory authorities.
If Seller receives a request from a data subject concerning Personal Data processed solely on Customer's behalf, Seller may refer the request to Customer and shall not respond substantively except on Customer's documented instructions or where required by law.
Seller may charge reasonable fees for material assistance beyond the ordinary operation of the Services unless the assistance is required because of Seller's breach of this DPA.
6. Return and deletion
After expiry or termination of the relevant Services, Customer may request return of Personal Data that is reasonably exportable from the Services within thirty (30) days, unless another period is agreed or required by law. Seller may provide such data in a standard format reasonably selected by Seller.
After the applicable retrieval period, Customer instructs Seller to delete or irreversibly anonymize the Personal Data unless Customer has requested return or applicable law requires retention. Personal Data may remain in ordinary backup or disaster-recovery systems until overwritten or deleted in the normal course, provided it remains protected and is not restored for ordinary business use except where necessary for recovery, security or legal compliance.
7. Compliance information and audits
Seller shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Seller may satisfy this obligation through appropriate security information, policies, summaries, independent assessments or reasonable compliance questionnaires where available.
If that information is not reasonably sufficient, Customer may request an audit of Seller's processing of Customer Personal Data. Unless required because of a Personal Data Breach, a supervisory authority request or reasonable evidence of material non-compliance, an audit may occur no more than once in any twelve-month period, on at least thirty (30) days' notice, during normal business hours, subject to confidentiality and without unreasonable disruption or access to other customers' information. Customer bears its own and Seller's reasonable audit costs unless the audit identifies a material breach of this DPA by Seller.
8. Liability, term and relationship with the Agreement
The exclusions, limitations and liability cap in the General Terms apply to this DPA and claims arising from processing under it. Nothing limits rights, liability or regulatory powers that cannot lawfully be limited under applicable data protection law. This DPA does not create a separate or additional liability cap.
This DPA takes effect automatically when the Agreement applies and Seller begins processing Personal Data on Customer's behalf. It remains in effect for as long as Seller processes such Personal Data. If this DPA conflicts with the General Terms regarding Processor processing, this DPA prevails to the extent of that conflict. The same governing-law and dispute provisions as the General Terms apply.
Schedule 1. Details of Processing
1. Subject matter and purpose
Processing of Personal Data relating to the Customer's Company Account and Authorized Users as necessary to create and administer user access, provide online courses and Subscription Packages, record access and course-related activity where the Service supports it, provide support, maintain security and otherwise provide Limitless Plant in accordance with the Agreement.
2. Duration
For the relevant Access Periods and any limited period thereafter required for account administration, support, return, deletion, backup retention or compliance with applicable law.
3. Categories of data subjects
- Customer company administrators and business contacts.
- Customer employees and other Authorized Users permitted to use Limitless Plant.
4. Types of Personal Data
- Name, business email address and company affiliation.
- Account and user identifiers.
- Subscription Package selection and Access Period information.
- Login, access and platform activity information.
- Course progress, completion or similar course activity information where generated by the Service.
- Technical and security information such as IP address, browser/device information and logs.
- Support communications and related information.
The Services are not intended for special categories of Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions or offences under Article 10 GDPR unless expressly agreed in writing.
5. Nature of processing
Collection, receipt, hosting, storage, organization, retrieval, display, transmission, support, security processing, backup and deletion as necessary to provide the Services.
Schedule 2. General Security Measures
Seller shall maintain security measures appropriate to the risks associated with the processing. Without representing that any specific certification or technical standard applies unless separately confirmed, the measures include controls appropriate to Seller's environment in the following areas:
- Access control and authentication designed to limit access to persons who need it for their responsibilities.
- Confidentiality obligations for personnel with access to Personal Data.
- Reasonable system protection, security updating and vulnerability-management practices.
- Logging, monitoring, backup and recovery measures appropriate to the Services.
- Measures designed to protect Personal Data against unauthorized disclosure, alteration, loss or destruction during storage and transmission, where appropriate.
- Procedures for identifying, assessing, escalating and responding to security incidents and Personal Data Breaches.
- Appropriate contractual and security controls for relevant service providers and Subprocessors.