# Data Processing Agreement

Version 1.0 — Personal-data processing for Cofleet’s hosted and managed service.

## Cover Page

Provider: Cofleet AB, company registration number 559594-0965, Finn Malmgrens väg 52, 121 38 Johanneshov, Sweden.

Customer: The organisation identified in the accepted Cofleet Terms of Service and workspace signup or onboarding record.

Agreement: The Cofleet Terms of Service, accepted Pilot Details and this DPA. A separately agreed DPA governing the same processing takes priority.

Provider Security Contact: markus@cofleet.app.

Customer Contact: The administrator designated in the workspace record, including the customer’s legal address and contact email. The customer must keep those records current.

Effective Date: The date of explicit acceptance of the Agreement incorporating this DPA. Acceptance must be by a person authorised to bind the customer. Viewing the DPA is not acceptance; no separate signature is required where it is validly incorporated and electronically accepted.

Standard Terms: This Cover Page and its annexes incorporate the Common Paper DPA Standard Terms, version 1.1, at https://commonpaper.com/standards/data-processing-agreement/1.1/. Defined terms have the meanings in those terms or the Agreement. The modifications below take priority over inconsistent DPA Standard Terms, subject to applicable transfer clauses and mandatory law.

Governing Member State: Sweden.

## Annex I — Parties and processing

Roles: Cofleet acts as processor when the customer is controller, and as subprocessor where the customer processes data for another controller. The customer must have any required upstream authorisation. Each party remains responsible for its independent processing of business contact and billing information.

Service and purpose: Organise, index and retrieve the customer’s selected company knowledge and provide relevant context to its authorised users and connected AI tools. Process account, access and operational records as needed to deliver, secure, troubleshoot and support that service.

Operations: Receive selected documents, notes and work communications; extract text and facts; store originals and authorised copies; create embeddings and indexes; consolidate and retrieve memories; process prompts and generate outputs; provide authorised context and citations through the app, API or MCP; manage access and background jobs; and return or erase the resulting data.

Instructions: The customer instructs Cofleet through the accepted Agreement, its selection of sources, permitted users, configuration and written instructions acknowledged by Cofleet. Enabling a connector does not authorise importing an entire account. Internal chat or external notifications are included only where enabled by the customer. Cofleet may not expand the permitted purposes or data categories solely by posting a notice.

Data subjects: Authorised users and employees, and customer, supplier and other business contacts whose information appears in the selected content.

Personal data: Names, business contact details, roles and work communications; selected document contents, titles and source metadata; prompts, context and outputs; account and workspace identifiers, permissions and timestamps; connector identifiers and credentials; and operational, access, security and support records relating to individuals.

Excluded data: GDPR Article 9 special-category data, criminal-offence data, national identification numbers and the other prohibited data in the Terms of Service. These cannot be added without a separate written agreement and safeguards.

Customer-controlled sources and recipients: Systems connected and tools or destinations explicitly authorised by the customer in the workspace or onboarding record. A customer-selected provider is not automatically a Cofleet subprocessor. Where Cofleet engages that provider, it must be listed and authorised in Annex III. Cofleet’s source-grant and workspace controls do not promise continuous replication of every source system’s permissions.

Frequency: On import, update, query, model processing and other customer-authorised use of the service.

Duration: During the accepted service period and the necessary return/deletion process. Any lawful residual retention remains restricted and protected by this DPA.

## Annex II — Security and lifecycle

Access and confidentiality: Cofleet must apply measures appropriate to the risks under GDPR Article 32, restrict access to authorised personnel bound by confidentiality, isolate customer workspaces, protect credentials, revoke access when no longer required and maintain incident response. Cofleet personnel have full administrative access and work from Sweden. They may access customer personal data only as necessary to provide, secure and support the service or follow the customer’s documented instructions. The provider processing and access locations in Annex III are separate from Cofleet personnel access.

Technical safeguards: Cofleet must maintain authenticated user access, workspace and database access controls, scoped and revocable API/MCP credentials, encryption of connector credentials, restricted secret storage, private database networking, non-public file storage, HTTPS for external connections and authenticated internal worker calls. Administrative privileges must be restricted to authorised personnel. Cofleet must review access and the effectiveness of these measures regularly. These obligations do not represent an independent certification or external audit.

Recovery: Cofleet must maintain protected database backups and recovery arrangements within its EU-hosted infrastructure. Backup access must be restricted, and restoration must preserve workspace access controls and reapply deletion instructions. Backup-count settings do not replace the expiry limits below.

Return and deletion: At the customer’s choice, Cofleet must return the personal data and delete remaining copies, or delete all personal data, after the processing services end, unless EU or Member State law requires retention. Cofleet must use a secure return method and verify deletion across original files, published copies, indexes, embeddings, memories, derived history, jobs, logs and personal-data-bearing audit records. Cofleet must confirm completion in writing. Any retained backup data must be inaccessible for ordinary use, protected by this DPA and deleted on its defined expiry; deletion instructions must be reapplied after restoration.

Retention limits: Customer content is retained while the account is active. Within 30 days after account closure, Cofleet must complete the customer’s requested return and remove active content and associated personal-data-bearing records, including audit records. Operational logs must expire after 30 days. Residual backups controlled by Cofleet must be deleted within 90 days after account closure and remain unavailable for ordinary use. Customer deletion instructions must be reapplied after any restoration. Records required by EU or Member State law may be retained only for the required purpose and period, under the continuing protections of this DPA.

Provider-managed residual copies: Cofleet must promptly instruct providers to delete data when it is no longer required. Google’s Cloud Data Processing Addendum permits up to 180 days from an irrecoverable deletion instruction to remove underlying provider-controlled copies. Cofleet must remove its recoverable copies within the limits above and send the corresponding instruction when doing so. Google’s underlying copies are separate from Cofleet-controlled backups and remain protected until deletion. Model abuse-monitoring retention is described in Annex III.

## Annex III — Subprocessors and locations

Authorised subprocessors: The customer authorises the providers below for the specified purposes and data categories, subject to this DPA’s change-notice, objection and transfer safeguards. Listing a provider does not authorise additional purposes or unrestricted disclosure. EU hosting does not mean that all provider processing or support access takes place exclusively within the EU. Cofleet must maintain an applicable data-processing agreement and lawful transfer safeguards for each engaged provider and remains responsible for its subprocessors.

Google Cloud EMEA Limited, Ireland: Cloud infrastructure and AI processing through Google Cloud, including application and self-hosted memory services, databases, file storage, secrets, identity/access services, operational monitoring, generation and embeddings. Permitted data includes selected content and derived data, prompts and outputs, account/access records, protected credentials and operational metadata needed for the service. Cofleet uses EU Google Cloud hosting; configured regional resources are in Belgium and generation uses the EU endpoint. Google’s Cloud Data Processing Addendum governs the processing and applicable international-transfer safeguards: https://cloud.google.com/terms/data-processing-addendum. Provider operations or support may involve countries where Google and its subprocessors maintain facilities, subject to service-specific location commitments; locations are described at https://cloud.google.com/terms/subprocessors. For Google’s hosted Gemini processing, prompts flagged for suspected abuse may be retained for up to 90 days for abuse review. This is separate from Cofleet’s operational logs and does not authorise model training. Cofleet does not represent that an abuse-monitoring exemption is in place. This provider arrangement applies to the hosted and managed service; a self-hosted enterprise deployment requires its own agreed processing arrangements.

Cloudflare, Inc., United States: DNS, network security and application/API traffic delivery, including the edge proxy serving app.cofleet.app. Permitted data includes IP addresses, request metadata, headers, authentication information and request/response bodies in transit as needed to deliver and protect that traffic. Cloudflare uses a global network; its processing and support are not restricted to the EU. Its Customer Data Processing Addendum governs processor obligations and applicable international transfers, including Standard Contractual Clauses: https://www.cloudflare.com/cloudflare-customer-dpa/. Its standard Self-Serve Subscription Agreement incorporates that DPA for covered personal data. Provider locations are described at https://www.cloudflare.com/gdpr/subprocessors/. Cofleet must restrict its own request logging and any recoverable copies according to Annex II; Cloudflare may process retained security records only as permitted by the applicable provider agreement and law. Domain registration alone does not authorise disclosure of customer source content.

PostHog, Inc., United States: Basic product analytics using its EU Cloud service hosted in Frankfurt, Germany. Permitted data is limited to basic product events, user/workspace identifiers, fixed categories and counts. Customer documents, source text, prompts and outputs, session recordings, advertising data and unrestricted automatic capture are excluded. Cofleet’s signed PostHog DPA governs processing and applicable international-transfer safeguards: https://posthog.com/dpa. EU hosting does not exclude permitted provider access from outside the EU. Cofleet must enforce this data scope and delete customer-related identifiable analytics records within the account-closure period in Annex II.

Other services: Self-hosted Hindsight runs within Cofleet’s Google Cloud infrastructure and is not a separate hosted subprocessor. Customer-selected sources and destinations remain governed by Annex I. Shared Slack channels are for business-contact coordination and general feedback, not a permitted destination for customer source content, credentials or personal data processed on the customer’s behalf under this DPA. Any additional Cofleet-engaged provider receiving such data must first be authorised under the subprocessor-change procedure.

## Modifications and additional obligations

Instructions and transfers: Cofleet will process personal data only on lawful documented instructions, including for international transfers, except where EU or Member State law requires otherwise. It will give advance notice of required processing where legally permitted, immediately flag instructions it believes unlawful, and pause affected processing while the parties resolve them. A regional hosting setting or this DPA alone is not a Chapter V transfer mechanism.

Subprocessors: Section 2.6 is modified to require at least 30 days’ written notice before an addition or replacement begins processing. The customer has that period to object on reasonable data-protection grounds. Cofleet will resolve the objection or offer termination of the affected service with a proportionate refund of unused prepaid fees before the change takes effect. Cofleet must impose substantially equivalent data-protection duties on each subprocessor and remains responsible for it.

AI and use restrictions: Cofleet will not sell customer personal data, use it for advertising, or use or authorise its use to train general-purpose or shared AI models. Generation and embeddings to deliver the authorised service remain permitted. The same restrictions must bind engaged providers. Imported content is not presumed anonymised or redacted.

Incidents and assistance: Cofleet must notify the customer without undue delay after becoming aware of a personal data breach, provide available details in phases, contain and investigate it, and cooperate. It must forward individual requests and assist with rights requests, security, breach duties, impact assessments and prior consultation as required by GDPR Articles 28 and 32–36. Mandatory assistance cannot depend on agreeing an extra fee first.

Information and audits: Cofleet must provide information needed to demonstrate Article 28 compliance and allow and contribute to customer or appointed-auditor inspections. Existing independent reports may be supplied if available, but no certification or report is promised. Reasonable confidentiality and notice arrangements cannot obstruct statutory rights or urgent regulatory inspection.

Deletion and priority: Annex II modifies inconsistent provisions in section 7. Residual retention is permitted only for a disclosed, defined and lawful purpose and period; general authorisation by another law is not sufficient where GDPR Article 28 requires deletion or return. The DPA continues while Cofleet or its subprocessors retain customer personal data. Applicable transfer clauses take priority, followed by this DPA and then the Agreement. Contractual liability follows the Agreement without limiting mandatory liability or individuals’ rights.

## Standard Terms attribution

Common Paper DPA Standard Terms, version 1.1, are used under the CC BY 4.0 licence. Cofleet’s changes are identified above. https://creativecommons.org/licenses/by/4.0/

