# Data Processing Agreement

Version 1.1 — Personal-data processing for Cofleet’s hosted and managed service.

## Cover Page

Provider: Cofleet AB, company registration number 559594-0965, Finn Malmgrens väg 52, 121 38 Johanneshov, Sweden.

Customer: The organisation identified in the accepted Cofleet Terms of Service and workspace signup or onboarding record. Its designated administrator, legal address and contact email are recorded there and must be kept current.

Agreement and acceptance: The accepted Terms of Service, Pilot Details and this DPA form the Agreement. This DPA takes effect on explicit acceptance by a person authorised to bind the customer; viewing it is not acceptance. No separate signature is needed when validly incorporated and electronically accepted. A separately agreed DPA governing the same processing takes priority.

Standard Terms: This Cover Page and its annexes incorporate the Common Paper DPA Standard Terms, version 1.1, at https://commonpaper.com/standards/data-processing-agreement/1.1/. Defined terms have the meanings there or in the Agreement. Cofleet’s modifications below take priority over inconsistent Standard Terms, subject to applicable transfer clauses and mandatory law.

## Key Terms and modifications

Provider Security Contact: markus@cofleet.app.

Restricted transfers: The Governing Member State is Sweden. Section 3 of the Standard Terms applies where its transfer conditions are met. Cofleet processes only on lawful documented instructions, including for transfers, unless EU or Member State law requires otherwise; it must give advance notice where legally permitted. It must immediately flag instructions it believes unlawful and pause affected processing while the parties resolve them. EU hosting or this DPA alone is not a Chapter V transfer mechanism.

Subprocessor changes (section 2.6): At least 30 days’ written notice is required before an addition or replacement begins processing. The customer may object during that period on reasonable data-protection grounds. Cofleet must resolve the objection or offer termination of the affected service with a proportionate refund of unused prepaid fees before the change takes effect. Subprocessors must be bound by substantially equivalent data-protection duties; Cofleet remains responsible for them.

AI and use restrictions: Cofleet will not sell customer personal data, use it for advertising, or use or authorise its use to train general-purpose or shared AI models. Generation and embeddings for the authorised service remain permitted. These restrictions also bind engaged providers. Imported content is not presumed anonymised or redacted.

Incidents and assistance: Section 4 applies, with notification of a personal data breach required without undue delay after awareness. Section 6 applies to requests and cooperation. Cofleet must forward individual requests and provide the assistance required by GDPR Articles 28 and 32–36; mandatory assistance cannot depend on agreeing an extra fee first.

Information and audits (section 5): Cofleet must provide information needed to demonstrate Article 28 compliance and allow and contribute to customer or appointed-auditor inspections. Independent reports may be supplied if available; no certification or report is promised. Confidentiality and reasonable notice arrangements cannot obstruct statutory rights or urgent regulatory inspection.

Priority and duration: Annex II overrides inconsistent section 7 provisions. Applicable transfer clauses take priority, then this DPA, then the Agreement. The DPA continues while Cofleet or its subprocessors retain customer personal data. Contractual liability follows the Agreement without limiting mandatory liability or individuals’ rights.

## Annex I — Parties and processing

Roles: Under section 1, Cofleet is processor for a customer acting as controller, or subprocessor for a customer acting for another controller. The customer must have required upstream authorisation. Each party separately controls its own business-contact and billing processing.

Service and purpose: Organise, index and retrieve selected company knowledge for authorised users and connected AI tools, and process account, access and operational records to deliver, secure, troubleshoot and support the service.

Operations: Receive selected documents, notes and work communications; extract text and facts; store originals and authorised copies; create embeddings and indexes; consolidate and retrieve memories; process prompts and generate outputs; provide authorised context and citations through the app, API or MCP; manage access and background jobs; and return or erase the resulting data.

Instructions (sections 2.2–2.3): The Agreement, source and user selections, configuration and written instructions acknowledged by Cofleet define permitted processing. A connector does not authorise importing an entire account. Internal chat or external notifications require customer enablement. Cofleet cannot expand permitted purposes or data categories merely by posting a notice.

Data subjects: Authorised users and employees, plus customer, supplier and other business contacts appearing in selected content.

Personal data: Names, business contact details, roles and work communications; selected document contents, titles and source metadata; prompts, context and outputs; account/workspace identifiers, permissions and timestamps; connector identifiers and credentials; and operational, access, security and support records relating to individuals.

Excluded data: GDPR Article 9 special-category data, criminal-offence data, national identification numbers and other data prohibited by the Terms. Adding these requires a separate written agreement and safeguards.

Sources and recipients: Explicitly customer-authorised systems, tools and destinations are recorded in the workspace or onboarding record. A customer-selected provider is not automatically a Cofleet subprocessor; a provider engaged by Cofleet must be listed and authorised in Annex III. Source-grant and workspace controls do not promise continuous replication of every source system’s permissions.

Frequency and duration: On import, update, query, model processing and other customer-authorised use, during the accepted service period and necessary return/deletion process. Lawful residual retention remains restricted and protected by this DPA.

## Annex II — Security and lifecycle

Personnel and access: Cofleet must apply measures appropriate to the risks under GDPR Article 32. Its personnel have full administrative access and work from Sweden; access is limited to authorised personnel bound by confidentiality and to what is necessary to provide, secure and support the service or follow documented customer instructions. Protect credentials, revoke access when no longer required, restrict administrative privileges and maintain incident response. Provider access locations are separate, as set out in Annex III.

Technical safeguards: Maintain authenticated user access; isolated workspaces and database access controls; scoped, revocable API/MCP credentials; encrypted connector credentials and restricted secret storage; private database networking and non-public file storage; HTTPS externally and authenticated internal worker calls. Review access and the effectiveness of these measures regularly. These measures do not represent independent certification or an external audit.

Recovery: Maintain protected database backups and recovery arrangements within EU-hosted infrastructure, with restricted access. Restoration must preserve workspace access controls and reapply deletion instructions. Backup counts do not replace expiry limits.

Return and deletion: At the customer’s choice after processing services end, securely return personal data and delete remaining copies, or delete all personal data. Verify deletion across originals, published copies, indexes, embeddings, memories, derived history, jobs, logs and personal-data-bearing audit records, and confirm completion in writing.

Retention limits: Keep customer content while the account is active. Complete the requested return and remove active content and associated personal-data-bearing records, including audit records, within 30 days after account closure. Operational logs expire after 30 days. Cofleet-controlled residual backups must be deleted within 90 days after closure; until then they must remain protected by this DPA and inaccessible for ordinary use.

Lawful retention: Records required by EU or Member State law may be retained only for the required purpose and period, under this DPA. Other residual retention needs a disclosed, defined and lawful purpose and period; general authorisation by another law is insufficient where GDPR Article 28 requires return or deletion.

Provider residual copies: Promptly instruct providers to delete data no longer required. Google’s Cloud Data Processing Addendum allows up to 180 days from an irrecoverable deletion instruction for underlying provider-controlled copies. Cofleet must remove its recoverable copies within the limits above and send the corresponding instruction when doing so. Google’s underlying copies are separate from Cofleet-controlled backups and remain protected until deletion. Gemini abuse-monitoring retention is below.

## Annex III — Approved subprocessors and locations

Scope: The customer authorises these providers only for the stated purposes and data categories, subject to the change-notice, objection and transfer safeguards above. Cofleet must maintain applicable data-processing agreements and lawful transfer safeguards. EU hosting does not mean all provider processing or support access is confined to the EU.

### Google Cloud EMEA Limited — Ireland

Processing: Cloud infrastructure and AI: application and self-hosted memory services, databases, file storage, secrets, identity/access, operational monitoring, generation and embeddings. Data includes selected content and derived data, prompts and outputs, account/access records, protected credentials and operational metadata needed for the service.

Locations and terms: EU Google Cloud hosting, with configured regional resources in Belgium and generation through the EU endpoint. Provider operations or support may involve countries where Google and its subprocessors have facilities, subject to service-specific location commitments. Google’s Cloud Data Processing Addendum governs processing and transfer safeguards: https://cloud.google.com/terms/data-processing-addendum. Provider locations: https://cloud.google.com/terms/subprocessors.

Abuse monitoring: Hosted Gemini prompts flagged for suspected abuse may be retained for up to 90 days for abuse review, separately from Cofleet’s operational logs. This does not permit model training; no abuse-monitoring exemption is represented. This arrangement covers the hosted and managed service; self-hosted enterprise deployments need separately agreed processing arrangements.

### Cloudflare, Inc. — United States

Processing: DNS, network security and application/API traffic delivery, including the app.cofleet.app edge proxy. Data includes IP addresses, request metadata, headers, authentication information and request/response bodies in transit as needed to deliver and protect traffic. Domain registration alone does not authorise disclosure of customer source content.

Locations and terms: Global network; processing and support are not restricted to the EU. Cloudflare’s standard Self-Serve Subscription Agreement incorporates its Customer DPA for covered personal data, including applicable international-transfer safeguards and Standard Contractual Clauses: https://www.cloudflare.com/cloudflare-customer-dpa/. Provider locations: https://www.cloudflare.com/gdpr/subprocessors/.

Retention: Cofleet’s request logs and recoverable copies follow Annex II. Cloudflare may retain security records only as permitted by its applicable agreement and law.

### PostHog, Inc. — United States

Processing: Basic product analytics using EU Cloud in Frankfurt, Germany. Only basic product events, user/workspace identifiers, fixed categories and counts are permitted. Customer documents, source text, prompts, outputs, session recordings, advertising data and unrestricted automatic capture are excluded.

Terms and retention: Cofleet’s signed PostHog DPA governs processing and international-transfer safeguards: https://posthog.com/dpa. EU hosting does not exclude permitted provider access from outside the EU. Cofleet must enforce the stated scope and delete customer-related identifiable analytics records within Annex II’s account-closure period.

### Other services and destinations

Self-hosted Hindsight runs inside Cofleet’s Google Cloud infrastructure and is not a separate hosted subprocessor. Customer-selected sources and destinations follow Annex I. Shared Slack channels are for business-contact coordination and general feedback, not customer source content, credentials or personal data processed for the customer under this DPA. Any additional Cofleet-engaged provider receiving such data needs prior authorisation through the subprocessor-change procedure.

## Standard Terms attribution

Common Paper DPA Standard Terms, version 1.1, are used under the CC BY 4.0 licence. Cofleet’s changes are identified above. https://creativecommons.org/licenses/by/4.0/
