DECCF Data Processing Addendum
Effective date: 2026-10-05
Parties and scope
This Addendum forms part of the Terms of Service. It applies where Per Wristel, Duvbergsvägen 65, 143 44 Vårby, Sweden (DECCF), processes personal data on your behalf. You are the account holder or the organisation you represent (Customer). If you represent an organisation, you confirm authority to bind it and must provide its identity and current contact address to deccf.app@outlook.com.
The Customer determines purposes and acts as controller. If it acts for another controller, it must have authority to appoint DECCF as a subprocessor. Customer Personal Data means personal data in private calculation content, including apps, models, cases, inputs, results and operation outcomes. DECCF's separate account administration, security and support processing is described in the Privacy Policy; that separate role does not permit additional use of Customer Personal Data.
Processing details
The subject and purpose are performing and retaining the calculations you request. Processing includes receiving and storing content, executing models, generating and displaying results, saving and reopening work, handling operation retries, and retrieving, correcting, returning or deleting data. Processing continues while you request calculation or storage and until data is returned or deleted under this Addendum.
Depending on your submissions, people concerned may include employees, contractors, customers, suppliers, business contacts or other people represented in a calculation. Data may include names, contact details, identifiers, financial and transaction information, employment information, assumptions and calculated information about those people. Limit submissions to what the calculation requires. The service is not offered for special categories of personal data under GDPR Article 9, criminal-offence data under Article 10 or payment-card data.
Keep third-party personal data in private content. Do not include it in published model or module code, descriptions or documentation, which may become dependencies of other users' work. Private case inputs for an installed published app remain covered by this Addendum.
Instructions and responsibilities
These accepted terms, your service actions and written support requests are documented instructions, including the processing and transfers described here. DECCF will process Customer Personal Data only on those instructions unless EU or Member State law requires otherwise. We will tell you before such legally required processing unless the law prohibits notice. We will promptly tell you if we consider an instruction incompatible with applicable EU or Member State data-protection law and may suspend it while this is resolved.
You are responsible for lawful basis, notices, accuracy, minimisation, retention decisions and permissions. Secure your sign-in account and authorise agents or other destinations only where you have the necessary rights. Your selected chat or agent provider is governed by your separate relationship with it.
Confidentiality and security
DECCF restricts access to people who need it for instructed processing or support. Authorised people must be bound by confidentiality obligations or an applicable statutory duty. We will maintain and review technical and organisational measures appropriate to processing risks under GDPR Article 32.
Current measures include authenticated account access, private saving by default, ownership and permission checks, revocable tokens and agent permissions, hashed DECCF session and access-token secrets, encrypted temporary calculation transfers, and isolated remote calculation execution with network access disabled. Providers supply infrastructure security measures. These measures do not guarantee availability, a particular recovery outcome or exclusive processing in one country. Retain copies needed for your own continuity.
Subprocessors and transfers
You give general written authorisation for necessary subprocessors. Current providers are Vercel, Inc. for hosting and remote calculation infrastructure; Databricks, Inc., including Neon and Neon, LLC, for database infrastructure; and Clerk, Inc. for authentication, to the extent it processes data on your behalf. Their agreements describe further subprocessors. Some provider account or service information is handled under their independent privacy notices.
We will notify your supplied contact of intended additions or replacements affecting Customer Personal Data and give an opportunity to object on reasonable data-protection grounds before the change takes effect. We will seek a workable resolution. If affected processing cannot be provided without the disputed provider, you may end that processing and request return or deletion. DECCF imposes applicable data-protection obligations through binding agreements and remains responsible for subprocessors' performance of those obligations.
Data may be processed in the United States and other countries where providers operate. The current Neon database is in Northern Virginia, USA; this does not identify every provider location. We will ensure transfers subject to GDPR Chapter V use an applicable lawful mechanism. Vercel's agreement and the Databricks agreement applicable through Neon's terms include European Commission Standard Contractual Clauses. Clerk's agreement provides for the EU–U.S. Data Privacy Framework where applicable, with contractual clauses as an alternative. Contact us for further information.
Assistance and incidents
Taking account of the processing and available information, DECCF will assist with individuals' requests for access, correction, deletion, restriction, objection and portability through service controls or manual support. We will refer requests about Customer Personal Data to you unless law requires another response. We will assist with GDPR Articles 32–36 obligations, including security, breach assessment, impact assessments and supervisory consultation.
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, providing available information about affected data and people, likely consequences, response measures and a contact. Information may arrive in stages during investigation. Notifications may be manual. You remain responsible for required notices to authorities and individuals.
Return and deletion
When instructed processing ends, DECCF will, at your choice, return or delete Customer Personal Data and arrange deletion of remaining copies unless EU or Member State law requires retention. Use available app, case and account-closure controls or request return or further deletion through deccf.app@outlook.com. Return will use an appropriate secure method after identity and authority verification; there is no automatic account-wide export.
Active deletion does not establish immediate erasure from every provider's recovery history or backup. We will issue necessary deletion instructions and restrict remaining copies pending deletion. If data is restored for recovery, we will reapply deletion instructions. Legally required retained data will be limited, protected and removed when no longer required. These duties continue while DECCF or its subprocessors hold Customer Personal Data on your behalf.
Evidence, audits and priority
DECCF will provide information reasonably necessary to demonstrate these duties and allow and contribute to audits, including inspections by your authorised auditor. Audits will be arranged with reasonable notice, confidentiality and protection of other customers' data. Documentation and available provider evidence may be used first where suitable, without preventing an audit required by law or a competent authority.
This Addendum takes priority over conflicting Terms concerning instructed processing. Mandatory data-protection law remains controlling. Contact for instructions, rights assistance, incidents and audits: deccf.app@outlook.com.