1. Parties and scope
This agreement is between Resly AB, company registration number 559266-6563, Kånnavägen 40, 341 31 Ljungby, Sweden (Resly), and the legal entity identified as the customer in the order or main agreement (Customer). Contact for data protection and incidents: support@resly.se.
The Customer is the controller and Resly the processor for the processing in Annex 1. Where the Customer is itself a processor, Resly acts as a subprocessor and the Customer must hold the necessary authority from the controller. GDPR means Regulation (EU) 2016/679 as applicable within the EU/EEA, including Norway.
This agreement and its annexes become binding when expressly incorporated into the parties’ main agreement or accepted by authorised representatives. Publication on a website alone does not conclude an agreement. It applies while Resly processes personal data on the Customer’s behalf, including read-only access after cancellation and the expiry of backups.
Processing for Resly’s own purposes, such as billing, bookkeeping, enquiries, demo bookings and consent-based analytics on the public website, is covered by the privacy policy. Consent to website analytics does not authorise Resly to use data processed on the Customer’s behalf for its own analytics purposes. This agreement prevails over the main agreement on conflicting data processing provisions. Mandatory data protection law and applicable standard contractual clauses always prevail.
2. Customer responsibilities and instructions
The Customer determines purposes, data submitted, recipients, permissions and retention. The Customer is responsible for a lawful basis, information to data subjects and lawful instructions. Special category data also requires an applicable Article 9 exception; criminal offence data is subject to Article 10 and must not be processed without applicable legal authorisation.
This agreement, its annexes, Customer settings and documented requests constitute instructions. Resly processes data only on documented instructions, including transfers outside the EEA. Where Union or Member State law requires processing, Resly informs the Customer beforehand unless that law prohibits notice on important grounds of public interest.
Resly immediately informs the Customer if, in its opinion, an instruction infringes applicable data protection rules and awaits clarification for the affected processing. Resly may not use customer documents for its own purposes. Customer documents, document contents, recipient details, signing evidence and signing links must not be transferred to PostHog for Resly’s website analytics, session replay or error collection.
3. Confidentiality and security
Resly ensures that persons with access are bound by confidentiality commitments or appropriate statutory confidentiality duties and receive only the access needed for their work.
Resly implements technical and organisational measures under Article 32, considering risk, the nature of the data, technology and costs. Measures must address confidentiality, integrity, availability, recoverability and regular evaluation. Annex 2 describes the safeguards. Changes must not reduce the agreed level of protection.
4. Subprocessors and other recipients
The Customer gives general written authorisation for the subprocessors identified in Annex 3. Resly must notify the Customer in writing at least 30 days before adding or replacing a subprocessor, describing its task, processing countries and relevant safeguards. The Customer may object on reasonable data protection grounds during this period.
The parties will seek to resolve objections through safeguards or an alternative. If unresolved, the Customer may terminate the affected service before the change takes effect without an early termination fee for that part. Resly must not allow the new subprocessor to process the Customer’s data while the objection remains unresolved.
Resly must impose equivalent data protection obligations by written agreement and remains fully liable to the Customer for subprocessors’ performance. Parties acting as independent controllers for certain processing must be identified separately, rather than automatically classified as subprocessors.
Authorisation to use a provider applies only where the requirements of sections 4 and 5 are met. Before the provider processes the Customer’s data, Resly must supply its legal identity, processing countries including remote access, task and applicable transfer safeguards. Provider agreements need not be attached to this agreement.
5. Processing locations and international transfers
Resly’s own hosting and storage, including backups, take place at Elastx in Sweden. External email, SMS and electronic identity services receive the information necessary for their functions. This agreement therefore does not mean that all processing by all providers takes place in Sweden.
Processing or access outside the EEA requires the Customer’s documented instructions and a basis under Chapter V GDPR, such as an applicable adequacy decision or standard contractual clauses with necessary assessments and supplementary safeguards. Resly must document the basis and provide information about safeguards on request. A DPA alone is not a basis for a third-country transfer.
6. Personal data breaches
Resly notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data. Information may be provided in stages and must not await completion of an investigation. Oskar Svärd is responsible for contacting the Customer using its registered contact details; Resly can be reached at support@resly.se.
Resly provides available information about the nature of the breach, affected data and individuals and approximate numbers, likely consequences, measures taken or proposed and a follow-up contact. Resly documents the breach, mitigates its effects and assists the Customer. The Customer is responsible for assessing notification to the supervisory authority and communication to data subjects.
7. Rights, impact assessments and supervision
Taking account of the nature of processing, Resly assists the Customer with Chapter III requests through appropriate technical and organisational measures insofar as possible. Requests concerning customer documents are forwarded to the Customer and Resly acts on its instructions unless otherwise required by law.
Resly assists with obligations under Articles 32–36, including breach handling, impact assessments and prior consultation, considering the nature of processing and information available. Customers can download files themselves and Resly assists on instruction with bulk exports, disclosure and erasure.
8. Retention, return and deletion
The Customer chooses return or deletion when the processing engagement ends. For return, Resly assists with export and then deletes remaining copies under this section, unless Union or Member State law requires retention.
Cancelling a subscription does not delete the company account. Documents remain available to view and download until the Customer deletes the envelope or account. The Customer must determine and implement appropriate retention, including after cancellation.
Deleting an envelope removes documents, signing evidence, recipient details and sender-supplied personal identity numbers from the active environment. Deleting the company account removes its corresponding data immediately. Copies may remain in backups for up to 90 days. During this time backups must have restricted access and be used only for recovery. Previously requested deletions must be reapplied after restoration.
Access logs are retained for one year and may contain an envelope ID after the envelope has been deleted. The ID no longer provides access to the deleted document. Logs must not be considered anonymous solely for this reason. On request, Resly must confirm deletion and identify remaining copies and their retention basis.
9. Information and audits
Resly makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, by the Customer or an auditor mandated by it.
The parties normally coordinate scope, timing and confidentiality to protect other customers’ data and operations. Such arrangements must not prevent statutory audits, urgent incident investigations or regulatory supervision. Charges for special assistance must be agreed in advance and must not obstruct Resly’s GDPR obligations.
10. Liability and language
The main agreement’s liability provisions apply between the parties to the extent consistent with mandatory law. This agreement does not limit data subjects’ rights, supervisory powers or liability that cannot be excluded under GDPR.
The Swedish and English versions are intended to have the same meaning. In case of a discrepancy, the Swedish version prevails unless otherwise agreed in writing. Swedish law and the main agreement’s applicable dispute provisions apply insofar as mandatory data protection rules do not provide otherwise.
Annex 1. Processing instructions
Subject matter and purpose: digital envelopes for viewing, identification, signing, storage and export, with related support and security. Operations include collection, transfer, storage, access, identity matching, logging, return and deletion. Processing is ongoing according to Customer use and the retention periods in section 8.
Data subjects: Customer users and administrators, recipients and signatories, and other individuals mentioned in customer documents, such as employees, customers, suppliers and owners.
Data: document contents and names, names, email addresses, optional telephone numbers and messages, IP addresses, timestamps, envelope IDs, verification methods and signing evidence. Dates of birth may be included depending on settings. Sender-supplied personal identity numbers are stored while the envelope exists; Resly does not insert those numbers into the generated document. Customers may themselves include identity numbers in uploaded document contents.
Personal identity numbers returned by an eID service are not stored where the sender has not supplied one. Supplied numbers are always matched during eID verification. Identification before viewing with identity-number matching requires the number before publication. In the current service, a protected envelope can be configured with email verification, SMS or BankID.
Special category data may be included only where the Customer has documented the relevant categories, legal authorisation and risk assessment and the parties have agreed sufficient safeguards in writing for that use. The Customer must select protected envelopes, verification methods, permissions and retention appropriate to the risk. Sensitive contents must not be included in unprotected emails, document names or notifications. Automatic enforcement of a special sensitive-document mode is not included in this agreement.
Annex 2. Security measures
Resly operates its own Kubernetes cluster at Elastx in Sweden. Documents, databases and backups are encrypted at rest, and internal and external traffic in Resly’s environment uses HTTPS/TLS. This describes Resly’s environment and does not mean email attachments are end-to-end encrypted to the recipient.
Two authorised persons have production access for incident handling and troubleshooting requested by the Customer. They have confidentiality commitments, individual accounts and keys, two-factor authentication and a required WireGuard connection to reach data. Access is logged and logs are stored in the cluster for one year. Support uses Chatwoot in Resly’s own environment and operational monitoring runs internally. Where support requires access to data covered by this agreement, processing follows the Customer’s documented instructions. The public website’s separate PostHog analytics does not cover that support processing.
New customer accounts currently default to all users seeing all envelopes in that account. Group settings can restrict access; administrators see everything within their account. Separate company accounts have their own users and administrators in the same database. Sharing a subscription does not confer access: an invitation from that separate account’s owner or administrator is required.
Resly must maintain documented procedures for restoration and reapplication of deletions, access reviews, incident handling, vulnerability management, key management and regular evaluation of the effectiveness of security measures under Article 32.
Annex 3. Provider register
The provider services used for hosting, communications and electronic identification are listed below. Authorisation for processing on the Customer’s behalf is subject to sections 4 and 5. Data is disclosed only to the extent necessary for the function the Customer uses.
Resly’s own hosting and backups at Elastx are in Sweden. External services may involve processing outside Sweden and the EEA; Postmark’s published terms cover the US and other countries. Resly must document and provide processing countries, legal recipients and transfer safeguards under section 5. Hosting in Sweden does not mean that all processing by external providers takes place in Sweden.
Independent processing by eID and communications providers must be distinguished from subprocessing. Resly must inform the Customer about such independent recipients and their roles. Stripe and Fortnox are used for Resly’s own payments, invoicing and bookkeeping and are not included in this register of processing on the Customer’s behalf.
PostHog Cloud EU is used for Resly’s own analytics on the public website following visitor consent, as described in the privacy policy. Cal.com is used for Resly’s demo bookings. These activities are outside the Customer’s processing engagement and subprocessor authorisation under this agreement. Resly must ensure that the Customer’s document and signing workflows are not covered by the website’s PostHog collection. If an external provider is later to process the Customer’s data on instruction, this agreement’s requirements for instructions, notice and authorisation apply before that processing begins.
| Provider | Function | Data processed |
|---|---|---|
| Elastx AB | Hosting and storage in Resly’s own Kubernetes cluster. | Documents, database and backups, together with associated data in the hosting environment. |
| Twilio | SMS delivery. | Recipient telephone number, SMS containing a signing link and necessary delivery information. No document attachments are sent by SMS. |
| Postmark | Email delivery. | Recipient email address, document name, optional message and delivery information. A copy of the signed document is attached if the customer enables that setting. |
| Freja | Direct integration for electronic identification. | Identification information and verification results for the eID function used by the Customer. |
| ZignSec | Provision of the BankID integration. | Identification information, matching against sender-supplied personal identity numbers and verification results. |