Handled.

Data Processing Agreement

Version 3 · Published 15 September 2026 · Editorial revision 16 September 2026 · Optional research and Outlook-check descriptions updated 24 September 2026 · For new agreements expressly accepting this version.

This DPA is part of the Terms of Service between your company (controller) and TON Creative Studios AB (org.nr 559029-8450), Västergatan 6D, 352 30 Växjö, Sweden (processor). It governs all personal data processed in your Handled workspace and is written to satisfy Article 28(3) GDPR. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails.

1. Details of processing

Optional subject-agent research: an administrator may permit sources for an agent; the responsible person separately authorizes their own accounts for the displayed agent subjects. Eligible new work can trigger bounded research using authorized context and connected-service excerpts. Encrypted findings and supporting evidence remain private to that person for up to 30 days, separate from ordinary Recent searches and shared agent records. Current ownership, consent and source access are checked before review, sharing and personal export. Revocation or loss of required access invalidates preparation. Only text explicitly reviewed and shared by the person becomes ordinary company work. Configured AI processing and transfers described in this agreement apply. Up to 50 preparation snapshots are retained separately from manual research; older already-shared preparations may be removed at capacity. Minimal attempt identifiers and timestamps remain until the corresponding run is removed to prevent automatic replay; mutation fingerprints expire after 30 days. Personal export and erasure cover these records. These feature-specific controls do not amend previously agreed erasure, recovery-copy or provider-retention commitments.

Optional Outlook checks: where available and separately enabled by the connected person, the service periodically reads bounded recent Inbox and Sent Items content to prepare private suggestions. Requested drafts use the suggestion’s supporting excerpt and context. Configured Anthropic processing, transfers and safeguards described in this agreement apply; this does not authorize automatic email sending or mailbox changes. Connecting a mailbox alone does not enable scheduled checks. Personal mailbox suggestions and their source-validated export are restricted to the connected person’s company membership, not made available to company administrators through these tools. Only content explicitly reviewed and published by the person becomes ordinary company work.

Active-service records for optional Outlook checks: encrypted pending suggestions, supporting excerpts, links and identifiers expire after 30 days. Keyed dismissal and expiry fingerprints contain no message text and expire after 90 days from their creation. Check records are retained for up to 90 days; encrypted source cursors are retained to continue enabled checks. Turning checks off clears pending suggestions, cursors and dismissal fingerprints. Disconnecting clears the mailbox’s derived records; it does not delete previously published company work. A person can export their pending suggestions when current source access can be verified; unverifiable evidence is omitted. Requested reply drafts are not automatically persisted. These feature-specific operational periods do not amend the agreed closure, erasure, recovery-copy or provider-retention commitments in section 8, or any previously accepted stronger rights.

2. Instructions

We process personal data only on your documented instructions — which this DPA, the Terms, and your company’s configuration and use of the product constitute — unless EU or member-state law requires otherwise, in which case we inform you before processing unless that law forbids it. We will tell you immediately if we believe an instruction infringes the GDPR.

3. Confidentiality

People authorised by us to process personal data are bound by contractual confidentiality obligations. Access to production data is limited to what operating the service requires and is logged.

4. Security

We implement the technical and organisational measures in Annex 1, taking into account the state of the art and the risks of the processing (Art. 32). We may update them, but never in a way that reduces the overall level of protection.

5. Sub-processors

Your company gives general authorisation for the sub-processors below. We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain fully liable to you for their performance.

Changes: we announce additions or replacements in the product and by email to your administrators at least 30 days before they take effect. You may object in writing on reasonable data-protection grounds within that period; if we cannot resolve the objection (for example by offering the service without the new sub-processor), you may terminate the affected service and receive a pro-rata refund of prepaid fees.

The table records published provider arrangements, not confirmation that every account-specific agreement or transfer assessment is complete. Stripe may act as controller or processor depending on the payment activity. Customer-connected services operate under the customer’s own agreement for their service; they are not automatically Handled subprocessors for every activity. Google Workspace and Microsoft 365 directory access is customer-authorized and read-only. Optional Microsoft research requires separate personal read-only authorization and service configuration. Outlook research uses the connected person’s own work or school mailbox; Teams research is restricted by Handled to approved channels and current personal access. Microsoft’s provider permissions are disclosed during consent. Authorized question and message excerpts may be processed by the configured AI provider. Questions, findings and supporting excerpts are saved in requester-only encrypted research history for up to 30 days, capped at 50 searches per person and company. Expiry, deletion and access validation apply to this private history; explicitly shared content follows the retention of Handled work; personal credentials are encrypted and not supplied to background agents. Microsoft service processing remains under the customer’s Microsoft agreement.

How the AI features work, what they read, and what they can never do is described in the AI purpose statement.

6. Transfers

The primary database and attachment store are in the EU. The API processes requests in the EU (Netherlands, since 22 September 2026), and other providers may process data outside the EEA. Handled remains responsible for applicable lawful transfer arrangements and any required supplementary measures. Account-specific evidence is still being completed; listing a published DPA, certification or contractual clause is not confirmation that it applies to the Handled account. On request we provide available contractual information and identify outstanding verification. This disclosure does not waive applicable transfer requirements or existing obligations.

7. Assistance

Taking into account the nature of the processing, we assist your company:

Data-subject rights (Art. 12–23): authorized administrators can use the available account and export controls. JSON export includes authorized records and attachment metadata; file contents require separate authorized downloads. Where a request cannot be satisfied in-product, we assist within 10 business days of your written request. Requests about workspace processing are forwarded to your administrators and supported by us. We answer requests about processing for which Handled is controller ourselves. Applicable statutory response deadlines are unaffected.

Security, breach notification, DPIAs (Art. 32–36): we notify your administrators without undue delay, and in any case within 48 hours of becoming aware, of a personal-data breach affecting your workspace, with the information Art. 33(3) requires as it becomes available. We provide the information reasonably needed for your data-protection impact assessments and prior consultations, to the extent it concerns processing by Handled and is not otherwise available to you.

8. Return, deletion and retention

On termination, at your choice, your company exports (returns) its records from Settings and/or we delete them. We delete workspace personal data from the active Handled service within 30 days of account closure. Individual erasure requests have a separate 7-day grace period before the erasure process runs; deactivation alone does not instruct deletion. These periods do not extend a shorter applicable legal deadline. The Privacy Policy explains residual personal data in retained company work and how to request assistance.

Recovery archives and provider-held records have distinct purposes and periods, set out below. Handled will exclude erased records and files from new Handled-managed recovery archives and remove them from existing Handled-managed local and off-host archives no later than 35 days after active-service erasure. Copying or replacing an archive does not restart its original expiry. This bounded commitment applies to Handled-managed archives; it is not a promise that every provider-held record disappears within 35 days.

Recovery copies must be restricted from ordinary use. Before returning a restored copy to service, Handled must reapply all relevant subsequent erasure instructions and verify file cleanup. Enforcement across every recovery path has not been fully verified. Restored data cannot be returned to the production service until this safeguard is demonstrated.

Retention schedule — 15 September 2026

Published provider periods below describe the identified category, not a new guarantee covering every service or exception. Account-specific scope and unresolved periods are stated explicitly. Unresolved entries do not authorize indefinite retention: Handled must resolve the period and lawful scope before approving new customer use involving real personal data on the affected service. Handled remains responsible for its appointed sub-processors and for implementing lawful controller instructions.

Where applicable law requires retention, we identify the data, legal requirement and period to your company unless legally prohibited, restrict use to that requirement and delete the data when it ends. Supplier safety or operational exceptions must be assessed for the actual purpose and lawful scope; listing them does not grant unrestricted use of workspace data. A provider-policy change does not automatically amend an agreed retention schedule.

On written request we confirm active-service deletion separately from final recovery-copy expiry, identify any remaining copies and their expiry or lawful retention criterion, and confirm completion after verification. We assist with relevant instructions for copies independently held by your company or recipients; those copies are outside Handled’s operational control.

9. Audits and information

We make available the information necessary to demonstrate compliance with Article 28. For routine reviews, once per calendar year on reasonable notice, we will answer your written security and compliance questions and provide available sub-processor certifications and audit summaries (including penetration-test summaries when available). Where an audit is reasonably necessary to verify compliance, you (or an independent auditor you mandate, not a competitor of ours) may audit the relevant processing on at least 20 business days’ notice (or as otherwise agreed in writing), during business hours, at most once per year, under confidentiality, at your cost, and without access to other customers’ data. Findings are shared with us and used only for compliance purposes. The ordinary frequency, advance notice and documentation-first process do not prevent an additional or accelerated audit reasonably necessary after a relevant incident, a material compliance concern or a competent authority’s request. Confidentiality arrangements and reasonable charges will not prevent exercise of applicable audit rights. A supervisory authority’s audit rights are unaffected.

10. General

This DPA is governed by the same law as the Terms. Liability follows the Terms. If any clause is invalid, the rest stands, and the invalid clause is replaced by what the parties would have agreed to achieve the same data-protection outcome.

Annex 1 — Technical and organisational measures

Contact: hello@handledspace.com.