Legal
Last updated: June 16, 2026 · Corners Sverige AB, trading as Artivex
This Data Processing Agreement ("DPA") supplements and forms part of the Artivex Terms of Service between Corners Sverige AB ("Artivex", "Processor") and the Customer ("Controller").
This DPA applies when the Customer uses the Artivex Platform to process personal data on behalf of data subjects— for example, when building a CRM that stores client contact details, an HR tool storing employee records, or any System in which personal data of third parties is stored or processed.
This DPA is entered into to ensure that processing activities comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national data protection laws.
Controller
The Customer — the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor
Artivex / Corners Sverige AB — the entity that processes personal data on behalf of the Controller under this DPA.
Personal Data
Any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
Processing
Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
Sub-processor
Any third party engaged by Artivex that processes personal data on behalf of the Controller as part of delivering the Platform services.
Data Subject
The natural person to whom the personal data relates.
Supervisory Authority
The public authority responsible for monitoring the application of the GDPR. For Artivex: the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten — IMY).
Standard Contractual Clauses (SCCs)
The contractual clauses adopted by the European Commission to facilitate lawful transfers of personal data to third countries.
Artivex processes personal data only as a data processor, acting on the documented instructions of the Customer (Controller). We do not determine the purposes or means of processing personal data within Customer Systems — that is the Customer's responsibility as Controller.
The subject matter of processing under this DPA is the operation of Customer-generated Systems on the Artivex Platform, including:
The Customer is responsible for ensuring that any personal data they store in their Artivex Systems has a lawful basis for processing under GDPR, and that data subjects have been informed of the processing where required.
The personal data processed under this DPA may relate to the following categories of data subjects, depending on the Customer's use case:
The Customer, as Controller, is responsible for determining which categories of data subjects are involved in their specific use case and ensuring appropriate notices and consents are in place.
The types of personal data processed under this DPA are determined by the Customer's System configuration. They may include:
This DPA is effective from the date the Customer first processes personal data through the Platform and remains in force for the duration of the service agreement between the parties.
Upon termination or expiry of the service agreement, the obligations of this DPA with respect to data security, confidentiality, and deletion continue until all personal data has been deleted or returned in accordance with Section 14.
Artivex undertakes to process personal data in accordance with the following obligations:
Artivex implements the following technical and organisational security measures to protect personal data processed through the Platform:
Encryption at rest
All data stored in the Platform database is encrypted at rest using database-level encryption via Supabase.
Encryption in transit
All data transmitted between clients and the Platform, and between Platform components, is encrypted using TLS 1.2 or higher.
Tenant isolation
Row-level security (RLS) is enforced at the database layer. No cross-tenant data access is architecturally possible.
Access control
Role-based access control (RBAC) and per-entity permissions govern which users can read, write, or delete data within each System.
Audit logging
All data access, modifications, and workflow executions are logged with timestamps and user identifiers.
Token scoping
MCP tokens are scoped per entity and permission.
MCP token scoping
MCP tokens issued for AI agent access are scoped per-entity with configurable read/write permissions. Tokens can be revoked at any time.
Security assessments
Regular security reviews of the Platform architecture and sub-processor security posture.
Artivex engages the following sub-processors to deliver the Platform. Each sub-processor is bound by a data processing agreement with Artivex that imposes equivalent data protection obligations.
| Name | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and storage — primary data store for all Build data, System data, and account data | EU (Ireland) |
| Stripe | Payment processing — handles all financial transactions and subscription management | US / EU |
| Resend | Transactional email delivery — sends system notifications, password resets, and alerts | US |
| Vercel | Application hosting and deployment — hosts Customer Systems and Platform frontend | Global (edge) SCC |
| OpenAI | AI step processing — processes data from AI workflow steps using GPT models, when configured by the Customer | US |
| Anthropic | AI step processing — processes data from AI workflow steps using Claude models, when configured by the Customer | US |
| Mistral AI | AI step processing — processes data from AI workflow steps using Mistral models, and powers EU-only AI mode, when configured by the Customer | EU (France) |
EU — Data stored in EU. SCC — Transfer governed by Standard Contractual Clauses.
The table above lists the principal sub-processors. The complete, current list of all sub-processors is maintained at artivex.io/subprocessors and is the authoritative source. Artivex will notify the Customer of any intended changes to the sub-processor list, including additions or replacements, with at least 30 days notice by email. The Customer may object to a sub-processor change within 14 days of notification by contacting david@artivex.io. If an objection cannot be resolved, either party may terminate the affected services with 30 days written notice.
Artivex's primary data storage is in the EU (Supabase, EU-West-1, Ireland). All processing that occurs in the EU remains within the EU.
Where sub-processors are located outside the European Economic Area (EEA) — including Stripe, Resend, Vercel, Anthropic, and OpenAI — data transfers are governed by one of the following mechanisms:
Customers who require copies of the specific SCCs in place with any sub-processor may request them by contacting david@artivex.io.
In the event that Artivex becomes aware of a personal data breach (as defined in GDPR Article 4(12)) affecting Customer personal data, Artivex will:
The Customer, as Controller, is responsible for determining whether notification to individual data subjects is required under GDPR Article 34, and for making any such notifications.
Artivex provides tools within the Platform to assist the Customer in responding to data subject requests, including:
The Customer, as Controller, is responsible for:
If a data subject contacts Artivex directly with a request relating to data stored in a Customer System, Artivex will redirect the request to the Customer within 5 business days without acting on it unilaterally.
The Customer may conduct audits of Artivex's compliance with this DPA, subject to the following conditions:
Artivex will provide reasonable cooperation with the audit, including access to relevant documentation, policies, and security assessment reports.
As an alternative to a direct audit, Artivex may provide the Customer with up-to-date third-party audit reports, certifications, or summaries of security assessments, where available.
On termination or expiry of the service agreement between the parties:
If no instruction is received from the Customer within 30 days of termination, Artivex will delete all Customer data as its default course of action.
Liability under this DPA is subject to the limitations set out in the Artivex Terms of Service.
Each party is liable for damages caused by processing that infringes the GDPR to the extent they are responsible for such infringement under GDPR Article 82.
Artivex will not be liable for any claims arising from the Customer's failure to comply with their own obligations as Controller under the GDPR, including but not limited to failure to establish a lawful basis for processing, failure to notify data subjects, or failure to respond to valid data subject requests.
This DPA is governed by and construed in accordance with the laws of Sweden, consistent with the Terms of Service.
Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the Swedish courts, unless otherwise required by applicable data protection law.
To request a signed copy of this DPA, to exercise rights under this DPA, or for any data protection enquiries:
Corners Sverige AB (trading as Artivex)