Template – applies once signed by both parties.
The agreement below is our standard agreement for StaffHub. It becomes binding only when signed by the employer (the customer) and Forss Management Consulting AB. Contact us and we will send it for signature. In case of discrepancy, the Swedish version prevails.
Data processing agreement for StaffHub under Article 28(3) of the General Data Protection Regulation (GDPR).
Last changed: 2026-10-01
Controller (“the Customer”): the employer that has entered into an agreement for StaffHub (“the main agreement”), with the details stated in the main agreement or on signature.
Processor (“the Supplier”):
Forss Management Consulting AB (Formacon), Corporate ID no. 559086-4780
Postal address: Lantmannagatan 33, 583 32 Linköping, Sweden
Web: formacon.se
Contact person: Pierre Lindbom
Email: pierre.lindbom@formacon.se
Phone: 0735-28 12 15
This agreement covers the personal data the Customer enters into StaffHub or has the Supplier process on its behalf. For data about user accounts and how the service is used and operated — sign-ins, technical logs, error reports and visitor statistics — the Supplier is itself the controller; that processing is described in the privacy policy.
Health: StaffHub only stores that a health check has been carried out or is planned, and when — never the result or a medical assessment. Even this may be data concerning health under Article 9. The Customer is responsible for having a legal basis for the processing, and access in the system is limited to administrators and HR.
Other special categories of personal data and data on criminal offences are not processed intentionally, and the service has no fields for them. The Customer is responsible for not entering them in free text or documents.
The Supplier processes the personal data only on the Customer’s documented instructions. This agreement, the main agreement and the Customer’s own choices in the service (for example which modules, integrations and AI features are enabled, and how long data is kept) constitute the complete instructions. Processing required by Union or Swedish law may take place without instruction; the Supplier then informs the Customer before processing, unless the law prohibits it. The Supplier immediately informs the Customer if, in its opinion, an instruction infringes the GDPR.
The Supplier does not use the data for its own purposes, does not sell it and never lets it be used to train AI models.
The Supplier ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality. Confidentiality continues after the agreement has ended.
The Supplier takes, among others, the following technical and organisational measures:
The Supplier may change the measures, provided the level of protection is not lowered.
The Customer gives a general prior authorisation for the Supplier to engage subprocessors. The Supplier enters into written agreements with each subprocessor imposing the same data protection obligations as this agreement, and is liable to the Customer for the subprocessor’s processing as for its own.
The Supplier notifies the Customer at least 30 days before a subprocessor is added or replaced. The Customer may object on reasonable grounds. If the parties cannot agree, the Customer may terminate the main agreement without cost for the remaining period.
Subprocessors when this agreement was last changed:
The Customer’s own Microsoft 365, which the document library reads from, and services the Customer connects itself via an API key are not the Supplier’s subprocessors. They are covered by the Customer’s own agreements with each provider.
The Supplier assists the Customer, through appropriate technical and organisational measures, in responding to requests for access, rectification, erasure, restriction, portability and objection. StaffHub has built-in support for data exports and erasure the Customer can use itself. A request received directly by the Supplier is forwarded to the Customer without undue delay and is not answered by the Supplier without the Customer’s instruction.
The Supplier assists the Customer in meeting its obligations regarding security (Article 32), notification of personal data breaches (Articles 33–34), data protection impact assessments (Article 35) and prior consultation with the supervisory authority (Article 36), taking into account the nature of the processing and the information available to the Supplier.
The Supplier notifies the Customer without undue delay and no later than 48 hours after becoming aware of a personal data breach affecting the Customer’s data. The notification contains, to the extent available: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Information not immediately available is provided as soon as it becomes available. The Supplier assists the Customer in investigating and containing the breach.
During the agreement, the Customer decides how long data about an employee is kept after employment ends (24 months by default), after which the system flags the records for erasure.
When the main agreement ends, the Supplier shall, at the Customer’s choice, delete all personal data or return it in a machine-readable format and then delete it. Deletion takes place within 30 days of the end of the agreement or the Customer’s request. Data in backups disappears as the backups are rotated out under section 7, no later than after 12 months, and is meanwhile not used for any purpose other than restoration. Longer storage only takes place where Union or Swedish law requires it.
The service, database and files are in Sweden. Encrypted copies of the backups are stored in Microsoft OneDrive, in the data centre Microsoft states as the storage location for the Supplier’s account (within the EU/EEA for European accounts). Other subprocessors and their locations are listed in section 8.
Transfers outside the EU/EEA only take place on a legal basis under Chapter V of the GDPR, for example an adequacy decision (as for companies certified under the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses. Today this concerns the AI features, where the text in question is sent to OpenAI in the USA, and push services that may be outside the EU/EEA. If the Customer wishes to avoid the transfer to the USA, the AI features should not be enabled.
The Supplier makes available to the Customer the information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer who is bound by confidentiality. Audits are primarily answered in writing. An on-site audit is announced at least 30 days in advance, takes place during normal working hours, at most once a year unless a breach or an authority requires otherwise, at the Customer’s expense and without disclosing other customers’ data.
Each party is liable for damage it has caused by breaching this agreement or the GDPR, in accordance with Article 82. Limitations of liability in the main agreement also apply to this agreement, but do not limit either party’s liability towards data subjects or for administrative fines imposed on that party by an authority.
The agreement applies from signature and for as long as the Supplier processes personal data on the Customer’s behalf. In case of conflict, this agreement prevails over the main agreement in matters concerning the processing of personal data. Amendments must be in writing and signed by both parties; changes to the list of subprocessors are however made under section 8.
Swedish law applies to the agreement. Disputes are settled by Swedish general courts, unless the main agreement states otherwise.
The agreement is signed by authorised representatives of the Customer and of Forss Management Consulting AB. It is not signed in this published version.