Data Processing Agreement
Last updated:
This agreement applies where an organisation uses thestory.run and we process personal data on its behalf: its employees’ accounts, what they write, and the connections they make to publish it. It supplements the main agreement for the use of the service. How we handle data generally, including on the marketing site, is in the Privacy Policy.
1. Scope
1.1 Swat.io GmbH, registered in the commercial register of the Commercial Court of Vienna under FN 348798 p (the “Processor”), processes personal data on behalf of its customer (the “Controller”; together the “Parties”) on the basis of this DPA, in the version valid when the main agreement is concluded.
1.2 The Processor may amend this DPA with at least 30 days’ notice, announced on its website and sent to the Controller’s last-notified email address. If the Controller does not object in writing to lab@swat.io within 30 days, the amendment is deemed accepted. On timely objection the prior version continues to apply, and the Processor may terminate on 14 days’ notice to the end of the month.
1.3 The Processor carries out the processing described in the Annex (the “Data Processing”) under the main agreement for the use of the thestory.run service.
2. Place of processing
2.1 The Data Processing takes place in a Member State of the European Union or in a state party to the Agreement on the European Economic Area. The sub-processors listed in the Annex are deemed approved at the processing locations stated there, including the transfer bases stated there for a sub-processor established outside the EEA.
2.2 One transfer is inherent in the service and is named here so that it is not a surprise: when a user of the Controller instructs the service to publish a piece to their own LinkedIn profile, the text and the user’s LinkedIn identity are transmitted to LinkedIn, which processes them outside the EEA. That transfer happens on the explicit instruction of the individual, for a post that is public by nature (Art. 49(1)(a) GDPR). No LinkedIn connection means no such transfer.
2.3 Any other transfer of Data Processing to a third country requires the Controller’s prior consent and is permitted only if the requirements of Art. 44 et seq. GDPR are met.
3. Obligations of the Processor
3.1 The Processor processes personal data exclusively on the Controller’s documented instructions; the Controller’s configuration of the service constitutes such instructions. If the Processor considers an instruction to be unlawful, it shall inform the Controller without undue delay. It may suspend execution of the instruction until the instruction is confirmed or amended.
3.2 The Processor takes appropriate technical and organisational measures under Art. 32 GDPR. In summary: TLS in transit; AES-256-GCM at rest for every credential held on the Controller’s behalf, under a rotatable key and bound to the record it belongs to; authentication tokens stored only as hashes; passwordless sign-in with single-use, rate-limited links; tenant isolation enforced on every query and covered by a dedicated test suite; and an append-only audit log of mutating actions.
The complete and current technical and organisational measures are published at thestory.run/toms. They are kept current there rather than frozen into this agreement, so that a security improvement takes effect when it is made. The measures are not reduced below the level described in this clause.
3.3 The Processor obliges every person authorised to process the data to confidentiality and instructs them on the resulting duties.
3.4 The Processor supports the Controller in answering data subjects’ requests and in fulfilling its obligations under Art. 32 to 36 GDPR, and forwards any request addressed to it directly without undue delay.
3.5 The Processor notifies the Controller without undue delay of any personal data breach concerning the Controller’s data, with the information the Controller needs for its own notification duties.
3.6 Upon termination of the main agreement, the Processor stores the Controller’s personal data for a further 30 days to allow the Controller to export it. The data is deleted thereafter. The Controller may request immediate deletion at any time. Statutory retention obligations remain unaffected.
Independently of that period, an individual user disconnecting their LinkedIn account causes the immediate deletion of the credential and the LinkedIn identifiers held for them.
3.7 The Processor informs the Controller of inspections and orders by supervisory authorities, insofar as these relate to the processing under this agreement and insofar as providing such information is legally permitted.
3.8 The Processor does not use the Controller’s personal data, or content its users write, to train machine-learning models: its own or a third party’s.
4. Sub-processors
4.1 The Controller authorises the use of sub-processors. Those listed in the Annex are deemed approved on conclusion of the contract.
4.2 The Processor informs the Controller of any intended change of sub-processor. The Controller may object in writing to lab@swat.io within 30 working days of notification; absent a timely objection the change is deemed approved.
4.3 Where the Processor engages a sub-processor, it concludes an agreement under Art. 28(4) GDPR imposing the same obligations as this DPA.
5. Rights of control and inspection
5.1 The Controller may, in agreement with the Processor, audit the Data Processing (itself or through an auditor) after reasonable notice, during business hours, and not more than once every twelve months. Where the Processor evidences correct implementation of its obligations, checks are limited to random samples.
5.2 The Processor provides the information the Controller needs to demonstrate compliance with Art. 28 GDPR.
5.3 For one inspection every twelve months to a reasonable extent, the Processor bears its own internal costs. If the scope of an inspection exceeds a reasonable extent, or if additional inspections are requested, the Processor shall inform the Controller and provide a cost estimate; commissioning and the resulting costs are then borne by the Controller. The Controller bears its own costs and the costs of external auditors in all cases.
6. Remuneration
6.1 The remuneration under the main agreement covers the Processor’s obligations here. Support beyond what the GDPR requires, or audits exceeding the frequency in clause 5.1, may be charged at the Processor’s standard rates.
7. Term
7.1 This DPA runs for as long as the main agreement, and ends with it. Obligations that outlive it by their nature, confidentiality, deletion, survive.
8. Final provisions
8.1 Austrian law applies, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods.
8.2 The liability of the parties is governed by the provisions of the GTC. The place of jurisdiction agreed in the GTC applies to all disputes arising out of or in connection with this agreement.
8.3 This agreement is provided in English and German. Only the English version is binding; the German version is a translation provided for information.
8.4 Should any provision be invalid, the remainder stands.
Annex: Description of the Data Processing
1. Subject
Provision of thestory.run: a coaching product with which the Controller’s employees write posts for their own professional social profiles, plan when to publish them, publish them, and coordinate as a team.
2. Duration
The duration of the main agreement.
3. Nature and purpose
- Storing and displaying accounts, organisations, teams, and roles.
- Storing what users write: ideas, drafts, finished pieces, coach conversations, and shared wins: and showing colleagues only what the Controller’s configuration permits (a finished or published piece; never an unfinished draft).
- Sending the text a user is working on to a large language model, to generate the coach’s questions and notes.
- On the individual’s instruction, publishing a piece to that individual’s own LinkedIn profile, and holding the access token needed to do so.
- Sending transactional email: sign-in links and notifications the user asked for.
- Optionally, posting short coordination notices into the Controller’s own Slack workspace.
4. Categories of personal data
- Contact data: email address, name, optional profile picture.
- Usage and session data: sign-in times, IP address and user-agent of a session, actions taken in the organisation.
- Content data: everything the user writes in the product, including coach conversations.
- Connection data: LinkedIn person identifier, LinkedIn profile name, a copy of the LinkedIn profile picture, and an encrypted LinkedIn access token.
No special categories of data under Art. 9 GDPR are requested by the service. What a user chooses to write is their own; the product does not ask for it.
5. Categories of data subjects
Employees and contractors of the Controller who use the service, and administrators who manage it.
6. Authorised sub-processors
- Amazon Web Services EMEA SARL: 38 Avenue John F. Kennedy, L-1855 Luxembourg
- Application hosting, database, file storage, and transactional email, all in
eu-central-1(Frankfurt); model inference via Amazon Bedrock under an EU inference profile; static hosting and CDN for the marketing site. - PostHog, Inc.: United States
- Product analytics. Processing and storage take place exclusively in the EU Cloud (Frankfurt). The Standard Contractual Clauses of the European Commission apply to any access from the USA.
- Slack Technologies, LLC: United States
- Optional transmission of coordination notices (topic and author, not the content) to the Controller's own Slack workspace. Used only if the Controller activates the function. The transfer to the USA is based on certification under the EU-US Data Privacy Framework.
LinkedIn is not a sub-processor: it is a recipient acting on the individual’s own publishing instruction, as described in clause 2.2.
Provider and contact
Swat.io GmbH: data protection contact lab@swat.io, company details at swat.io/en/imprint.