Data Processing Agreement
Last updated 22 September 2026
This agreement applies between the company that uses Lanthea (the controller) and Fly by wire AB (org. no. 559316-3313), which provides it (the processor). It is part of the Terms of Service and meets Article 28 of the General Data Protection Regulation (GDPR).
1. Subject, duration and purpose
The processor processes personal data on the controller's behalf to provide the service: to store and organise the controller's records, to read documents and mail with AI, to answer questions from the controller's members, and to send the email the service sends. The processing lasts as long as the controller uses the service.
2. The personal data and the people it concerns
- Members and invited people: names, email addresses, roles, and who did what in the service.
- The controller's customers and suppliers and their contact persons: names and contact details in invoices and receipts.
- People named on receipts, such as participants in business entertainment and people who paid privately.
- Trips: addresses, distances, purposes and, when recorded with the iOS app, GPS routes.
- Mail in connected mailboxes: the sender, subject and beginning of the text of each new message, and the attached documents of mail filed as receipts.
- Questions and answers in the members' conversations with the agent.
The service is not meant for special categories of personal data, such as health information, and the controller should not enter them.
3. Instructions
The processor processes the personal data only on the controller's documented instructions: this agreement, the Terms of Service, and what the controller's members do in the service. If Union or Swedish law requires other processing, the processor tells the controller first, unless the law forbids it. The processor tells the controller if it considers an instruction to break the GDPR.
4. Confidentiality
Everyone at the processor who can reach the personal data is bound to confidentiality.
5. Security
The processor takes appropriate technical and organisational measures under Article 32 of the GDPR. Among them: the service and its data are hosted in Sweden; traffic to the service is encrypted; connection tokens and app passwords are encrypted at rest with a key kept outside the database; sign-in codes and session tokens are stored only as fingerprints; and each member reaches only what their role allows.
6. Subprocessors
The controller gives the processor general authorisation to use subprocessors. The current ones are listed on the Subprocessors page. The processor tells the controller's owners at least 30 days before adding or replacing one, and the controller may object on reasonable grounds; if no solution is found, the controller may end the agreement. The processor binds each subprocessor to the same data protection obligations as this agreement and remains responsible for it.
7. Transfers outside the EU and EEA
Personal data is transferred to a country outside the EU and EEA only with the safeguards of Chapter V of the GDPR, such as an adequacy decision like the EU–US Data Privacy Framework, or the European Commission's standard contractual clauses.
8. Assistance
As far as it can, the processor helps the controller to answer requests from the people the data concerns, and with security, data protection impact assessments and prior consultation under Articles 32 to 36 of the GDPR.
9. Personal data breaches
The processor tells the controller without undue delay after becoming aware of a personal data breach, with what is known about it, so that the controller can meet its obligations under Articles 33 and 34 of the GDPR.
10. When the processing ends
When the controller's owners delete the company in the service, or the agreement ends, the processor deletes the personal data, unless Union or Swedish law requires it to be kept. Until then the controller can export its records from the service.
11. Audits
The processor makes available the information needed to show that it meets this agreement, and allows audits by the controller or an auditor it appoints, with reasonable notice and at the controller's cost.
12. Liability, law and notices
Liability follows the Terms of Service and Article 82 of the GDPR. Swedish law applies, and disputes are settled by Swedish courts. Notices under this agreement: support@lanthea.ai.