Last updated 9 October 2026
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between Prim Group AB (organisation number 556651-0136), Kiselvägen 8, 506 70 Frufällan, Sweden (“Lodar”, “we”), and the business that uses Lodar (“the Customer”), as described in our terms and conditions. It applies when Lodar processes personal data on the Customer's behalf, and meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
If your organisation needs a signed copy, write to [email protected] and we'll send one, together with the current list of subprocessors.
1.Roles
For personal data that Lodar processes on the Customer's behalf, the Customer is the controller and Lodar is the processor. Personal data that Lodar processes for its own purposes, such as the accounts of the people who use the service, is covered by our privacy policy, where Lodar is the controller.
Words such as “personal data”, “processing” and “personal data breach” have the meaning they have in the GDPR.
2.What is processed
- Purpose and nature. Providing Lodar to the Customer: testing the Customer's product pages and newsletters with AI shoppers, analysing the results, suggesting changes, and publishing approved changes to connected systems.
- Types of personal data. Personal data that appears in the material Lodar handles for the Customer, for example names in public product reviews captured in screenshots, content the Customer uploads or writes in the service (such as newsletters, questions to Ask Lodar and notes), and data from systems the Customer connects. The AI shoppers do not log in and do not collect data about the Customer's own customers.
- Data subjects. People whose data appears in that material, for example reviewers on the Customer's site and the Customer's staff.
- Special categories. Lodar is not intended for special categories of personal data, and the Customer should not provide them.
- Duration. As long as the agreement lasts, and until the data is deleted as described in section 10.
3.The Customer's instructions
Lodar processes personal data only on the Customer's documented instructions, unless the law requires otherwise; in that case we will tell the Customer before processing, unless the law forbids it. The agreement, this DPA and the Customer's use and settings of the service are the Customer's instructions. If we believe an instruction breaks the GDPR or other data protection law, we will tell the Customer.
The Customer is responsible for having a legal basis for the processing, and for the personal data it provides to Lodar or lets Lodar access.
4.Confidentiality
Everyone at Lodar who can access the Customer's personal data is bound by confidentiality, and has access only as far as their work requires.
5.Security
We take appropriate technical and organisational measures to protect personal data, including:
- Encryption of data in transit, and of the credentials for the Customer's connected systems at rest.
- Storage of the database and files in the EU.
- Access control that keeps each customer's data separate, and limits staff access to what support and operations need.
- Short-lived links for screenshots and reports, so stored files are never public.
- A log of every change made to the Customer's store through integrations, so it can be traced and undone.
We review these measures as the service and the risks change.
6.Subprocessors
The Customer gives Lodar general authorisation to use subprocessors. We use providers in these categories, and give the Customer the full, named list on request:
- Database and authentication: EU
- File storage (screenshots, reports): EU
- Application hosting and the test workers: EU
- AI model providers (the shoppers, findings and suggested fixes): USA
- Email delivery (summaries and notifications): EU
We will tell the Customer at least 30 days before adding or replacing a subprocessor. The Customer may object on reasonable grounds related to data protection. If we can't resolve the objection, the Customer may terminate the affected part of the service before the change takes effect.
Each subprocessor is bound by a written agreement with data protection obligations at least as protective as those in this DPA. Lodar remains responsible to the Customer for its subprocessors.
7.Transfers outside the EU and EEA
Where a subprocessor processes personal data outside the EU and EEA, we ensure the transfer meets chapter V of the GDPR, through the EU–US Data Privacy Framework where the provider is certified under it, or the European Commission's standard contractual clauses together with any additional measures needed.
8.Assistance
Taking into account the nature of the processing, we help the Customer respond to requests from data subjects exercising their rights, and with data protection impact assessments and prior consultations with supervisory authorities where they concern Lodar. If a data subject contacts us directly about data we process for the Customer, we will pass the request on to the Customer.
9.Personal data breaches
We will notify the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Customer's personal data. The notice will describe, as far as we know at the time, what happened, the data and people affected, the likely consequences, and what we are doing about it. We will keep the Customer updated and help it meet its own obligations to notify.
10.When the agreement ends
When the agreement ends, the Customer can ask us to export its test results. We delete the Customer's personal data within 90 days of the agreement ending, including copies, unless the law requires us to keep it. Data in backups is deleted as the backups expire.
11.Audits
We make available the information the Customer needs to show that the obligations in Article 28 are met. The Customer may, at its own cost and with at least 30 days' notice, have an independent auditor bound by confidentiality inspect our compliance, at most once a year unless a supervisory authority requires otherwise or after a personal data breach. Audits are carried out without disrupting the service or revealing other customers' data.
12.Liability and precedence
Each party's liability under this DPA follows the limits in the agreement, unless mandatory law says otherwise. If this DPA and the rest of the agreement conflict on the processing of personal data, this DPA applies.
13.Changes and term
This DPA applies for as long as Lodar processes personal data on the Customer's behalf. We may update it, for example when the law or the service changes. We will tell the Customer at least 30 days before a material change takes effect, in the same way as for the terms and conditions. Swedish law applies, as set out in the agreement.
14.Contact
Questions about this DPA, requests for a signed copy or the list of subprocessors: [email protected].