These contractual terms take effect when Stockholm IT Academi AB and the customer expressly incorporate or accept them in an order or written agreement. Publishing or reading this page does not create acceptance.
1. Parties, scope and precedence
The processor is Stockholm IT Academi AB, organisation number 559337-9141, Fallskärmsgatan 1 lgh 1302, 128 34 Skarpnäck, Stockholm, Sweden. The controller is the customer identified in the order or written acceptance of this agreement. Privacy correspondence is directed to gdpr@sita.dev.
This agreement governs personal data processed on the customer’s behalf in BIGI. It supplements the service agreement and prevails in a conflict about that processing. GDPR terms, including personal data, controller, processor, processing and personal data breach, have their statutory meanings. Each party remains responsible for its own obligations under applicable data protection law.
2. Processing particulars
Subject matter and purpose: providing the customer’s workspace and authorised Instagram conversation, campaign, lead and content functions. Operations include receipt, storage, organisation, retrieval, context selection, AI-assisted generation, authorised transmission, activity recording, export and erasure.
Data subjects: the customer’s authorised users, Instagram followers and account correspondents, leads, and people included in customer-authorised media. Data categories: account and profile identifiers, contact details, comments, messages, timestamps, campaign and lead responses, uploaded media, business knowledge and necessary technical records. Special-category data is not required and must not be submitted without a separately agreed lawful scope and appropriate safeguards.
Duration: for the service period and the period necessary to complete return or deletion, subject to legally required retention. The controller determines the lawful purpose, data supplied, permitted campaign scope and retention settings within the service’s supported controls.
3. Documented instructions
The processor shall process personal data only on the controller’s documented instructions, including instructions concerning transfers, unless required by applicable Union or Member State law. In that case the processor shall inform the controller of the legal requirement before processing unless the law prohibits that information on important grounds of public interest.
The service agreement, accepted order, authorised workspace settings and the controller’s verified written requests constitute instructions. The processor shall inform the controller immediately if, in its opinion, an instruction infringes applicable data protection law, and may suspend the affected instruction while the parties resolve it. The processor shall not use controller personal data for its own unrelated purposes.
4. Confidentiality and security
The processor shall ensure that persons authorised to process the data are committed to confidentiality or under an appropriate statutory duty. Access shall be limited to the authorised service purpose and revoked when no longer needed.
The processor shall implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, cost, processing and risks. The measures described in Annex A are the baseline; changes must not materially reduce the agreed level of protection. The controller remains responsible for authorised-user access, its own source material and suitable review of business actions.
5. Subprocessors
The controller gives general written authorisation to the subprocessors identified in the provider register incorporated at acceptance. The processor shall give at least 30 days’ advance notice of an intended addition or replacement that will process the controller’s data, allowing a reasonable opportunity to object on substantiated data protection grounds before the change takes effect.
The parties shall seek a reasonable resolution to an objection. If no suitable alternative can be agreed, the controller may terminate the affected service before the new subprocessor begins processing, with a refund of prepaid fees for the unused affected service period. The processor shall impose substantially equivalent relevant data protection obligations on each subprocessor and remain fully liable to the controller for performance of those obligations.
6. International transfers
The processor shall not transfer personal data to a third country or international organisation without the controller’s documented instructions and an applicable Chapter V basis. Where required, the parties shall implement the applicable standard contractual clauses and any necessary supplementary measures before the transfer.
The processor shall provide information reasonably required to assess the applicable destination, mechanism and measures. Nothing in this agreement represents that a transfer assessment, provider-region schedule or separate standard contractual clauses have already been executed. Those deployment-specific documents form part of the agreed processing record when applicable.
7. Individuals’ rights and assistance
Taking account of the nature of processing, the processor shall assist the controller through appropriate technical and organisational measures, insofar as possible, with requests to exercise data-subject rights. A request received directly shall be forwarded or routed to the controller without undue delay; the processor shall not decide the request on the controller’s behalf unless instructed or legally required.
The processor shall assist with the controller’s obligations under Articles 32 to 36, taking account of the processing and information available, including security assessments, impact assessments and prior consultations. Assistance beyond standard service controls may be subject to reasonable, agreed charges; charges must not prevent performance of the processor’s mandatory obligations.
8. Personal data breaches
The processor shall notify the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data. Available information shall include the nature of the breach, affected categories and approximate numbers where known, a contact point, likely consequences and measures taken or proposed. Information may be provided in phases without undue further delay as facts become available.
The processor shall take reasonable steps to contain and remediate the incident, preserve relevant evidence and cooperate with the controller. The controller determines its own notifications to individuals and authorities unless law assigns that obligation directly to the processor. Notification is not by itself an admission of fault.
9. Demonstrating compliance and audits
The processor shall make available the information necessary to demonstrate compliance with Article 28 and allow and contribute to audits, including inspections, by the controller or an independent auditor mandated by it.
The parties shall agree reasonable notice, confidentiality and security arrangements that protect other customers’ data and avoid unnecessary disruption. Documentary evidence may be used first where it adequately addresses the issue. These arrangements shall not defeat a lawful audit right, an urgent incident investigation or a competent authority’s powers.
10. Return, deletion and end of processing
At the controller’s choice, the processor shall return or delete the personal data after the end of the processing service and delete existing copies, unless applicable Union or Member State law requires storage. The controller should communicate its choice and request an export before ending access. Deletion shall be completed without undue delay, with confirmation and an explanation of any lawful exception.
Copies awaiting expiry in restricted backups shall remain protected and unavailable for ordinary service use, and shall be deleted under the applicable documented provider cycle. If a backup is restored, the processor shall reapply the relevant deletion instructions. The agreement continues to protect any lawfully retained data until deletion.
Annex A. Baseline security measures
Access and separation: authenticated sessions, server-side authorisation, workspace-scoped access and restriction of operational access to authorised personnel. Connection protection: encrypted server-side Instagram tokens, state-verified authorisation returns and verification of incoming Meta webhook signatures.
Action safeguards: approved business sources, server-side action checks, scoped campaigns, review modes, automation pause and human takeover. Data lifecycle: available workspace exports, verified deletion requests, configurable supported record retention and scheduled cleanup with recovery of failed operations.
Operational measures: HTTPS for hosted transport, protection of server secrets, security-relevant audit information, incident investigation and controlled handling of provider access. These measures do not constitute a certification, guaranteed absence of vulnerabilities or proof that an external supplier’s assurance review is complete.
Annex B. Provider and processing record
The BIGI subprocessor register identifies Vercel for hosting, Supabase for database and files, Google Cloud Vertex AI for configured generation, OpenAI for optional fallback text, Groq for configured transcription and Resend for service email. Meta supplies the connected Instagram platform under its own applicable terms and role.
At acceptance, the parties must incorporate the applicable provider register and deployment-specific locations, retention arrangements and transfer documents into their processing record. The controller can request those documents at gdpr@sita.dev. This clause does not supply missing provider facts by assumption or claim that publication has completed contractual onboarding.
Useful links
Contact the privacy team · Company details · Privacy notice · Request deletion · GDPR & processing · Data processing agreement · Subprocessors · Terms
Your rights: Swedish Authority for Privacy Protection · EU General Data Protection Regulation