Data Processing Agreement

Last updated: August 22, 2026

This Data Processing Agreement (the "DPA") forms part of the Agreement between the Customer and Ankra AB ("Ankra") described in theTerms of Service. It applies automatically to every Customer from the Commencement Date and governs Ankra's processing of personal data contained in Customer Data. Capitalised terms not defined here have the meaning given in the Terms of Service.

No signature is required. Where a Customer needs a countersigned copy for its records, or needs the Standard Contractual Clauses executed separately, email[email protected].

In the event of a conflict between this DPA and the rest of the Agreement concerning the processing of personal data, this DPA prevails.

1. Roles and scope

1.1. The Customer is the controller, and Ankra is the processor, of personal data contained in Customer Data that Ankra processes in providing the Ankra Service. Where the Customer is itself a processor for a third-party controller, Ankra is a sub-processor and the Customer warrants that its instructions are consistent with that controller's instructions.

1.2. Annex 1 describes the subject matter, duration, nature and purpose of the processing, the categories of data subjects and the categories of personal data.

1.3. "Data Protection Law" means Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other law applicable to the processing of personal data under the Agreement, in each case as amended. Terms such as "personal data", "processing", "controller", "processor", "personal data breach" and "data subject" have the meaning given in the GDPR.

2. Processing on instructions

2.1. Ankra will process personal data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do so by European Union or member state law to which Ankra is subject, in which case Ankra will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

2.2. The Customer's documented instructions are: the Agreement; the configuration the Customer and its Users apply within the Ankra Platform, including which clusters and repositories are connected, which features are enabled, and which prompts are submitted to the AI Features; and any further written instructions agreed between the parties.

2.3. Ankra will inform the Customer without delay if, in its opinion, an instruction infringes Data Protection Law. Ankra is not obliged to carry out a legal review of the Customer's instructions.

3. Confidentiality

3.1. Ankra ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process personal data only as needed to perform the Agreement.

4. Security

4.1. Ankra implements and maintains the technical and organisational measures set out in Annex 2, which the parties agree are appropriate to the risk of the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.

4.2. Ankra may update the measures in Annex 2 from time to time, provided that an update does not materially reduce the overall level of protection. The current version is published at this page.

5. Sub-processors

5.1. The Customer gives Ankra general authorisation to engage sub-processors. The sub-processors engaged on the date of this DPA, and the purpose and location of each, are listed atankra.ai/trust, which forms Annex 3.

5.2. Ankra will give the Customer at least 30 days' notice of any intended addition or replacement of a sub-processor, by email to the Account's administrators or by notice in the Ankra Platform, and will update Annex 3 at the same time.

5.3. The Customer may object to a new sub-processor on reasonable grounds relating to data protection by written notice within that 30-day period. If the parties cannot resolve the objection in good faith within a further 30 days, either party may terminate the part of the Ankra Service that cannot be provided without the new sub-processor, and Ankra will refund any prepaid Service Fees for the terminated part on a pro-rata basis.

5.4. Ankra imposes on each sub-processor data protection obligations that are no less protective than those in this DPA, by way of a written contract, and remains fully liable to the Customer for the performance of each sub-processor's obligations.

6. Data subject rights

6.1. Taking into account the nature of the processing, Ankra assists the Customer with appropriate technical and organisational measures to respond to requests from data subjects exercising their rights. The self-service functions of the Ankra Platform, including the ability to view, edit and delete User accounts and to export Customer Data, are the primary means of that assistance.

6.2. If a data subject contacts Ankra directly about personal data processed on the Customer's behalf, Ankra will forward the request to the Customer within 5 business days and will not respond to it except to confirm that it has been forwarded, unless required by law.

7. Personal data breach

7.1. Ankra will notify the Customer without undue delay, and in any event within 72 hours, after confirming a personal data breach affecting Customer Data. Notice goes to the email addresses of the Account's administrators.

7.2. The notice will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach. Ankra may provide the information in phases as it becomes available.

7.3. Ankra will cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation and remediation of the breach. Notification under this clause is not an admission of fault.

8. Impact assessments and consultation

8.1. Taking into account the nature of the processing and the information available to it, Ankra will provide reasonable assistance to the Customer with data protection impact assessments and with prior consultation of a supervisory authority, where required by Data Protection Law. Ankra may charge its then-current professional services rates for assistance that goes beyond providing the information published at ankra.ai/trust and ankra.ai/security.

9. Deletion and return

9.1. On termination of the Agreement, the Customer may export Customer Data for 30 days as described in the Terms of Service. Ankra will then delete Customer Data from its systems within 30 days, except where European Union or member state law requires storage of the personal data, and except for copies held in backups, which are overwritten in the ordinary course within 90 days and are not accessed in the meantime except for restoration of the Ankra Platform as a whole.

9.2. On written request, Ankra will confirm in writing that deletion has been completed.

10. Audit

10.1. Ankra will make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR. The documentation published at ankra.ai/trust and ankra.ai/security, together with written responses to the Customer's reasonable questions, is the first means of doing so.

10.2. Where that information is insufficient to demonstrate compliance, the Customer or an independent auditor mandated by the Customer and bound by confidentiality may audit Ankra's relevant processing activities, no more than once in any 12-month period, on at least 30 days' written notice, during business hours, in a manner that does not unreasonably disrupt Ankra's operations or compromise the security of other customers, and at the Customer's cost. A supervisory authority may audit at any time as provided by Data Protection Law.

10.3. Ankra will state plainly which third-party certifications and audit reports it holds. Ankra does not currently hold a SOC 2 report; the state of its information security programme is described at ankra.ai/trust.

11. International transfers

11.1. The Ankra Platform and its primary data stores are hosted in the European Union.

11.2. Where Ankra or a sub-processor transfers personal data to a country outside the European Economic Area that is not the subject of an adequacy decision, the transfer is made under the Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this DPA by reference with the following selections: Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) with the notice period in clause 5.2; Clause 11 optional language does not apply; Clause 13 applies with the Swedish Authority for Privacy Protection as competent supervisory authority; Clause 17 option 1 with Swedish law; Clause 18 with the courts of Sweden. Annexes 1 and 2 of this DPA serve as Annexes I and II of the Standard Contractual Clauses.

11.3. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, is incorporated by reference and takes precedence to the extent of any conflict. For transfers subject to Swiss law, the Standard Contractual Clauses are read with the adaptations required by the Swiss Federal Data Protection and Information Commissioner.

11.4. The Customer may request details of the safeguard relied on for a given sub-processor at [email protected].

12. Liability

12.1. Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms of Service. Nothing in this DPA limits a data subject's rights against either party under Article 82 of the GDPR.

13. Term, changes and law

13.1. This DPA applies for as long as Ankra processes personal data on the Customer's behalf, including the period in clause 9.

13.2. Ankra may update this DPA to reflect changes in Data Protection Law, in the Ankra Service, or in the Standard Contractual Clauses, in accordance with the change procedure in the Terms of Service. A change that materially reduces the Customer's protection takes effect for an existing Customer only at the start of its next Renewal Term.

13.3. This DPA is governed by Swedish law and is subject to the jurisdiction clause of the Terms of Service, except where the Standard Contractual Clauses require otherwise. Ankra's lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten).

Annex 1 — Details of processing

Subject matterProvision of the Ankra Service: a Kubernetes deployment, management and operations platform, including its AI Features, as described in the Terms of Service.
DurationThe Term of the Agreement, plus the export and deletion period in clause 9.
Nature and purposeHosting, storing, transmitting, analysing and displaying Customer Data so that the Customer can operate its Kubernetes clusters through the Ankra Platform; generating AI-assisted analysis and configuration on the Customer's instruction; providing support; metering usage for billing.
Categories of data subjectsThe Customer's Users (employees, contractors and agents who hold an Account); and, incidentally, individuals whose personal data appears in the Customer's cluster metadata, log excerpts, configuration or prompts.
Categories of personal dataUser identifiers: name, email address, authentication identifiers, IP address, browser and device information. Platform records: audit events attributed to a User, support correspondence, chat prompts and AI outputs. Cluster-derived data: resource names, labels, annotations, events, configuration and log excerpts, which may incidentally contain personal data the Customer has placed there.
Special categoriesNone intended. The Customer must not submit special-category data, criminal-offence data, or data subject to sector-specific regimes such as health or payment-card data, to the Ankra Service, and must not place it in a Playground Environment at all.
FrequencyContinuous, for the duration of the Agreement.

Annex 2 — Technical and organisational measures

AreaMeasures
EncryptionAll data in transit between the Customer, the Ankra Agent and the Ankra Platform is encrypted using TLS 1.2 or higher. Data at rest in Ankra's databases and backups is encrypted. Customer credentials and cloud provider secrets are held in a dedicated secrets manager and are never written to logs.
Access controlRole-based access control within the Customer's organisation; multi-factor authentication and single sign-on available to Customers; Ankra personnel access to production systems is restricted to named engineers, granted on a least-privilege basis, authenticated with MFA and logged.
Tenant isolationCustomer Data is logically separated by organisation at the application and database layers. Playground Environments are isolated per tenant on shared infrastructure and are destroyed on expiry.
Data minimisationThe Ankra Agent runs inside the Customer's cluster and transmits metadata, events and configuration to the Ankra Platform. Secrets are redacted at source before transmission. SOPS-encrypted values are decrypted inside the Customer's cluster, not on the Ankra Platform.
AuditAn append-only audit log records administrative actions, including every action performed through the AI Features.
Availability and recoveryProduction databases are backed up to object storage in the EU with continuous write-ahead-log archiving. Backups are retained for no more than 90 days. The Ankra Platform is monitored continuously and its status is published at status.ankra.io.
Vulnerability managementDependencies and container images are scanned for known vulnerabilities as part of the build pipeline. Security advisories may be reported to [email protected] under the disclosure policy published at ankra.ai/security/disclosure.
Incident responseA documented incident response process covering detection, containment, notification under clause 7, and post-incident review.
PersonnelAnkra personnel with access to Customer Data are bound by confidentiality obligations and receive security and data protection training.

Annex 3 — Sub-processors

The current list of sub-processors, with the purpose and hosting location of each, is published atankra.ai/trust and is incorporated into this DPA. Changes are notified under clause 5.

Contact

Data protection questions, signed copies and objections under clause 5:[email protected]. Security incidents: [email protected].