Legal

GDPR & Data Processing Agreement

Updated: 2026-07-01

When the Customer (the "Controller") sends SMS to their own recipients via SveaSMS, Global Trade Rhino LLC (the "Processor") acts as data processor. This DPA applies automatically upon acceptance of the Terms of Service and use of the Service to process personal data covered by the GDPR or equivalent law.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller for the purpose of delivering the SMS service. Duration: as long as the Customer's account is active plus statutory retention periods.

2. Categories of data subjects and data

Data subjects: the Customer's recipients, contacts and representatives. Categories: phone numbers, sender IDs, message content, metadata (timestamp, DLR status, country).

3. Processor obligations

  • Process data only on the Controller's documented instructions (these terms constitute such instructions).
  • Ensure confidentiality of personnel.
  • Apply appropriate technical and organisational measures under Art. 32 GDPR.
  • Notify the Controller without undue delay of a personal data breach affecting the Controller's data.
  • Assist the Controller with data-subject rights and DPIAs, to a reasonable extent and against reasonable compensation.
  • Delete or return data at the end of the agreement, subject to statutory retention requirements.

4. Subprocessors

The Controller grants general prior authorisation for the Processor's use of subprocessors. A list is provided on request. On change of subprocessor the Controller is informed and may object within 30 days; where the objection is well-founded either party may terminate the affected part of the agreement.

5. International transfers

For transfers outside the EU/EEA the EU Commission's Standard Contractual Clauses (SCC 2021/914) or equivalent safeguard is applied, together with appropriate supplementary technical and organisational measures.

6. Audit

The Controller may once per year, on at least 30 days' written notice, request an audit of the Processor's compliance with this DPA. Audits are primarily satisfied by the Processor sharing a recent independent third-party report (e.g. SOC 2 or ISO 27001) where such exists. On-site audits only where strictly necessary, at the Processor's standard rates and under NDA.

7. Liability

The limitations of liability in the Terms of Service also apply to this DPA to the extent permitted by law. Each party bears its own fines under Art. 83 GDPR.

8. Conflicts

In case of conflict between this DPA and other parts of the agreement, this DPA prevails as regards processing of personal data.