Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Pitchwise Terms of Service between Bantaba AB and the Customer. By accepting the Terms of Service, the Customer agrees to the terms of this DPA. This DPA governs the processing of personal data by Bantaba AB as a data processor on behalf of the Customer as a data controller, in connection with the Customer's use of the Pitchwise Service. This document has been drafted for compliance with GDPR Article 28. It should be reviewed by a qualified legal professional before being relied upon in regulated-sector or high-risk processing contexts.
1. Parties
1.1 Data Controller
The "Controller" is the Customer identified in the Pitchwise account registration – the natural person or legal entity that accesses or uses the Pitchwise Service and determines the purposes and means of processing Visitor Personal Data through that use.
1.2 Data Processor
The "Processor" is Bantaba AB, a Swedish limited liability company with organisation number 559320-2640, having its registered address at c/o Magine Pro, Östermalmsgatan 26A, 114 26 Stockholm, Sweden (operating the Pitchwise service).
1.3 Relationship
The parties enter into this DPA in their respective capacities as data controller and data processor under GDPR Article 28. Where Bantaba AB processes personal data for its own purposes (such as account management and billing), Bantaba AB acts as an independent data controller and such processing is governed by the Pitchwise Privacy Policy, not this DPA.
2. Definitions
Terms used in this DPA have the meanings given in GDPR unless otherwise defined below. Capitalised terms not defined here have the meanings given in the Pitchwise Terms of Service.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
"Personal Data" means any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1), processed by the Processor on behalf of the Controller under this DPA.
"Processing" has the meaning given in GDPR Article 4(2) and "Process" and "Processed" shall be construed accordingly.
"Data Subject" means the natural person to whom the Personal Data relates — in the context of this DPA, primarily Visitors who access Customer Data shared via the Service.
"Visitor" means any third party who accesses Customer Data (including documents and Data Rooms) shared by the Controller through the Service.
"Sub-processor" means any third-party entity engaged by the Processor to process Personal Data under this DPA on behalf of the Controller.
"Security Incident" means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.
"SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"EEA" means the European Economic Area.
"Supervisory Authority" means the competent data protection authority — for Bantaba AB, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
"Hidden Data" means Visitor engagement records that are retained in the Processor's database but are not accessible to the Controller due to the access limitations of the Controller's current Subscription Plan.
3. Subject Matter, Nature, and Purpose of Processing
3.1 Subject Matter
This DPA governs the processing of Personal Data by the Processor on behalf of the Controller in connection with the Controller's use of the Pitchwise Service, specifically the collection and processing of Visitor engagement data generated when Visitors access Customer Data shared by the Controller via the Service.
3.2 Nature of Processing
The Processor will perform the following processing operations on behalf of the Controller:
- Collection of Visitor email addresses (where provided or required by the Controller's link settings);
- Collection of IP-derived location data (country and approximate city level);
- Recording and storage of document engagement data (time spent per page or slide, completion rate, return visits, download activity);
- Linking engagement records to individual Visitor identities where email verification is enabled;
- Storage and display of engagement analytics in the Controller's Pitchwise dashboard, subject to the access limits of the Controller's active Subscription Plan;
- Deletion of Visitor Personal Data upon account termination or following the retention periods described in Section 3.4.
3.3 Purpose of Processing
The Processor processes Visitor Personal Data solely for the purpose of providing the document tracking and analytics features of the Service to the Controller, enabling the Controller to understand how Visitors engage with shared documents and Data Rooms. The Processor does not use Visitor Personal Data for its own commercial purposes, advertising, or profiling.
The Processor may display non-personalised promotional content (such as a "Powered by Pitchwise" banner) within the document viewer. Such display does not constitute processing of Visitor Personal Data for the Processor's own commercial purposes and does not require separate consent.
3.4 Duration of Processing
3.4.1 Active Subscription
The Processor processes Visitor Personal Data for the duration of the Controller's active subscription to the Service, including periods during which the Controller holds a Free plan.
3.4.2 Account Deletion
When the Controller deletes their Pitchwise account, access to the account and all associated data ceases immediately. The Processor retains Visitor Personal Data associated with the deleted account for a period of up to 90 days from the date of deletion, solely for the purposes of backup integrity, infrastructure purge cycles, and legal compliance. During this 90-day period, the data is not accessible to the Controller or any third party. Following the 90-day period, the Processor will permanently delete or irreversibly anonymise all associated Visitor Personal Data.
The Controller is solely responsible for exporting any Visitor Personal Data it wishes to retain prior to deleting its account. The Processor is not obliged to make data available for export after account deletion. The Service provides data export functionality during the active subscription period to facilitate this.
3.4.3 Plan Downgrade
When the Controller's Subscription Plan is downgraded (including automatic downgrade to the Free plan following cancellation of a paid subscription), Visitor engagement records beyond the free plan visibility limit (currently the five oldest records per document) become Hidden Data. Hidden Data is retained in the Processor's database and remains subject to this DPA but is not accessible to the Controller through the Service interface.
Hidden Data may become accessible again if the Controller subsequently upgrades to a paid Subscription Plan that includes the relevant data. If the Controller's account is later deleted, Hidden Data is subject to the 90-day deletion schedule described in Section 3.4.2.
Hidden Data follows the same retention lifecycle as visible Visitor engagement data. It is retained for the duration of the Controller's active subscription including periods on the Free plan and is subject to the 90-day deletion schedule in Section 3.4.2 upon account termination. The lawful basis for retaining Hidden Data during the active subscription period is the Processor's legitimate interest in maintaining data continuity, enabling Controllers to recover their full engagement history if they subsequently upgrade to a paid plan. This legitimate interest has been assessed as proportionate given that the data is not accessible to any party during Hidden Data status and that Controllers may regain access by upgrading at any time.
4. Processing on Controller's Instructions
4.1 Instruction Framework
The Processor shall process Personal Data only on documented instructions from the Controller. The Controller's use of the Service features — including configuration of link settings, email verification requirements, access controls, and Data Room permissions — constitutes the Controller's documented processing instructions for the purposes of GDPR Article 28(3)(a).
4.2 Instructions Under These Terms
This DPA, together with the Pitchwise Terms of Service and the Controller's in-product configuration, constitutes the complete documented instructions of the Controller to the Processor as at the effective date of this DPA.
4.3 Instructions Contrary to Law
If the Processor reasonably believes that a processing instruction from the Controller would violate GDPR or other applicable EU or Member State data protection law, the Processor shall promptly notify the Controller in writing before carrying out the instruction. The Processor is not required to carry out instructions that would place it in breach of applicable law.
4.4 Processor's Own-Purpose Processing
The Processor may process Personal Data for its own purposes (including security monitoring, fraud prevention, and aggregate service analytics) where it acts as an independent data controller. Such processing is not governed by this DPA and is described in the Pitchwise Privacy Policy.
5. Confidentiality
The Processor shall ensure that all personnel authorised to process Personal Data under this DPA are subject to appropriate confidentiality obligations, whether by contract, professional obligation, or statutory duty. The Processor shall limit access to Personal Data to personnel who require access for the performance of the Service.
6. Security of Processing
6.1 Technical and Organisational Measures
In accordance with GDPR Article 32, the Processor shall implement and maintain appropriate technical and organisational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, as a minimum:
6.1.1 Infrastructure Security
- All Customer Data and Visitor Personal Data is hosted on Amazon Web Services (AWS) infrastructure located in Sweden (EU), within the eu-north-1 region;
- Data is encrypted at rest using AES-256 encryption;
- Data is encrypted in transit using TLS 1.2 or higher;
- Access to production infrastructure is restricted to authorised personnel using multi-factor authentication.
6.1.2 Access Controls
- Role-based access controls limit Processor personnel access to Personal Data to those with a legitimate need;
- Access logs are maintained and reviewed regularly;
- Privileged access to production systems requires additional authentication.
6.1.3 Application Security
- Document links incorporate access token authentication;
- Email verification workflows confirm Visitor identity before granting document access where enabled by the Controller;
- The Service supports link revocation, domain whitelisting, download controls, and link expiry as Controller-configurable security features.
6.1.4 Organisational Measures
- Personnel with access to Personal Data receive appropriate data protection training;
- Bantaba AB maintains a record of processing activities as required by GDPR Article 30;
- Bantaba AB has designated a contact point for data protection matters at privacy@pitchwise.se.
6.2 Review and Updates
The Processor shall regularly review and update its technical and organisational security measures to account for changes in technology, processing activities, and the risk environment.
6.3 Controller's Security Responsibilities
The Controller is responsible for implementing appropriate security measures on its own systems and for configuring the Service's security features (email verification, download controls, domain whitelisting, link expiry, and access revocation) in a manner appropriate to the sensitivity of the Customer Data being shared.
7. Sub-processors
7.1 General Authorisation
The Controller provides general written authorisation for the Processor to engage Sub-processors for the purpose of delivering the Service. By accepting this DPA, the Controller authorises the Processor to engage the Sub-processors listed in Annex 2 of this DPA.
7.2 Sub-processor Obligations
The Processor shall ensure that each Sub-processor is bound by a written contract imposing data protection obligations substantially equivalent to those in this DPA, in accordance with GDPR Article 28(4). Where Sub-processors are engaged for the transfer of data outside the EEA, the Processor shall ensure appropriate transfer mechanisms are in place (see Section 10).
7.3 Changes to Sub-processors
The Processor shall notify the Controller of any intended addition or replacement of Sub-processors at least 30 days before the change takes effect. Notification will be made by updating the Sub-processor list at www.pitchwise.se/privacy-policy and sending an email notification to the Controller's account email address.
If the Controller objects to a new Sub-processor on reasonable data protection grounds, the Controller must notify the Processor in writing within 14 days of receiving the notification. The parties shall work in good faith to resolve the objection. If no resolution is reached within 30 days, the Controller may terminate its subscription without penalty by written notice.
7.4 Liability for Sub-processors
The Processor remains fully liable to the Controller for the performance of any Sub-processor's data protection obligations to the extent that the Sub-processor fails to fulfil those obligations. This reflects the mandatory requirement of GDPR Article 28(4) and cannot be excluded by contract. The Processor's aggregate contractual liability to the Controller remains subject to the limitation of liability in the Pitchwise Terms of Service.
8. Assistance with Data Subject Rights
8.1 Obligation to Assist
The Processor shall assist the Controller in fulfilling its obligations under GDPR Chapter III (Data Subjects' Rights), including the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and objection (Article 21), insofar as such rights relate to Personal Data processed by the Processor under this DPA.
8.2 Requests from Data Subjects
If the Processor receives a request directly from a Visitor or other Data Subject exercising their rights under GDPR, the Processor shall, without undue delay, forward the request to the Controller and shall not respond to the Data Subject directly unless authorised to do so by the Controller or required by law. The Controller, as data controller, is responsible for responding to Data Subject requests.
8.3 Technical Assistance
Where technically feasible, the Processor shall provide the Controller with tools and mechanisms to enable the Controller to fulfil Data Subject requests — including the ability to export, delete, or anonymise specific Visitor engagement records from the Controller's dashboard. Requests for technical assistance that fall outside standard Service functionality may be subject to reasonable additional charges.
9. Security Incidents and Breach Notification
9.1 Notification Obligation
In the event of a confirmed Security Incident involving Personal Data processed under this DPA, the Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of the Security Incident, to the extent that the 72-hour timeframe is practicable given the circumstances.
9.2 Content of Notification
The Processor's notification shall include, to the extent then known:
- A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and Personal Data records affected;
- The name and contact details of the Processor's data protection contact point;
- The likely consequences of the Security Incident;
- The measures taken or proposed by the Processor to address the Security Incident, including measures to mitigate its possible adverse effects.
Where not all information is available at the time of initial notification, the Processor may provide information in phases as it becomes available.
9.3 Controller's Notification Obligations
The Controller, as data controller, is responsible for determining whether to notify the relevant Supervisory Authority under GDPR Article 33 and whether to communicate the Security Incident to affected Data Subjects under GDPR Article 34. The Processor shall provide reasonable assistance to the Controller in meeting these obligations.
9.4 Incident Response
The Processor shall take prompt action to contain and remediate any Security Incident and shall keep the Controller reasonably informed of the Processor's response, investigation, and remediation activities.
10. International Data Transfers
10.1 Primary Storage Location
Personal Data processed under this DPA is primarily stored within the EEA on AWS infrastructure located in Sweden (eu-north-1 region). No international transfer of data occurs solely through the Processor's primary infrastructure.
10.2 Transfers via Sub-processors
Certain Sub-processors engaged by the Processor are located outside the EEA, including in the United States. Transfers of Personal Data to these Sub-processors are made on the basis of:
- The EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795), where the Sub-processor is certified under the Framework; or
- EU Standard Contractual Clauses (SCCs) adopted pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor), where no adequacy decision applies.
Details of the transfer mechanism applicable to each Sub-processor are set out in Annex 2 of this DPA.
10.3 Transfer Impact Assessments
Where SCCs are used as the transfer mechanism, the Processor has conducted or will conduct a Transfer Impact Assessment (TIA) in accordance with Clause 14 of the SCCs. The Processor will make the results of applicable TIAs available to the Controller on request.
10.4 Controller-Initiated Transfers
If the Controller configures the Service in a way that results in Personal Data being accessible by Visitors or other parties outside the EEA (for example, sharing documents with recipients in third countries), the Controller is responsible for ensuring that such transfers are lawful and appropriately safeguarded.
11. Further Assistance Obligations
11.1 Data Protection Impact Assessments
The Processor shall provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments (DPIAs) under GDPR Article 35, to the extent that such DPIAs relate to the processing activities described in this DPA.
11.2 Prior Consultation
Where a DPIA indicates that a processing activity presents a high residual risk and the Controller is required to consult the relevant Supervisory Authority under GDPR Article 36, the Processor shall cooperate with any resulting consultation and provide the Supervisory Authority with the information it requires in relation to the Processor's processing activities.
11.3 Compliance Demonstration
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in GDPR Article 28 and this DPA. Requests for compliance information should be directed to privacy@pitchwise.se.
12. Deletion and Return of Personal Data
12.1 Deletion Following Account Termination
When the Controller deletes their Pitchwise account, Visitor Personal Data associated with that account is retained by the Processor for a period of up to 90 days from the date of deletion, solely to maintain backup integrity and to complete infrastructure purge cycles. During this retention period, the data is not accessible to any party through the Service interface. Upon expiry of the 90-day period, the Processor shall permanently delete or irreversibly anonymise all Visitor Personal Data associated with the deleted account, and shall instruct all Sub-processors to do the same.
12.2 Controller's Responsibility to Export Prior to Deletion
The Controller acknowledges that account deletion takes immediate effect and that access to Visitor Personal Data ceases immediately upon deletion. The Controller is solely responsible for exporting any Visitor Personal Data it wishes to retain before initiating account deletion. The Service provides data export functionality throughout the active subscription period for this purpose.
The Processor has no obligation to make Visitor Personal Data available for retrieval or export after the Controller's account has been deleted.
12.3 Deletion of Hidden Data
Hidden Data (Visitor engagement records retained but not accessible to the Controller following a plan downgrade) is subject to the same 90-day deletion schedule as other Visitor Personal Data upon account deletion. If the Controller upgrades to a paid plan before deleting their account, Hidden Data becomes accessible again and is no longer treated as Hidden Data for the purposes of this DPA.
12.4 Deletion on Request
The Controller may request deletion of specific Visitor Personal Data (for example, to comply with a Data Subject erasure request under GDPR Article 17) at any time during the active subscription period. The Processor shall process such requests within 30 days of receipt and confirm completion to the Controller.
12.5 Legal Retention Requirements
The Processor may retain Personal Data beyond the periods specified in this Section to the extent required by applicable EU or Swedish law (including tax, accounting, or regulatory obligations), provided that: (a) the Processor notifies the Controller of such retention; (b) the data is processed only for the purpose of satisfying the relevant legal obligation; and (c) appropriate technical measures are applied to prevent access for other purposes.
13. Audit Rights
13.1 Information and Audit
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28 and shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, in accordance with GDPR Article 28(3)(h).
13.2 Audit Procedure
The Controller shall give the Processor at least 30 days' prior written notice of any audit. Audits shall be conducted:
- During the Processor's normal business hours and in a manner that minimises disruption to the Service;
- No more than once per calendar year, unless there is a reasonable basis to believe a Security Incident has occurred;
- At the Controller's own cost, unless the audit reveals material non-compliance by the Processor with this DPA, in which case the Processor shall bear its own reasonable costs.
13.3 Audit Alternatives
The Processor may satisfy the Controller's audit rights in whole or in part by providing up-to-date third-party audit reports, certifications, or attestations (such as SOC 2, ISO 27001, or equivalent). The Controller may request copies of such reports by emailing privacy@pitchwise.se.
13.4 Confidentiality of Audit
Information obtained in connection with an audit shall be treated as Confidential Information under the Pitchwise Terms of Service and shall only be used for the purpose of verifying compliance with this DPA.
14. Liability
The liability of the parties under this DPA is subject to the limitations and exclusions set out in Section 12 of the Pitchwise Terms of Service, to the fullest extent permitted by applicable law.
Nothing in this DPA limits or excludes either party's liability: (a) for death or personal injury caused by negligence; (b) for fraud or fraudulent misrepresentation; (c) under mandatory applicable law, including GDPR supervisory fines, which are assessed directly by competent authorities and are not subject to contractual liability caps; or (d) for any other matter that cannot lawfully be excluded or limited.
In proceedings under GDPR Article 82 (liability and the right to compensation), each party is responsible for the damage caused by processing for which it is responsible. Where both parties have contributed to damage, liability shall be apportioned according to their respective responsibility for the damage.
15. General Provisions
15.1 Precedence
In the event of a conflict between this DPA and the Pitchwise Terms of Service regarding the processing of Personal Data, this DPA shall prevail to the extent of the conflict.
15.2 Governing Law
This DPA is governed by the laws of Sweden, and the parties submit to the exclusive jurisdiction of the Swedish courts, with Stockholm District Court as the court of first instance, for any dispute arising under this DPA. To the extent required by applicable law, the mandatory data protection law provisions of the relevant EU Member State(s) of the Controller shall also apply.
15.3 Amendments
Bantaba AB may update this DPA from time to time to reflect changes in applicable law or its processing activities. Material changes will be communicated to Controllers at least 30 days before they take effect. Continued use of the Service following the effective date of an updated DPA constitutes acceptance of the updated terms.
15.4 Severability
If any provision of this DPA is held invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remainder of the DPA will continue in full force.
15.5 Entire Agreement on Data Processing
This DPA, together with the Pitchwise Terms of Service and Privacy Policy, constitutes the entire agreement between the parties regarding the processing of Personal Data in connection with the Service and supersedes all prior agreements and understandings on that subject.
Annex 1 — Details of Processing Activities
A. Controller
The Customer identified in the Pitchwise account registration.
B. Processor
Bantaba AB, operating as Pitchwise. Contact for data protection matters: privacy@pitchwise.se.
C. Subject Matter and Duration
Processing of Visitor Personal Data in connection with the Controller's use of the Pitchwise document sharing and analytics Service, for the duration of the Controller's active subscription plus the 90-day post-deletion retention period described in Section 3.4.2.
D. Nature and Purpose of Processing
Collection, storage, analysis, and display of Visitor engagement data to enable the Controller to track how Visitors interact with documents and Data Rooms shared via the Service. Processing enables the Controller to measure engagement (open rates, time per page, completion rates, return visits) and attribute engagement records to individual Visitor identities where email verification is enabled. Access to engagement data is subject to the limits of the Controller's active Subscription Plan.
Category
Examples
Conditions
F. Categories of Data Subjects
Visitors – natural persons who access Customer Data (documents, Data Rooms, secure links) shared by the Controller through the Service. This may include investors, buyers, advisors, partners, fund managers, legal professionals, and any other third party to whom the Controller sends a Pitchwise secure link.
G. Special Categories of Personal Data
No special categories of personal data (as defined in GDPR Article 9) are processed under this DPA. Controllers must not upload documents containing special category data unless they have sought and received specific written confirmation from Bantaba AB that the Service is configured to support such processing.
H. Processing Operations
- Collection of Visitor email addresses via email-gated links or data room invitations;
- Recording of document access events including timestamp, IP address, and device metadata;
- Recording of page-level engagement metrics per Visitor session;
- Storage of engagement records in the Controller's secure Pitchwise dashboard, subject to Subscription Plan access limits;
- Retention of Hidden Data during plan downgrade periods, inaccessible to the Controller, on the basis of legitimate interest in data continuity;
- Linking of engagement records to verified email identities where email verification is enabled;
- Deletion or anonymisation of Visitor Personal Data following the 90-day post-deletion retention period.
Annex 2 — Sub-processor List
The following Sub-processors are engaged by Bantaba AB as of the effective date of this DPA. The Controller provides general authorisation for the engagement of these Sub-processors in accordance with Section 7 of this DPA.
Sub-processor
Country
Purpose
Transfer Mechanism
This Sub-processor list is maintained and updated at www.pitchwise.se/privacy-policy. Bantaba AB will notify Controllers of any material changes to this list in accordance with Section 7.3 of this DPA.
Annex 3 — Technical and Organisational Security Measures
The following measures are implemented by Bantaba AB in accordance with Section 6 of this DPA and GDPR Article 32. These measures are reviewed and updated regularly.
Encryption
- Data at rest: AES-256 encryption on all AWS storage volumes;
- Data in transit: TLS 1.2 minimum on all connections between the Service and end users;
- Document link tokens: cryptographically signed access tokens for all shared links.
Access Control
- Role-based access control (RBAC) for all internal systems;
- Multi-factor authentication (MFA) required for all production system access by Bantaba AB personnel;
- Principle of least privilege applied to all data access rights;
- Access logs maintained and reviewed on a regular basis.
Infrastructure and Availability
- Primary hosting on AWS eu-north-1 (Stockholm, Sweden) within the EEA;
- Automated backups with defined retention periods;
- DDoS protection via AWS Shield;
- Monitoring and alerting for infrastructure anomalies.
Application Security
- Input validation and output encoding to prevent injection attacks;
- Secure session management with short-lived tokens;
- Controller-configurable security features: email verification, domain whitelisting, download controls, link expiry, password protection, and instant revocation;
- Regular dependency updates and vulnerability scanning.
Organisational Measures
- Data protection training for all personnel with access to Personal Data;
- Confidentiality obligations in all employment and contractor agreements;
- Record of processing activities maintained under GDPR Article 30;
- Designated data protection contact point: privacy@pitchwise.se;
- Incident response procedure documented and tested;
- Vendor security assessments for all Sub-processors.
This Data Processing Agreement was last updated on 17 July 2026 (Version 1.2). Changes from Version 1.1: Section 3.4.3 updated to confirm Hidden Data retention lifecycle and document legitimate interest basis. For questions about this DPA, to request a customised enterprise DPA, or to submit a data subject rights request, contact Bantaba AB at privacy@pitchwise.se or by post at Bantaba AB, c/o Magine Pro, Östermalmsgatan 26A, 114 26 Stockholm, Sweden.

view, and close with confidence.


114 26 Stockholm, Sweden