General Terms for Kolla
Last updated: September 17, 2026
This translation is provided for convenience; in case of conflict the Swedish version prevails.
Kolla is a tool for agencies and others who work with content to have material reviewed and approved by their clients. These Terms apply between Lind Studio AB and whoever uses Kolla – a company, an organization, a sole trader, or a private individual. The Terms include a Data Processing Agreement (Appendix 1), which applies when we process personal data on the Customer's behalf.
The key points
This is a summary. The full Terms apply.
- Kolla is built for businesses, but private individuals may also buy the Service. If you are a consumer, you always have the rights that mandatory consumer law gives you, including a 14-day right of withdrawal. See section 23.
- You buy the subscription from Polar, not from us. Polar Software, Inc. is the seller and merchant of record. It invoices you and handles VAT, refunds, and chargebacks. We grant you the right to use Kolla under these Terms. See section 10.
- The subscription renews automatically until you cancel it in Polar's customer portal. Cancellation takes effect on the next renewal date. Fees paid for a period that has started are not refunded unless required by law or Polar's terms.
- An approval in Kolla is not a signature. We do not verify who opens a review link. You and your client decide what an approval means between you. See section 6.
- Our liability is limited. See section 17.
- Swedish law applies, and disputes are heard by Swedish courts, with Luleå District Court as the court of first instance.
- We may change the Terms on 30 days' notice. If you do not accept a change, you may terminate the agreement before the change takes effect.
1. Parties, scope, and formation of the agreement
1.1 The Supplier
The Kolla Service is provided by Lind Studio AB, company registration number 559593-4265, with its registered office in Boden, Sweden.
Address: Tråggränd 20, 961 42 Boden, Sweden Email: hello@kolla.media Website: kolla.media
Lind Studio AB is referred to below as "we", "us", or "our". Kolla is the name of the Service.
1.2 The Customer
The "Customer" is the company, organization, sole trader, or private individual that creates an Organization in Kolla, orders a subscription, or uses the Service.
The Service is designed for use in a trade, profession, or business, but private individuals may also become Customers. A Customer who is an individual and uses the Service mainly for purposes outside any trade or business is a consumer; section 23 then also applies. A Customer who is an individual must be at least 18 years old. The person who creates the Organization, orders a subscription, or otherwise accepts the Terms on the Customer's behalf confirms that they are authorized to represent and bind the Customer.
1.3 Formation of the agreement
The agreement is formed when the Customer, after being given access to these Terms, creates an Organization in Kolla, orders a subscription, or otherwise starts using the Service. The Terms are available on kolla.media in a form that can be saved and reproduced.
Sections 10 to 12 of the Swedish Act (2002:562) on Electronic Commerce and Other Information Society Services do not apply between the parties, except where the Customer is a consumer.
A Reviewer who opens a review link does not become a party to this agreement. See section 5.
1.4 Contract documents
The agreement between the Customer and us consists of:
- these General Terms, including Appendix 1 (Data Processing Agreement),
- the current Subprocessor List, which also states where the Service is hosted,
- the price, subscription type, included client allowance, and active client count shown when the subscription was ordered or changed, and
- any separate written agreement that expressly identifies the provision it replaces.
The purchase of the subscription is also governed by Polar's buyer terms. See section 10.
The Customer's own purchasing terms or standard terms do not form part of the agreement, even if attached to an order, unless we have expressly accepted them in writing.
1.5 Language
The Terms are written in Swedish. Any translation we publish is provided for convenience. If the texts differ, the Swedish text prevails.
2. Definitions
Service: the web-based Kolla service at kolla.media and app.kolla.media, including the review portal for Reviewers, related emails, and the Documentation.
Organization: the Customer's workspace in Kolla, containing the Customer's Users, projects, clients, contacts, and Customer Content.
User: an individual whom the Customer has given an account in its Organization, such as an employee or consultant. Users are included within the separate member limits shown in the Service.
Active Client: a separately managed business that the Customer has activated for review work in Kolla. Several contacts, projects, brands, or social channels for the same managed business may belong to one client; separately managed businesses must have separate client records.
Reviewer: a person at the Customer's client, or another external person whom the Customer invites to review, comment on, or approve material through a review link. Reviewers are free of charge and do not need to create an account.
Customer Content: images, video, text, captions, comments, project and client details, Reviewer contact details, and anything else that the Customer, its Users, or Reviewers add to the Service, including technical versions created to display the material, such as previews.
Service Data: technical information about how the Service is used, such as the features used, file sizes, upload, comment, and approval times, error reports, and security logs. Service Data does not include the contents of files, captions, or comments.
Documentation: the description of the Service's features, limits, and requirements available on kolla.media or in the Service.
Polar: Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA, which sells Kolla subscriptions as reseller and merchant of record.
3. The Service
3.1 What Kolla does
Kolla lets the Customer upload material, organize it into projects for each client, send review links to Reviewers, collect comments and approvals, and track the status of each post. The Service has technical limits, for example on storage space, maximum file size, and how long review links remain valid. The limits in force at any given time are shown in the Service and may change in accordance with sections 3.3 and 20.
3.2 What Kolla is not
Unless expressly agreed otherwise, Kolla is not:
- a system for electronic signatures or qualified electronic timestamps,
- an archive or backup of the Customer's material,
- a legal, editorial, or regulatory review of the material, or
- a guarantee that the material may be published.
3.3 Early version
Kolla is a new service under active development. Features may be added, changed, or removed, and features marked beta, test, or preview are provided as is. If we remove a core feature during a period for which the Customer has already paid, the Customer may cancel the subscription and receive a refund of the portion of the fee covering the period after termination.
3.4 Availability and support
We aim to make the Service available around the clock but do not guarantee any level of availability or response time. The Service may be unavailable because of maintenance, faults, security measures, or disruptions at suppliers we use. We give advance notice of planned maintenance that affects the Service when reasonably practicable.
Support is available in Swedish and English at hello@kolla.media on weekdays. Polar is the first point of contact for questions about payments, receipts, and invoices. See section 10.
4. Accounts, Organizations, and Users
The person who creates an Organization becomes its administrator. The administrator can invite Users, manage the subscription, and delete the Organization's data. The Customer is responsible for its administrators and Users and must ensure that:
- the details about the Customer and its Users are accurate,
- each account is used only by the person to whom it belongs,
- login details are protected,
- access is removed when a person should no longer have it, and
- we are told immediately about suspected unauthorized access.
The Customer is responsible for everything done through its accounts, except where it results from a security failure for which we are responsible.
5. Reviewers and review links
5.1 How review links work
When the Customer sends a review request, the Reviewer receives an email with a personal link. Anyone who has the link can open the material, comment, and approve it without signing in. The link must therefore be treated as an access credential. It stops working when its validity period ends. The Customer can end access early by deleting the project.
We do not verify the identity of the person who opens the link. We record the person to whom the link was sent, when it was opened, the version of the material shown, and the decisions and comments submitted, together with technical information about the browser.
5.2 The Customer's responsibility for Reviewers
The Customer chooses which Reviewers to invite and is responsible for ensuring that:
- the Customer has the right to give us the Reviewer's name and email address and to send review requests to the Reviewer,
- the Reviewer receives the information about personal data processing that the Customer must provide as controller,
- the Reviewer is authorized to access the material, and
- the link is not shared with unauthorized persons.
When the Customer adds a Reviewer, a record for the Reviewer is created in the Service's identity system so that comments and approvals can be linked to the correct person. This is part of the Service and is done on the Customer's instructions.
5.3 The Reviewer's status
A Reviewer does not become a party to this agreement or enter into an agreement with us by opening a link. The Reviewer uses the review portal on the Customer's instructions. Section 7.3 (Prohibited content and use) and section 15 (Rights to the Service) also apply to the Reviewer's use, and the Customer is responsible to us for each Reviewer's compliance with them.
6. Approvals
6.1 What is recorded
When a Reviewer approves or requests changes, the Service records the decision, the time, the review request through which the decision was submitted, and the exact version of the post shown, including the image, video, and caption. The approval is tied to that version. If the Customer later changes the post, the Service creates a new, unapproved version that must be sent for review again.
6.2 What an approval means
An approval in Kolla is a record of a decision in the Service. It is not an electronic signature, a contract, or proof that the person who approved was authorized to represent a particular company. We do not verify that the Reviewer is the named person or that the person is authorized to approve.
The Customer decides in its own agreement with its client what an approval means between them, who may approve, and how changes after approval will be handled. We are not a party to that relationship.
7. Customer Content
7.1 The Customer owns its content
The Customer or the Customer's rights holder retains all rights to Customer Content. The Customer grants us a limited, non-exclusive right to store, copy, convert, display, and transmit Customer Content only to the extent needed to provide the Service to the Customer, provide support at the Customer's request, handle security incidents, and meet legal obligations. This right ends when the content is deleted, subject to the period stated in section 12.
We do not use Customer Content to train AI models, in our own marketing, or for any purpose other than providing the Service. We may use Service Data and de-identified statistics to operate, secure, bill for, and develop the Service.
7.2 The Customer's warranties
The Customer is responsible for Customer Content and warrants that it has all rights, licenses, and consents needed to upload the material, share it with Reviewers, and allow us to process it. The Customer also warrants that the material and its planned use comply with applicable law, advertising rules, and the rules of the relevant social media platforms.
The Customer must keep its own originals of its material.
7.3 Prohibited content and use
The Service must not be used to:
- store or distribute content that is unlawful or infringes another person's rights,
- process personal data without a legal basis,
- upload sensitive personal data on a large scale, patient records, full payment card details, passwords, or security-classified information,
- distribute malicious code,
- attempt to gain unauthorized access to the Service or other customers' data,
- circumvent security features or subscription limits,
- send spam or unsolicited communications through the Service,
- impersonate another person,
- resell the Service or build a competing service by systematically copying it, or
- decompile or reverse engineer the Service, except where mandatory law permits it.
8. Illegal content, notices, and action
8.1 Notice
Anyone who believes that content in Kolla is illegal may report it to hello@kolla.media. The notice should include:
- the reason the content is considered illegal,
- the location of the content, such as the review link or project name,
- the reporting person's name and email address, and
- a statement that the information in the notice is accurate and submitted in good faith.
We acknowledge receipt, assess the notice promptly, carefully, and impartially, and tell the reporting person our decision. A person performs the assessment. We do not use automated tools to monitor or assess Customer Content, and we do not review content in advance.
8.2 Action
If we become aware that content is illegal or breaches section 7.3, we may remove or hide the content, disable a review link, or restrict or suspend the Customer's or a User's access. The action must be proportionate and limited to what is needed.
When we take such action, we tell the affected Customer what we did, why we did it, the facts on which we based the decision, whether the action resulted from a notice or our own review, and how the Customer may object. We may act first and inform the Customer afterwards where there is an urgent security risk or the law requires it.
If we become aware of information that gives reason to suspect a criminal offence involving a threat to a person's life or safety, we provide the information to the competent authority.
8.3 Point of contact
Authorities, Customers, and Reviewers can contact us about content at hello@kolla.media. We communicate in Swedish and English.
9. Trial period
A new Organization receives a free 14-day trial for up to five Users. No payment card is required. A person may start only one trial.
If the trial ends without a subscription, the Organization becomes read-only. The Customer can view and delete its material and subscribe, but cannot create new material or send new review requests. Review links already sent continue to work until they expire. We do not automatically delete the Customer's material when the trial ends. Deletion is handled under section 12.
During the trial, the Service is provided as is, and section 17 applies.
10. Subscriptions, prices, and payment through Polar
10.1 Polar is the seller
Kolla subscriptions are sold by Polar Software, Inc. as reseller and merchant of record. This means that:
- the Customer buys the subscription from Polar, and the purchase is governed by Polar's Checkout Buyer Terms and Polar's Privacy Policy,
- Polar calculates, charges, and remits VAT, issues the receipt and invoice, and is the name shown on the Customer's account statement,
- Polar handles refunds, chargebacks, and payment questions, and
- we grant the right to use Kolla under these Terms and are responsible for the Service and support.
We do not issue our own invoices for the subscription.
10.2 Prices
Current prices are shown on kolla.media and in the Service before the subscription is ordered. For Customers who are not consumers, prices exclude VAT; Polar adds VAT at checkout under the rules that apply to the Customer. For Customers who are consumers, the total price including VAT is shown no later than in Polar's checkout. Customers with a valid VAT registration number may enter it at checkout or in Polar's customer portal.
The monthly base price includes the client allowance shown when the subscription is ordered. Each additional Active Client is charged at the agreed monthly rate. The base price remains payable when fewer clients are active, including when none are active. Users and Reviewers do not carry a per-person charge. Preparing client records, contacts, projects, or drafts does not activate a client.
10.3 Renewals and changes
Subscriptions are paid monthly in advance and renew automatically for another month until canceled.
A client is activated when its first review request is accepted for sending, or when an administrator activates it. Activation above the included allowance requires an administrator to approve the client and displayed charge. Polar charges the prorated amount for the remainder of the monthly period. Successful activation remains in effect if the subsequent review email cannot be sent or the administrator closes the composer; sending can be retried.
Deactivation takes effect at the next monthly renewal. Until then, that client remains active and counts toward the charge. Keeping the client active before that date restores its future renewal charge without an extra charge for the current period. There is no ordinary refund for choosing to deactivate. Billing errors caused by Kolla are corrected separately through Polar.
A client can be deleted through the Service only after deactivation has taken effect. Existing review links keep their normal authorization and expiry rules after deactivation; new review emails require activation. Deleting data can end existing access. Contact support for exceptional data-removal requests.
While an approved checkout can still complete, changes to the quoted active-client set are paused. Refreshing an old checkout resumes the same purchase until Polar confirms that it has ended.
We may change prices for a new subscription period. We tell the Customer at least 30 days before the new price takes effect, and the Customer may cancel the subscription before then.
10.4 Cancellation and refunds
The Customer may cancel the subscription at any time in Polar's customer portal, which is accessible from the Service settings. Cancellation takes effect at the end of the current period, and the Customer retains access to the Service until then.
Fees for a period that has started are not refunded unless required by mandatory law, these Terms (sections 3.3, 10.3, 11.3, and 20), or Polar's refund process. Polar issues refunds to the original payment method.
10.5 Failed payment
If a renewal payment fails, Polar makes further attempts to collect it. During that time, the Customer keeps access to the Service but cannot activate additional clients or add Users. If payment remains outstanding, the Organization becomes read-only in the same way as after a trial (section 9) until payment is made or a new subscription is purchased.
11. Term, termination, and suspension
11.1 Term
The agreement remains in force for as long as the Customer has an Organization in Kolla. Section 10 sets out the subscription term.
11.2 Termination by the Customer
The Customer may cancel the subscription at any time under section 10.4 and terminate the agreement by asking us to delete the Organization at hello@kolla.media. There is no notice period except that a subscription runs until the end of its current period.
11.3 Termination by us
We may terminate the agreement on 60 days' notice. The Customer will then receive a refund of the portion of any prepaid fees covering the period after termination.
Either party may terminate the agreement immediately if the other party materially breaches it and does not remedy the breach within 14 days after written notice, or if the breach cannot be remedied.
11.4 Suspension
We may restrict or suspend the Customer's access to the Service if the Customer materially breaches the agreement, if its use creates a security risk or risks harming the Service, other customers, or a third party, if there are reasonable grounds to suspect illegal use, or if required by law or a government authority's decision. Section 8.2 on information to the Customer applies. The suspension must be limited to what is needed and lifted when the grounds for it no longer exist.
12. Export, switching provider, and deletion
12.1 Data export
At any time during the agreement, the Customer may ask us to export its exportable data. We provide the export free of charge, without undue delay and no later than 30 days after the request, in structured, commonly used, machine-readable formats. These consist of original files in their original formats, such as JPEG, PNG, and MP4, and projects, posts, captions, versions, review requests, decisions, comments, clients, contacts, and timestamps in JSON or CSV. The Subprocessor List describes the data structures and formats included.
The export does not include the Service's software, design, or other elements that are our trade secrets or intellectual property.
12.2 Switching provider
The Customer may at any time request a switch to another service or to its own infrastructure; no notice is required to start the switch (maximum notice period: zero days). A 30-day transition period runs from the request, during which the agreement remains in force and we:
- deliver the export under section 12.1 and give reasonable assistance and the information the Customer needs to complete the switch,
- keep the Service running at an unchanged level of security, and
- inform the Customer of known risks of disruption.
The agreement ends when the switch is complete or, if the Customer instead chooses deletion, when we receive the request. We confirm the termination in writing. Section 12.3 then applies.
12.3 Retrieval period and deletion
When the agreement or subscription ends, the Customer's data remains available in the Service in read-only mode for at least 30 days so the Customer can retrieve it. After that, or earlier at the Customer's request, we delete Customer Content from the Service's active systems within 90 days. Once completed, deletion is final.
We may retain limited information for longer where needed for accounting, to show that the agreement has been performed, for security investigations, or to handle legal claims. Appendix 1 also applies to personal data.
The Customer may delete projects and material in the Service at any time. Such deletion takes effect immediately and cannot be undone.
13. Personal data
When we process personal data in Customer Content, such as details about Reviewers and people shown in the material, we do so as processor on the Customer's behalf. The Customer is the controller. The Data Processing Agreement in Appendix 1 applies to that processing.
For processing where we determine the purposes ourselves, such as processing the Customer's account and contract details, payment details, support, and security, we are the controller. Our Privacy Policy describes that processing.
We use subprocessors to provide the Service. The Customer authorizes the subprocessors listed in the Subprocessor List and any changes notified under Appendix 1.
14. Confidentiality
Each party must keep the other party's confidential information secret and use it only to perform the agreement. Confidential information includes unpublished Customer Content, campaign plans, prices that differ from the price list, and technical information about the Service. This duty does not apply to information that is or becomes public without a breach of the agreement, that the recipient already lawfully knows, or that must be disclosed by law or a government authority's decision. Information may be disclosed to employees, advisers, and subcontractors who need it for the agreement and are bound by confidentiality. This duty applies during the agreement and for three years afterwards. For trade secrets, it applies for as long as the information remains a trade secret.
15. Rights to the Service
All rights to Kolla, including its software, design, interfaces, Documentation, and trademarks, belong to us or our licensors. During the agreement, the Customer receives a limited, non-exclusive, non-transferable right to use the Service for its own business and to work with its clients and Reviewers, within the scope of the subscription.
We may freely use suggestions and feedback from the Customer to improve the Service. We do not use the Customer's name or logo as a reference without the Customer's consent.
16. Third-party services
The Service relies on subcontractors for services including hosting, storage, authentication, email, and payments. We select and monitor them with reasonable care. We are not responsible for the availability, rules, or decisions of social media platforms or other external services, such as a decision not to publish or to remove material.
17. Defects, warranties, and limitation of liability
17.1 Defects in the Service
We must provide the Service with professional skill and care and substantially in accordance with the Documentation. The Customer must report defects without undue delay. If there is a material defect, we must correct it or provide a reasonable workaround within a reasonable time. If we cannot remedy a defect that materially prevents the Customer from using the Service, the Customer may cancel the subscription and receive a refund of the portion of prepaid fees covering the period after termination. This is the Customer's remedy for defects, subject to the exceptions in section 17.3.
We do not warrant that the Service is error-free or always available, that emails will always be delivered, that a review link will be opened only by the intended recipient, that a Reviewer has particular authority, or that an approval has any particular legal effect.
17.2 Limitation of liability
We are liable only for direct loss that we cause through breach of contract or negligence. We are not liable for indirect loss, meaning loss of profit or revenue, lost business opportunities, loss of goodwill, lost savings, the cost of replacement services, penalties or damages payable by the Customer to a third party, or other consequential loss.
We are not liable for loss caused by the Customer sending a review link to the wrong person, a recipient sharing the link, a Reviewer lacking authority, the Customer publishing a version other than the approved version, the content or legality of Customer Content, decisions by external platforms, or the Customer failing to retain its own originals.
Our total liability for all events in any twelve-month period is limited to the greater of (a) the fees paid by the Customer for the Service during the twelve months before the event giving rise to the claim and (b) half of one price base amount under the Swedish Social Insurance Code.
17.3 Exceptions
The limitations in this section do not apply to willful misconduct or gross negligence, personal injury, a breach of section 14 (Confidentiality), or liability that cannot be limited under mandatory law. Appendix 1 governs liability for personal data.
17.4 Claims
A claim must be made in writing without undue delay and no later than twelve months after the Customer discovered, or should have discovered, the circumstance on which the claim is based.
18. Third-party claims
The Customer must indemnify us for damages, costs, and reasonable legal fees that we incur because of a third-party claim based on Customer Content, the Customer's use of the Service, or the Customer's instructions infringing another person's rights or breaking the law, provided that we promptly tell the Customer about the claim and allow the Customer to control the defense.
We will similarly indemnify the Customer against a third-party claim based on the Service itself, when used under the agreement, infringing another person's intellectual property rights. We may choose to obtain the right for the Customer to continue using the Service, modify the Service to end the infringement, or terminate the affected part and refund prepaid fees for the remaining period. Our liability under this section is subject to the limit in section 17.2.
19. Force majeure
A party is not liable for delay or failure caused by circumstances beyond its reasonable control, such as widespread internet or power outages, major cyberattacks, natural disasters, epidemics, war, government action, or industrial disputes. The affected party must inform the other party and take reasonable steps to limit the consequences. Inability to pay is not force majeure.
20. Changes to the Terms
We may change these Terms. We notify the Organization's administrator by email or through the Service at least 30 days before a change takes effect. Changes required by law or a government authority's decision, needed to address a security risk, solely editorial, or favorable to the Customer may take effect earlier.
If the Customer does not accept a change, it may terminate the agreement before the change takes effect and receive a refund of the portion of prepaid fees covering the period after termination. Changes do not apply retroactively.
21. Notices and assignment
Notices to the Customer are given by email to the Organization's administrator or through the Service. The Customer is responsible for keeping its contact details current. Notices to us must be sent to hello@kolla.media.
The Customer may not assign the agreement without our written consent. We may assign the agreement to a company that takes over the Service or the business that operates it, provided that the Customer's rights are not reduced. We may use subcontractors and remain responsible for them as we are for ourselves.
If a provision is invalid, the remaining provisions continue to apply. A party's failure to enforce a right immediately does not mean that it waives that right. Provisions that by their nature must apply after the agreement ends, such as those on payment, rights, confidentiality, deletion, liability, and disputes, continue to apply.
22. Governing law and disputes
Swedish law governs the agreement. The parties must first try to resolve a dispute through negotiation. A dispute that cannot be resolved within 30 days after one party has requested negotiations in writing will be decided by the ordinary Swedish courts, with Luleå District Court as the court of first instance.
23. Special terms for consumers
This section applies when the Customer is a consumer, that is, an individual who uses the Service mainly for purposes outside any trade or business. Where the Customer is a consumer, references to the Customer's business are to be read as the Customer's own use.
23.1 Mandatory consumer law prevails
If anything in these Terms conflicts with a rule of mandatory consumer law, such as the Swedish Consumer Sales Act (2022:260) or the Swedish Distance and Off-Premises Contracts Act (2005:59), the rule of law applies instead of the term. This applies, among other things, to the limitations of our liability and of your remedies for defects (section 17), the time limit for claims (section 17.4), and the duty to indemnify us against third-party claims (section 18). The statement that a feature or the Service is provided as is during a certain period (sections 3.3 and 9) applies to you only to the extent the Consumer Sales Act allows.
23.2 Right of withdrawal
You may withdraw from the purchase of a subscription within 14 days from the day you ordered it, without giving a reason. To withdraw, notify Polar, for example through the link in your receipt or in Polar's customer portal, or email us at hello@kolla.media and we will make sure the purchase is withdrawn with Polar. You may use the Swedish Consumer Agency's standard withdrawal form, available at konsumentverket.se, but you do not have to.
If you have expressly requested that the Service start during the withdrawal period, then if you withdraw you pay a proportional part of the fee for the time up to the point when you told us or Polar that you were withdrawing. If you have not made such a request, we refund the full fee, even if you have used the Service. Polar issues the refund within 14 days to the payment method you used, and the subscription ends.
The right of withdrawal applies to subscription purchases. You can always close a free account under section 11.2.
23.3 Automatic renewal
Your subscription renews automatically under section 10.3. If your subscription period is longer than one month, we remind you by email no later than one month before the last day on which you can cancel to avoid renewal.
23.4 Disputes
Section 22 does not prevent you from bringing a claim before the court where you live or from using other dispute resolution options that the law gives you. You may also refer a dispute to the Swedish National Board for Consumer Disputes (Allmänna reklamationsnämnden, ARN), Box 174, SE-101 23 Stockholm, arn.se. We participate in ARN proceedings.
24. Contact
Lind Studio AB Company registration number: 559593-4265 Registered office: Boden, Sweden Tråggränd 20 961 42 Boden, Sweden Email: hello@kolla.media
Appendix 1 – Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the General Terms for Kolla and applies when Lind Studio AB (the "Processor") processes personal data on behalf of the Customer (the "Controller"). Terms used here have the same meaning as in the EU General Data Protection Regulation (GDPR) and the General Terms.
B1. Subject matter and duration of processing
The Processor processes personal data to provide the Kolla Service under the General Terms for as long as the agreement remains in force and thereafter during the retrieval and deletion period stated in section 12 of the Terms.
B2. Nature and purpose of processing
Storage, display, conversion into previews, transmission to Reviewers, emailing review requests and notifications, recording comments, approvals, and versions, backup, and deletion, in each case to enable the Controller to have material reviewed and approved.
B3. Categories of personal data and data subjects
Personal data: names, email addresses, companies, and roles of Users and Reviewers; comments, decisions, and timestamps; images, video, audio, and text that may contain personal data about people who are depicted or mentioned; technical information about Reviewers' browsers; and a hashed IP address associated with review sessions.
Data subjects: the Controller's employees and consultants (Users), contacts at its clients (Reviewers), people who appear in uploaded material, and other people whose data the Controller adds to the Service.
The Service is not intended for processing sensitive personal data on a large scale, and the Controller must not add such data without a separate agreement.
B4. The Controller's responsibilities
The Controller is responsible for ensuring that the processing has a legal basis, that data subjects receive the information to which they are entitled, that data added to the Service is necessary for the purpose, and that its instructions to the Processor are lawful. The General Terms, the Service's features and settings, and the Controller's use of them constitute its documented instructions.
B5. The Processor's obligations
The Processor must:
- process personal data only on the Controller's documented instructions, including with regard to transfers to a third country, unless processing is required by EU or Swedish law. In that case, the Processor will inform the Controller of the legal requirement before processing unless the law prohibits that information,
- promptly inform the Controller if the Processor considers that an instruction infringes data protection law,
- ensure that persons who process the personal data are bound by confidentiality,
- implement the security measures in B7,
- engage subprocessors only in accordance with B8,
- taking into account the nature of the processing, help the Controller respond to requests from data subjects to exercise their rights through appropriate technical and organizational measures,
- help the Controller meet its obligations concerning security, personal data breaches, data protection impact assessments, and prior consultation, taking into account the nature of the processing and the information available to the Processor,
- delete or return the personal data after processing ends in accordance with B10, and
- give the Controller the information needed to demonstrate compliance with Article 28 of the GDPR and allow and contribute to audits under B11.
The Processor will promptly forward to the Controller any request that it receives directly from a data subject and that concerns processing by the Controller.
B6. Personal data breaches
The Processor must notify the Controller without undue delay, and no later than 72 hours after becoming aware of a personal data breach affecting the Controller's data. The notice will be sent to the Organization's administrator and, to the extent known, describe the nature of the breach, the affected categories of data subjects and data, the likely consequences, the measures taken, and a contact point. Information that is not immediately available will be provided in stages.
B7. Security measures
The Processor implements technical and organizational measures appropriate to the risk, including:
- encryption of all communications with the Service using TLS and encryption of stored data by our storage providers,
- individual accounts, access controls by Organization and role, and access to customer data by the Processor's staff only where needed for support, operations, or security,
- review links containing random, single-use secrets that are stored as hashes and expire after a limited period,
- storage of IP addresses for review sessions only as hashes,
- logging of security-relevant events,
- separate development and production environments, code review, and version control,
- suppliers with documented security programs, including SOC 2, and data processing agreements, and
- incident response and deletion procedures.
B8. Subprocessors
The Controller gives the Processor general authorization to engage subprocessors. The Subprocessor List identifies the subprocessors engaged when the DPA is entered into.
The Processor must inform the Controller by email to the Organization's administrator at least 30 days before a new or replacement subprocessor starts processing personal data and must update the list. The Controller may object in writing within 14 days after the notice on reasonable data protection grounds. If the parties cannot agree on a solution, the Controller may terminate the agreement before the change takes effect and receive a refund of prepaid fees covering the period after termination. If a subprocessor must be replaced urgently because of a security incident or similar event, the replacement may take place on shorter notice, and the Processor will inform the Controller as soon as possible.
The Processor must enter into a written agreement with each subprocessor that imposes data protection obligations equivalent to those in the DPA. The Processor remains fully liable to the Controller for the subprocessor's performance.
B9. Transfers to third countries
Several of the Processor's subprocessors are established in the United States. Transfers to them rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework where the subprocessor is certified under that framework. Other transfers rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and the supplementary measures in B7. If an adequacy decision ceases to apply, the Standard Contractual Clauses apply. The Subprocessor List states the transfer mechanism used for each subprocessor.
B10. Deletion and return
When the agreement ends, the Processor deletes the personal data under section 12 of the General Terms unless the Controller has already requested an export. The Processor may retain data for longer only where required by EU or Swedish law and must not then process it for any other purpose. Data in backups is overwritten under the subprocessors' regular procedures and no later than 90 days after deletion.
B11. Audits
On request, the Processor provides the information needed to demonstrate compliance with the DPA, such as descriptions of security measures and subprocessors' audit reports to the extent they may be shared. If that information is insufficient, the Controller, or an independent auditor accepted by both parties, may audit the Processor's processing no more than once in any twelve-month period. The Controller must give 30 days' written notice, and the audit must take place during normal business hours without unnecessarily disrupting operations. Each party bears its own audit costs. Audits by a supervisory authority are unaffected.
B12. Liability and term
Each party is responsible for any administrative fine imposed on it by a supervisory authority. Otherwise, the limitation of liability in section 17 of the General Terms also applies to the DPA, except to the extent that mandatory law prevents this.
The DPA remains in force for as long as the Processor processes personal data on the Controller's behalf. If the DPA conflicts with the General Terms, the DPA prevails on matters concerning the processing of personal data.