Diffa

Data Processing Agreement

Version 1, in force from 2026-10-03

The Swedish version governs if the two differ.

Diffa is provided by Sliti & Klay Group AB, reg. no. 559524-2891, Remigatan 41, SE-261 45 Landskrona, Sweden. In this agreement Sliti & Klay Group AB is “Diffa”, “we” or “the processor”. “You” is the company that uses Diffa and is the controller of its bookkeeping data.

The agreement applies as an appendix to Diffa’s terms of service from the day you start using Diffa. It needs no signature. It meets the requirements of Article 28 of the General Data Protection Regulation (GDPR).

1. Parties and roles

You are the controller of the bookkeeping data Diffa processes for you. Diffa is the processor. For the data about your account, for billing and for support, Diffa is instead the controller itself. That is described in the privacy policy and is not covered by this agreement.

If you are an accounting firm using Diffa for client companies, the client company is the controller, you the processor and Diffa the subprocessor. You are responsible for your agreement with the client company allowing Diffa to be engaged on the terms stated here.

2. Instructions

Diffa processes personal data only on your documented instructions. The instructions are the terms of service, this agreement and the settings you make in the service: which sources you connect, which accounts you approve, when you switch bookkeeping on.

If Diffa considers an instruction to breach the GDPR or other law, we say so before following it. If the law requires Diffa to process data in another way, we inform you in advance, where the law allows it.

3. What is processed

The processing covers the data needed to book your platform payouts.

  • Data subjects: your customers and counterparties on the platforms, to the extent an id, a country or an amount can be linked to a person, as well as the users you give access to Diffa.
  • Data: the platforms’ ids for payouts, orders or fees, amounts, currency, country, VAT details and the accounting system’s vouchers. Names, addresses, e-mail, phone and card details about your customers are removed before anything is stored.
  • Purpose: to fetch material, code it, book it in your accounting system, reconcile and keep the material.
  • Location: Sweden (Google Cloud, Stockholm), with the exceptions in section 7.
  • Duration: during the term and afterwards as described in section 12.

4. Diffa’s obligations

Diffa processes the data confidentially and only for your purpose. The people who work with the data are bound by confidentiality. Diffa helps you meet your obligations under sections 9 and 10. Diffa also gives you the information needed to show that the agreement is followed.

5. Restriction

Diffa never sells, rents out or shares your data or personal data with third parties for their own purposes. The data is not used for advertising or profiling. It is handed only to subprocessors under section 6, to the platform or accounting system you connected yourself and when law or an authority’s decision requires it.

6. Subprocessors

Diffa may engage subprocessors for the processing. Who they are, what they do, where they are and on what basis data is transferred is on the page Subprocessors. Today they are Google Cloud for hosting, Google (Firebase) for sign-in, Resend for e-mail, Stripe for billing, OpenAI for Ask Diffa and Cloudflare for diffa.se.

If we want to replace or add a subprocessor, we notify you by e-mail 30 days in advance. You may object within 30 days. If you object on reasonable grounds, we refrain from the change or let you terminate the part of the service concerned, at no cost for the remaining time.

Diffa enters into written agreements with every subprocessor giving at least the same protection as this agreement. Diffa is liable to you for the subprocessor’s work.

7. Transfers outside the EU

Bookkeeping data is stored in Sweden. Transfers outside the EU/EEA happen only when a subprocessor requires it, under the EU Commission’s standard contractual clauses or another basis the GDPR allows. You authorise Diffa to enter into standard contractual clauses on your behalf with such subprocessors.

Today this concerns Google (Firebase) for sign-in, OpenAI for Ask Diffa and Cloudflare for diffa.se. What is sent to OpenAI is stated in the privacy policy: never names, registration numbers, amounts or keys.

8. Security

Diffa protects the data with technical and organisational measures appropriate to the risk. These include encryption at rest as well as in transit, key management in Cloud KMS where the keys never leave the service, access control with least privilege, logging of access to customer data, data minimisation at the source, separate environments for test versus production. The measures are described on the page Security and are updated as the service develops, without lowering the protection.

9. Personal data breaches

If Diffa discovers a personal data breach concerning your data, we notify you without undue delay, aiming for within 48 hours of discovery. The notification describes what happened, which data as well as data subjects are affected as far as known, what consequences it may have and what we are doing about it. What you need to notify the Swedish Authority for Privacy Protection within 72 hours, you get from us.

10. Assistance

Diffa helps you answer data subjects who request access, correction, deletion, restriction or portability or who object, to the extent the answer requires data Diffa holds. Diffa also assists with data protection impact assessments and with prior consultation of the supervisory authority. If assistance requires extensive work, Diffa may charge at cost.

11. Audit

You have the right to verify that the agreement is followed, once a year, with 30 days’ notice. First you receive documentation plus the reports and certificates Diffa holds. If that is not enough, you or an auditor approved by Diffa, bound by confidentiality, may audit on site, on weekdays and without disturbing operations. You bear the cost of the audit. If the supervisory authority requires an inspection, it takes place according to the authority’s decision.

12. When the agreement ends

When the agreement with you ends, Diffa deletes the personal data within 90 days, except what the law requires us to keep and the material behind vouchers that is kept until 31 December of the eighth year after the voucher’s year under the terms of service. Backups are overwritten on their rotation. Before deletion you get your data out under section 12 of the terms of service. On request we confirm the deletion in writing.

13. Change of processor

If the Diffa business is taken over by another company, that company may step in as processor in Diffa’s place, on the terms here. We notify you in advance, under section 19 of the terms of service.

14. Liability and law

The limitation of liability in the terms of service also applies to this agreement, except where the GDPR does not allow liability to be limited. Swedish law applies. Disputes are decided as set out in the terms of service.

Questions about the agreement go to support@diffa.se.