Data processing agreement (DPA)
Last updated: 9 August 2026
1. Parties
This data processing agreement ("DPA") applies between: • Controller: the association (the "Association") that has registered an account in the Membly service and is represented by its administrator upon acceptance of this agreement. • Processor: Monile AB ("Membly"), company reg. no. 559273-6051, Nackagatan 3, 116 49 Stockholm, Sweden. This DPA forms an integral part of Membly's terms of service and meets the requirements of Article 28 of the GDPR. In the event of a conflict between the terms of service and this DPA, the DPA prevails for all processing of personal data covered by Article 28.
2. Subject matter, duration, nature and purpose
• Subject matter: processing of members' personal data for the purpose of providing association management tools via the Membly service. • Duration: the agreement applies for as long as the Association has an active account in the service, and for the period thereafter required for data export and erasure under section 11. • Nature and purpose of the processing: storage, access management, display, search, communication facilitation, payment processing, backup, association-level statistics, and other operational functions within the service that the Association activates. • The Association's role: controller of the members' personal data. • Membly's role: processor, processing the data exclusively on the Association's documented instructions.
3. Types of personal data and categories of data subjects
Categories of data subjects: the association's members, leaders, administrators, guardians, contact persons and any minor members. Types of personal data processed: • Identity and contact details (name, email, telephone, profile picture). • Membership data (membership status, roles, tags, custom fields). • Communication content (chat, feed, documents). • Attendance and activity data. • Payment metadata (actual card details are handled by Stripe, not by Membly). • Family relationships (guardian links). • Any national identity numbers for LOK subsidy reporting (sport). The Association is responsible for not entering special categories of personal data (Article 9 GDPR) other than on a specific legal basis.
4. The Association's instructions
Membly processes the personal data solely on the Association's documented instructions. The terms of service, this DPA and the Association's configuration of the service (settings, integrations, data flows) constitute the Association's initial instructions. Membly notifies the Association without undue delay if Membly considers that an instruction infringes applicable data protection legislation. Membly does not process the personal data for its own purposes beyond what is required to provide the service (e.g. security, operations and aggregated statistics without identifiability).
5. Confidentiality
Membly ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is limited to those employees who need it in order to perform their duties ("need to know").
6. Security measures (Article 32 GDPR)
Membly implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. This includes, among other things: • Encryption in transit: TLS 1.2+ for all communication. • Encryption at rest: AES-256 in the Supabase database and for the storage of attachments. • Access control: role-based access, Row-Level Security (RLS) in the database, separation between service roles. • Strong authentication: magic link for user login; mandatory multi-factor authentication for Membly's administrative access. • Audit logs: security-relevant events are logged for at least 12 months. • Backups: daily backups with 30 days' retention; restoration tests are carried out regularly. • Incident management: documented incident response plan; readiness to notify within 72 hours. • Vulnerability management: continuous monitoring, regular patching, and review of third-party dependencies. Membly evaluates and updates the security measures on an ongoing basis to meet new threats and technical standards.
7. Sub-processors
The Association gives general authorisation for Membly to engage the following sub-processors for the processing of personal data: • Supabase Inc. — database, authentication and file storage. EU (AWS eu-west, Ireland). • Stripe Payments Europe Ltd. — payment processing. Ireland. • Vercel Inc. — hosting and frontend delivery. USA, EU-US Data Privacy Framework + SCC. • Resend (Drip Email Inc.) — transactional email. USA, EU-US Data Privacy Framework. • Anthropic PBC — AI features (Claude API). USA, SCC. • Voyage AI (MongoDB, Inc.) — AI embeddings (vectorisation of association content) for AI search and the knowledge base. USA, SCC. • Sentry (Functional Software, Inc.) — error reporting. USA, EU-US Data Privacy Framework + SCC. • Upstash, Inc. — rate limiting and technical deduplication of webhooks (Redis). USA, SCC. • Google Ireland Limited (with Google LLC, USA) — address lookup and geocoding (Google Places/Maps). EU-US Data Privacy Framework + SCC. Membly ensures that the sub-processors are bound by the same data protection obligations as set out in this DPA. Membly notifies the Association of planned changes to sub-processors (additions or replacements) at least 30 days in advance. The Association may object to the change within 14 days; if it does, the parties will seek a joint solution, and if no such solution is reached the Association is entitled to terminate the affected part of the service at no additional cost.
8. Assistance with requests and incidents
Membly assists the Association, taking into account the nature of the processing and within reasonable limits: • With requests from data subjects exercising rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, data portability, objection). The service offers self-service tools for administrators; for more complex cases Membly provides technical support. • With the Association's obligations under Articles 32–36 GDPR (security, notification of incidents, impact assessments). In the event of a personal data breach affecting the Association's members, Membly notifies the Association without undue delay and at the latest within 72 hours of the breach being discovered. The notification contains at least: the nature of the breach, the categories of data and data subjects concerned, the likely consequences, and the measures taken or proposed.
9. Right of audit
The Association is entitled, once per calendar year, to request written documentation demonstrating that Membly complies with the obligations under this DPA. This normally comprises a summary of security measures, any third-party assessments and the list of sub-processors. An on-site or in-depth audit may be carried out by the Association or by an independent auditor appointed by the Association, against reasonable cost coverage for Membly's preparation and participation. The audit must be planned at least 30 days in advance, conducted during normal office hours and without undue impact on Membly's operations. The auditor must sign a confidentiality agreement before access is granted to sensitive information.
10. International transfers
To the extent the processing involves the transfer of personal data to a third country outside the EU/EEA, Membly ensures that appropriate safeguards are in place: • The EU-US Data Privacy Framework for sub-processors certified under the framework. • The EU Standard Contractual Clauses (Commission Decision 2021/914), Module 3 (processor-to-processor), for other transfers. • Where necessary, supplementary technical and organisational measures in line with the recommendations of the European Data Protection Board (EDPB). The Association authorises Membly to enter into standard contractual clauses with sub-processors in the Association's name where this is necessary.
11. Return and erasure on termination
On termination of the agreement, or at the Association's request: • Membly makes available an export window of at least 30 days during which the Association can download all data via the service's export functions. • After the export window, Membly erases the Association's personal data within 90 days, including any backups in line with the ordinary rotation schedule. • Personal data that must be retained under a legal obligation (e.g. accounting data under Chapter 7, Section 2 of the Swedish Accounting Act) is stored separately and only for as long as the obligation persists. At the Association's request, Membly can provide written certification that erasure has been carried out.
12. Governing law, amendments and contact
This DPA is governed by Swedish law. Disputes are settled as set out in Membly's terms of service. Membly may update this DPA to reflect new legal requirements, security standards or changes of sub-processors. Material changes are notified to association administrators by email at least 30 days in advance. If the Association does not accept the change, the Association is entitled to terminate the service at no additional cost. Contact: Monile AB ("Membly") Company reg. no. 559273-6051 Nackagatan 3, 116 49 Stockholm, Sweden Email: privacy@membly.app
Language versions
This document was drafted in Swedish. The English translation is provided for convenience only. In the event of any discrepancy between the versions, the Swedish version governs.
