About these terms
These platform terms govern access to and use of the OptiTech platform, provided by OptiTech Sverige AB ("OptiTech", "we", "us"), registration number 559489-8917, Karlslundsvägen 8, 177 44 Stockholm, Sweden.
By creating an account or using the platform, you accept these terms on behalf of your organization ("Customer", "you"). If you accept on behalf of a company, you confirm that you are authorized to bind it. Use of our public website is governed separately by the Terms of use.
The service
OptiTech is a compliance automation platform built for Nordic organizations. It turns regulatory compliance into a continuous, automated process instead of a yearly project. Depending on your plan, the platform includes:
- Gap analysis. Automated assessment of your current state against the requirements of frameworks such as NIS2 (the Swedish Cybersecurity Act), DORA, the EU AI Act, GDPR, and ISO 27001, with a prioritized action plan
- AI-generated documentation. Policies, procedures, and other governance documents drafted by the platform in Swedish or English, based on your organization's profile and the applicable legal texts
- Continuous evidence collection. Integrations with your cloud, identity, HR, and finance systems that collect evidence automatically and map it to controls, so your compliance posture is always current
- Incident reporting. Structured workflows for preparing and tracking incident notifications to Swedish and EU authorities, including MSB and IMY deadlines
- Vendor management. Assessment and monitoring of your suppliers and their subcontractors, supporting the supply chain requirements of NIS2 and DORA
- Audit export and trust center. Auditor-ready exports of controls and evidence, and a public trust center page where you share your security posture with customers
We improve the platform continuously and may add, change, or retire features. Material changes that reduce the core functionality of your plan are announced in advance.
AI-generated content
Parts of the platform use AI to generate drafts, such as policies, gap analysis summaries, questionnaire answers, and suggested control mappings. AI output is a starting point, not legal advice. You are responsible for reviewing, adapting, and approving AI-generated content before relying on it. OptiTech does not guarantee that AI-generated documents meet the requirements of any specific regulation or auditor.
We do not use your customer data to train models made available to other customers.
Regulatory responsibility
The platform helps you prepare, structure, and track regulatory obligations, including incident notifications with statutory deadlines such as the 24-hour early warning under NIS2. The legal responsibility for meeting those obligations, including the content, accuracy, and timeliness of reports submitted to authorities such as MSB or IMY, always remains with you. OptiTech is a tool provider and does not act as your representative before any authority unless separately agreed in writing.
Accounts and access
You are responsible for the accuracy of your account information, for keeping credentials confidential, and for all activity under your accounts. Notify us without undue delay at info@optitech-sverige.se if you suspect unauthorized access.
You assign roles and permissions to your users and are responsible for keeping them appropriate, including removing access for people who leave your organization. Seats are personal and may not be shared.
Plans, fees, and payment
Plans and prices are described on the pricing page or in your order form. Prices are stated in Swedish kronor (SEK) unless otherwise agreed. Unless otherwise agreed in writing:
- Subscriptions renew automatically for the same period unless canceled before the end of the current term
- Fees are invoiced in advance and due within 30 days
- Plan limits, such as the number of frameworks, users, or monitored vendors, follow the plan you have selected. If your usage grows beyond your plan, we contact you about an upgrade
- Prices can change at renewal, with at least 30 days notice
- Fees are exclusive of VAT and other applicable taxes
Trials and beta features
We may offer free trials, pilots, or features marked as beta or early access. These are provided as is, may change or end at any time, and are excluded from any service level commitments. Data created during a trial is deleted 30 days after the trial ends unless you convert to a paid plan.
Customer data
You own the data you and your users submit to the platform, including evidence, documents, policies, incident records, vendor assessments, and integration data ("customer data"). You grant us the rights needed to host, process, and display that data in order to provide the service. We do not sell customer data or use it for advertising.
You are responsible for having the necessary rights to the data you submit and for its legality. You can export your customer data at any time in standard formats, including auditor-ready exports.
Integrations and third-party services
The platform connects to third-party systems you choose to integrate, such as cloud providers, Microsoft 365, identity providers, HR systems, and Swedish services such as Fortnox. When you enable an integration:
- You confirm that you are authorized to connect the system and grant us the access needed to collect evidence from it
- Access is read-only wherever the third-party service allows it, and credentials and tokens are stored encrypted
- You can revoke an integration at any time in the platform or from the third-party system
Third-party services are governed by their own terms. We are not responsible for their availability or for changes to their APIs, but we work to restore affected integrations promptly.
Data processing and subprocessors
Where we process personal data on your behalf, we do so as a processor under the GDPR and our data processing agreement. Our own processing as a controller is described in the Privacy policy. We use vetted subprocessors under data processing agreements; the current list is available on the subprocessors page.
Data is processed within the EU/EEA. Where you select a specific data region for your workspace, customer data is stored in that region. Where a transfer outside the EU/EEA occurs, we use safeguards such as the European Commission's standard contractual clauses.
Security
We implement appropriate technical and organizational measures to protect the platform and customer data, including:
- Encryption of data in transit and at rest
- Role-based access controls and authentication requirements
- Logging, monitoring, and alerting on anomalous activity
- Regular penetration testing by independent providers
- A documented incident response process. We notify you without undue delay of incidents affecting your data
Acceptable use
You may not use the platform to break the law, infringe third-party rights, distribute malicious code, attempt to gain unauthorized access to systems or data, or resell the service without our written consent. You may not use the platform to fabricate evidence or misrepresent your compliance posture to auditors, authorities, or customers.
We may suspend access that threatens the security or integrity of the service, and will notify you as soon as reasonably possible. Suspension is a last resort and access is restored when the issue is resolved.
Confidentiality
Each party protects the other party's confidential information with at least the same care as its own, and uses it only to fulfill this agreement. This applies to your compliance data, incident records, and vendor assessments, and to our non-public product information and pricing. Confidentiality survives termination for five years. Disclosures required by law or a competent authority are permitted, with notice to the other party where legally possible.
Intellectual property
OptiTech retains all rights to the platform, including software, design, and documentation. You receive a limited, non-exclusive, non-transferable right to use the platform during the subscription term. Feedback you provide may be used to improve the service without obligation.
Availability and support
We aim to keep the platform available around the clock, with planned maintenance announced in advance and scheduled outside Swedish business hours where possible. Service level commitments, where applicable to your plan, are described in the service level agreement.
Support is provided in Swedish and English via info@optitech-sverige.se during Swedish business days. Response targets depend on your plan and on the severity of the issue; issues that block statutory reporting deadlines are treated with the highest priority.
Term and termination
These terms apply for as long as you have an active subscription. Either party may terminate for material breach that is not cured within 30 days of written notice. Upon termination, you can export your customer data for 30 days, after which we delete it from production systems, except where retention is required by law.
Warranties and disclaimers
We provide the platform with reasonable skill and care. Except as expressly stated in these terms, the platform is provided "as is" without warranties of any kind.
OptiTech supports your compliance work but does not guarantee that you meet the requirements of any framework, law, or certification, that an audit will succeed, or that an authority will accept a report. Passing a gap analysis or having green controls in the platform is not proof of legal compliance. That responsibility remains yours.
Limitation of liability
To the extent permitted by law, neither party is liable for indirect or consequential damages, including regulatory sanctions, lost profits, or loss of goodwill, and each party's total liability under these terms is limited to the fees paid by Customer during the 12 months preceding the claim. This limitation does not apply to breaches of confidentiality, infringement of the other party's intellectual property, or liability that cannot be limited under applicable law.
Force majeure
Neither party is liable for failure to perform caused by circumstances beyond its reasonable control, such as widespread internet or infrastructure outages, acts of authorities, war, or natural disasters. Each party works to limit the effects and resumes performance as soon as possible.
Changes to these terms
We may update these terms from time to time. Material changes are announced at least 30 days in advance. Continued use of the platform after changes take effect means you accept the updated terms.
Governing law and disputes
These terms are governed by Swedish law. Disputes are subject to the exclusive jurisdiction of the Swedish courts, with the Stockholm District Court as the court of first instance.
Miscellaneous
- Order of precedence. If a signed order form conflicts with these terms, the order form controls
- Assignment. Neither party may assign this agreement without the other party's consent, except to an affiliate or in connection with a merger or acquisition
- Notices. Formal notices are sent in writing to the contact persons registered on the account, or to info@optitech-sverige.se
- References. With your prior consent, we may use your name and logo as a customer reference
Contact
Questions about these terms? Contact us at info@optitech-sverige.se or by mail at OptiTech Sverige AB, Karlslundsvägen 8, 177 44 Stockholm, Sweden.