Legal & Compliance Schedule
Last Revised: September 2026 // DigitalBuildWork, Göteborg, Sweden
01. Entity Identification
Entity: DigitalBuildWork
Activity: Digital Development, Web Service Engineering, Automated Deployment Workflows, Secure Software Layer Construction
Registered Address: 411 01 Komedigatan 19, Göteborg, Sweden
Contact: [email protected] | +46 73 890 31 75
02. Privacy Policy & Data Retention
Retention Schedule
Contact form submissions are retained for 24 months from the date of submission. Project documentation and deliverables are retained for the duration of the active engagement plus 36 months post-completion for warranty and audit purposes.
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation), DigitalBuildWork processes personal data submitted through our contact consoles exclusively for client communication, project delivery, invoicing, and statutory tax reporting obligations under Swedish law.
Data Controller: DigitalBuildWork, 411 01 Komedigatan 19, Göteborg, Sweden. All personal data is stored within encrypted EU-hosted cloud infrastructure compliant with ISO/IEC 27001 information security standards.
Data Categories Processed: Full name, business email address, phone number, company name, project scope details, and communication records.
Legal Basis: Processing is conducted under Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) (legitimate interest in responding to business inquiries). Consent is obtained explicitly via form checkbox for marketing communications.
Data Subject Rights: You have the right to access, rectify, erase, restrict processing, object to processing, and port your personal data. Submit requests to [email protected]. Requests are processed within 30 calendar days in accordance with GDPR Article 12.
Data Sharing: DigitalBuildWork does not sell, rent, or distribute personal information to unauthorized third parties. Data may be shared with essential service providers (hosting, payment processing) strictly under Data Processing Agreements compliant with GDPR Article 28.
International Transfers: Where data is transferred outside the European Economic Area, DigitalBuildWork ensures adequate safeguards through Standard Contractual Clauses (SCCs) or equivalent mechanisms as required under GDPR Chapter V.
CCPA Compliance: California residents have additional rights under the California Consumer Privacy Act including the right to know, delete, and opt-out of the sale of personal information. DigitalBuildWork does not sell personal data.
03. Terms of Service
Engagement Lifecycle
All services are governed by explicitly contracted Statements of Work (SOW) executed between the client and DigitalBuildWork. No work commences without a signed SOW and initial payment as specified therein.
Scope of Work: DigitalBuildWork provides digital development services including web service engineering, deployment automation, security auditing, and ongoing maintenance retainers as defined in individual project agreements.
Payment Terms: Invoices are issued as per the SOW schedule. Late payments accrue interest at 1.5% per month. DigitalBuildWork reserves the right to suspend work after 14 days of unpaid invoices. All prices are quoted in USD unless otherwise specified.
Intellectual Property: Upon complete settlement of all agreed invoices, DigitalBuildWork assigns all worldwide intellectual property rights in client-specific deliverables, source code, design tokens, and digital assets directly to the Client. Pre-existing tools, frameworks, and libraries remain the property of DigitalBuildWork.
Confidentiality: Both parties agree to maintain strict confidentiality of proprietary information exchanged during the engagement. This obligation survives termination for a period of 24 months.
Limitation of Liability: DigitalBuildWork's aggregate liability under any engagement shall not exceed the total fees paid by the Client for the specific service giving rise to the claim. DigitalBuildWork shall not be liable for indirect, incidental, or consequential damages.
Termination: Either party may terminate with 30 days written notice. DigitalBuildWork retains payment for work completed up to the termination date. All completed deliverables are transferred upon final settlement.
05. Refund & Reimbursement Policy
Refund Schedule
Refund eligibility is determined by the project phase at the time of cancellation request, as defined below.
Pre-Work Cancellation (Before SOW Execution): Full refund of any advance payments within 14 business days. No cancellation fees apply.
Phase 1 — Discovery & Audit (Days 1-3): 75% refund of the total project fee. DigitalBuildWork retains 25% to cover completed audit work, documentation, and resource allocation.
Phase 2 — Architecture & Development (Days 4-14): 50% refund of the remaining balance. All completed deliverables and source code up to the cancellation date are transferred to the Client.
Phase 3 — Deployment & Handover (Days 15+): No refund. All completed work and intellectual property are transferred. DigitalBuildWork provides a 30-day post-cancellation support window for the transferred assets.
SLA Retainer Cancellation: Monthly retainers may be cancelled with 30 days written notice. The current billing period is non-refundable. No early termination fees apply beyond the current period.
Dispute Resolution: Refund disputes are first addressed through direct negotiation between the parties. Unresolved disputes are subject to mediation under the Stockholm Chamber of Commerce arbitration rules, with the seat of arbitration in Göteborg, Sweden.
Processing Time: Approved refunds are processed within 14 business days to the original payment method. DigitalBuildWork provides written confirmation of all refund transactions.
06. Security Audits & Compliance
Security Audit Schedule
DigitalBuildWork conducts quarterly internal security reviews and annual third-party penetration testing across all operational systems.
Infrastructure Security: All production systems are deployed on EU-hosted cloud infrastructure with automated vulnerability scanning, WAF protection, and encrypted data-at-rest and data-in-transit using AES-256 and TLS 1.3 respectively.
Access Control: Role-based access control (RBAC) is enforced across all internal systems. Multi-factor authentication (MFA) is mandatory for all team members. Privileged access is audited and logged continuously.
Incident Response: DigitalBuildWork maintains a documented incident response plan with defined escalation procedures. Security incidents are reported to affected clients within 72 hours in accordance with GDPR Article 33 breach notification requirements.
Compliance Framework: DigitalBuildWork operates in alignment with ISO/IEC 27001 information security management standards, SOC 2 Type II principles, and applicable Swedish data protection regulations (Personuppgiftslagen). Annual compliance reviews are conducted.
Client Security Deliverables: Upon engagement completion, clients receive a security hardening report detailing implemented controls, SSL/TLS configuration, header policies, and recommended ongoing security practices.