Provided by LMK Group AB
Welcome to Mapdash (“the Service”), a SaaS-based mapping and CRM platform developed and operated by LMK Group AB, corporate registration number 559538-0725, with registered address at Stenkullavägen 44, Stockholm 112 65, Sweden (“LMK Group AB”, “the Provider”, “we”, “us”).
By creating an account, accessing or using Mapdash you agree to be bound by these Terms of Service. If you do not agree to these terms, you may not use the Service.
1. About the Service
Mapdash is a cloud-based platform designed for door-to-door sales teams. The Service provides tools for territory management, lead tracking, appointment scheduling, route optimization, and team analytics.
The Service is intended for business users (B2B). If you use Mapdash on behalf of a company or organization, you represent and warrant that you are authorized to bind that entity to these terms.
2. Account & Access
- You must provide accurate and complete information when creating an account.
- You are responsible for safeguarding your login credentials and for all activity that occurs under your account.
- You must notify us immediately at team@mapdash.ai if you suspect unauthorized use of your account.
- We reserve the right to suspend or terminate accounts that violate these terms or are used for unlawful purposes.
3. Subscription & Payment
Mapdash is offered on a subscription basis. Current pricing, plan details, and billing cycles are presented during sign-up or in-app.
- Subscriptions renew automatically unless cancelled before the end of the current billing period.
- All fees are quoted in the currency indicated at the time of purchase and are exclusive of applicable taxes unless stated otherwise.
- We may change pricing with at least 30 days’ notice. Continued use of the Service after a price change constitutes acceptance of the new price.
- Payments are processed by our payment provider, Stripe. By subscribing you also agree to Stripe’s terms.
4. Data Ownership
Your data is yours. All data you or your team members enter into Mapdash — including leads, customers, addresses, markers, notes, and any other content — remains your property.
- We do not sell, share, or use your data for our own independent commercial purposes.
- We act as a data processor (personuppgiftsbiträde) under GDPR with respect to data you store in the Service. You are the data controller.
- Upon termination of your subscription you may request an export of your data. We will make reasonable efforts to provide the data in a structured, commonly used format.
- After a reasonable retention period following termination (typically 90 days), your data will be permanently deleted from our active systems.
5. Acceptable Use
You agree not to:
- use the Service for any unlawful, fraudulent, or harmful purpose;
- attempt to reverse-engineer, decompile, or disassemble any part of the Service;
- interfere with or disrupt the integrity or performance of the Service;
- access the Service through automated means (bots, scrapers) without our prior written consent;
- resell, sublicense, or redistribute the Service without authorization.
6. GDPR & Data Processing
As a Swedish company we comply with the EU General Data Protection Regulation (GDPR). Our roles and responsibilities are as follows:
Customer data in Mapdash
- You (the customer) are the data controller.
- LMK Group AB is the data processor.
- This relationship is governed by our Data Processing Agreement (DPA), which forms part of these terms.
LMK Group AB’s own processing
- We are the data controller for contact details of our customer contacts (e.g. administrators, billing contacts), invoicing data, support tickets, and website visitor data.
- See our Privacy Policy for full details.
7. Demo Requests & Sales Inquiries
When you submit a demo request or sales inquiry through our website, you consent to the following:
- We will store the personal information you provide (name, phone number, company name, and any additional details) for the purpose of following up on your request and for legitimate sales purposes.
- We may contact you by phone, email, or other means you have provided to discuss your demo request and our services.
- Your information will be retained for up to 24 months following your inquiry unless you request earlier deletion.
- The legal basis for this processing is consent (Article 6(1)(a) GDPR), which you grant by submitting the form.
- You may withdraw your consent at any time by contacting us at team@mapdash.ai, after which we will delete your data without undue delay.
8. Intellectual Property
The Service, including its design, source code, features, documentation, logos, and branding, is the intellectual property of LMK Group AB and is protected by applicable copyright and trademark laws.
These terms do not grant you any right, title, or interest in the Service beyond the limited right to use it under these terms.
9. Availability & Warranties
We strive to keep Mapdash available and reliable but cannot guarantee uninterrupted, error-free operation.
- The Service is provided “as is” and “as available” without warranties of any kind, express or implied.
- We may perform scheduled maintenance that temporarily affects availability. We will notify users in advance where possible.
10. Limitation of Liability
To the maximum extent permitted by applicable law:
- LMK Group AB shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the Service.
- Our total liability for any claim relating to the Service shall not exceed the amount you paid us in the 12 months preceding the claim.
11. Termination
- You may cancel your subscription at any time through your account settings or by contacting us.
- We may terminate or suspend your access if you materially breach these terms, subject to reasonable notice where practicable.
- Upon termination, your right to use the Service ceases. Sections relating to data ownership, limitation of liability, and governing law survive termination.
12. Changes to These Terms
We may update these Terms of Service from time to time. The latest version will always be available on our website.
For material changes we will notify you via email or an in-app notification at least 30 days before they take effect. Continued use of the Service after such notice constitutes acceptance of the updated terms.
13. Governing Law & Disputes
These terms are governed by and construed in accordance with the laws of Sweden.
Any disputes arising from or in connection with these terms shall be resolved by the courts of Sweden, with Stockholm District Court as the court of first instance.
14. Contact
If you have any questions about these Terms of Service, please contact us:
- Company: LMK Group AB
- Org. no.: 559538-0725
- Address: Stenkullavägen 44, Stockholm 112 65, Sweden
- Email: team@mapdash.ai
Data Processing Agreement (DPA)
between the Customer and LMK Group AB (Mapdash)
Last updated: 2026-09-27
This Data Processing Agreement ("DPA") has been entered into between:
1. Data Controller ("Customer", "Controller")
The legal entity that subscribes to and uses Mapdash under the Mapdash Terms of Service.
2. Data Processor ("Provider", "Processor")
LMK Group AB, corporate registration number 559538-0725, with its address at Stenkullavägen 44, Stockholm 112 65, which develops and operates the Mapdash Service.
Together referred to as the "Parties" and individually as a "Party".
1. Relationship to the Mapdash Terms of Service
1.1 This DPA is an annex to and an integral part of the agreement governing use of the Mapdash Service, the "Mapdash Terms of Service" ("Main Agreement").
1.2 In the event of a conflict between the Main Agreement and this DPA, this DPA shall prevail to the extent that the conflict concerns the processing of personal data.
1.3 Terms not defined here have the meanings given in the EU General Data Protection Regulation (GDPR) or in the Main Agreement.
2. Definitions
For the purposes of this DPA:
- "GDPR": Regulation (EU) 2016/679 of the European Parliament and of the Council.
- "Personal Data": Any information referred to in Article 4(1) GDPR.
- "Processing": Any operation or set of operations referred to in Article 4(2) GDPR.
- "Data Subjects": The natural persons whose personal data is processed.
- "Sub-processor": A subcontractor engaged by the Processor to process personal data on behalf of the Controller.
- "Service": The cloud-based Mapdash software service under the Main Agreement.
- "Customer Data": All data stored by the Customer in the Service, including personal data.
3. Purpose, Nature, Duration and Categories of Personal Data
3.1 Purpose
The Processor processes personal data exclusively for the following purposes:
- providing, operating and maintaining the Mapdash Service
- enabling the Customer to manage leads, customers, territories, field sales and related workflows
- providing support, troubleshooting, security and technical improvements to the Service (including logging, incident management and performance optimization).
3.2 Nature of Processing
Processing may include, among other things:
- collection, recording, organization and storage
- structuring, processing, filtering and analysis
- display, compilation, export and transfer to the Customer's authorized users
- erasure and deletion in accordance with retention procedures.
3.3 Duration
This DPA applies for the entire period during which the Processor processes personal data on behalf of the Customer under the Main Agreement.
Following termination of the Main Agreement, the Processor shall handle the personal data in accordance with Section 11 of this DPA (Erasure and Return).
3.4 Categories of Data Subjects
Typical categories of data subjects may include:
- the Customer's current and potential customers (leads/prospects)
- contact persons at the Customer's end customers
- natural persons whose addresses/properties are mapped in the Service
- the Customer's employees or consultants who use the Service.
3.5 Types of Personal Data
Typical personal data may include:
- name, address, email address, telephone number
- address details for homes/properties (including coordinates)
- internal classifications, statuses, notes or comments that the Customer records about leads/customers
- user details for login and permissions (e.g. name, email).
The Customer is responsible for ensuring that only personal data necessary for the purposes and consistent with the GDPR is processed in the Service.
4. General Obligations of the Processor
The Processor undertakes to:
4.1 Process personal data only in accordance with documented instructions from the Controller, as set out in:
- this DPA
- the Main Agreement
- other written instructions provided by the Controller, provided that these are reasonable and consistent with the Main Agreement.
4.2 Inform the Controller without delay if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data protection legislation.
4.3 Ensure that persons authorized to process personal data on behalf of the Processor:
- process it only in accordance with the Controller's instructions, and
- are subject to an appropriate confidentiality undertaking or duty of confidentiality.
5. Security
5.1 The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
5.2 Such measures may include, where relevant:
- pseudonymization and encryption of personal data
- the ability to ensure ongoing confidentiality, integrity, availability and resilience
- the ability to promptly restore access to personal data in the event of an incident
- regular testing and evaluation of security measures.
5.3 The Controller is responsible for:
- secure management of internal user accounts, passwords and permissions
- internal procedures for access, logging and staff training.
6. Sub-processors
6.1 The Processor may engage Sub-processors to carry out processing on behalf of the Controller, such as providers of hosting, databases, email services and log management.
6.2 The Processor shall ensure that:
- each Sub-processor enters into a written agreement imposing equivalent data protection obligations to those in this DPA, in accordance with Article 28(4) GDPR
- the Sub-processor processes personal data only in accordance with the Processor's instructions.
6.3 The Processor shall maintain an up-to-date list of material Sub-processors, which may be provided on the website or upon request.
6.4 In the event of material changes (e.g. the addition or replacement of a Sub-processor), the Processor shall inform the Controller in advance, to the extent practicable. The Controller shall then have the right to raise objections if processing by that Sub-processor entails disproportionate risks.
6.5 If the Controller objects to a new Sub-processor and the Parties cannot agree on a solution, the Controller may have the right to terminate the Main Agreement in accordance with its terms.
6.6 The Processor remains fully liable to the Controller for the acts and omissions of Sub-processors insofar as they carry out processing on behalf of the Controller.
7. Transfers to Third Countries
7.1 If personal data is transferred to a country outside the EU/EEA ("third country"), the Processor shall ensure that the transfer complies with Chapter V GDPR, for example through:
- an adequacy decision by the European Commission, or
- Standard Contractual Clauses (SCCs) or other appropriate safeguards.
7.2 Upon request, the Processor shall provide the Controller with information about the third-country transfers that take place and the legal mechanism used.
8. Assistance to the Controller
Taking into account the nature of the processing, the Processor shall assist the Controller, to the extent reasonable and proportionate, in:
8.1 Responding to requests from data subjects (Articles 12–23 GDPR) – e.g. the rights of access, rectification, erasure, restriction, data portability and objection. This shall be done by:
- providing functionality in the Service that facilitates handling such requests, or
- otherwise assisting the Controller in accordance with written instructions.
8.2 Carrying out data protection impact assessments (DPIAs) and consulting the supervisory authority where required under Articles 35–36 GDPR.
8.3 Fulfilling obligations under Articles 32–36 GDPR, such as:
- security
- incident reporting
- cooperation with supervisory authorities.
To the extent that this entails additional work beyond what is normally included in the Service, the Processor may be entitled to reasonable compensation as agreed.
9. Personal Data Breaches
9.1 If the Processor becomes aware of a personal data breach (as defined in Article 4(12) GDPR) affecting personal data processed on behalf of the Controller, the Processor shall:
- notify the Controller without undue delay
- provide the information reasonably available and needed by the Controller to fulfill its obligations under the GDPR, including any notification to the supervisory authority and data subjects.
9.2 The Processor shall take the technical and organizational measures necessary to contain and remedy the consequences of the breach.
10. Review and Audit
10.1 The Controller has the right, to the extent required by Article 28(3)(h) GDPR, to verify that the Processor complies with this DPA.
10.2 Such review may take place through:
- access to relevant summary documents and audits (e.g. third-party reports, certifications), or
- a specific on-site audit conducted by the Controller or an independent auditor appointed by the Controller.
10.3 Reviews shall:
- be preceded by reasonable written notice
- be conducted in a manner that does not unnecessarily disrupt the Processor's operations
- be limited to what is necessary to verify compliance.
Unless otherwise required by mandatory law, the Processor may be entitled to reasonable compensation for costs arising from extensive audits that go beyond normal standard practice.
11. Erasure or Return of Personal Data
11.1 Upon termination of the Main Agreement, or when instructed in writing by the Controller, the Processor shall:
- erase or return all personal data processed on behalf of the Controller, in the agreed format (e.g. through the Service's standard export function), and
- delete any copies, unless continued storage is required by law.
11.2 Deletion from backup systems shall take place in accordance with the Processor's normal data retention and deletion procedures.
11.3 The Processor may retain data required to fulfill legal obligations (e.g. accounting legislation) or to handle legal claims, to the extent permitted by law.
12. Responsibilities of the Controller
The Controller is responsible for:
12.1 Ensuring that the processing of personal data in the Service has a lawful basis under the GDPR and that data subjects have received the necessary information.
12.2 Not storing or processing sensitive personal data or other data requiring special protection in the Service unless expressly agreed and the Service is intended for such processing.
12.3 Ensuring that instructions given to the Processor comply with the GDPR and other applicable law.
12.4 Informing the Processor without delay of changes affecting the processing (e.g. changes in purposes, categories of data subjects or types of personal data).
13. Liability and Damages
13.1 The Parties acknowledge that the allocation of liability under the GDPR is primarily governed by the GDPR itself, in particular Articles 82–83.
13.2 As between the Parties:
- each Party shall be liable for the damage it causes the other Party through a breach of this DPA or the GDPR, to the extent that such damage has not been caused or aggravated by the other Party's own omission or breach
- each Party shall take reasonable steps to mitigate its loss.
13.3 Any limitations of liability in the Main Agreement shall also apply to this DPA, to the extent consistent with the GDPR and mandatory law. However, no limitation of liability shall apply in contravention of the GDPR provisions on data subjects' right to compensation.
14. Term, Governing Law and Dispute Resolution
14.1 This DPA takes effect when the Controller begins using the Service under the Main Agreement and remains in effect for as long as the Processor processes personal data on behalf of the Controller.
14.2 This DPA is governed by Swedish law, excluding its conflict-of-law rules, and shall be interpreted in accordance with the GDPR and other applicable data protection legislation.
14.3 Any disputes arising from this DPA shall be handled in accordance with the dispute resolution provisions of the Main Agreement (Mapdash Terms of Service), meaning that disputes shall be resolved by the ordinary courts of Sweden, with Stockholm District Court as the court of first instance, unless otherwise required by mandatory law.

