Data processing agreement
This English translation is provided for convenience. In case of discrepancy, the Danish version prevails.
Drawn up under Article 28(3) of the GDPR · Version 1.1 · 1 May 2026 · Last corrected: 25 August 2026
Corrected 25 August 2026. The list of sub-processors has been corrected: Supabase is now listed with AWS Ireland (eu-west-1) instead of AWS Frankfurt (eu-central-1). Only the entry was wrong. The sub-processor, the processing and the location within the EU are unchanged.
This Data Processing Agreement ("DPA") is entered into as part of the Terms of Service between the Customer and Ejerblik ApS. The DPA is binding on both parties from the moment the Agreement is entered into. If you would like to read the full Terms of Service, you will find them at ejerblik.com/en/terms-of-service.
1. Parties and roles
Controller: The Customer (as defined in the Terms of Service), the company or person who creates an account on ejerblik.com.
Processor: Ejerblik ApS, VAT DK46454928, [email protected].
2. Subject matter and duration of the processing
The Processor processes personal data on behalf of the Controller for the purpose of providing the Ejerblik platform. The processing lasts for as long as the Terms of Service are in force, plus a 30-day deletion period after the agreement ends.
3. Categories of data subjects
- The Customer’s employees and management
- External partners (accountants, advisers, IT suppliers)
- Contact persons linked to digital assets
4. Types of personal data
Ordinary personal data: Name, email address, telephone number, position or role, company affiliation.
Access data: Role configuration, department, 2FA status, last login.
Communication: Support messages, AI conversations, feedback.
5. Obligations of the Processor
(a) Processing on documented instructions. To process personal data only on documented instructions from the Controller, unless EU law or Danish law requires otherwise. In the latter case, the Controller is informed before the processing takes place, unless the law prohibits it.
(b) Confidentiality. To ensure that every person authorised to process personal data has committed to confidentiality or is under a statutory duty of confidentiality.
(c) Security (GDPR Article 32). To implement appropriate technical and organisational measures, including:
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest (Supabase/AWS)
- Row-level security (RLS) at database level
- Two-factor authentication on administrator accounts
- Automated backup and disaster recovery
- Access control on the principle of least privilege
- Regular security reviews
(d) Sub-processors. To use sub-processors only with the Controller’s prior general written authorisation. The current list is set out in section 7 below. New sub-processors are notified 14 days in advance. The Controller may object before the notice period expires.
(e) Assistance with data subject rights. To assist the Controller in responding to requests from data subjects under GDPR Articles 15 to 22.
(f) Assistance with compliance. To assist the Controller with obligations under GDPR Articles 32 to 36 (security, impact assessment, prior consultation).
(g) Deletion. On termination of the processing, to delete all personal data within 30 days, unless EU law or Danish law requires it to be retained.
(h) Audit. To make available to the Controller all information necessary to demonstrate compliance and to allow for audits.
6. Personal data breaches
The Processor notifies the Controller of a personal data breach without undue delay and no later than 48 hours after becoming aware of it. The notification must contain:
- A description of the breach, including the categories and number of data subjects concerned
- Contact details for the Processor’s contact person
- A description of the likely consequences
- A description of the measures taken or proposed
7. Approved sub-processors
Last updated: 1 May 2026. For sub-processors based in the USA, EU standard contractual clauses (SCCs) under Commission Decision 2021/914 have been implemented.
| Sub-processor | Function | Data location |
|---|---|---|
| Supabase Inc. (USA, DPA + SCCs) | Database, authentication, file storage | AWS Ireland (eu-west-1) |
| Hetzner Online GmbH (DE) | Application server and hosting | Falkenstein, Germany |
| Resend Inc. (USA, DPA + SCCs) | Transactional email | EU |
| Anthropic Inc. (USA, DPA + SCCs) | AI assistant (AInette) | USA (no data persistence) |
| MailerLite UAB (LT) | Newsletter (with consent only) | EU |
| Umami Software | Web analytics (with consent only) | EU |
| Microsoft Corporation | Behavioural analytics, heatmaps and session recordings (with consent only) | EU |
8. Duration of the DPA
This DPA applies for as long as the Terms of Service are in force. The DPA terminates automatically 30 days after the Agreement ends, once deletion has been completed.
Legal disclaimer: This document is under review by a solicitor specialising in IT law and data protection. The content may change before final approval. Contact us at [email protected] with any questions.