The Parties
- Data Controller
- As defined in the Service Agreement
- Data Processor
- Marketingfabrikken ApS, CVR 41837128, Denmark
- Contact at the Data Processor
- Ebbe Kjær Skau, Partner, +45 42 35 31 65, ebbe@marketingfabrikken.dk
- Notifications of unauthorised data processing
- Ebbe Kjær Skau, Partner, +45 42 35 31 65, ebbe@marketingfabrikken.dk
Hereinafter referred to individually as the “Data Controller”, the “Data Processor” or a “Party”, and collectively referred to as the “Parties”.
Introduction
Both Parties confirm that the undersigned are authorised to enter into this data processing agreement (the “Agreement”). This Agreement forms part of and governs the provisions on the processing of personal data that follow from the service agreements entered into between the Parties (the “Service Agreements”):
- Agreement on access to CRM, CMS and other relevant platforms and documents that may contain customer data.
Definitions
Personal data, Special categories of personal data (Sensitive personal data), Processing of personal data, the Data Subject, the Data Controller and the Data Processor shall have the meaning that follows from applicable legislation on the processing of personal data, including the General Data Protection Regulation (EU) 2016/679 (GDPR) of 27 April 2016.
Background
The Agreement concerns the Data Processor's processing of personal data on behalf of the Data Controller and describes how the Data Processor shall contribute to ensuring the protection of personal data on behalf of the Data Controller and its Data Subjects by means of technical and organisational measures in accordance with applicable legislation on the processing of personal data, including the General Data Protection Regulation (GDPR).
The purpose of the Data Processor's processing of personal data on behalf of the Data Controller is to fulfil the Service Agreements and this Agreement.
This Agreement takes precedence over any conflicting provisions on the processing of personal data in the Service Agreements or in other agreements entered into between the Parties. This Agreement applies for as long as the Parties have a valid Service Agreement that includes the processing of personal data.
The Data Processor's obligations
The Data Processor undertakes to process personal data solely on behalf of, and on the basis of instructions from, the Data Controller. Upon entering into this Agreement, the Data Controller instructs the Data Processor that the processing of personal data shall take place in the following manner: i) solely in accordance with applicable legislation, ii) in order to fulfil all obligations under the provisions of the Service Agreement, iii) as further specified through the Data Controller's ordinary use of the Data Processor's services, and iv) as set out in this Agreement.
The Data Processor has no reason to believe that applicable legislation prevents the Data Processor from complying with the above instructions. The Data Processor shall, if the Data Processor becomes aware thereof, notify the Data Controller of instructions or other processing-related matters on the part of the Data Controller which, in the Data Processor's opinion, are contrary to applicable legislation on the processing of personal data.
The categories of Data Subjects and personal data subject to processing under this Agreement are set out in Appendix A.
The Data Processor shall ensure that the personal data is subject to confidentiality, integrity and availability in accordance with applicable legislation on the processing of personal data. The Data Processor shall implement systematic, organisational and technical measures to ensure an appropriate level of security, taking into account the state of the technology and the costs of implementation relative to the risks involved in the processing and the nature of the personal data to be protected.
The Data Processor shall assist the Data Controller with appropriate technical and organisational measures, insofar as this is possible and taking into account the nature of the processing and the information available to the Data Processor, for the fulfilment of the Data Controller's obligations under applicable legislation on the processing of personal data to respond to requests from Data Subjects and regarding the general exercise of Data Subjects' rights pursuant to Articles 32 to 36 of the General Data Protection Regulation (GDPR).
If the Data Controller requests information about security measures, documentation or other forms of information regarding how the Data Processor processes personal data, and such requests exceed the standard information made available by the Data Processor for compliance with applicable legislation on the processing of personal data as a data processor, the Data Processor is entitled to charge the Data Controller for such requested additional work.
The Data Processor and its employees shall ensure confidentiality regarding the personal data processed under the Agreement. This provision also applies after the termination of the Agreement.
The Data Processor shall, without undue delay, notify the Data Controller of incidents that the Data Controller is required by law to report to Datatilsynet (the Danish Data Protection Agency) or to Data Subjects.
In addition, the Data Processor shall, to the extent appropriate and lawful, notify the Data Controller of: i) requests for the disclosure of personal data received from a Data Subject, and ii) requests for the disclosure of personal data from public authorities, such as the police.
The Data Processor does not respond directly to enquiries from Data Subjects unless the Data Controller has given its consent. The Data Processor does not disclose personal data to public authorities, such as the police, unless there is a lawful basis for doing so.
The Data Processor has no ownership of or control over whether or how the Data Controller chooses to make use of any third-party integrations via the Data Processor's API, via direct connection to the database or similar. The responsibility for such third-party integrations rests solely with the Data Controller.
The Data Controller's obligations
By signing this Agreement, the Data Controller confirms that:
- The Data Controller has the right to process and disclose the personal data in question to the Data Processor (including any sub-processors used by the Data Processor).
- The Data Controller has sole responsibility for ensuring the accuracy, integrity, content, reliability and lawfulness of the personal data disclosed to the Data Processor.
- The Data Controller has fulfilled all mandatory requirements and obligations to provide information to, notify or obtain authorisation from the relevant supervisory authorities or Data Subjects in connection with the processing of the personal data.
- The Data Controller is, when using the services made available by the Data Processor under the Service Agreement, obliged not to disclose sensitive personal data, unless this is expressly agreed in Appendix A to this Agreement.
Use of sub-processors and transfer of data
As part of the delivery of services to the Data Controller under the Service Agreements and this Agreement, the Data Processor has a general right to make use of sub-processors. These sub-processors may be other external third-party suppliers. The Data Processor shall ensure that sub-processors are subject to the same obligations as set out in this Agreement.
The Data Processor shall maintain an up-to-date list (see Appendix B) of sub-processors on the Data Processor's website. The sub-processor agreements can be requested via the website or by written request to the Data Processor.
If the sub-processors are located outside the EU, the Data Controller consents to the Data Processor ensuring a proper legal basis for the transfer of personal data outside the EU on behalf of the Data Controller, including by entering into the EU Commission's Standard Contractual Clauses.
The Data Controller shall be notified in advance of any replacement of sub-processors processing personal data. If the Data Controller has objections to new sub-processors in this connection, the Parties shall obtain and review information and documentation about the sub-processor demonstrating its compliance with the General Data Protection Regulation (GDPR).
Security
The Data Processor is obliged to ensure an appropriate level of security in its products and services. The Data Processor provides this level of security through organisational, technical and physical security measures in accordance with the requirements for information security measures set out in Article 32 of the General Data Protection Regulation (GDPR).
In addition, the internal framework for the protection of personal data prepared by the Data Processor is intended to ensure the confidentiality, integrity, security and availability of personal data. The following measures are of particular importance in this connection:
- Classification of personal data to ensure the implementation of security measures corresponding to risk assessments.
- Assessment of the use of encryption and anonymisation as risk-mitigating measures.
- Restriction of access to personal data to those who need access in order to fulfil obligations under this Agreement or the Service Agreement.
- Control systems that detect, prevent and report breaches in connection with the processing of personal data, and restore data afterwards.
- Use of security self-assessments to analyse whether current technical and organisational measures are sufficient to protect personal data, taking into account the requirements set out in applicable legislation on the processing of personal data.
Audits
The Data Controller may carry out audits to verify that the Data Processor complies with this Agreement, up to once a year. If it is a statutory requirement applicable to the Data Controller, the Data Controller may request more frequent audits.
To request an audit, the Data Controller must submit a detailed audit plan to the Data Processor at least four weeks prior to the proposed audit date, describing the proposed scope, duration and start time of the audit. If third parties are to carry out the audit, this must as a general rule be agreed between the Parties. If processing takes place in a “multitenant” environment or similar, the Data Controller grants the Data Processor the right to decide, for security reasons, that the audits shall be carried out by a neutral third party of the Data Processor's choosing.
If the requested scope of the audit has been covered by an ISAE, ISO or similar security report, carried out by a qualified third-party auditor within the last 12 months, and the Data Processor confirms that no material changes have been made to the audited measures, the Data Controller confirms that such findings are accepted instead of requesting a new audit of the measures covered by the report.
In all cases, audits must be carried out during normal working hours at the location in question, in accordance with the Data Processor's policies, and must not unreasonably interfere with the Data Processor's business operations.
The Data Controller bears all costs in connection with audits requested by the Data Controller. Assistance from the Data Processor exceeding the standard service made available by the Data Processor for compliance with applicable legislation on the processing of personal data will be subject to a fee.
Duration and termination
This Agreement applies for as long as the Data Processor processes personal data on behalf of the Data Controller under the Service Agreements. The Agreement terminates automatically upon termination of the Service Agreement. Upon the termination of this Agreement, the Data Processor shall delete or return the personal data processed on behalf of the Data Controller in accordance with the applicable provisions of the Service Agreement. Unless otherwise agreed in writing, the costs of such measures are based on: i) an hourly rate for the time spent by the Data Processor, and ii) the complexity of the requested processing.
The Data Processor may retain personal data after the termination of the Agreement to the extent required by law, subject to the same technical and organisational security measures as set out in this Agreement.
Amendments and additions
Amendments to the Agreement are made on the basis of notification, whereby written notice is given and/or notification is made on the Data Processor's website, after which amendments and/or additions enter into force.
If any provision of this Agreement becomes invalid, this shall not affect the validity of the remaining provisions. The Parties shall replace the invalid provision with a lawful provision that reflects the purpose of the invalid provision.
Liability
Both Parties have individual liability and shall be held separately liable for paying all administrative fines, and damages to Data Subjects, imposed on the respective Party by the authorities or a court pursuant to the GDPR. The liability between the Parties is governed by the Service Agreement.
Governing law and venue
This Agreement is subject to the governing law and venue set out in the Service Agreement entered into between the Parties.
Appendix A: Categories of personal data and Data Subjects
Categories of Data Subjects:
- The data controller's customers
- The data controller's employees
- The data controller's contact persons
- Other categories of Data Subjects whose personal data may be subject to processing
Categories of personal data:
- Contact details such as name, email address, phone number, IP address
- Other categories of personal data that may be subject to processing
Types of sensitive personal data subject to processing under the Agreement: This section is only relevant if the Data Processor is to process sensitive personal data on behalf of the Data Controller as part of the Service Agreement. In order for the Data Processor to process such data on behalf of the Data Controller, the Data Processor must be notified thereof in writing, including which types of sensitive personal data are being processed.
Appendix B: List of sub-processors
| Company | Country | Activity | Server location |
|---|---|---|---|
| Funnel.io | Sweden | Retrieving figures for dashboards | No storage of data |
| Netlify, Inc. | USA | Hosting of marketingfabrikken.dk and receipt of form enquiries | Global CDN; transfer to the USA under the EU Commission's Standard Contractual Clauses (SCC) |
| Azehosting ApS | Denmark | Maintains server for hosting | Hetzner Online GmbH, Falkenstein/Vogtland, Germany, as well as Amazon AWS in Frankfurt, Germany, Ireland, England and France (addresses kept confidential for security reasons) |