DRAFT — not reviewed by counsel
This agreement is drafted to Article 28 of the GDPR, but it has not been reviewed by a lawyer and the list of sub-processors is incomplete. It should not be entered into as it stands.
Data Processing Agreement
DanskVersion 2026-07-10 · effective 2026-07-10
This is a convenience translation. In the event of any discrepancy, the Danish text governs.
1. Parties and subject matter
This agreement is entered into between the customer (the controller) and Firmatal (the processor), and governs the processor's processing of personal data on the controller's behalf under Article 28 of the GDPR. It applies for as long as the controller holds an account with the processor.
2. Nature and purpose of the processing
The processor provides a lookup API returning data from the Danish CVR register and the Norwegian Brønnøysund registers. When the controller performs a lookup, the processor processes the personal data returned on the controller's behalf, for the purpose of delivering the response and maintaining usage records.
3. Types of personal data and categories of data subjects
- Data subjects: directors, board members, owners, auditors and other natural persons holding a registered role in a company.
- Categories of data: name, role and role title, start date, ownership percentage, and the company's address and contact details.
- Excluded: the processor does not store dates of birth, although both source registers publish them, and processes no special categories of personal data.
4. Instructions
The processor processes personal data only on documented instructions from the controller. The controller's use of the API constitutes those instructions. The processor shall inform the controller if, in its opinion, an instruction infringes the GDPR.
5. Confidentiality
The processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. Security
The processor has implemented the following technical and organisational measures under Article 32:
- Credentials are encrypted at rest with AES-256 and are never rendered back into a form.
- API access requires a bearer token; tokens are stored hashed and can be revoked by the customer at any time.
- All traffic to the service is over TLS.
- Access to the production database is limited to named administrators.
- Dates of birth are never stored, although both source registries publish them.
- Registry entities flagged as advertising-protected are excluded from any bulk or marketing-facing output.
7. Sub-processors
The controller grants general authorisation for the processor to engage sub-processors. The processor shall inform the controller before adding or replacing a sub-processor, giving the controller the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Frisbii A/S | Subscription billing and payment processing | Danmark (EU) |
Incomplete: further sub-processors are not yet named. This agreement cannot be entered into until the list is complete.
8. Transfers to third countries
Personal data is processed within the EU/EEA. No transfer to a third country takes place without prior written agreement and a valid transfer mechanism.
9. Assistance to the controller
The processor assists the controller in complying with Articles 32-36, and in responding to data subject requests for access, rectification, erasure and restriction. Such requests are forwarded without undue delay.
The processor notes that the data originates from public registers. Rectification must be made in the source register; the processor's copy is updated at the next synchronisation.
10. Personal data breaches
The processor notifies the controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach.
11. Deletion
On termination, the processor deletes the controller's account data no later than 30 days after termination. Accounting records are retained for 5 years under Danish bookkeeping law, a legal obligation within the meaning of Article 28(3)(g).
12. Audit
The processor makes available all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections.
13. Contact
14. Governing law and venue
This agreement is governed by Danish law. Venue is the controller's home court in Denmark.