Data Processing Agreement (DPA)
Appendix 1 to the Terms and Conditions
Last updated: 2026-03-25
1. Roles
- The Customer acts as Data Controller
- DK Cloud Solutions ApS acts as Data Processor
2. Subject Matter
The Data Processor processes personal data solely for the purpose of providing the cloud services described in the agreement.
3. Categories of Personal Data
Processing may include:
- Ordinary personal data
- Confidential or sensitive data, depending on the Customer's use of the Services
4. Instructions
The Data Processor shall process personal data only on documented instructions from the Data Controller.
5. Technical and Organizational Security Measures
The Data Processor has implemented security measures aligned with ISO/IEC 27001, including:
- Encryption of data at rest and in transit
- Access control and activity logging
- Security incident response procedures
- Regular risk assessments
- Employee confidentiality obligations and security training
6. Personal Data Breaches
In the event of a personal data breach:
- The Data Controller shall be notified without undue delay
- Relevant information shall be provided to enable regulatory notification
7. Subprocessors
An up-to-date list of subprocessors shall be made available. The Data Controller shall be informed of material changes.
8. Transfers to Third Countries
As a general rule, no transfers to third countries occur. Any transfer shall only take place in compliance with Chapter V of the GDPR.
9. Audit and Inspection Rights
The Data Controller is entitled to receive documentation demonstrating compliance, including:
- ISO/IEC 27001-aligned controls
- Relevant audit reports or certifications
On-site audits require reasonable prior notice and must not unreasonably interfere with operations.
10. Termination
Upon termination of the Services:
- Personal data shall be deleted or returned at the Data Controller's choice
- Deletion shall be documented upon request