Standard Contractual Clauses
This Data Processing Agreement forms the basis for the processing of personal data that Unioo performs on your behalf as a customer. The Data Processing Agreement is approved and takes effect when you register. This Data Processing Agreement is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”) in order to regulate Unioo's processing of personal data on your behalf as a customer.
1. Contents
- 2 Preamble
- 3 The rights and obligations of the controller
- 4 The processor acts according to instructions
- 5 Confidentiality
- 6 Security of processing
- 7 Use of sub-processors
- 8 Transfer of data to third countries or international organisations
- 9 Assistance to the controller
- 10 Notification of personal data breach
- 11 Erasure and return of data
- 12 Audit and inspection
- 13 The parties' agreement on other terms
- 14 Commencement and termination
- 15 Annex A Information about the processing
- 16 Annex B Sub-processors
- 17 Annex C Instruction pertaining to the processing of personal data
- 18 Annex D The parties' regulation of other subjects
2. Preamble
2.1 These Clauses set out the rights and obligations of the processor when processing personal data on behalf of the controller.
2.2 These Clauses have been designed to ensure the parties' compliance with Article 28(3) of Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
2.3 In the context of the provision of the processor's system in accordance with the Terms of January 2025, the processor processes personal data on behalf of the controller in accordance with these Clauses.
2.4 These Clauses shall take precedence over any similar provisions contained in other agreements between the parties.
2.5 Four annexes are attached to these Clauses and form an integral part of the Clauses.
- a. Annex A contains details about the processing of personal data, including the purpose and nature of the processing, type of personal data, categories of data subjects, and duration of the processing.
- b. Annex B contains the controller's conditions for the processor's use of sub-processors and a list of sub-processors authorized by the controller.
- c. Annex C contains the controller's instructions with regard to the processing of personal data, the minimum security measures to be implemented by the processor, and how audits of the processor and any sub-processors are to be conducted.
- d. Annex D contains provisions for other activities which are not covered by the Clauses.
2.6 The Clauses along with the annexes shall be retained in writing, including electronically, by both parties.
2.7 These Clauses shall not exempt the processor from obligations to which the processor is subject pursuant to the General Data Protection Regulation or other legislation.
3. The rights and obligations of the controller
3.1 The controller is responsible for ensuring that the processing of personal data takes place in compliance with the General Data Protection Regulation (see Article 24 of the Regulation), the applicable data protection provisions in other EU or Member State law, and these Clauses.
3.2 The controller has the right and obligation to make decisions about the purposes and means of the processing of personal data.
3.3 The controller shall be responsible, among other things, for ensuring that there is a legal basis for the processing of personal data that the processor is instructed to perform.
4. The processor acts according to instructions
4.1 The processor shall process personal data only on documented instructions from the controller, unless required to do so by Union or Member State law to which the processor is subject. Such instructions shall be specified in Annexes A and C. Subsequent instructions can also be given by the controller throughout the duration of the processing of personal data, but such instructions shall always be documented and kept in writing, including electronically, in connection with these Clauses.
4.2 The processor shall immediately inform the controller if instructions given by the controller, in the opinion of the processor, contravene the Regulation or the applicable data protection provisions in other EU or Member State law.
4.3 If the controller maintains the instruction despite the processor's notification, the controller shall indemnify and hold harmless the processor for any consequential liability for acting in accordance with the instruction. The processor is entitled not to execute the instruction if it would involve the processor acting in breach of obligations and requirements directly applicable to the processor.
5. Confidentiality
5.1 The processor shall grant access to the personal data being processed on behalf of the controller only to persons under the processor's authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only on a need-to-know basis. The list of persons to whom access has been granted shall be kept under periodic review. On the basis of this review, such access to personal data can be withdrawn if access is no longer necessary, and personal data shall consequently not be accessible anymore to those persons.
5.2 The processor shall, at the request of the controller, demonstrate that the concerned persons under the processor's authority are subject to the abovementioned confidentiality obligation.
6. Security of processing
6.1 Article 32 of the General Data Protection Regulation states that the controller and processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
6.2 The controller shall evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. Depending on their relevance, these measures may include:
- a. Pseudonymization and encryption of personal data
- b. The ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services
- c. The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
- d. A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
6.3 According to Article 32 of the Regulation, the processor shall – independently of the controller – also evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. For this purpose, the controller shall provide the processor with the necessary information to identify and assess such risks.
6.4 Furthermore, the processor shall assist the controller in ensuring compliance with the controller's obligations pursuant to Article 32 of the Regulation, by, inter alia, providing the controller with information concerning the technical and organizational security measures already implemented by the processor pursuant to Article 32 of the Regulation, along with all other information necessary for the controller to comply with its obligation under Article 32 of the Regulation.
6.5 If subsequently – in the controller's assessment – mitigation of the identified risks requires further measures to be implemented by the processor than those already implemented by the processor pursuant to Article 32 of the Regulation, the controller shall specify these additional measures to be implemented in Annex C.
7. Use of sub-processors
7.1 The processor shall meet the requirements specified in Article 28(2) and (4) of the General Data Protection Regulation in order to engage another processor (a sub-processor).
7.2 The processor shall therefore not engage another processor (a sub-processor) for the fulfillment of these Clauses without the prior general written authorization of the controller.
7.3 The processor has the controller's general authorization for the engagement of sub-processors. The processor shall inform in writing the controller of any intended changes concerning the addition or replacement of sub-processors with at least 14 days' notice, thereby giving the controller the opportunity to object to such changes before the engagement of the concerned sub-processor(s). Longer notice periods for specific sub-processing services can be specified in Annex B. The list of sub-processors already authorized by the controller can be found in Annex B.
7.4 Where the processor engages a sub-processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in these Clauses shall be imposed on that sub-processor by way of a contract or other legal act under EU or Member State law, providing in particular sufficient guarantees that the sub-processor will implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the Regulation.
7.5 The processor shall therefore be responsible for requiring that the sub-processor at least complies with the obligations to which the processor is subject pursuant to these Clauses and the Regulation.
7.6 A copy of such a sub-processor agreement and subsequent amendments shall – at the controller's request – be submitted to the controller, thereby giving the controller the opportunity to ensure that the same data protection obligations as set out in these Clauses are imposed on the sub-processor. Clauses on business-related issues that do not affect the legal data protection content of the sub-processor agreement shall not require submission to the controller.
7.7 If the sub-processor does not fulfill its data protection obligations, the processor shall remain fully liable to the controller for the performance of the sub-processor's obligations. This does not affect the rights of the data subjects under the Regulation, in particular those foreseen in Articles 79 and 82 of the Regulation, against the controller and the processor, including the sub-processor.
8. Transfer of data to third countries or international organizations
8.1 Any transfer of personal data to third countries or international organizations by the processor shall only occur on the basis of documented instructions from the controller and shall always take place in compliance with Chapter V of the Regulation.
8.2 If transfers of personal data to third countries or international organizations, which the controller has not instructed the processor to perform, are required under EU or Member State law to which the processor is subject, the processor shall inform the controller of that legal requirement prior to processing unless that law prohibits such information on important grounds of public interest.
8.3 Without documented instructions from the controller, the processor therefore cannot within the framework of these Clauses:
- a. Transfer personal data to a controller or processor in a third country or in an international organization
- b. Transfer the processing of personal data to a sub-processor in a third country
- c. Process the personal data in a third country
8.4 The controller's instructions regarding the transfer of personal data to a third country including, if applicable, the transfer mechanism under Chapter V of the Regulation upon which they are based, shall be set out in Annex C.6.
8.5 These Clauses shall not be confused with standard data protection clauses within the meaning of Article 46(2)(c) and (d) of the Regulation, and these Clauses cannot be relied upon by the parties as a transfer mechanism under Chapter V of the Regulation.
9. Assistance to the controller
9.1 Taking into account the nature of the processing, the processor shall assist the controller by appropriate technical and organizational measures, insofar as this is possible, in the fulfillment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the Regulation.
9.2 This means that the processor shall, insofar as this is possible, assist the controller in the controller's compliance with:
- a. The right to be informed when collecting personal data from the data subject
- b. The right to be informed when personal data have not been obtained from the data subject
- c. The right of access
- d. The right to rectification
- e. The right to erasure ('the right to be forgotten')
- f. The right to restriction of processing
- g. The notification obligation regarding rectification or erasure of personal data or restriction of processing
- h. The right to data portability
- i. The right to object
- j. The right not to be subject to a decision based solely on automated processing, including profiling
9.3 In addition to the processor's obligation to assist the controller pursuant to Clause 6.3, the processor shall furthermore, taking into account the nature of the processing and the information available to the processor, assist the controller in ensuring compliance with:
- a. The controller's obligation to without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority, the Data Protection Authority, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons
- b. The controller's obligation to without undue delay communicate the personal data breach to the data subject when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons
- c. The controller's obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a data protection impact assessment)
- d. The controller's obligation to consult the competent supervisory authority, the Data Protection Authority, prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk.
9.4 The parties shall define in Annex C the appropriate technical and organizational measures by which the processor is required to assist the controller as well as the scope and the extent of the assistance required. This applies to the obligations foreseen in Clause 9.1 and 9.2.
10. Notification of personal data breach
10.1 In case of any personal data breach, the processor shall, without undue delay after having become aware of it, notify the controller of the personal data breach.
10.2 The processor's notification to the controller shall, if possible, take place within 72 hours after the processor has become aware of the breach to enable the controller to comply with the controller's obligation to notify the personal data breach to the competent supervisory authority, cf. Article 33 of the Regulation.
10.3 In accordance with Clause 9.2.a, the processor shall assist the controller in notifying the personal data breach to the competent supervisory authority. This means that the processor shall assist in obtaining the following information which, pursuant to Article 33(3) of the Regulation, shall be stated in the controller's notification to the competent supervisory authority:
- a. The nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned
- b. The likely consequences of the personal data breach
- c. The measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
10.4 The parties shall define in Annex C all the elements to be provided by the processor when assisting the controller in the notification of a personal data breach to the competent supervisory authority.
11. Erasure and return of data
11.1 On termination of the provision of personal data processing services, the processor shall be under obligation to delete all personal data processed on behalf of the controller, unless Union or Member State law requires storage of the personal data.
12. Audit and inspection
12.1 The processor shall make available to the controller all information necessary to demonstrate compliance with Article 28 of the Regulation and these Clauses, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
12.2 Procedures applicable to the controller's audits, including inspections, of the processor and sub-processors are specified in Annexes C.7. and C.8.
12.3 The processor shall be required to provide the supervisory authorities, which pursuant to applicable legislation have access to the controller's and processor's facilities, or representatives acting on behalf of such supervisory authorities, with access to the processor's physical facilities on presentation of appropriate identification.
13. The parties' agreement on other terms
13.1 The parties may agree on other clauses concerning the provision of the personal data processing service, specifying e.g. liability, as long as these clauses do not contradict directly or indirectly these Clauses or prejudice the fundamental rights or freedoms of the data subject as provided for in the Regulation.
14. Commencement and termination
14.1 These Clauses shall become effective on the date of both parties' signature.
14.2 Both parties shall be entitled to require these Clauses to be renegotiated if changes to the law or inexpediency of these Clauses give rise to such renegotiation.
14.3 These Clauses shall apply for the duration of the provision of personal data processing services. For the duration of the provision of personal data processing services, these Clauses cannot be terminated unless other clauses governing the provision of personal data processing services have been agreed between the parties.
14.4 If the provision of personal data processing services is terminated, and the personal data is deleted or returned to the controller pursuant to Clause 11.1 and Annex C.4, these Clauses may be terminated by written notice by either party.
15. Annex A - Information about the processing
A.1. The purpose of the processor's processing of personal data on behalf of the controller
The purpose of the processor's processing of personal data on behalf of the controller is to allow the controller to use the processor's system ("the System"), which is owned and administered by the processor as described in the Terms of January 2025.
The System is targeted at associations that are controllers of the association data they process. In the System, associations have a tool to gather the board's work, documents, and communication, membership administration, including member payments, meeting notices, and other member communications. The System also enables the sharing of data between the association and the association's bank.
A.2. The processor's processing of personal data on behalf of the controller primarily concerns (the nature of the processing)
The System is hosted by the processor, who thus stores information that the controller enters and/or uploads into the System, but the processor can also process, import, disclose, and/or delete the information.
A.3. The processing includes the following types of personal data about data subjects
The information primarily concerns the association and the association's activities, but will naturally include personal data.
The processor processes the following information about the controller's management members: Contact information (e.g., name, address, telephone, email) and information contained in minutes or other uploaded material about the association, membership in the association, fees and charges, role in the board, information about board work and tasks, as well as copies of identification documents for KYC at the bank (health insurance card, driver's license, or passport), including CPR number.
The processor processes the following information about the controller's association members: Contact information (e.g., name, address, telephone, email) and information contained in minutes or other uploaded material about the association, membership in the association, fees and charges.
The processor processes the following information about other individuals who may appear in documents and communications that the controller stores in the System: Information appearing in minutes or other uploaded material about the association.
The processor processes the following information about employees of the controller: Contact information (e.g., name, address, telephone, email) and information contained in minutes or other uploaded material about the association.
The System is not designed or intended to process special categories of data (sensitive personal data), and the controller therefore undertakes not to register and/or upload sensitive personal data in the System.
A.4. The processing includes the following categories of data subjects
- The Controller's management members
- The controller's association members
- Other individuals who may appear in documents and communications that the controller stores in the System
- Employees of the controller
A.5. The processor's processing of personal data on behalf of the controller may begin after the entry into force of these Clauses. The processing has the following duration
The processing is not time-limited and continues until the agreement is terminated by either party. The processor will delete the information no later than 30 days after the end of the agreement.
16. Annex B - Sub-processors
B.1. Approved sub-processors
The processor's System depends on a number of subcontractors to operate. Such sub-processors are third-party providers within and outside the EU/EEA.
At the entry into force of these Clauses, the controller has approved the use of the following sub-processors.
NAME, ADDRESS (INCL. COUNTRY) AND CONTACT INFORMATION | DATA STORAGE | LEGAL BASIS OUTSIDE EU | DESCRIPTION OF PROCESSING |
---|---|---|---|
E-conomic A/S Gærtorvet 3, 1799 København V Denmark CVR: 29403473 Contact: [email protected] | Denmark | N/A | Accounting |
Criipto ApS Gammel Kongevej 3E 1610 København V Denmark CVR: 35142207 Contact: [email protected] | Denmark | N/A | Digital Signature |
OVH Groupe SAS 2 Rue Kellermann 59100 Roubaix France VAT-ID: 22 537407926 [email protected] | EU (Germany, France) | N/A | Email Solution |
OVH Groupe SAS 2 Rue Kellermann 59100 Roubaix France VAT-ID: 22 537407926 [email protected] | EU (Germany, France) | N/A | Server Solution |
SendGrid Inc. 1801 California Street Co 80202 USA [email protected] | EU (Ireland, Germany) | EU - DPF | Email Service |
Intercom R&D 18-21 St. Stephens Green Dublin 2 Ireland CVR: 522750 [email protected] | EU (Germany) | N/A | Customer Service Software |
LINK Mobility A/S Artillerivej 86 2300 København S Denmark CVR: 29821363 [email protected] | Denmark | N/A | SMS services |
Billwerk+ GmbH Lyoner Straße 14 60528 Frankfurt am Main Germany CVR: 103504 [email protected] | Denmark/EU (Germany) | N/A | Payment Solution |
Sendinblue SAS 106 boulevard Haussmann 75008 Paris France CVR: 498 018 298 [email protected] | EU (France–Germany) | N/A | Email service |
Herodesk ApS Voldbækvej 1 8220 Brabrand Denmark CVR: 44196972 [email protected] | Denmark | N/A | Customer Service Software |
HeySender ApS Njalsgade 76, 4 2300 København S Denmark CVR: 37304041 [email protected] | Denmark | N/A | Email Service |
B.2. Notice for approval of sub-processors
The general notice period follows from Clause 7.3 of the Clauses, i.e., 14 days.
17. Annex C - Instruction pertaining to the processing of personal data
C.1. The subject of/instruction for the processing
The processor's processing of personal data on behalf of the controller shall be carried out by the processor performing the following:
The processor may process personal data to the extent necessary to provide the service to the controller.
The controller instructs the processor to store the information on behalf of the controller and disclose it to third parties (e.g., the controller's bank) if the controller uses this function in the System.
The processor is also instructed to disclose contact information (name, telephone number, and email address) about the controller's board members to the bank that the controller has connected via the System.
The controller also instructs the processor to send out notifications by email or SMS on behalf of the controller, if the controller uses this function in the System.
In addition, the processor shall:
- If necessary, assist the controller with importing information to the System
- Store the data that the controller entrusts to the Processor in a cloud environment
- Access information to the extent necessary for support and maintenance
C.2. Security of processing
The security level should reflect: that, as a predominant rule, ordinary types of information are processed (and not sensitive information), but that copies of identification documents containing CPR numbers may also be processed for KYC requirements towards the controller's bank.
Data security is a high priority for the processor, who works seriously with data protection and is based on recognized security standards. The processor has implemented security measures to ensure data protection for all processed information. The processor also regularly conducts internal follow-ups regarding the adequacy and compliance with policies and measures.
The processor is then entitled and obliged to make decisions about which technical and organizational security measures should be implemented to establish the necessary (and agreed) level of security.
However, the processor shall – under all circumstances and as a minimum – implement the following measures, which have been agreed with the controller:
- The processor has set up measures for employees who can access the processed information. Different levels of access have been established, and if access is gained, this is logged.
- The processor regularly backs up data as a measure against physical breakdowns or technical incidents that might affect operations. These backups are distributed across different data centers to prevent physical breakdowns from having permanent consequences for the software's operation.
- It is a requirement that all data transmission takes place on an encrypted connection. Personal data is deleted effectively and securely when IT equipment is disposed of.
- Personal data is not stored in printed form. Employees of the processor may not print or extract information from the System.
- The processor will ensure that data processed in the System is encrypted ("at rest" and "in transit").
- The processor ensures that activities in the system are logged for general monitoring, security, and maintenance of systems that process the information. Logs are used to verify the uptime of the System and handle unexpected errors, etc.
C.3 Assistance to the controller
The processor shall, as far as possible – within the scope and extent described below – assist the controller in accordance with Clause 9.1 and 9.2 by implementing the following technical and organizational measures:
The controller has, via their user account, access to administer, extract, and delete information that is stored by the processor. If the processor receives requests from data subjects for insight into information processed for the controller, such requests will be forwarded to the controller.
The processor provides the necessary information to the controller regarding the technical and organizational security measures that the processor has implemented in accordance with Article 32 of the Regulation, and all other information necessary for the controller's compliance with its obligation under Article 32 of the Regulation.
The processor continuously monitors its systems and has established internal procedures and processes that ensure information to the controller in case of personal data security breaches.
The processor provides such other assistance than specifically mentioned above as the controller may request to fulfill the controller's obligations under points 9.1 and 9.2, including participation in the preparation of impact assessments. For such assistance, the processor is entitled to payment based on time spent. The fixed hourly rate is DKK 950 excluding VAT.
C.4 Storage period/erasure procedures
The controller has access to delete information in the controller's user account themselves.
Upon termination of the service regarding processing of personal data, the processor shall delete the personal data in accordance with Clause 11.1, unless the controller – after signing these Clauses – has changed the controller's original choice. Such changes shall be documented and kept in writing, including electronically, in connection with the Clauses.
C.5 Processing location
Processing of the personal data covered by these Clauses cannot, without the controller's prior written general approval, take place at locations other than those specified in Annex B for sub-processors.
Approved processing locations for the processor are the processor's address, as listed at the beginning of these Clauses.
C.6 Instruction on the transfer of personal data to third countries
At the entry into force of the data processing agreement, the controller has approved the use of the sub-processors mentioned in Annex B specifically for the processing described for each party.
If the controller does not, in these Clauses or subsequently, give documented instructions regarding the transfer of personal data to a third country, including, for example, by approving a sub-processor in a third country, the processor is not entitled, within the framework of these Clauses, to make such transfers.
For approved third-country transfers, the following applies:
- that it is ensured that an agreement on the transfer of personal data has been entered into in accordance with the European Commission's standard contractual clauses (EU Standard Contractual Clauses) or that transfers can take place on another basis, e.g., the EU-US Data Privacy Framework, and
- that supplementary measures (e.g., encryption) have been implemented for transfers of data to unsafe third countries, which are not considered to have an adequate level of protection under the GDPR.
C.7 Procedures for the controller's audits, including inspections, with the processing of personal data entrusted to the processor
When deemed necessary, the controller may conduct an audit of the processor.
The controller or a representative of the controller has the right to conduct inspections, including physical inspections, of the locations from which the processor carries out processing of personal data, including physical locations and systems used for or in connection with the processing. Such inspections can be carried out when the controller deems it necessary.
The controller shall notify the processor of its desire to conduct an inspection with 4 weeks' notice and with an indication of which specific matters are to be inspected. The controller and processor agree on the timing, theme, organization, duration, security, and confidentiality of the inspection.
Based on the results of the statement/inspection report, the controller is entitled to request the implementation of additional measures to ensure compliance with the General Data Protection Regulation, data protection provisions in other EU law or Member States' national law, and these Clauses.
The controller and processor agree that the processor will be compensated based on time spent for the assistance that the processor provides to the controller pursuant to Section 12 of the Clauses, including as described in this Annex C, point C7.
C.8 Procedures for audits, including inspections, of the processing of personal data entrusted to sub-processors
The processor shall continuously monitor that the selected subcontractors continue to meet the required technical and organizational measures and the required security level.
If the sub-processor prepares and publishes audit reports documenting and confirming that the sub-processor processes data in accordance with the obligations herein, the processor is not obligated to take further control measures.
Any costs incurred by the processor and sub-processors in connection with conducting a physical audit or inspection of the sub-processor shall be borne by the controller. The processor and any sub-processors are additionally entitled to compensation for the time spent on the inspection.
18. Annex D - The parties' regulation of other subjects
With reference to Clause 4.1, the controller acknowledges that to the extent approved sub-processors are used outside the EU, cf. Annex B, these will also be subject to local legislation. The data exporter will ensure that the information is adequately protected by the data importer.
The agreement, including contact information, can be found when you log into the system.