Data processing agreement
This is an English translation for convenience. If there is any conflict, the Danish version at digitalafdeling.mondaybrew.dk/databehandleraftale applies.
Effective from 2 October 2026.
01Parties and scope
The data processing agreement is part of the terms for the subscription "Your digital department" and for separate tasks agreed in connection with it. It applies when mondaybrew ApS, CVR 45 21 77 79 (the processor), processes personal data on behalf of the customer (the controller). The customer accepts the data processing agreement together with the terms.
The data processing agreement meets the requirements of Article 28 of the General Data Protection Regulation. In case of any discrepancy between the terms and the data processing agreement, the data processing agreement takes precedence in matters concerning the processing of personal data.
02Instructions
The processor only processes personal data on documented instructions from the controller. The terms, the data processing agreement and the tasks the customer approves on the task board make up the instructions.
The processor informs the controller immediately if, in the processor’s opinion, an instruction infringes data protection rules. The processor may only process the data for other purposes if EU law or Danish law requires it.
03Content of the processing
The purpose and nature of the processing, the types of personal data and the categories of data subjects are set out in Annex A.
04Confidentiality
Only persons who need access to carry out the tasks get access to the personal data. They are subject to a duty of confidentiality. Access is removed when it is no longer needed.
05Security
The processor implements appropriate technical and organisational measures under Article 32, so that the risk of the processing is sufficiently limited. The measures are set out in Annex C.
06Sub-processors
The controller gives general authorisation for the processor to use sub-processors. The sub-processors used today are listed in Annex B.
The processor gives notice of planned additions or replacements of sub-processors at least 14 days in advance on this page and on the customer’s task board. If the controller objects, the controller can cancel the subscription under the terms before the change takes effect.
The processor ensures that sub-processors are subject to data protection obligations that give equivalent protection, typically through the sub-processor’s own data processing terms. The processor is liable to the controller for the sub-processors’ fulfilment of their obligations under these terms and within the limitation of liability in the terms.
07Transfers to third countries
Some sub-processors process personal data outside the EU/EEA, primarily in the USA. Transfers only take place on a valid transfer basis, typically the EU-U.S. Data Privacy Framework or the European Commission’s standard contractual clauses. With the data processing agreement, the controller instructs these transfers.
08Assistance to the controller
As far as possible, the processor assists the controller in responding to requests from data subjects, with impact assessments and with prior consultation of the Danish Data Protection Agency (Datatilsynet). Extensive assistance is handled as a task on the board or by agreement against payment.
09Personal data breaches
The processor notifies the controller without undue delay and, where possible, no later than 48 hours after becoming aware of a personal data breach. The notification contains the information the processor has, so that the controller can assess the breach and, if necessary, report it to the Danish Data Protection Agency within 72 hours.
10Deletion and return
On termination, the processor deletes, no later than 30 days after termination, the personal data the processor holds from the customer outside the customer’s own systems, unless legislation requires it to be stored. Data in the customer’s own systems stays there, and the processor’s access is removed. Copies at sub-processors are deleted under their terms.
11Audit and inspection
The processor makes available the information needed to demonstrate compliance with Article 28 and the data processing agreement. With reasonable notice, the controller may have an independent auditor carry out an audit. The controller pays its own costs and the processor’s time spent on the audit.
12The controller’s obligations
The controller is responsible for having a legal basis for the processing and for informing the data subjects about it. The controller only gives access to the personal data the tasks require.
Special categories of personal data under Article 9, data about criminal offences and CPR numbers (Danish civil registration numbers) are not processed under the subscription unless this has been agreed in writing in advance.
13Duration and liability
The data processing agreement applies for as long as the processor processes personal data for the controller. The parties’ liability follows the terms, including the limitation of liability.
AAnnex A: The processing
Subject Description Purpose To deliver the tasks the customer orders under the subscription or separately, for example setup, changes, bug fixing, integration, automation, AI, testing and monitoring of the customer’s digital systems. Nature Access to, reading, changing, transferring and deleting data in the customer’s systems, including with AI tools that work directly in the systems. Data subjects The customer’s customers and leads, employees, users of the customer’s website and systems, and business partners. Data Ordinary personal data, for example name, email, phone, address, company, order and customer history, communication, technical identifiers such as IP address, cookie and click IDs, and other data held in the customer’s systems. Duration For as long as the subscription or the separate task runs, and until deletion under section 10. Location EU/EEA and the USA, see Annex B. BAnnex B: Sub-processors
Sub-processor Purpose Location Anthropic (Claude) AI models that carry out and assist the work USA OpenAI (ChatGPT and Codex) AI models that carry out and assist the work USA Google (Workspace) Email, calendar, meetings and file sharing EU/USA Vercel and associated database provider Running the task board and its database EU/USA Hetzner Online Server for automations Finland DigitalOcean via Cloudways Hosting of websites when they are on mondaybrew’s server account Germany The customer’s own suppliers, for example the customer’s CRM, webshop or hosting, are not sub-processors for mondaybrew. They have their own agreement with the customer.
CAnnex C: Security measures
- Access to the customer’s systems is through users, roles or keys that the customer can restrict and revoke.
- Access credentials are stored securely and are not shared with anyone other than those carrying out the task.
- Two-factor authentication is used on mondaybrew’s own accounts where the service supports it.
- Data is transferred over encrypted connections.
- The customer tests changes before they go live, see the terms.
- Access is removed and data is deleted on termination, see section 10.
Questions? Email kc@mondaybrew.dk.