Data Processing Addendum (DPA)

Last updated: 2025

This Data Processing Addendum ("DPA") supplements and forms part of the Nordcraft Terms of Service or another agreement between the Customer and Møller & Hansen EDB ApS, trading as Nordcraft, CVR 43652125, Æblehaven 15A, 2500 Valby, Denmark ("Nordcraft") (the "Agreement"). Nordcraft may be contacted at hello@nordcraft.com. By accepting the Agreement or using the Services, Customer enters into this DPA on behalf of itself and, where applicable, its authorized affiliates.

1. Definitions

Capitalized terms not defined herein shall have the meaning set forth in the Agreement.

"Applicable Data Protection Law" means the GDPR, the UK GDPR, the UK Data Protection Act 2018, and other data protection laws that apply to Nordcraft's processing of Covered Data under the Agreement. "GDPR" means Regulation (EU) 2016/679. "UK GDPR" has the meaning given in section 3(10) of the UK Data Protection Act 2018.

"Covered Data" means Personal Data processed by Nordcraft on behalf of Customer in connection with the Services. Covered Data does not include Personal Data for which Nordcraft determines the purposes and means of processing in its independent capacity as Controller.

"Customer's Controller" means, where the Customer acts as a Processor on behalf of a third party (e.g., an agency building a site for a client), the underlying Controller.

"Anonymous Data" means information derived from Covered Data that has been irreversibly anonymized so that no individual is identified or identifiable by means reasonably likely to be used.

"Special Categories of Personal Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation, as set out in Article 9 GDPR.

"Personal Data", "Data Subject", "Controller", "Processor", "Sub-processor", and "processing" have the meanings given under Applicable Data Protection Law. "EU SCCs" means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the ICO International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0.

2. Role of the Parties

The Parties acknowledge and agree that, for purposes of Applicable Data Protection Law:

Customer acts as the Data Controller, and Nordcraft acts as the Data Processor. To the extent Customer processes Covered Data on behalf of a Customer's Controller (e.g., an agency model), Customer acts as the Processor, and Nordcraft acts as a Sub-processor.

3. Processing Instructions

3.1 Instructions: Nordcraft shall process Covered Data only on Customer's documented instructions, including those in the Agreement, this DPA, and Customer's use and configuration of the Services, unless applicable law requires otherwise. Where legally permitted, Nordcraft will inform Customer before processing required by law. Nordcraft will promptly inform Customer if it believes an instruction infringes Applicable Data Protection Law.

4. Customer Obligations & Special Categories

4.1 Customer Responsibilities: Customer is responsible for the lawfulness, fairness, and transparency of its processing; the accuracy and quality of Covered Data; providing required notices; obtaining required authorizations; and issuing lawful instructions. Customer represents that it has all rights necessary for Nordcraft to process Covered Data as described in the Agreement and this DPA.

4.2 Restricted Data: The Services are not designed for protected health information subject to HIPAA, payment-card data subject to PCI DSS, or Special Categories of Personal Data. Customer shall not submit such data unless Nordcraft has expressly approved the processing in writing. Customer remains responsible for establishing an applicable legal basis and Article 9 condition and for implementing appropriate safeguards. Nothing in this Section excludes Nordcraft's responsibility for its own compliance with Applicable Data Protection Law.

5. Nordcraft Obligations

5.1 Confidentiality: Nordcraft shall ensure that its personnel authorized to process Covered Data are bound by strict obligations of confidentiality.

5.2 Security: Nordcraft shall implement and maintain appropriate technical and organizational measures (as detailed in Annex II) to protect Covered Data against unauthorized access, loss, or destruction.

5.3 Data Subject Rights and Compliance Assistance: Nordcraft will promptly forward to Customer any request from a Data Subject relating to Covered Data and, taking into account the nature of processing, provide reasonable technical and organizational assistance for Customer's response. Nordcraft will also provide reasonable assistance with security obligations, breach notifications, data protection impact assessments, prior consultations, and regulator inquiries, taking into account the nature of processing and information available to Nordcraft.

5.4 Security Incidents: Nordcraft shall notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Covered Data (a "Security Incident"). Nordcraft will provide information reasonably available to it that Customer needs to meet applicable notification duties and will provide updates as material information becomes available. Notification does not constitute an admission of fault or liability.

5.5 Return or Deletion: Following termination or expiry of the Services, Nordcraft will, at Customer's choice and subject to the functionality of the Services, return or delete Covered Data within thirty (30) days, unless applicable law requires retention. Covered Data in backups will be isolated from further processing and deleted through Nordcraft's ordinary backup lifecycle. Customer is responsible for exporting Covered Data before its account becomes unavailable.

5.6 Audits: Nordcraft will make available information reasonably necessary to demonstrate compliance, including available third-party reports or questionnaires. If that information is insufficient, Customer may conduct an audit no more than once per calendar year on at least thirty (30) days' notice, during normal business hours, in a confidential and non-disruptive manner, and at Customer's expense. These limits do not apply where a competent authority requires otherwise, following a Security Incident affecting Customer, or where Customer has reasonable evidence of material non-compliance. Customer shall ensure that any auditor is independent, qualified, and not a competitor of Nordcraft.

5.7 Assistance Costs: Nordcraft may charge reasonable fees, based on time and materials, for assistance beyond functionality and information ordinarily included with the Services, unless the assistance is required because of Nordcraft's breach of this DPA. Nordcraft will provide advance notice of material fees where reasonably practicable.

5.8 Liability and Mandatory Rights: Liability arising under this DPA is subject to the exclusions and limitations in the Agreement to the maximum extent permitted by law. Nothing in the Agreement or this DPA limits rights or liability that cannot lawfully be limited, including rights granted to Data Subjects under the EU SCCs or UK Addendum.

6. Sub-processors

6.1 General Authorization: Customer grants Nordcraft general authorization (and confirms it has the Customer's Controller's authorization) to engage third-party Sub-processors to assist in providing the Services.

6.2 Approved Sub-processors: The currently approved Sub-processors are listed in Annex III.

6.3 Notice and Objection: Nordcraft shall notify Customer by email or platform notification at least fourteen (14) days before a new Sub-processor begins processing Covered Data and will maintain an updated sub-processor notice. Customers may subscribe to email notifications of Sub-processor changes by sending a request to hello@nordcraft.com. Customer may object during that period on reasonable, documented data protection grounds. The Parties will work in good faith toward a commercially reasonable resolution. If no resolution is available, Customer may stop using and terminate only the affected part of the Services. Any refund is governed by the Agreement.

6.4 Sub-processor Terms and Responsibility: Nordcraft shall enter into a written agreement with each Sub-processor that imposes data protection obligations appropriate to the processing and no less protective in substance than the relevant obligations in this DPA. Nordcraft remains responsible to Customer for each Sub-processor's performance of those obligations.

7. Anonymous Data and Service Metrics

Nordcraft may generate and use operational metrics that do not contain Covered Data to operate, secure, support, and improve the Services. Nordcraft may also use Anonymous Data for analytics and service improvement only where the anonymization is irreversible and the information no longer constitutes Personal Data under Applicable Data Protection Law. Nordcraft will not attempt to re-identify Anonymous Data or disclose it in a form that could reasonably identify Customer or a Data Subject.

8. Data Location and International Transfers

8.1 Processing Locations: Covered Data may be processed in the EEA and in other locations where Nordcraft or its authorized Sub-processors operate, as described in this DPA. Nordcraft will not transfer Covered Data in violation of Applicable Data Protection Law.

8.2 Restricted Transfers: Where processing involves a transfer of Covered Data that requires a transfer mechanism under Chapter V GDPR or the UK GDPR, the Parties will apply the mechanism described in this Section. A Customer's access to Covered Data from its own location is not, by itself, treated as a transfer by Nordcraft to Customer under this DPA.

8.3 EU Restricted Transfers: Where Customer transfers Covered Data to Nordcraft in a manner subject to the EU SCCs, the EU SCCs are incorporated by reference and apply only to that restricted transfer. The official text adopted by Commission Implementing Decision (EU) 2021/914 applies without modification except for the selections and information permitted by the EU SCCs and specified below.

Module Two (Controller to Processor) applies where Customer is a Data Controller and Nordcraft is a Data Processor.

Module Three (Processor to Processor) applies where Customer acts as a Processor and Nordcraft acts as a Sub-processor.

Module Four applies only where Customer is a Processor exporting Covered Data to Nordcraft as a Controller and the conditions for Module Four are met. It does not apply merely because Customer accesses an EEA-hosted environment from outside the EEA.

8.4 Electronic Execution: Acceptance of the Agreement or this DPA constitutes signature and execution of the applicable EU SCCs and UK Addendum. Customer enters them on its own behalf and, where authorized, on behalf of its relevant affiliates.

8.5 Specific SCC Parameters: For the purposes of the Standard Contractual Clauses incorporated by reference under Section 8.3:

Docking Clause (Clause 7): The optional docking clause shall apply.

Sub-processors (Clause 9): Option 2 ("General written authorization") shall apply, subject to the 14-day advance notice period set forth in Section 6.3.

Redress (Clause 11): The optional independent redress mechanism language shall not apply.

Supervisory Authority (Clause 13): The competent supervisory authority will be determined in accordance with Clause 13 of the EU SCCs. Where Clause 13 designates the authority of the Member State in which the data importer is established, the authority is the Danish Data Protection Agency (Datatilsynet).

Governing Law (Clause 17): The EU SCCs are governed by the laws of Denmark.

Jurisdiction (Clause 18): The courts of Denmark have jurisdiction under Clause 18 of the EU SCCs, without limiting a Data Subject's rights under that clause.

Annexes and Parties: Annexes I, II, and III of this DPA complete the corresponding EU SCC annexes to the extent applicable. Customer is the data exporter, identified by the account and Agreement details supplied to Nordcraft. Møller & Hansen EDB ApS is the data importer, with the identity and contact details stated at the beginning of this DPA.

8.6 UK Restricted Transfers: Where a transfer is subject to the UK GDPR and requires an appropriate safeguard, the UK Addendum is incorporated into this DPA and applies with the applicable EU SCC module. The information in the Agreement and Annexes I through III completes the corresponding tables of the UK Addendum; neither party may end the UK Addendum solely because the ICO issues a revised approved addendum. References to the EU SCCs in this DPA include the UK Addendum where required by context.

8.7 Order of Precedence: For processing matters, the EU SCCs or UK Addendum prevail over this DPA to the extent of a conflict, this DPA prevails over the Agreement, and the Agreement otherwise remains in effect.

Annex I: Details of Data Processing

The following details describe the processing and, where applicable, complete Annex I of the EU SCCs. Processing occurs on a continuous basis or as initiated by Customer through its use of the Services. The subject matter and purpose are the provision, operation, security, support, and improvement of the Services in accordance with Customer's documented instructions.

DetailDescription
Categories of Data SubjectsEnd-users visiting Customer applications hosted on Nordcraft; Customer's employees, agents, or contractors using the Nordcraft platform.
Categories of Personal DataAccount and contact details; authentication and access information; technical and usage data such as IP address, device, browser, logs, and identifiers; and any form submissions, database content, files, prompts, or other Personal Data that Customer chooses to process through the Services.
Special Categories of Personal DataNot intended or authorized by default. Customer must comply with Section 4.2 before processing restricted data.
Processing OperationsCollection, transmission, hosting, organization, storage, retrieval, consultation, display, support, security, deletion, and other operations initiated by Customer or reasonably necessary to provide the Services. Transfers may occur continuously while the Services are used.
Duration of ProcessingFor the term of the Agreement and up to thirty (30) days afterward to permit export and deletion, subject to ordinary backup cycles and legally required retention as described in Section 5.5.

Annex II: Technical and Organizational Measures (TOMs)

Access Control: Access to production systems and Covered Data is restricted to authorized personnel and service providers based on operational need, using access-control and least-privilege principles. Personnel with access are subject to confidentiality obligations.

Transmission Security: Nordcraft uses HTTPS/TLS to protect Covered Data transmitted over supported public network connections.

System Protection: Nordcraft uses proportionate measures designed to protect the Services from unauthorized access and common network threats, including security capabilities supplied by its infrastructure providers.

Availability and Recovery: Nordcraft uses hosted infrastructure and operational recovery measures designed to support availability appropriate to the Services. Specific service levels apply only where expressly agreed in the Agreement.

Annex III: Authorized Sub-processors

Customer generally authorizes the following categories and providers to process Covered Data where the relevant service or feature is used. The exact contracting entity, processing location, and transfer safeguard may depend on Customer configuration and the provider's then-current service terms.

Sub-processorPurpose / ActivityEntity LocationSafeguard / Mechanism
Cloudflare, Inc.Edge CDN, DNS, WAF Security & Core InfrastructureEEA and other provider locationsAdequacy decision or contractual safeguards, as applicable
Amazon Web Services EMEA SARLAI Chat Bot Processing (Optional Feature)Provider locations, depending on feature configurationContractual safeguards, as applicable
Supabase Inc.Backend Database / Auth IntegrationSelected project region and other provider locationsAdequacy decision or contractual safeguards, as applicable
Stripe, Inc.Payment Processing & BillingEEA, UK, USA, and other provider locationsAdequacy decision or contractual safeguards, as applicable
Google Cloud EMEA LimitedAI Chat Bot Processing (Optional Feature)Provider locations, depending on feature configurationContractual safeguards, as applicable

International Transfers: Where a listed provider processes Covered Data in a country that is not recognized as adequate, Nordcraft will use an appropriate transfer mechanism required by Applicable Data Protection Law, such as the EU SCCs, UK Addendum, or an applicable adequacy framework.

Feature-specific providers process Covered Data only when the corresponding feature is enabled or used. Customer should not submit Personal Data to an optional AI feature unless it is authorized to do so and has assessed that use for its intended context.

Built in Nordcraft