1.1 This agreement (the "Agreement") has been entered into between the user company (the "Data Controller") and Crediwire ApS (the "Data Processor" or "Crediwire"), each referred to as a "Party" and collectively the "Parties".
1.2 The Data Processor processes the types of personal data on behalf of the Data Controller that are listed in Annex 1, and which are necessary for the use of the Crediwire service. The personal data relates to the registered persons listed in Annex 1.
1.3 When the Data Controller transfer financial data, the Data Controller instructs the Data Processor to anonymize all data for use in statistics and benchmarking.
2.1 The Data Processor may only process personal data for purposes that are necessary for the Data Controller to use the Crediwire service.
3.1 To the extent that the Data Controller processes personal data in connection with the use of the Crediwire service, the Data Controller is responsible for the existence of a legal basis for processing, including that any consent is specific, freely given, unambiguous and informed. The Data Controller is obliged, at the Data Processor's request, to explain in writing and / or document the basis for processing.
3.2 The Data Controller warrants that the data subjects, which the personal data relates to, receive the required information about the processing of personal data. Crediwire's privacy policy, which may at any time be found at Crediwire's website (https://www.crediwire.com/privacy/privacy-policy).
4.1 The Data Processor may only process the personal data necessary for making the Crediwire-service available to the Data Controller in accordance with the terms and conditions, which may at any time be found at Crediwire's website (https://www.crediwire.com/privacy/terms-and-conditions) ("Terms and Conditions"). The Data Processor is obligated to comply with all data protection legislation in force from time to time.
4.2 The Data Processor must take all necessary technical and organizational security measures, including any additional measures, required to ensure that the personal data specified in sec. 1.2 and 1.3 is not accidentally or unlawfully destroyed, lost or impaired or brought to the knowledge of unauthorized third parties, abused or otherwise processed in a manner which is contrary to the Danish data protection legislation in force at any time.
4.3 The Data Processor must ensure that employees authorized to process the personal data have committed themselves to confidentiality or are under appropriate statutory obligations of confidentiality.
4.4 If so requested by the Data Controller, the Data Processor must state and/or document that the Data Processor complies with the requirements of applicable data protection legislation, including the requirement for documentation of data flows and written procedures/policies for the processing of personal data.
4.5 If the Data Processor process personal data in another EU/EEA member state, the Data Processor is obligated to comply with applicable legislation regarding security measures in the country in question.
4.6 The Data Processor must notify the Data Controller if there is a suspicion that data protection rules have been breached or other irregularities in connection with the processing of the personal data occur within 48 hours. If requested by the Data Controller, the Data Processor must assist the Data Controller with clarifying the extent of the security breach, including notifying the data subjects and the relevant authorities including the Danish Data Protection Agency and/or data subjects.
4.7 The Data Processor must notify the Data Controller if there is an interruption in operations of IT systems as soon as is reasonable.
4.8 The Data Processor must make available to the Data Controller all information necessary to demonstrate that the Processor have implemented the necessary technical and organizational security measures. At the expense of the Data Controller, the Data Processor allows for and agrees to contribute with input in connection with a yearly data protection audit by an independent third party. The Data Controller must compensate the Data Processor for time spend in relation to such audits. At the request of the Data Controller, the Data Processor will send a copy of the Data Processor’s latest ISAE 3402 audit report, which is updated yearly.
4.9 The Data Processor, or and any of its sub-data processors, must send requests and objections from data subjects to the Data Controller, for the Data Controller's further handling, unless the Data Processor is entitled to handle such requests and objections itself. If requested by the Data Controller, the Data Processor must assist the Data Controller in answering handling any such requests and/or objections.
5.1 The Data Processor may only transfer the personal data as stipulated in sec. 1.2 to sub-data processors with the written approval from the Data Controller. The Data Controller may only disclose personal data to third parties with the written approval from the Data Controller or if this follows from applicable legislation.
5.2 The Data Controller hereby grants the Data Processor a general written authorisation to engage Sub-processors. The Data Processor shall provide the Data Controller with at least one month’s prior written notice of any intended addition or replacement of a Sub-processor. The Data Controller may raise reasonable and relevant objections to such changes before they take effect.
5.3 When the Data Controller has approved that the Data Processor can use a sub-data processor the Data Processor must impose the same obligations on the sub-data processor as set out in this Agreement by entering into a separate data processing agreement with such sub data controller on terms identical to the terms of this Agreement ("back-to-back" terms).
5.4 If the personal data is transferred to sub-data processors outside EU/EEA, it must, in the data processing agreement, be stated that the data protection legislation applicable in the Data Controller's country applies to sub-data processors. If the receiving sub-data processor is established within the EU/EEA, it must be stated in the data processing agreement that the receiving EU country's specific statutory requirements regarding data processors, e.g. concerning demands for notification to national authorities must be complied with.
5.5 Where Personal Data is transferred to a Sub-processor in a country outside the EU/EEA, or to an international organisation, the Data Processor shall ensure that the transfer is made in accordance with Chapter V of the General Data Protection Regulation.
5.5.1 Where the recipient is covered by an adequacy decision adopted by the European Commission pursuant to Article 45 of the General Data Protection Regulation, the transfer may be based on that adequacy decision. This includes transfers made under the EU–US Data Privacy Framework, provided that the recipient is validly certified and the transfer falls within the scope of that certification.
5.5.2 Where no applicable adequacy decision exists, the Data Processor shall ensure that appropriate safeguards are in place pursuant to Article 46 of the General Data Protection Regulation. Such safeguards may include the applicable module of the European Commission’s Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with any supplementary measures required in light of the circumstances of the transfer.
5.5.3 The Data Processor shall monitor the continued validity of the applicable transfer mechanism. If the transfer mechanism ceases to provide a lawful basis for the transfer, or if the relevant Sub-processor can no longer comply with its obligations, the Data Processor shall without undue delay implement an alternative lawful transfer mechanism or suspend the affected transfer and inform the Data Controller.
5.6 At the time of signing this Agreement, the Data Processor engages the sub-data processors listed in Schedule 2.
6.1 The Parties liability are regulated by ordinary Danish rules on tort and damages. However, no Party is entitled to claim damages for indirect losses or consequential damage irrespective of whether these are suffered by the Data Controller, the Data Processor or a third party. Losses in relation to lost business potential, loss of profit, operating loss, loss of goodwill, loss of data, hereunder as part af recreation of data, will always be considered indirect losses or consequential damage.
6.2 The Data Processor's total liability to pay damages under the Agreement is capped in accordance with sec. 12 in the Terms and Conditions.
7.1 The Agreement becomes effective according to sec. 15 of the Terms and Conditions.
7.2 The Agreement will terminate in accordance with sec. 15 of the Terms and Conditions. However, the Data Processor remains subject to the obligations stipulated in this Agreement, as long as the Data Processor processes personal data on behalf of the Data Controller.
7.3 Upon termination of this Agreement the Data Controller is entitled to demand deletion or return all personal data unless retention of the personal data is prescribed by EU or national law. Personal data will be handed over on an ordinary machine-readable media determined by the Data Processor. Personoplysningerne udleveres på et af Databehandleren besluttet medie i et almindeligt læsbart format.
8.1 This Agreement is governed by Danish law.
8.2 Any claim or dispute arising from or in connection with this Agreement are subject to Danish law. Any claim or dispute must be brought before the City Court of Copenhagen.
For user-companies that transfer/disclose data to other companies (e.g. accountants, lawyers, or estates in bankruptcy):
Data subjects:
Types of personal data:
For user-companies transferring/disclosing their own data (SMEs):
Data subjects:
Types of personal data:
For user-companies only accessing other user-companies’ data (e.g. banks)
Data subjects:
Types of personal data:
Appendix 2 – Sub-data processors
Regarding the Data Processor's cloud-based infrastructure the Data Processor use Amazon Web Services (hereafter "AWS"), a branch of Amazon.com. The Data Processor has entered into a data processor agreement with AWS on standard terms.
Regarding automatic emails the Data Processor use MailChimp, a branch of Rocket Science Group company (https://mailchimp.com), established in USA. The Data Processor has entered into a data processor agreement with MailChimp on standard terms.
For email correspondence between the Data Processor and the Data Controller the Data Processor use Google Workspace, a Google LLC product (https://workspace.google.com), established in USA. The Data Processor has entered into a data processor agreement with Google LLC on standard terms.
The Data Processor has entered into a data processor agreement with Intercom, Inc. a Delaware corporation with offices at 55 2nd Street, 4th Fl., San Francisco, CA 94105, USA, (https://intercom.com), on standard terms for showing messages to the user based on their behavior and with the purpose of improving the user experience.