Data Processing Agreement (DPA)
Last updated: 2026-07-02
This Data Processing Agreement (DPA) applies when Engii-Soft A/S processes personal data on behalf of a customer using EngiiCore. It forms an annex to our Terms of Service and is entered into under Article 28 of the General Data Protection Regulation (GDPR). This version is a draft and should be reviewed by a lawyer before signing.
Parties and roles
The customer is the data controller and Engii-Soft A/S is the data processor for the personal data the customer puts into the service. Engii-Soft processes the data only on the customer's behalf and on the customer's documented instructions.
Subject matter, duration, nature and purpose
The processing covers the activities necessary to provide EngiiCore and lasts for as long as the customer relationship exists. The purpose is to deliver the service's features (e.g. project, time, order and invoice handling) to the customer.
Categories of personal data and data subjects
The processing may cover ordinary personal data about the customer's staff, customers and contacts (e.g. name, contact details, job title, and time and task data). The customer must not enter special-category (sensitive) personal data unless otherwise agreed in writing.
Processing on instructions
Engii-Soft processes personal data only on the customer's documented instructions, including these terms, unless EU or Danish law requires otherwise. Engii-Soft informs the customer if, in its view, an instruction infringes data-protection law.
Confidentiality
Engii-Soft ensures that the persons processing the personal data have committed to confidentiality or are under an appropriate statutory duty of confidentiality.
Security (Article 32)
Engii-Soft implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk — including [encryption, access control, backup and logging; to be specified].
Sub-processors
The customer gives a general authorisation for Engii-Soft to use sub-processors. Our current sub-processors are listed at [list/URL]. We impose the same data-protection obligations on sub-processors as in this agreement and remain liable for their processing. For any replacement or addition we give the customer reasonable notice so the customer can object.
Assistance with data-subject rights
Engii-Soft assists the customer, to a reasonable extent, in responding to requests from data subjects exercising their rights (access, rectification, erasure, etc.).
Personal data breach
Engii-Soft notifies the customer without undue delay — and no later than [48 hours] after becoming aware — of a personal data breach, and assists with the information the customer needs to meet its obligations.
Assistance with impact assessments
Engii-Soft assists the customer with data-protection impact assessments (DPIAs) and prior consultation of the supervisory authority, to the extent relevant to the processing.
Transfers to third countries
Personal data is transferred to countries outside the EU/EEA only on a valid transfer basis, e.g. the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
Audit and inspection
Engii-Soft makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections. This may be satisfied through, e.g., recognised audit reports [e.g. ISO 27001 / ISAE 3402, if applicable].
Deletion and return
On termination of the service, Engii-Soft deletes or returns all personal data at the customer's choice and deletes existing copies, unless EU or Danish law requires continued storage.
Liability and precedence
Liability is governed by the Terms of Service. In case of conflict between this DPA and the Terms of Service, this DPA prevails as regards the processing of personal data.
Contact
Questions about this Data Processing Agreement can be directed to [email].