Data Processing Agreement

Standard contractual clauses

(January 2020 – Openframe revision September 2026)

pursuant to Article 28(3) of Regulation (EU) 2016/679 (the General Data Protection Regulation) concerning the Processor’s processing of personal data

This English version is a convenience translation prepared using the terminology of the Danish Data Protection Agency’s standard contractual clauses under GDPR Article 28(8) and established international data-processing agreement practice. It is intended to preserve the legal effect of the Danish text and is not a word-for-word translation. In the event of any conflict or ambiguity, the Danish version shall prevail.

between

the Customer

hereinafter the "Controller"

and

Openframe ApS
CVR 42049581
Nannasgade 28,
2200 Copenhagen N
Denmark

hereinafter the "Processor"

each a "Party" and together the "Parties"

HAVE AGREED the following standard contractual clauses (the “Clauses”) in order to ensure compliance with the GDPR and to safeguard the privacy and fundamental rights and freedoms of natural persons.

Contents

  1. Preamble

  2. Rights and obligations of the Controller

  3. The Processor acts on documented instructions

  4. Confidentiality

  5. Security of processing

  6. Use of sub-processors

  7. Transfers to third countries or international organisations

  8. Assistance to the Controller

  9. Notification of a personal data breach

  10. Erasure and return of data

  11. Audit, including inspection

  12. The Parties’ agreement on other matters

  13. Commencement and termination

  14. Contact persons

  15. Fees for assistance under these Clauses

Annex A – Details of the processing

Annex B – Sub-processors

Annex C – Instructions regarding the processing of personal data

Annex D – Other terms agreed by the Parties

2. Preamble

These Clauses set out the Processor’s rights and obligations when processing personal data on behalf of the Controller.

These Clauses are designed to ensure the Parties’ compliance with Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”).

In connection with the provision of Openframe’s SaaS platform and related services under the Parties’ principal agreement (the “Principal Agreement”), the Processor processes personal data on behalf of the Controller in accordance with these Clauses.

The Clauses shall take precedence over any corresponding provisions in other agreements between the Parties. Commercial terms, including fees, termination and limitation of liability, are governed by the Principal Agreement and Annex D, provided they do not contradict these Clauses or prejudice the rights of data subjects.

Four annexes are attached to these Clauses and form an integral part of them.

Annex A – contains further details of the processing, including its purpose and nature, the types of personal data, the categories of data subjects and the duration of the processing.

Annex B – sets out the Controller’s conditions for the Processor’s use of sub-processors and a list of sub-processors authorised by the Controller.

Annex C – contains the Controller’s instructions for the Processor’s processing of personal data, a description of the minimum security measures to be implemented by the Processor, and how supervision of the Processor and any sub-processors is to be carried out.

Annex D – contains provisions concerning other matters not covered by these Clauses.

The Clauses and the annexes shall be retained in writing, including electronically, by both Parties.

These Clauses do not relieve the Processor of obligations imposed on the Processor by the GDPR or any other applicable law.

3. Rights and obligations of the Controller

The Controller is responsible for ensuring that the processing of personal data is carried out in accordance with the GDPR (see Article 24), data-protection provisions in other Union law or in the national law of the Member States1, and these Clauses.

The Controller has the right and the obligation to decide the purpose(s) and the means of the processing of personal data.

The Controller is responsible, among other things, for ensuring that there is a lawful basis for the processing which the Processor is instructed to carry out. The Controller is further responsible for informing data subjects and for the content of the personal data that the Controller and its users enter into the platform, cf. Annex D.

4. The Processor acts on documented instructions

The Processor may process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject. Those instructions shall be specified in Annexes A and C. Subsequent instructions may also be given by the Controller while the processing is taking place, but they must always be documented and retained in writing, including electronically, together with these Clauses. A subsequent instruction that would change the platform’s standard functionality, security level or sub-processors is binding only if accepted by the Processor in writing. The Processor may make such acceptance conditional on a reasonable additional fee and implementation period, cf. Clause 16 and Annex D.

The Processor shall immediately inform the Controller if, in the Processor’s opinion, an instruction infringes the GDPR or data-protection provisions of other Union or Member State law. Until the Controller has provided further written clarification, the Processor is entitled to refrain from carrying out the disputed instruction, and such refrainment shall not constitute a breach.

5. Confidentiality

The Processor shall grant access to personal data processed on behalf of the Controller only to persons who are subject to the Processor’s instructions, who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only to the extent necessary. The list of persons who have been granted access shall be reviewed on an ongoing basis. On the basis of that review, access shall be withdrawn if it is no longer necessary, and the personal data shall thereafter no longer be accessible to those persons.

Upon request from the Controller, the Processor shall be able to demonstrate that the persons who are subject to the Processor’s instructions are bound by the confidentiality obligation referred to above.

6. Security of processing

Article 32 of the GDPR provides that the Controller and the Processor shall, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk. The Controller shall assess the risks to the rights and freedoms of natural persons posed by the processing and implement measures to mitigate those risks. Depending on their relevance, such measures may include:

  • pseudonymisation and encryption of personal data;

  • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

  • the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident; and

  • a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

Pursuant to Article 32, the Processor shall also — independently of the Controller — assess the risks to the rights of natural persons posed by the processing and implement measures to mitigate those risks. For that assessment, the Controller shall provide the Processor with the information necessary to identify and assess such risks.

In addition, the Processor shall assist the Controller in complying with the Controller’s obligations under Article 32 by, among other things, making available the information necessary regarding the technical and organisational security measures already implemented by the Processor under Article 32, and any other information required for the Controller’s compliance with Article 32. If, in the Controller’s assessment, addressing the identified risks requires measures beyond those already implemented by the Processor, the Controller shall specify those additional measures in Annex C. The Processor is not obliged to implement additional measures that would change the agreed service or entail unreasonable cost, unless the Parties so agree and the Controller bears the associated costs.

7. Use of sub-processors

The Processor shall comply with the conditions referred to in Article 28(2) and (4) of the GDPR in order to engage another processor (a sub-processor).

The Processor shall therefore not engage a sub-processor for the purpose of these Clauses without the Controller’s prior general written authorisation.

The Processor has the Controller’s general authorisation to use sub-processors. The Processor shall inform the Controller in writing of any intended changes concerning the addition or replacement of sub-processors at least 14 days in advance, thereby giving the Controller the opportunity to object to such changes before the relevant sub-processor(s) is/are used. A longer notice period for specific processing activities may be set out in Annex B. The list of sub-processors already authorised by the Controller appears in Annex B. The legal effect of an objection is exclusively governed by Annex B.2.

Where the Processor engages a sub-processor for carrying out specific processing activities on behalf of the Controller, the Processor shall, by way of a contract or other legal act under Union or Member State law, impose on that sub-processor the same data-protection obligations as those set out in these Clauses, in particular providing sufficient guarantees that the sub-processor will implement the technical and organisational measures in such a manner that the processing will meet the requirements of these Clauses and the GDPR.

The Processor is therefore responsible for requiring that the sub-processor as a minimum complies with the Processor’s obligations under these Clauses and the GDPR. Sub-processor agreement(s) and any subsequent amendments shall, at the Controller’s request, be provided in copy to the Controller, so that the Controller can verify that equivalent data-protection obligations have been imposed. Provisions on commercial terms that do not affect the data-protection content of the sub-processor agreement need not be provided. The Processor may redact or withhold commercial terms and security information that are subject to confidentiality vis-à-vis the sub-processor, provided that the data-protection content is apparent.

In its agreement with the sub-processor, the Processor shall include the Controller as a third-party beneficiary in the event of the Processor’s insolvency, so that the Controller may step into the Processor’s rights and enforce them against sub-processors, for example by instructing the sub-processor to erase or return the personal data. This obligation applies to the extent the relevant sub-processor’s standard terms make such a third-party beneficiary clause reasonably practicable. Where the sub-processor is a hyperscale cloud provider whose terms do not permit a third-party beneficiary, the Processor’s obligation is limited to ensuring a contractual arrangement that otherwise satisfies Article 28(4).

If the sub-processor fails to fulfil its data-protection obligations, the Processor remains fully liable to the Controller for the performance of the sub-processor’s obligations. This is without prejudice to the rights of data subjects under the GDPR, in particular Articles 79 and 82, vis-à-vis the Controller and the Processor, including the sub-processor.

8. Transfers to third countries or international organisations

Any transfer of personal data to a third country or an international organisation may be carried out by the Processor only on the basis of documented instructions from the Controller and shall always take place in accordance with Chapter V of the GDPR.

If a transfer of personal data to a third country or an international organisation which the Processor has not been instructed to carry out is required by Union or Member State law to which the Processor is subject, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

Without documented instructions from the Controller, the Processor may not, within the scope of these Clauses:

  • transfer personal data to a controller or a processor in a third country or to an international organisation;

  • entrust the processing of personal data to a sub-processor in a third country; or

  • process the personal data in a third country.

The Controller’s instructions regarding transfers of personal data to a third country, including the applicable transfer tool under Chapter V of the GDPR, shall be set out in Annex C.6.

These Clauses are not to be confused with standard contractual clauses as referred to in Article 46(2)(c) and (d) of the GDPR, and these Clauses cannot in themselves constitute a basis for transfers of personal data as referred to in Chapter V of the GDPR.

9. Assistance to the Controller

Taking into account the nature of the processing, the Processor shall, as far as possible, assist the Controller by appropriate technical and organisational measures in fulfilling the Controller’s obligation to respond to requests for the exercise of data subjects’ rights laid down in Chapter III of the GDPR. This means that the Processor shall, as far as possible, assist the Controller in ensuring compliance with:

  • the obligation to provide information when personal data are collected from the data subject;

  • the obligation to provide information where personal data have not been obtained from the data subject;

  • the right of access;

  • the right to rectification;

  • the right to erasure (“right to be forgotten”);

  • the right to restriction of processing;

  • the obligation to notify in connection with rectification or erasure of personal data or restriction of processing;

  • the right to data portability;

  • the right to object; and

  • the right not to be subject to a decision based solely on automated processing, including profiling.

In addition to the Processor’s obligation to assist the Controller pursuant to Clause 6, third paragraph, the Processor shall, taking into account the nature of the processing and the information available to the Processor, also assist the Controller with:

  • the Controller’s obligation to notify a personal data breach to the competent supervisory authority, the Danish Data Protection Agency (Datatilsynet), without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons;

  • the Controller’s obligation to communicate a personal data breach to the data subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons;

  • the Controller’s obligation to carry out, prior to the processing, an assessment of the impact of the envisaged processing operations on the protection of personal data (a data protection impact assessment); and

  • the Controller’s obligation to consult the competent supervisory authority, Datatilsynet, prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the Controller to mitigate the risk.

The Parties shall specify in Annex C the necessary technical and organisational measures by which the Processor is to assist the Controller, and the scope and extent of such assistance. This applies to the obligations following from Clauses 9.1 and 9.2. Assistance going beyond the platform’s ordinary self-service functionality shall be charged in accordance with Clause 16, unless the assistance is solely caused by the Processor’s breach of these Clauses.

10. Notification of a personal data breach

The Processor shall notify the Controller without undue delay after becoming aware that a personal data breach has occurred.

The Processor’s notification to the Controller shall, where feasible, be made no later than 24 hours after the Processor has become aware of the breach, so that the Controller can comply with its obligation to notify the personal data breach to the competent supervisory authority, cf. Article 33 of the GDPR.

In accordance with Clause 9.2(a), the Processor shall assist the Controller in notifying the breach to the competent supervisory authority. This means that the Processor shall assist in providing the following information, which according to Article 33(3) must be included in the Controller’s notification of the breach:

  • the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

  • the likely consequences of the personal data breach; and

  • the measures taken or proposed to be taken by the Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

The Parties shall specify in Annex C the information that the Processor is to provide in connection with its assistance to the Controller in relation to the Controller’s obligation to notify a personal data breach to the competent supervisory authority.

11. Erasure and return of data

Upon termination of the services relating to the processing of personal data, the Processor shall erase all personal data that have been processed on behalf of the Controller and confirm to the Controller that the data have been erased, unless Union or Member State law requires storage of the personal data. Prior to erasure, the Controller shall have access to export data as set out in Annex C.4. The Processor is not obliged to return data in another format or by way of a manual extract unless the Parties so agree and the Controller bears the costs pursuant to Clause 16.

12. Audit, including inspection

The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR and these Clauses, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

The procedures for the Controller’s audits, including inspections, of the Processor and sub-processors are set out in further detail in Annexes C.7 and C.8.

The Processor shall grant supervisory authorities which, under applicable law, have access to the Controller’s or the Processor’s facilities, or representatives acting on behalf of such authorities, access to the Processor’s physical facilities upon due identification.

13. The Parties’ agreement on other matters

The Parties may agree other terms concerning the service relating to the processing of personal data, for example as regards liability, provided that such other terms do not directly or indirectly contradict these Clauses or prejudice the fundamental rights and freedoms of the data subject under the GDPR.

14. Commencement and termination

The Clauses enter into force at the earliest of: (a) the Controller’s acceptance of the Principal Agreement to which these Clauses are annexed; (b) the Controller’s written acceptance of the Clauses; or (c) the Controller’s first use of the platform. Use of the platform constitutes acceptance of the Clauses.

Either Party may require the Clauses to be renegotiated if legislative changes or inadequacies in the Clauses give rise thereto.

The Clauses remain in force for as long as the service relating to the processing of personal data continues. During that period the Clauses may not be terminated unless other terms governing the provision of the service relating to the processing of personal data are agreed between the Parties.

If the provision of the services relating to the processing of personal data ceases, and the personal data have been erased or returned to the Controller in accordance with Clause 11.1 and Annex C.4, the Clauses may be terminated by written notice by either Party.

15. Contact persons of the Controller and the Processor

The Controller (the Customer) shall designate a contact person at the commencement of the agreement. Until otherwise notified, the Processor may contact the person named in the Principal Agreement or the administrator user designated by the Controller in the platform.

The Parties shall keep each other informed of changes regarding contact persons.

The Processor may be contacted as follows:

Name: Jesper Ring

Title: CEO

Telephone: +45 5077 8840

Email: jr@openframe.org / info@openframe.org

16. Fees for assistance under these Clauses

The Processor is entitled to separate remuneration on a time-spent basis for assistance that does not form part of the ordinary operation and maintenance of the platform, including in relation to Clauses 6 (third paragraph), 7, 9, 10, 11 and 12 and Annexes C.3, C.4, C.7 and C.8. Fees shall be calculated in accordance with the Processor’s consultancy rates from time to time, subject to a minimum of one hour per request, unless otherwise agreed in the Principal Agreement.

The Processor shall not charge for assistance that is solely necessitated by the Processor’s breach of these Clauses, including notification of a personal data breach caused by the Processor.

Where a request is estimated to exceed two hours’ work, the Processor may make performance conditional on the Controller’s prior written acceptance of an estimate. If acceptance is not given, the Processor is not obliged to carry out the work, other than that which the GDPR mandatorily requires.

Annex A – Details of the processing

A.1. Purpose of the Processor’s processing of personal data on behalf of the Controller

The purpose is to provide Openframe’s SaaS platform and related services so that the Controller, on its documented instructions, can collect, store, structure, assess, calculate, document, share and report information concerning construction projects, buildings, portfolios and sustainability matters, including (without limitation) certification, ESG and EU Taxonomy reporting, and follow-up during operations.

A.2. Nature of the processing

The processing consists of hosting, storage, display, search, logging, access management, calculation, export, notification and disclosure to users to whom the Controller has granted access, as well as technical support upon request. The processing takes place in a multi-tenant environment in which the Controller’s data are logically segregated from other customers’ data.

A.3. Types of personal data

Ordinary personal data, to the extent they appear in the platform, typically:

(a) User and profile data: name, email address, telephone number, title, organisation, role and access rights.

(b) Project, building and portfolio data entered by users, including documentation, assessments, calculation inputs, comments and free text.

(c) Technical log data relating to use of the platform: timestamps, actions, user identity and, where relevant, IP address and browser information, to the extent processed in order to provide and secure the service on behalf of the Controller.

The processing is not intended to include Danish civil registration numbers (CPR numbers), data relating to criminal convictions and offences, or special categories of personal data under Article 9. If such data are nevertheless uploaded, Annexes C.1 and D.3 apply.

A.4. Categories of data subjects

(a) Employees, consultants and other users of the Controller.

(b) Individuals at the Controller’s business partners whom the Controller invites, including (without limitation) advisers, contractors, facilities-management providers, certification bodies, investors and public-authority contacts.

(c) Other natural persons whose data the Controller or its users enter in documents or free-text fields. The Processor has no obligation to identify such persons.

A.5. Duration of the processing

The processing may commence upon the entry into force of these Clauses. It continues for the term of the Principal Agreement and thereafter for the period set out in Annex C.4, including the backup cycle and any legally required retention.

Annex B – Sub-processors

B.1. Authorised sub-processors

Upon the entry into force of these Clauses, the Controller has authorised the use of the following sub-processors:

NameCompany / VAT no.AddressDescription
VNTRS consulting AB—Göransgatan 63, 112 38 Stockholm, SwedenTechnical development of the Openframe platform and related support, to the extent access to personal data is granted.
Google Cloud (Google Ireland Limited / Google Cloud EMEA Limited, as applicable, with Google LLC as a sub-processor of the sub-processor)IE 6388047V / DK branch 28866984Gordon House, Barrow Street, Dublin 4, Ireland / Sankt Petri Passage 5, 2., 1165 Copenhagen KStorage of data, including files and databases; hosting and operation of the web application and background processes. Processing is configured to data centres in the EU/EEA. Used for platform.openframe.org.
Amazon Web Services, Danish branch of Amazon Web Services EMEA SARL, LuxembourgDK branch 39009323Lyskær 3 C, 1 tv, 2730 Herlev, DenmarkStorage of data, including files and databases; hosting and operation of the web application and background processes. Processing is configured to data centres in the EU/EEA. Used for app.openframe.org and backup services.

Sub-processors that process personal data solely where Openframe acts as an independent controller (for example CRM, billing, product analytics and Openframe’s own IT operations) are not sub-processors under these Clauses, cf. Annex D.1.

The Processor may update the list in accordance with B.2. A current list may also be made available in the platform or at a URL designated by the Processor.

B.2. Notice of and objection to sub-processors

The Processor shall notify the Controller in writing, including by email to the designated contact person or by notice in the platform, at least 14 days before a new or replacement sub-processor is put into use.

The Controller may object only if the objection is in writing, is based on concrete and legitimate data-protection grounds, and is received before expiry of the notice period. Failure to object constitutes authorisation.

A timely objection does not oblige the Processor to refrain from engaging the sub-processor. The Processor shall discuss the objection in good faith. If the Processor cannot accommodate the objection without unreasonable cost, delay or degradation of the service, the Controller’s sole remedy is to terminate the Principal Agreement on 30 days’ written notice, without any claim for damages, compensation or refund of fees already due or prepaid for the then-current period. The Processor is not liable in damages by reason of a sub-processor being engaged after notice has been given.

Replacement of a sub-processor with an affiliated entity, or with a provider performing the same function within the EEA with equivalent guarantees, may be notified on 7 days’ notice.

Annex C – Instructions regarding the processing of personal data

C.1. Subject matter / instructions

The Processor’s processing of personal data on behalf of the Controller consists of the following.

The Processor provides the digital SaaS platform Openframe, including the modules Openframe Build, Openframe In Use, Openframe Portfolio and any other modules to which the Controller subscribes from time to time. The platform is used to manage processes, communications, assessments, calculations, certification, ESG and Taxonomy documentation and other documentation, based on data uploaded and entered by the Controller and its invited users.

The Controller itself invites users from its own and other organisations to each project, building or portfolio, and instructs each user to work with the agreed data. The Controller is responsible for instructing all users as to how data are to be processed, which data may be uploaded and processed, and with whom they may be shared.

The Controller’s users access the platform themselves via a browser using their own usernames and passwords. The Processor does not access project data of its own motion unless requested by the Controller or the Controller’s invited users through Openframe ApS’ support function. The Processor may also access data to the extent necessary to deliver, operate, troubleshoot and secure the platform, including in the event of a security incident, and to comply with legal requirements. Such access is logged where technically and proportionately feasible.

Personal data

Data may take the form of profile data for each user, uploaded documents and files, and entries in free-text fields.

Profile data

For each user, at least an email address is registered and used as username. That username may not be changed, as it is the Controller’s requirement to be able to identify a user’s actions in each project. A user may voluntarily provide name, telephone number, address, title and organisation.

The Controller instructs users in the proper handling of these personal data. In reports and log files the user shall be identifiable by email address (or by name if entered), so that it is recorded who performed the relevant entry or action.

Other profile data shall be available to other users in a given project, or to the Controller’s staff with rights thereto, but shall be capable of being erased or amended if the user so requests.

A user’s contact and profile data shall be erased in the production environment without undue delay following documented instructions from the Controller, typically by contacting info@openframe.org. The Processor shall acknowledge erasure by email. Name and email address may continue to appear in the project history and logs so that actions can be attributed during the life of the project. Those records are erased only when the project is erased in accordance with C.4.

Uploaded documents and files

Users may freely upload documents and files, and the Controller instructs users in the proper handling of personal data in that connection. Users may not themselves erase uploaded documents and files, as these must remain available in the project for documentation purposes, but the Controller may instruct the Processor to erase specific documents and files.

Uploaded documents, files and other project data are erased when the project is erased in accordance with C.4. The Controller may also instruct the Processor to erase specific documents and files.

Free-text entries

Users may freely enter personal data in free-text fields in the platform. The Controller instructs users in the proper handling of personal data in that connection. Users shall, via the project’s designated administrator or equivalent role, themselves be able to erase and amend text in free-text fields so that the new or corrected text appears in reports going forward from the time of correction. Entries shall remain visible in log files.

Free-text input is erased when the project is erased in accordance with C.4, unless the Controller’s administrator has previously amended or erased the text in the platform. History and log files follow C.4.

Special categories of personal data

Openframe ApS is not to process special categories of personal data for the Controller. The Controller is responsible for instructing invited users in the proper handling of personal data. The Controller warrants that no CPR numbers, special categories of personal data or data relating to criminal convictions and offences will be uploaded, unless the Parties have entered into a written addendum. If this is breached, the Processor may, without liability, erase or block the relevant data and/or file.

Platform updates

The Processor is instructed to inform the Controller and users of new features or updates to the platform that may affect which data are processed and how they are processed. Such information may be given, for example, by email to users. All users shall be informed of this through a user agreement when they create their profile on the platform.

The Processor shall have formal procedures to ensure that updates are assessed and implemented within a reasonable time.

For critical security updates, the Processor shall have procedures ensuring that they can, so far as possible, be implemented within 48 hours.

Artificial intelligence and automated processing

The Processor may apply automated processing, including machine learning and AI functionality forming part of the agreed service, solely in order to deliver, secure and improve the functions to which the Controller has access. The customer’s personal data shall not be used to train general or third-party models. Aggregated and irreversibly anonymised data may be used for product development, cf. Annex D.5.

C.2. Security of processing

The security level shall reflect the following.

The service processes personal data. The service shall be delivered with a security level that minimises the risk of personal data being misused or of data subjects otherwise having their rights infringed. The processing nevertheless concerns only limited personal data about the data subjects, and the overall volume of personal data is limited. Special categories of personal data, data relating to criminal convictions and offences, and data such as CPR numbers are not collected. The collected data are assessed to be capable of misuse only to a very limited degree. It is important that personal data are not freely accessible, that access to the platform is protected against unauthorised access, and that data in transit are protected so far as possible.

The Processor is thereafter entitled and obliged to decide which technical and organisational security measures are to be implemented in order to establish the necessary (and agreed) security level.

The Processor shall in any event, as a minimum, implement the following measures agreed with the Controller:

  • Users of the Openframe platform have access only to their own data and to data necessary for the performance of their tasks.

  • All passwords registered in the platform are stored and transmitted in encrypted form or replaced by a hash.

  • All communication between users and Openframe’s systems is encrypted using HTTPS (TLS).

  • The Openframe platform uses a verified certificate.

  • Access to personal data is limited to Processor staff for whom it is necessary.

  • The Processor’s own staff access personal data only by means of personal passwords or keys.

  • Data are stored on Google Cloud or Amazon Web Services (AWS) secured cloud platforms in the EU.

  • Data at rest are encrypted by the cloud sub-processor using its standard encryption.

  • Backups are taken in accordance with the Processor’s backup policy. Backups are stored within the EEA unless C.6 applies.

  • The Processor applies access control on a need-to-know basis, and multi-factor authentication is made available where that function forms part of the agreed service.

Any additional measures that the Controller may wish beyond the foregoing apply only if agreed in writing, and the Controller bears the additional cost.

C.3. Assistance to the Controller

The Processor shall, as far as possible — within the scope and extent set out below — assist the Controller in accordance with Clauses 9.1 and 9.2 by implementing the following technical and organisational measures.

In connection with the Controller’s information obligation, the system will be able to display a text to new users. That text is prepared by the Controller, and it is the Controller’s responsibility to ensure that it is accurate.

If the Processor receives requests from data subjects, for example for access, rectification, erasure or other requests, those requests are forwarded to the Controller. In many cases the Controller will then be able to handle the request itself. If necessary, the Processor will, on instruction, assist the Controller with handling requests if the Controller so requests in writing.

The Controller shall, to the greatest extent possible, use the platform’s self-service functions. The Processor’s manual assistance is charged in accordance with Clause 16.

In the event of a personal data breach, the Processor shall make available the information reasonably in its possession that is necessary for the Controller’s notification under Article 33(3). The Processor is not obliged to carry out the Controller’s risk assessment or to notify Datatilsynet.

C.4. Retention period / erasure routine

Personal data in the production environment are erased in accordance with the following rules, which constitute the Controller’s instructions on erasure:

(a) Following documented instructions from the Controller, the designated personal data, user profiles and/or projects are erased in the production environment without undue delay (immediate erasure).

(b) A project is erased automatically three months after the Controller has closed the project, unless the Controller has in the meantime given other documented instructions.

(c) A project is also erased automatically where the Controller has not paid for the platform/service for three consecutive months, or three months after termination of the services relating to the processing of personal data, unless the Controller has in the meantime given other documented instructions.

Upon termination of the service, the Processor shall erase the personal data in accordance with Clause 11.1 and this C.4, unless the Controller — after signature of these Clauses — has changed its original choice from erasure to return. Such changes shall be documented and retained in writing, including electronically, together with the Clauses. A change from erasure to return may be made only if the Processor accepts it and the Controller bears the costs.

Until erasure in the production environment, the Controller has access to export its own data via the platform’s export function, to the extent that function is made available.

After erasure in the production environment, data may for a period be restored from project backup. Backup is retained for 14 days on platform.openframe.org and for 30 days on app.openframe.org. On platform.openframe.org the 14 days comprise seven days’ rolling (point-in-time) backup upon activity and a further seven days of daily backup. On app.openframe.org a project backup is taken daily upon activity on the project. Once a user profile has been erased, subsequent backups do not contain the erased profile. When the backup period has expired, user profiles and other personal data have been erased from the platform and cannot be restored, unless longer retention is required by law.

The Processor may retain anonymised and aggregated data without time limitation. Data that the Processor processes as an independent controller, cf. Annex D.1, are not covered by this erasure routine.

Confirmation of erasure is given by the Processor’s written statement by email upon request, typically issued by the support team. The Processor is not obliged to disclose erasure logs beyond what is proportionate.

C.5. Location of processing

Processing of the personal data covered by these Clauses may not, without the Controller’s prior written approval, take place at locations other than the following:

Within the EEA, including the Processor’s locations in Denmark and sub-processors’ data centres in the EU/EEA as set out in Annex B. Remote support and administration may take place from locations within the EEA. Any processing in a third country may take place only in accordance with C.6.

C.6. Instructions regarding transfers of personal data to third countries

The Controller instructs the Processor that personal data are as a starting point processed in the EEA as set out in C.5.

The Controller further instructs the Processor that a transfer to a third country may take place where necessary to deliver the service or to use an authorised sub-processor, including in connection with intra-group support, troubleshooting or sub-contracting by the cloud provider, provided the transfer is carried out in accordance with Chapter V of the GDPR. The transfer tool is, as applicable: (a) a valid adequacy decision, including the EU-U.S. Data Privacy Framework for certified organisations; (b) the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) with any necessary supplementary measures; or (c) another valid tool under Chapter V.

The Controller hereby gives documented instructions for such transfers to the sub-processors listed in Annex B and their sub-processors. Upon request, the Processor shall state which transfer tool is used in the specific case. A transfer impact assessment prepared by the Processor or the sub-processor shall be made available to the extent it exists and can be disclosed without breach of confidentiality.

C.7. Procedures for the Controller’s audits, including inspections, of processing entrusted to the Processor

Supervision is carried out primarily by the Processor, once per 12-month period and upon written request, making available one of the following, at the Processor’s choice: (a) the Processor’s written self-assessment of compliance with these Clauses; (b) a response to a reasonable security questionnaire; or (c) an existing third-party report or certification (for example D-Mærket, ISAE 3000, ISAE 3402, SOC 2 or ISO 27001), to the extent such a report or certification exists for the relevant services. The Processor is not obliged to commission a new external audit report at the Controller’s or its own expense unless the Parties separately agree.

A physical or logical inspection at the Processor may be required only if the documentation provided under the first paragraph of C.7 is manifestly inadequate, or if there is concrete and reasonably founded suspicion of material breach. Inspection may be carried out no more than once per 12-month period, on at least 30 days’ written notice, during the Processor’s ordinary business hours, and only by the Controller or an independent auditor who is not a competitor of the Processor. The inspection shall not give access to other customers’ data, to the Processor’s other trade secrets beyond what is necessary, or to sub-processors’ data centres. The Processor may require a confidentiality undertaking.

The Controller shall bear its own costs as well as the Processor’s time spent and external costs in accordance with Clause 16. The Processor shall allocate reasonable time, not exceeding one working day per 12-month period, unless otherwise agreed.

C.8. Procedures for audits, including inspections, of processing entrusted to sub-processors

Once a year, at its own expense, the Processor shall obtain documentation of the sub-processor’s compliance with the GDPR, data-protection provisions in other Union or Member State law, and these Clauses.

The Parties agree that the following types of documentation, statements or reports may be used in accordance with these Clauses:

  • the sub-processor’s own statements regarding compliance with the GDPR and information security; and

  • audit reports or assurance reports regarding compliance with the GDPR and information security performed by an independent third party.

For hyperscale cloud sub-processors (including Google Cloud and AWS), the obligation is discharged by the Processor obtaining or referring to the sub-processor’s generally available SOC, ISO or equivalent reports. The Controller has no right to physical inspection at sub-processors or to disclosure of reports that the sub-processor does not make available to its customers.

Annex D – Other terms agreed by the Parties

D.1. Roles and scope

The Processor processes personal data as a processor only where the data form part of the Controller’s account in the platform as part of the agreed service (customer content).

Openframe ApS is an independent controller for processing where Openframe determines the purposes and means, including: (a) establishment and administration of the customer relationship, contract and billing; (b) user identities to the extent necessary to provide a multi-tenant SaaS service; (c) information security, prevention of misuse and logging for Openframe’s own purposes; (d) product analytics, troubleshooting, capacity management and further development of the platform on the basis of usage and telemetry data; and (e) Openframe’s statutory accounting and regulatory reporting. Such processing is not subject to these Clauses, but to Openframe’s own privacy information and applicable law.

D.2. Controller warranties

The Controller warrants that there is a valid lawful basis, that data subjects have been informed to the extent required, and that the Controller is entitled to entrust the processing to the Processor. The Controller is solely responsible for the personal data that the Controller and its users enter, and for the instructions they give to other users.

D.3. Unlawful or incompatible content

The Processor is not obliged to review customer content. If the Processor becomes aware of data that conflict with C.1, these Clauses or applicable law, the Processor may block or erase the relevant data and notify the Controller, without this constituting a breach.

D.4. Liability and indemnity

As between the Parties, the Processor’s aggregate liability under these Clauses is limited to the liability cap in the Principal Agreement. If no cap is agreed, liability is limited to the fees paid by the Controller for the platform in the 12 months preceding the event giving rise to the claim. Liability for indirect or consequential loss, loss of business, loss of profit, loss of goodwill, the Controller’s own administrative fines or claims by the Controller’s customers is excluded to the extent permitted by mandatory law.

Nothing in these Clauses limits data subjects’ non-waivable rights under Articles 79 and 82 of the GDPR.

The Controller shall indemnify and hold the Processor harmless against claims, fines and costs arising out of the Controller’s instructions, the absence of a lawful basis, failure to inform data subjects, or personal data that the Controller or its users have entered in breach of these Clauses.

D.5. Anonymised data and AI

The Processor may create and use aggregated and irreversibly anonymised data for statistics, benchmarking, product development and marketing, provided that individuals and the Controller cannot reasonably be identified. The customer’s personal data shall not be used to train general models or third-party AI unless the Controller has given separate written instructions.

D.6. Additional instructions and changes to the service

The Controller may not unilaterally impose on the Processor new processing activities, certifications, locations or security requirements that would materially change the agreed service. Such requirements require a written agreement and may be separately priced.

D.7. Confidentiality of security documentation

Security questionnaires, statements, audit reports and other documentation disclosed under these Clauses are the Processor’s confidential information and may be used only for the Controller’s supervision. They may not be disclosed to any third party except the Controller’s professional advisers under a duty of confidentiality or a supervisory authority.

D.8. Changes to annexes

The Processor may update Annex B in accordance with B.2 and may continuously adjust technical and organisational measures provided the level of protection is not materially reduced. Other amendments to the Clauses require agreement, cf. Clause 14.2, or follow from mandatory law.

D.9. Relationship to the Principal Agreement

The Principal Agreement governs delivery, fees, termination and other commercial terms. In the event of conflict between the Principal Agreement and these Clauses on data protection, the Clauses prevail. In the event of conflict on commercial terms, including the liability cap, the Principal Agreement prevails unless that would conflict with mandatory data-protection law.


Footnotes

  1. References to a “Member State” in these Clauses shall be understood as references to EEA Member States. ↩