Data Processoragreement.
For schools and companies: the agreement that must be in place before we can process personal data on your behalf.
⚠️ This is a professional draft — not legal advice
Version 0.9 — draft · August 2026
The text is written against article 28 of the data protection regulation point by point and describes the processing the platform actually performs. It has NOT been reviewed by a lawyer or a data protection advisor. If the agreement is to be signed, it must first be reviewed by a lawyer.
Until then the document may be issued as a basis for dialogue — but it must be issued WITH this note, and the outstanding fields below must be filled in.
Outstanding fields that must be filled in before delivery
- HostStack — legal entity, home country and/or transfer basis not confirmed. See Annex B.
- PostStack — legal entity, home country and/or transfer basis not confirmed. See Annex B.
- Log ind med Facebook — legal entity, home country and/or transfer basis not confirmed. See Annex B.
- Browserens push-tjeneste — legal entity, home country and/or transfer basis not confirmed. See Annex B.
Until a sub-processor's home country and transfer basis is confirmed with the provider itself, the agreement cannot be signed: section 10 would otherwise contain an assumption rather than a basis.
The parties
DATA PROCESSOR (os):
- Camsilo (v/ Casper Madsen)
- Address: Ørstedvej 15, 6560 Sommersted
- Company reg. no.: 45925145
- Contact (e-mail): kontakt@camsilo.dk
DATA CONTROLLER (jer):
- Organization name: [udfyldes af den dataansvarlige]
- Company reg. no.: [udfyldes af den dataansvarlige]
- Address: [udfyldes af den dataansvarlige]
- Contact person for data protection: [udfyldes af den dataansvarlige]
- Data Protection Officer (if you have one): [udfyldes af den dataansvarlige]
1. The parties and the agreement's relationship to the main agreement
This data processing agreement is entered into between the customer (the school, company or other organisation that creates an account and invites users) as DATA CONTROLLER, and Discebo as DATA PROCESSOR.
The agreement is an integral part of the main agreement on the use of Discebo (the subscription). In case of conflict between this agreement and the main agreement, this agreement takes precedence with regard to processing of personal data. The agreement runs as long as the customer has an active account and ends at the same time as the main agreement — but clause 8 on deletion remains in force until the deletion is completed.
The Danish text is the binding version. Translations are a help to the reader and do not change the agreement's content.
2. Subject, duration, nature and purpose of the treatment
SUBJECT MATTER: Discebo provides a learning and work platform. The processor's processing of personal data takes place solely as part of delivering the functionality the customer has chosen: teaching and assessment, time registration, shift and absence management, mileage and expenses, payroll and bookkeeping exports, customer register, jobs and locations, documents, forms, signing, messages and notifications.
CHARACTER: collection, recording, organisation, storage, alteration, search, display, compilation into reports and extracts, sharing with the sub-processors listed in Appendix B, and deletion and anonymisation.
PURPOSE: solely to provide the platform on customer's instructions. The data processor NEVER processes customer personal data for its own purposes — neither to train models, for marketing, for profiling nor to develop new products on customer's data.
DURATION: the processing continues until the main agreement ends, and the subsequent deletion or return under clause 8 is completed.
3. Categories of affected persons and types of personal data
Categories of affected persons: students and course participants; teachers and guidance counselors; employees, apprentices and hourly workers in a company on the platform; managers and administrators; the company's own customers and contact persons (who often never used the platform themselves); recipients of inquiries and links from the customer portal.
Types of personal information — common information (art. 6): name, email address, telephone number, address, region, role, affiliation to school, class, group, team or company, employment date and employee number, profile picture, short description, education and experience, qualifications and certificates with expiry date, job search status, answers to quizzes and tests and assessments and feedback, active learning time, registered working hours and shifts, kilometres driven and routes, expenses with associated receipt photos, absence with type and period, wage basis and wage statements, offers, invoices and credit notes, cases and tasks with photos and notes, drive files, form completions, signatures with timestamp, IP address and device information for operational safety, messages and posts and notifications.
Types of personal data — special categories (art. 9): the platform contains a STRUCTURED field for absence type 'illness', which is included in the salary extract. Information about a person's sick leave is health information. The processing takes place on the customer's instruction as part of the customer's employment-related obligations and is based for the customer's behalf on art. 9, para. 2, letter b, cf. data protection law § 12. The customer is responsible for having the necessary basis; the data processor processes the information only on instruction. Free text fields (such as a note about work clothes or a message) may furthermore in practice come to contain health information, without that being the intention.
Criminal convictions and legal violations (art. 10) are not treated and the platform has no fields for it.
4. Instruction — and its limit
The data processor may only process personal data according to documented instructions from the data controller. The customer's instructions consist of: this agreement with annexes, the main agreement, and the choices the customer makes in the platform's own settings (including which modules are activated, what rights each role has, and whether AI functions may be used).
The processor shall immediately inform the controller if an instruction, in the processor's assessment, conflicts with the data protection regulation, data protection law or other applicable data protection law.
The data processor does not transfer personal data to a third country or international organisation without documented instruction, unless EU law or Danish law requires it. The transfers the customer hereby instructs in are exhaustively described in Annex B.
5. Confidentiality
The data processor ensures that only those persons who currently have a need for access to fulfil the agreement receive access to the personal data — and only to the information their task requires. Access is removed as soon as the need ceases.
These persons are bound by confidentiality. The confidentiality obligation continues after employment or cooperation has ceased. The processor can, upon request, document who has or has had such access.
All administrative access to a customer's data — including when a support employee views the platform as a user to help — is logged with who, when and why. The log can be provided to the controller.
6. Safety (art. 32)
The data processor implements appropriate technical and organisational measures taking into account the risk to individuals. The measures implemented at the time of the agreement are described in Annex C. The measures may be changed, but never to a lower level of protection without prior written notice to the data controller.
The data controller is responsible for the choices made in the platform's permission setup: which roles can see what, who can approve, and who gets admin access. The data processor provides the mechanism and by default closes a new function to roles that have not explicitly been granted access.
7. Assistance to the data controller
The data processor assists the data controller in fulfilling the rights of data subjects under articles 12-23: access, rectification, erasure, restriction, data portability and objection. The platform contains self-service for access and erasure, and the data processor also provides manual assistance within 10 working days if a request cannot be fulfilled via self-service.
Access is granted to the requester's own information. Where information necessarily involves a third party — for example that another user has blocked the person in question — only the requester's own information is provided, cf. art. 15, para. 4, on the right of access must not infringe others' rights.
The data processor further assists the data controller in complying with art. 32-36: security, notification of breaches, notification of data subjects, impact assessments and prior consultation — to the extent that the information is only available from the data processor.
If an affected person submits their request directly to the data processor, the data processor forwards it to the data controller without undue delay and does not respond on the data controller's behalf.
8. Deletion and return at termination
Upon termination of the agreement, the data controller chooses whether personal data shall be DELETED or RETURNED. If return is chosen, it takes place in a commonly used, machine-readable format. If the data controller makes no choice, the data processor deletes the data after a period of 30 days from termination, following prior written notice.
The deletion also includes existing backups as these expire according to the normal retention schedule. The data processor confirms in writing when the deletion is complete.
EXCEPTION — legally required retention: where EU law or Danish law requires continued retention, only the necessary information is retained, only for as long as it is required, and only for that purpose. This applies in particular to accounting materials, including invoices and credit notes, which under the Accounting Act must be retained for 5 years from the end of the financial year the material concerns.
Be aware of the distinction between a PERSON's deletion and the COMPANY's data: if a single user deletes their personal account, the company's business data is not deleted with it, because the company is the data controller for them. If they are to be deleted, that happens under this agreement — not by the user deleting their account.
9. Sub-processors
The data controller hereby gives general approval for the data processor to use the sub-processors listed in Annex B. The approval covers only those listed and only for the stated purposes.
The processor imposes on each sub-processor the same data protection obligations as in this agreement by written agreement and remains fully responsible to the controller for the sub-processor's compliance.
When adding or replacing a sub-processor, the processor informs the data controller in writing at least 30 days before the change takes effect. The data controller may within 14 days of notification make reasoned objection. If the parties cannot find a solution, the data controller can terminate the agreement with effect from the time the change was to take effect, with proportional refund of prepaid subscription.
The data controller can obtain an updated list at any time. Annex B below IS that list: it is generated from the same source in the code as the platform's personal data policy shows, precisely so that there cannot be two lists saying something different.
10. Transfer to third countries
The data processor endeavours to process personal information within the EU/EEA. Where a sub-processor processes information outside the EU/EEA, this is explicitly stated in Annex B together with the specific transfer mechanism under articles 44-49 for that sub-processor.
Appendix B specifies for each one whether the basis is the European Commission's standard contractual clauses (SCC), a certification under the EU-U.S. Data Privacy Framework, or a decision on an adequate level of protection. The basis has been verified with the supplier itself, and the source is stated with a date. Where the basis could NOT be confirmed, it is listed as an outstanding deficiency rather than as an assumption.
Specifically about the AI functions: they only send data out when a user themselves activates the function, and they do not take part in any automatic background processing. If the data controller wants no transfer to the respective third country at all, the AI functions can be turned off for the organisation, after which no data is sent there.
11. Breach of personal data security
The data processor notifies the data controller without undue delay and within 48 hours of becoming aware of a personal data breach, cf. article 33, section 2. The deadline is set shorter than the data controller's own 72-hour deadline to the Danish Data Protection Authority, so the data controller has real time to report it.
The notification contains, to the extent the information is available: the nature of the breach, which categories and how many data subjects and information are involved, the likely consequences, the measures taken or proposed, and a contact point. If the information is not available all at once, it is provided gradually without further unnecessary delay.
The processor NEVER reports a breach to the Data Protection Authority on behalf of the controller unless explicitly agreed in writing in the specific case, and does not notify affected persons without agreement.
12. Documentation and revision
The processor shall, upon request, make available the information necessary to demonstrate compliance with Article 28, and shall allow and contribute to audits and inspections, as per Article 28, Section 3, Letter h.
The data controller can conduct an audit once per year — and additionally after a breach affecting the data controller — either itself or by an independent third party that is not a competitor to the data processor and which signs a confidentiality declaration. The audit is notified in writing at least 30 days in advance, is conducted during normal working hours and must not disrupt operations unnecessarily.
The controller bears its own costs for the audit. The processor's participation is free of charge during the annual audit and audit after a breach; beyond that, fees can be agreed based on time spent.
The data processor keeps a record of the categories of processing carried out on behalf of the data controller, see art. 30, para. 2, and provides it on request.
13. Responsibility, changes and choice of law
The parties' responsibility follows art. 82 and the main agreement. Limitations of liability in the main agreement cannot limit an affected person's rights under the regulation or a party's responsibility to a supervisory authority.
Changes to the agreement are agreed in writing. However, the data processor may unilaterally change Annex B according to the procedure in point 9 and Annex C if the change does not lower the level of protection.
The agreement is governed by Danish law and disputes are resolved by the Danish courts with the data processor's home jurisdiction as the first instance unless otherwise provided by mandatory rules.
Annex A — scope of treatment
The subject matter, nature, purpose and duration of the processing are set out in section 2. Categories of data subjects and types of personal data — including the structured health field for sick leave — are set out in section 3. The instructions are set out in section 4.
Annex B — approved sub-processors
The list is the same as shown in the platform's privacy policy: it comes from one place in the code, and a new integration cannot be used without appearing here.
| Sub-processor | Treatment facility | Purpose | Personal data | Transfer basis and source |
|---|---|---|---|---|
| HostStack ([udfyldes af den dataansvarlige])HostStack | [udfyldes af den dataansvarlige] | Hosting af selve platformen: applikationsserver, database og fillager. | Alle data på platformen, fordi de fysisk ligger på leverandørens diske. | [udfyldes af den dataansvarlige][udfyldes af den dataansvarlige] — driftaftalen og leverandørens databehandlervilkår findes ikke i kodebasen, og hverken region eller juridisk enhed kunne bekræftes 2026-08-05. |
| Stripe Payments Europe, Ltd. (Irland) og Stripe, Inc. (USA)Stripe | Irland (EU) og USA | Kortbetaling og abonnementsstyring for både personlige abonnementer og firma-pladser. | Navn, e-mailadresse, betalingsoplysninger og abonnementets status. Vi gemmer selv kun en reference til abonnementet — aldrig fulde kortoplysninger. | Stripe oplyser selv at overførsler til USA hviler på BÅDE en certificering under EU-U.S. Data Privacy Framework OG EU-Kommissionens standardkontraktbestemmelser (SCC).stripe.com/legal/privacy-center — afsnittene «Is Stripe certified under the EU-U.S Data Privacy Framework?» og «How to get a copy of the SCCs or UK Addendum?», læst 2026-08-05. |
| Anthropic PBCClaude (AI-assistent, oversættelse, diktat, kvitteringsscan) | USA | Alle AI-funktioner: fag-assistenten, sags-assistenten, oversættelse af beskeder, diktat af opgavetekst, aflæsning af kvitteringsfotos og rejseplan-forslag. | Det indhold du selv sender til funktionen. Konkret: hele samtalen i assistenten; sags-assistenten sender desuden en skjult kontekst med sagens navn, kundens navn, adresse, status og materialeoverblik inkl. anslået materialepris. Oversættelsen sender hele teksten i den besked du oversætter. Diktatet sender din dikterede tekst. Kvitteringsscanningen sender selve FOTOET af kvitteringen — altså leverandør, beløb, moms, dato, eventuel kilometerstand og alt andet der er med i billedet. Rejseplanen sender destination, datoer og antal personer. | EU-Kommissionens standardkontraktbestemmelser (SCC, modul 2 og 3) via Anthropics databehandleraftale, der automatisk indgår i deres erhvervsvilkår. Anthropic påberåber sig IKKE en certificering under EU-U.S. Data Privacy Framework: deres egen privatlivspolitik nævner udelukkende SCC og adgangsafgørelser.anthropic.com/legal/privacy (senest opdateret 8. juli 2026): «We rely on standard contractual clauses to transfer information … to certain affiliates and third parties in countries without an adequacy decision». DPA'ens indarbejdelse: privacy.claude.com/en/articles/7996862. Begge læst 2026-08-05. ⚠️ Offentlige kilder er UENIGE om Anthropics DPF-status — derfor er SCC anført som grundlaget, fordi det er det leverandøren selv skriver. |
| PostStack ([udfyldes af den dataansvarlige])PostStack | [udfyldes af den dataansvarlige] | Al udgående e-mail (kvitteringer, nulstilling af adgangskode, afmeldingslink, nyhedsbreve) og den indgående postkasse som henvendelser til platformen lander i. | Modtagerens navn og e-mailadresse samt mailens fulde indhold. For indgående post desuden afsenderens adresse og eventuelle vedhæftninger. | [udfyldes af den dataansvarlige][udfyldes af den dataansvarlige] — ⚠️ EFTERPRØVET 2026-08-05: poststack.dev offentliggør hverken juridisk enhed, hjemland, privatlivspolitik, databehandleraftale eller behandlingssted. Uden dem er art. 28, stk. 1's krav om «tilstrækkelige garantier» ikke dokumenteret, og hjemlandet kan derfor heller ikke oplyses her. |
| BunnyWay, informacijske storitve d.o.o.Bunny Stream / bunny.net | Slovenien (EU) | Lagring, transkodning og levering af video du uploader. | Selve videofilen og dens indhold, samt IP-adressen på den der ser eller uploader videoen. | Handled within the EU/EEA — no transfer basis needed.bunny.net/gdpr — leverandøren er BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenien, altså inden for EU. Læst 2026-08-05. ⚠️ Bemærk: leverandørens EGEN underdatabehandlerliste (bunny.net/gdpr/sub-processors) omfatter tjenester i USA. Aktiveres deres transkriptionsfunktion, sendes lyd videre — den er IKKE i brug i Discebo i dag, og bliver den det, hører den sin egen post her. |
| Google Ireland Limited (og Google LLC, USA)Google Analytics 4 | Irland (EU) og USA | Statistik over hvordan sitet bruges. | Besøgs-id i en cookie, hvilke sider du ser, hvor du kom fra og dit browsersprog. | Googles databehandlervilkår anvender en «Alternative Transfer Solution» med EU-Kommissionens standardkontraktbestemmelser (SCC) som den udtrykkelige tilbagefaldsordning, hvis den løsning ikke er i kraft. Selve behandlingen sker for europæiske kunder hos Google Ireland Limited.business.safety.google/adsprocessorterms — «if Google has not adopted, or informs Customer that Google is no longer adopting an Alternative Transfer Solution for any Restricted European Transfers, then … the SCCs … will apply». Læst 2026-08-05. |
| Google Ireland Limited (og Google LLC, USA)Log ind med Google | Irland (EU) og USA | Godtgør over for os at du er indehaver af en Google-konto, så du kan logge ind uden en ekstra adgangskode. | Vi modtager dit navn, din e-mailadresse og et konto-id. Google ser at du logger ind på Discebo. | Google fastlægger selv formål og midler for sin egen konto-behandling og er dermed selvstændig dataansvarlig efter sin egen politik. Vi overfører ingen data til Google ud over den forespørgsel du selv udløser.policies.google.com/privacy — Googles egen politik gælder for kontoen. Læst 2026-08-05. |
| Meta Platforms Ireland Limited ([udfyldes af den dataansvarlige])Log ind med Facebook | Irland (EU) og [udfyldes af den dataansvarlige] | Godtgør over for os at du er indehaver af en Facebook-konto, så du kan logge ind uden en ekstra adgangskode. | Vi modtager dit navn, din e-mailadresse og et konto-id. Meta ser at du logger ind på Discebo. | [udfyldes af den dataansvarlige][udfyldes af den dataansvarlige] — ⚠️ Metas overførselsgrundlag for login-flowet er IKKE efterprøvet 2026-08-05, og posten skal derfor udfyldes eller integrationen fjernes, før politikken udleveres. |
| Vipps MobilePay ASMobilePay | Norge (EØS) | Betaling med MobilePay, hvor en virksomhed har slået det til. | Beløb, betalingsreference og betalerens MobilePay-oplysninger. | Handled within the EU/EEA — no transfer basis needed.developer.vippsmobilepay.com — API'et ligger på vipps.no, og leverandøren er norsk. Norge er omfattet af EØS-aftalen, så der er ingen tredjelandsoverførsel. Læst 2026-08-05. |
| Google LLC (FCM), Apple Inc. (APNs) og Mozilla Corporation (autopush)Browserens push-tjeneste | USA — hvilken af dem, afgøres af din browser, ikke af os | At levere notifikationer til din telefon eller computer, når nogen skriver til dig eller der sker noget der vedrører dig. | Det endpoint din egen browser har udstedt (en unik adresse til netop den browser-installation) samt selve notifikationen — men KUN i krypteret form. Indholdet krypteres ende-til-ende til din browsers egne nøgler efter RFC 8291, så push-tjenesten videresender en blob den ikke selv kan læse. Den kan altså se AT der blev sendt noget til din enhed og hvornår, men ikke hvad der står. | [udfyldes af den dataansvarlige][udfyldes af den dataansvarlige] — ⚠️ Overførslen sker til den push-tjeneste DIN BROWSER har valgt (Googles FCM, Apples APNs eller Mozillas autopush). Vi har intet kundeforhold til nogen af dem og kan derfor hverken indgå en aftale eller fremvise et grundlag; den dataansvarlige må tage stilling til om overførslen kan hvile på art. 49, stk. 1, litra b (nødvendig for at opfylde en aftale den registrerede selv har anmodet om — brugeren slår notifikationer til aktivt) eller om funktionen skal begrænses. Forholdet der taler for: indholdet er krypteret ende-til-ende til brugerens egne nøgler (RFC 8291), så det der reelt overføres i klartekst, er endpointet og tidspunktet. Teknisk kilde: RFC 8291 + RFC 8292 (VAPID); afsendelsen sker i src/lib/push/send.ts via web-push-pakken. |
Annex C — technical and organisational measures
The measures below were implemented in the platform at the time of the agreement. The list contains only what actually has been built.
- Access codes — Passwords are never stored in plain text, but as a scrypt-derived key with individual salt. The processor cannot see or recreate a password.
- Sessions — The login cookie is httpOnly and signed with a secret key, and the signature is verified with every request in constant time. If a user changes password or their account is locked, all existing sessions on that account are immediately invalidated.
- Transport — All traffic to and from the platform is encrypted (HTTPS/TLS). This also applies to calls to the sub-processors mentioned in Annex B.
- Access control — Permissions are managed per module and per level (no access, view, edit, approve) and verified on the server with each action — not just in the user interface. A new module is by default CLOSED for roles that have not explicitly been granted access, so an expansion of the platform cannot open data by accident.
- Separation of customers — Each organization's data is bound to the organization's id, and every query verifies membership and permissions before retrieving data. Files and images are only delivered through a controlled route, not from an open address.
- Logging — Administrative actions and access on behalf of a user are logged with who, when and what. The activity log has a fixed retention limit of 180 days, and rows pointing to a user as actor are deleted when the account is deleted.
- Abuse protection — Login, registration and functions that consume resources are rate-limited. The IP address is used for this and not kept longer than necessary.
- Data backup — Regular security backups are made of the structured database and stored files. Recovery is tested.
- Deletion — Deletion of an account is carried out as a coherent cascade across all data layers with associated files and images, not as a marking of the row. Where information must be retained for legal reasons, the personally identifiable part is anonymised instead.
- Data minimization in AI functions — The AI functions send only what the function requires, and store no response with the provider at our behest. Receipt scanning returns only the read fields and does not store the image with the provider.
Signature
The agreement is entered into by both parties signing — either physically, with digital signature, or by the organisation's administrator approving the agreement's version number in the platform's settings, whereby the approval is saved with time and name.
If you need the agreement as a signed document, or if you have your own standard agreement you prefer to use, write to us — we respond to both.
More about your data
See also our privacy policy, ours cookiepolicy and our Terms of trade.