Data Processing Agreement

Data Processing Agreement

Last updated: 19. juli 2026

Read the data processing agreement, or generate your own completed agreement with company and processing details.

This is an English translation provided for convenience. The Danish version is the legally binding document; in case of any discrepancy, the Danish text prevails.

This data processing agreement (the "Data Processing Agreement") sets out the terms under which Webits ApS ("Webits", the "Data Processor") processes personal data on behalf of the customer (the "Customer", the "Data Controller") as part of the provision of the products and services agreed between the parties.

The Data Processing Agreement is an integral part of the agreement between the Customer and Webits and supplements our terms of business. It has been entered into in order to satisfy the requirements of Article 28(3) of the EU General Data Protection Regulation 2016/679 ("GDPR") and applies to the extent that Webits processes personal data on behalf of the Customer. Where Webits processes personal data as an independent data controller (for example regarding the Customer's contact persons), this is governed by our cookie and privacy policy and not by this Data Processing Agreement.

1. Background and purpose

The Customer is the data controller for the personal data that the Customer allows Webits to process through the use of Webits' services (for example web hosting, email, servers, backup, Microsoft 365 and related solutions). Webits processes this personal data as data processor solely for the purpose of providing the agreed services.

The Customer warrants that the Customer has the necessary legal basis for the processing of the personal data entrusted to Webits, and that the Customer otherwise complies with its obligations as data controller.

2. Instructions

Webits processes personal data only in accordance with documented instructions from the Customer, unless processing is required under EU law or Danish law. The Customer's instructions consist of this Data Processing Agreement, the agreement entered into between the parties and the Customer's use of the services. Additional or amended instructions shall be agreed in writing.

Webits shall notify the Customer if, in Webits' opinion, an instruction infringes the data protection rules.

3. Processing activities

The nature, purpose, duration and type of the processing as well as the categories of data subjects and personal data are set out in Annex A. The processing comprises the operations necessary to provide the agreed services, including storage, hosting, operation, backup, support and related data processing.

The processing continues for as long as Webits provides services to the Customer, and ceases upon termination of the agreement, cf. clause 10.

4. Webits' obligations

Webits:

  • processes personal data only in accordance with the Customer's instructions, cf. clause 2,
  • ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality,
  • implements appropriate technical and organisational measures, cf. clause 5,
  • assists the Customer, cf. clause 6,
  • complies with the conditions for engaging sub-processors, cf. clause 7,
  • notifies of personal data breaches, cf. clause 8, and
  • makes available the information necessary to demonstrate compliance with Article 28 of the GDPR, and allows for audits, cf. clause 9.

5. Security (technical and organisational measures)

Webits implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks of the processing, cf. Article 32 of the GDPR. The measures include, among other things, network segmentation, access control based on the principle of least privilege, logging and monitoring, DDoS protection, encryption where relevant, backup as well as contingency and recovery procedures.

A more detailed description of the measures is set out in our policy on security and operations. The measures are updated on an ongoing basis in line with technological developments and the threat landscape.

6. Assistance to the Customer

Webits reasonably assists the Customer with:

  • responding to requests from data subjects for the exercise of their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, data portability and objection), and
  • complying with the Customer's obligations under Articles 32–36 of the GDPR, including security, notification of breaches, communication to data subjects as well as data protection impact assessments (DPIA) and prior consultation.

Assistance beyond what follows directly from the Data Processing Agreement may be invoiced in accordance with Webits' applicable hourly rates.

7. Sub-suppliers and data processors

The Customer grants Webits general authorisation to engage sub-processors. An overview of the sub-processors used is set out in Annex B.

Webits ensures that written agreements have been entered into with the sub-processors imposing on them data protection obligations equivalent to those incumbent on Webits under this Data Processing Agreement. Webits is liable to the Customer for the sub-processor's compliance with the obligations.

Webits notifies the Customer of planned changes concerning the addition or replacement of sub-processors with reasonable notice, so that the Customer has the opportunity to object. If the Customer raises a reasoned objection, the parties shall seek an amicable solution; if no solution can be found, the Customer may terminate the affected service.

Transfer to third countries. Processing generally takes place within the EU/EEA. Where personal data is transferred to a third country or an international organisation, Webits ensures a valid transfer basis under Chapter V of the GDPR — for example an adequacy decision, the European Commission's Standard Contractual Clauses (SCC) or the EU-U.S. Data Privacy Framework.

8. Notification of personal data breaches

Webits notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer. The notification includes — to the extent the information is available — a description of the nature of the breach, the likely consequences and the measures taken or proposed to be taken to address the breach and mitigate its adverse effects.

The notification enables the Customer to fulfil its own obligations, including any notification to the Danish Data Protection Agency (Datatilsynet) within 72 hours and communication to the affected data subjects. It is the Customer, as data controller, who is responsible for making the notification to the supervisory authority and any communication to the data subjects.

9. Audit and documentation

Upon the Customer's request, Webits makes available the information necessary to demonstrate Webits' compliance with Article 28 of the GDPR and this Data Processing Agreement. This may be done by presenting relevant audit reports (for example ISAE 3402) or other documentation.

In addition, the Customer may — upon reasonable prior notice and during normal business hours — arrange for an audit, including an inspection, carried out by the Customer or an independent auditor authorised by the Customer. Audits must not unduly disrupt Webits' operations or compromise the security and confidentiality of other customers. Webits' reasonable costs and time spent in connection with the audit may be invoiced to the Customer.

10. Termination

Upon termination of the provision of the services, Webits — at the Customer's choice — deletes or returns all personal data processed on behalf of the Customer, and deletes existing copies, unless EU law or Danish law requires continued storage.

Deletion and any specific retention periods otherwise follow the terms applicable to the individual service, including the termination and deletion rules as well as backup retention set out in the terms of business.

11. Liability and other terms

The parties' liability under this Data Processing Agreement is governed by the liability provisions of the terms of business, including the limitation of liability in clause 12 of the terms of business, to the extent that this is compatible with applicable law. The Data Processing Agreement is subject to Danish law with venue as specified in the terms of business.

In the event of any discrepancy between this Data Processing Agreement and the remaining agreement between the parties, the Data Processing Agreement shall prevail as regards the processing of personal data.


Annex A — Processing activities

Subject matter of the processing: Processing of personal data as necessary to provide the services agreed between the parties (hosting, email, servers, backup, Microsoft 365 and related solutions).

Duration: The processing continues for as long as Webits provides services to the Customer.

Nature and purpose: Storage, hosting, operation, backup, support and other processing necessary for the provision of the services.

Types of personal data: The personal data that the Customer chooses to store or process via the services. As a general rule, ordinary personal data is processed (for example name, contact details, user information and the content of emails and files). The Customer must not entrust sensitive personal data or data concerning criminal offences for processing without a prior written agreement on the necessary supplementary measures.

Categories of data subjects: The persons whose data the Customer chooses to process via the services, for example the Customer's own customers, users, employees, contact persons and business partners — including end users of applications that Webits has developed, operates and/or hosts for the Customer. The Customer, as data controller, is responsible for the legal basis for processing this data and for the content that end users upload or share.

Annex B — Sub-processors

Webits uses the following sub-processors for the provision of the services:

Sub-processorPurposeLocationTransfer basis
Microsoft (Azure and Office 365)Platform (PaaS) and software services used for web productsData centres in the EU (including the Netherlands and Ireland)Processing within the EU/EEA
OVHcloudDedicated servers for web productsData centres in the EU (Germany)Processing within the EU/EEA
DigitalOceanCloud solutions for cloud-based web productsData centres in the EUProcessing within the EU/EEA; in the event of any transfer outside the EU/EEA, SCC/DPF are used
Curanet A/SDomain registration on behalf of the CustomerData centre in DenmarkProcessing within the EU/EEA
PleskSupport and operation of the hosting platform's system softwareSwitzerlandAdequacy decision (Switzerland)
StripeProcessing of card paymentsEU/USASCC and/or the EU-U.S. Data Privacy Framework

The overview is updated on an ongoing basis. In connection with domain administration, disclosure may also occur to official naming and registry authorities such as Punktum dk, ICANN and RIPE; these act as independent data controllers/authorities and not as sub-processors for Webits.

Publisher

The website is owned and published by:

Webits ApS CVR number: 41336404 Fadet 43 st. tv. 1799 København V

Phone: +45 44 14 44 30 Email: info@webits.dk · Data Protection Officer: dpo@webits.dk

Managing Director: Martin Bennetzen

Ready to make IT something you never have to think about?

Tell us about your challenge — we'll get back to you with a concrete proposal for a solution.