Data processing agreement

pursuant to Article 28(3) of Regulation 2016/679 (databeskyttelsesforordningen – databeskyttelsesforordningen)

Based on the supervisory authority’s standard contractual clauses


The Parties

The data controller: The business that has registered as a customer of Billit (hereinafter the “data controller”).

The data processor: Decoos Holding AB Reg. no.: 559211-6502 Hyllie Kyrkoväg 53C 216 16 Limhamn, Sweden (hereinafter the “data processor”)

This data processing agreement (the “Agreement”) is accepted by the data controller upon registering as a customer of the bookkeeping system Billit (billit.dk / billit.se) and forms part of the contractual relationship between the parties.

1. Background and purpose

1.1. The data processor provides the cloud-based bookkeeping system Billit to the data controller. When the system is used, the data processor processes personal data on behalf of the data controller.

1.2. The Agreement sets out the rights and obligations that apply to the data processor’s processing of personal data on behalf of the data controller, cf. Article 28(3) of databeskyttelsesforordningen.

1.3. The Agreement takes precedence over any corresponding provisions in other agreements between the parties as regards the processing of personal data.

2. Nature and purpose of the processing

2.1. The processing is carried out for the purpose of providing digital bookkeeping to the data controller, including recording of transactions, storage of vouchers, invoicing, e-invoicing, bank reconciliation, VAT reporting, financial reports and backup.

2.2. Categories of data subjects: The data controller’s customers, suppliers, employees, owners and other business contacts, as well as the data controller’s users of the system.

2.3. Types of personal data: Ordinary personal data, including name, address, email address, telephone number, business registration number, bank details, payment details and information appearing in uploaded vouchers (invoices, receipts, etc.). Special categories of data or data relating to criminal convictions are not intentionally processed; the data controller is responsible for not uploading such data unless necessary for the bookkeeping.

2.4. Duration: The processing takes place for as long as the data controller uses the system, and during the subsequent retention period, cf. clause 11.

3. Obligations of the data controller

3.1. The data controller warrants that there is a legal basis for the processing and that the instructions in this Agreement are lawful.

3.2. The data controller is responsible for the accuracy of the data entered and uploaded into the system.

4. The data processor acts on instructions

4.1. The data processor may only process personal data on documented instructions from the data controller, unless processing is required under EU or national law to which the data processor is subject (e.g. the retention requirements of the Danish bogføringsloven). This Agreement and the data controller’s use of the system’s functions constitute the instructions.

4.2. The data processor shall immediately inform the data controller if, in the data processor’s opinion, an instruction infringes databeskyttelsesforordningen or other data protection legislation.

5. Confidentiality

5.1. The data processor ensures that only persons with a work-related need have access to the personal data, and that such persons have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security of processing

6.1. The data processor implements appropriate technical and organisational measures pursuant to Article 32 of databeskyttelsesforordningen, including:

  • Access to the system requires personal login; passwords are stored hashed.
  • Role-based access control, so that users only have access to their own companies’ data.
  • Encryption of all communication between user and system (HTTPS/TLS).
  • Validation and inspection of uploaded files before storage.
  • Automatic, continuous backup of records and vouchers; copies are stored separately from the operating environment.
  • Logical separation of data per company in the database.
  • Continuous updating of the system with security patches and monitoring of operations.

7. Use of sub-processors

7.1. The data processor has the data controller’s general authorisation to engage sub-processors. The data processor shall inform the data controller of any intended changes with at least 30 days’ notice, thereby giving the data controller the opportunity to object.

7.2. At the conclusion of the Agreement, the data processor uses the following sub-processors:

Sub-processor Service Location
hosting.com Hosting of system and database Netherlands (EU)
hosting.com Storage of backups (cloud server, separate from the operating environment) Netherlands (EU)
Dropbox International Unlimited Company Storage of backups Ireland/USA (EU-U.S. Data Privacy Framework)
hosting.com Email server for emails sent from the system Netherlands (EU)

7.3. The data processor imposes the same data protection obligations as set out in this Agreement on sub-processors by way of written agreement and remains liable to the data controller for the sub-processor’s fulfilment thereof.

8. Transfers to third countries

8.1. Personal data is, as a general rule, processed within the EU/EEA. If transfers to third countries take place (e.g. via a sub-processor), the data processor ensures that the transfer is based on a valid transfer mechanism pursuant to Chapter V of databeskyttelsesforordningen (e.g. the European Commission’s standard contractual clauses or an adequacy decision).

9. Assistance to the data controller

9.1. Taking into account the nature of the processing, the data processor assists the data controller by appropriate technical and organisational measures in fulfilling the data controller’s obligation to respond to requests for exercising the data subjects’ rights (access, rectification, erasure, restriction, data portability and objection).

9.2. The data processor further assists the data controller in ensuring compliance with the obligations pursuant to Articles 32–36 of databeskyttelsesforordningen (security of processing, notification of breaches, data protection impact assessments and prior consultation).

10. Notification of personal data breaches

10.1. The data processor notifies the data controller without undue delay — and no later than 48 hours after having become aware of it — of any personal data breach, so that the data controller can comply with its obligation to notify the supervisory authority within 72 hours.

10.2. The notification shall, as far as possible, contain the information set out in Article 33(3) of databeskyttelsesforordningen.

11. Erasure and return of data

11.1. Upon termination of the data controller’s use of the system, the data processor shall, on request, provide the data controller’s data, including in SAF-T format, in accordance with the rules of the Danish bogføringsloven.

11.2. The data processor retains records and vouchers for the period required by the Danish bogføringsloven (5 years from the end of the financial year to which the material relates), unless the data controller demonstrates that the material is stored in another lawful manner. Thereafter the data is erased.

12. Audit and inspection

12.1. The data processor makes available to the data controller all information necessary to demonstrate compliance with Article 28 of databeskyttelsesforordningen and allows for and contributes to audits, including inspections, conducted by the data controller or an auditor mandated by the data controller, upon reasonable notice.

13. Commencement and termination

13.1. The Agreement enters into force upon the data controller’s registration as a customer of the system and applies for as long as the data processor processes personal data on behalf of the data controller.

13.2. The Agreement cannot be terminated separately for as long as the main service is provided.

14. Governing law and supervisory authority

14.1. For customers registered via billit.dk, the Agreement is governed by Danish law, references to bookkeeping legislation refer to the Danish Bookkeeping Act, and the competent supervisory authority is the Danish Data Protection Agency (Datatilsynet). For customers registered via billit.se, the Agreement is governed by Swedish law, references to bookkeeping legislation refer to the Swedish Bookkeeping Act (1999:1078), and the competent supervisory authority is the Swedish Authority for Privacy Protection (IMY).