Legal
Data Processing Agreement for the Board
Last updated: 29 September 2026. The agreement is signed before operation begins and applies together with the terms for the Board.
1. Parties and purpose
This agreement is made between the Customer as controller and Prozanta Operations, company reg. no. 40306285, Tangevej 5, 6690 Gørding, Denmark, as processor.
It governs Prozanta's processing of personal data on the Customer's behalf where the Board is operated by Prozanta, and it meets the requirement for a written agreement in Article 28(3) GDPR.
Where the Board runs on the Customer's own server, Prozanta processes no personal data for the Customer and this agreement does not apply.
This is a translation of the Danish original at prozanta.dk/databehandleraftale. In the event of any discrepancy, the Danish text applies.
2. Nature, purpose and duration of the processing
The purpose is to make the Board available to the Customer: to store what the Customer's teams record at the daily operations meeting, to show the history back to them and to their manager, and to send the daily message to the addresses the Customer has specified.
The processing consists of storage, display, calculation of the figures that can be derived from the records, and sending email.
Where the Customer also has an advisory agreement with Prozanta, Prozanta additionally reviews the Customer's boards in order to advise on operations — for example when meeting frequency falls or actions are not closed. This is done on the Customer's instruction as part of the agreed service, and the Customer may ask in writing at any time for it to stop, without that changing anything else in the agreement. Without an advisory agreement, Prozanta looks at the Customer's data only when the Customer asks for help.
The processing continues for as long as the agreement on the Board is in force and ends in accordance with clause 9.
3. Categories of data subjects and data
Data subjects: the Customer's employees and managers who take part in the meeting or are responsible for an action, and the people who receive the daily message.
Data:
• The name or initials of the person responsible for an action
• Email addresses entered by the Customer as recipients of the daily message
• Free text about deviations and actions, written by the Customer's employees, which may contain information about individuals
• Photographs of deviations, taken by the Customer's employees, which may show individuals
• Timestamps for when the board was opened and when actions were closed
The Board is not built for special categories of data under Article 9 or for criminal conviction data, and the Customer must not record such data in it. The Customer is responsible for instructing its employees accordingly.
Prozanta does not measure who wrote what. There are no personal logins, and the software does not link records to an individual.
4. Instructions
Prozanta processes personal data only on documented instructions from the Customer. This agreement, the terms for the Board and the written agreement between the parties together constitute those instructions.
Prozanta informs the Customer if an instruction in Prozanta's opinion infringes data protection law.
Prozanta does not transfer personal data to a third country beyond what follows from the sub-processors in clause 6, and does not do so without the Customer's instruction or a requirement under EU or Danish law. Where processing is required by law, Prozanta informs the Customer unless the law prohibits it.
Prozanta does not use the Customer's personal data for its own purposes, including not for statistics, product development on identifiable data, marketing or model training.
5. Confidentiality and security
Only those people at Prozanta who need access in order to provide and operate the Board have access to the Customer's data. They are bound by confidentiality.
Prozanta has implemented measures under Article 32. The principal ones are:
• All traffic to and from the Board is encrypted in transit (TLS)
• Data is encrypted at rest with the hosting provider
• Team and manager codes are stored only as a cryptographic digest, never in clear text
• Access to one team is separated from other teams by a signed session, and the number of login attempts is limited
• A full extract of the database is taken daily and kept encrypted and separate from operations for at least 30 days, and restoration is exercised every quarter
• Access to the operating environment requires two factors
• Changes to the software are reviewed and tested before release
The level is kept under review. Prozanta may replace a measure with one that protects at least as well.
6. Sub-processors
By entering into this agreement the Customer gives general authorisation for Prozanta to use the sub-processors listed below.
Prozanta has entered into agreements with each of them imposing the same obligations as follow from this agreement, and Prozanta remains liable to the Customer for their processing.
If Prozanta changes or adds a sub-processor, the Customer is notified in writing at least 30 days in advance and may object within that period. If Prozanta maintains the change, the Customer may terminate the agreement on the Board with effect from the day it takes effect, without payment for the remaining period.
| Sub-processor | Service | Place of processing |
|---|---|---|
| Vercel Inc. | Operation of the software and the database | United States, under the EU-US Data Privacy Framework |
| Resend | Delivery of the daily message | EU (Ireland); any transfers to the United States under the EU-US Data Privacy Framework |
| Upstash | Temporary processing of IP addresses to limit login attempts | EU |
7. Assistance to the Customer
Prozanta assists the Customer in meeting its obligations:
• With requests from data subjects for access, rectification, erasure, restriction, portability or objection. The Customer can export, correct and delete data directly in the Board; where that is not sufficient, Prozanta assists within five working days
• With security, breach notification, communication to data subjects and impact assessments under Articles 32 to 36
Assistance beyond the ordinary may be charged by time spent, where the scope has been notified in advance.
8. Personal data breaches
If Prozanta becomes aware of a personal data breach, the Customer is notified without undue delay and no later than 24 hours after Prozanta became aware of it.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures Prozanta has taken or proposes. Where not all information is available at once, it is provided in phases.
The Customer notifies the Danish Data Protection Agency and the data subjects. Prozanta does not notify on the Customer's behalf unless agreed in writing.
9. Deletion and return
The Customer may export all of its data from the Board at any time.
When the agreement on the Board ends, the Customer has 30 days to export its data. Prozanta assists on request.
No later than 60 days after termination, Prozanta deletes all personal data entrusted by the Customer, including copies in backups as they roll. Prozanta confirms deletion in writing. The Customer may ask for deletion to take place sooner.
Prozanta does not retain the Customer's data beyond that point unless EU or Danish law requires it. Where it does, the legal basis is stated.
10. Documentation and audit
Prozanta makes available the information necessary for the Customer to demonstrate compliance with Article 28.
The Customer may audit Prozanta's processing once a year, and in addition following an established breach. The audit may take the form of a written review, a meeting or an auditor appointed by the Customer. Prozanta is given at least 14 days' notice, and the audit is scheduled so as not to disrupt operation for other customers.
The Customer bears its own costs. Prozanta's time spent beyond one working day a year may be charged as agreed.
11. Entry into force, duration and governing law
The agreement takes effect on signature and applies for as long as Prozanta processes personal data for the Customer.
It is governed by Danish law. Disputes are settled under clause 11 of the terms of business.
In the event of conflict, this agreement prevails over the terms of business and the terms for the Board in matters concerning the processing of personal data.
Getting the agreement signed
Write to contact@prozanta.com and we will send the agreement for signature with your details filled in. If you have your own data processing agreement, we will review that instead.