dezky
beta
← Back to home
data processing agreement

Data Processing Agreement

This Data Processing Agreement (DPA) governs how Dezky ApS processes personal data on behalf of the customer when using the dezky platform. It forms an annex to the main agreement between the parties.

Last updated: 5 June 2026 · version 1.0

1. Parties and roles

The customer is the data controller, and Dezky ApS (company reg. 43 14 18 21, Åtoften 33, 6710 Esbjerg V, Denmark) is the data processor.

dezky processes personal data only on the customer's documented instructions — including this agreement and the customer's use of the platform — and will inform the customer if, in dezky's opinion, an instruction infringes applicable data-protection law.

2. Subject matter, duration and purpose

The subject matter is the personal data the customer and its users place into the modules (mail, calendar, contacts, files, video, chat and identity/SSO).

The purpose is to provide and operate the platform. Processing lasts for the term of the main agreement, after which data is deleted or returned per section 9.

3. Categories of data subjects and data

Data subjects: the customer's employees, contacts and any other individuals whose data the customer chooses to process in the platform.

Data: names, email addresses, contact details, calendar and meeting data, file content, messages, and login/user-administration data. The customer decides what data is placed into the platform.

4. Processor obligations

Confidentiality: everyone with access to personal data is bound by confidentiality.

Security: dezky implements appropriate technical and organisational measures under GDPR Art. 32 (see below).

Assistance: dezky helps the customer respond to data-subject requests and comply with Arts. 32–36 (security, breaches and impact assessments).

5. Sub-processors

The customer grants dezky general authorisation to use sub-processors; the current ones are listed below.

dezky imposes the same obligations on sub-processors as in this agreement and gives the customer reasonable notice of changes so the customer can object.

6. International transfers

Content and operational data is hosted in the EU (Germany) and is not transferred outside the EU/EEA. dezky has no US parent or subsidiary.

Payment processing is handled by an EU-based sub-processor. Any exceptional transfer to a third country requires a valid basis under GDPR Chapter V.

7. Personal-data breaches

dezky notifies the customer without undue delay and no later than 72 hours after becoming aware of a breach, with the information the customer needs to meet its own obligations.

8. Audits and inspections

dezky makes available documentation to demonstrate compliance, including relevant certifications and audit logs, and allows audits on reasonable notice without unduly disrupting operations.

9. Deletion and return

On termination, dezky deletes or returns all personal data at the customer's choice and deletes existing copies, unless law requires continued storage. The customer can export its data at any time via open standards.

10. Governing law and venue

This agreement is governed by Danish law, and disputes are settled by the Danish courts.

Sub-processors

Hetzner Online GmbHHosting, object storage and backupGermany (EU)
Stripe Payments Europe, Ltd.Billing and payment dataIreland (EU)

Technical and organisational measures

  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Access control with single sign-on and multi-factor
  • ISO 27001-certified operator, Tier III data centres
  • Audit log with 13-month retention
  • Redundant, encrypted backups
  • Customer-held encryption keys (BYOK) on Enterprise
  • Least privilege and segregated environments

Contact

Questions about data processing or to request the signed agreement: privacy@dezky.eu