Data processing agreement.
Last updated: 13 August 2026 · Forms part of the terms of service
This agreement is between you (the controller) and AddonNordic ApS, CVR 46495985, Denmark (the processor). It applies whenever we process personal data on your behalf, and it takes effect when you create an account. It is written to satisfy Article 28(3) of the GDPR, and the sections below follow that article’s requirements in order.
1. Subject matter, duration, nature and purpose
Subject matter: retrieving, storing and monitoring information published by official business registers and sanctions lists about companies you select.
Duration: for as long as you have an account, plus the deletion period in section 10.
Nature and purpose: automated retrieval, comparison over time, alerting, and producing an exportable record, so that you can meet due-diligence and anti-money-laundering obligations.
2. Categories of data and data subjects
Data subjects: individuals named in public business registers in connection with the companies you monitor — typically directors and other officers, and beneficial owners where a register publishes them.
Categories of data: name, role, appointment and resignation dates, registered address, and where published, nationality, year of birth and extent of ownership or control. Also any match records arising from sanctions and PEP screening.
We do not process special categories of data under Article 9. Sanctions and PEP screening results are not a criminal-convictions record: they indicate that a name resembles an entry on a published list, nothing more.
3. Processing only on your instructions
We process personal data only on your documented instructions. Your use of the service — the companies you add, the monitoring you enable, the exports you take — constitutes those instructions. We will tell you if we believe an instruction breaches data protection law. If we are required by EU or member-state law to process data otherwise, we will inform you first unless that law prohibits it.
We do not use your data for our own purposes, do not sell it, and do not use it to train machine-learning models.
4. Confidentiality
Everyone we authorise to process your data is bound by confidentiality and only has access where it is necessary for their work.
5. Security measures
We take appropriate technical and organisational measures under Article 32, including: data transmitted over encrypted connections and stored on encrypted storage; access to production data restricted to those who need it; credentials for upstream registries held server-side only and never present in any client; each customer’s data separated and access checked on the server for every request; and logging that lets us investigate an incident.
We hold no security certification, and our security page states that plainly rather than leaving you to discover it.
6. Assisting you
We will help you respond to requests from data subjects exercising their rights, and assist with your obligations under Articles 32 to 36 — security, breach notification, and data protection impact assessments — taking into account the nature of the processing and the information available to us. If a data subject contacts us directly about data you monitor, we will pass it to you rather than acting on it ourselves.
7. Subprocessors
You give general authorisation for us to engage the subprocessors listed at /subprocessors. That page is part of this agreement. We impose data protection obligations on each of them no less protective than those in this agreement, and we remain fully liable to you for their performance.
We will publish an intended addition or replacement on that page and notify account holders by email before it takes effect. If you object on reasonable data protection grounds, tell us; if we cannot resolve it, you may terminate the affected part of the service and receive a refund for the unused period.
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and give you the information you need to meet your own notification obligations: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. We will not wait until we have a complete picture before telling you.
9. International transfers
Monitoring data and account records are processed and stored in the EU. One subprocessor — our email provider — sends from Ireland but stores its delivery logs in the United States; that transfer is covered by the European Commission’s standard contractual clauses and is recorded on the subprocessors page. Any future transfer outside the EU or EEA will be handled the same way: an appropriate mechanism in place, and named on that page before it takes effect.
10. Deletion and return
You can export your data at any time while your account is open — the audit trail export is a feature of the service, not something you have to request. When your account ends, we delete the personal data we process on your behalf within 30 days, except where EU or member-state law requires us to keep it, such as invoicing records under accounting rules.
11. Audits
We will make available the information needed to demonstrate compliance with Article 28 and allow for audits by you or an auditor you mandate. In practice we ask that you write to us first: most questions are answered by this agreement, the security page and the subprocessor list, and an on-site audit of a company of our size is rarely the fastest route to the answer you need.
12. Contact and changes
Write to contact@addonnordic.dk for anything under this agreement, including a countersigned copy if your procurement process requires one. If we change this agreement in a way that affects you, we will notify account holders by email and update the date at the top.