Data Processing Agreement
This page summarizes the Data Processing Agreement (DPA) that applies automatically to every Kompena account by virtue of the Terms of Service. It governs how we process personal data on your behalf when you connect data sources or use the platform. A signed, full-text copy is available on request for your own compliance records.
1. Roles
Where your connected data sources (store, ad accounts, email platform, analytics) include personal data about your customers, visitors, or staff, you are the data controller and Kompena ApS is the data processor. We process that data solely to provide the platform (computing your growth score, generating recommendations, and, where engaged, delivering execution tasks) and only on your documented instructions as expressed through your use of the product.
2. Subject matter and duration
Processing covers the categories of data described in the Privacy Policy (connected-source metrics and metadata, task-related files and communications) for as long as your account is active, plus the retention periods set out in that policy.
3. Our obligations as processor
- ·Process personal data only as necessary to provide the service and on your instructions.
- ·Ensure personnel with access are bound by confidentiality obligations.
- ·Implement appropriate technical and organizational security measures (Section 5).
- ·Assist you in responding to data-subject requests relating to data you control.
- ·Notify you without undue delay if we become aware of a personal-data breach affecting your data.
- ·Delete or return personal data at the end of the engagement, per the retention schedule in the Privacy Policy.
- ·Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits on reasonable notice.
4. Sub-processors
We engage a limited set of sub-processors to provide the service: infrastructure hosting, and, for text generation in recommendations, an AI provider. Execution-retainer work is delivered by Kompena itself and adds no sub-processor. We maintain a current, public register of every sub-processor at /legal/sub-processors, and will notify customers of new sub-processors with at least 14 days' notice, during which you may object on reasonable data-protection grounds.
Every sub-processor is bound by written terms imposing data-protection obligations equivalent to this DPA, including EU hosting or Standard Contractual Clauses where a transfer outside the EU/EEA is unavoidable.
5. Security measures
- ·Encryption of personal data in transit (TLS 1.2+) and at rest.
- ·Row-level security enforcing per-customer data isolation at the database layer.
- ·Role-based access control and least-privilege access for staff.
- ·Read-only connector scopes, with no write or delete access into your connected accounts.
- ·Logged, auditable access to production data.
- ·Regular access reviews and a documented incident-response process.
6. International transfers
Our primary hosting is within the EU. Where a sub-processor is located outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (or an equivalent adequacy mechanism) as the transfer safeguard, as noted in the sub-processor register.
7. Deletion on request
You may request deletion of your data at any time via account settings or by emailing privacy@kompena.com. On account closure, connected-source data and derived scores are deleted within 30 days; billing records are retained per Section 6 of the Privacy Policy to meet Danish bookkeeping-law requirements.
8. Liability
Liability under this DPA is governed by the limitation-of-liability provisions in the Terms of Service, except where a higher liability is mandated by applicable data-protection law.
9. Requesting a signed copy
If your compliance process requires a signed, full-text DPA (e.g. for a vendor-security review), email legal@kompena.com with your company details and we'll send an executable copy.