Data processing agreement
Last updated 29 September 2026
1. Parties and roles
This agreement is between enkelt.design (CVR 45871290), Lille Bygade 13, 2635 Ishøj, Denmark ("we"), and a customer that uses StatOSS for a business ("you"). It is part of the terms and needs no signature.
You are the controller and we are the processor of the personal data in your account. For account and billing data we are the controller; see the privacy page.
2. The processing
- Purpose: providing StatOSS as described in the terms.
- Data subjects: your team, your subscribers, the people you let see a private page, and people named in your content.
- Data: names, email addresses, subscribers' choices, chat channels and webhook addresses, session IP addresses and browsers, and content you add. Do not add special categories of data.
- Duration: while your account exists, then as in section 9.
3. Instructions
We process the data only on your documented instructions: the terms, your settings, and your use of the dashboard and API. We tell you if we believe an instruction breaks the law, and before any processing the law requires of us, unless the law forbids it.
4. Confidentiality and security
Everyone who processes the data for us is bound to confidentiality. We apply the measures on the security page and do not reduce their level of protection.
5. Subprocessors
You authorise the companies on the subprocessors page. Each is bound by a data processing agreement meeting Article 28(4) GDPR, and we remain liable for them. We list a new subprocessor 30 days before it starts and email account owners. You may object by email; if we cannot resolve the objection, you may end the service and we refund unused time.
6. Transfers
Transfers outside the EEA rely on the EU-US Data Privacy Framework or Standard Contractual Clauses, as listed on the subprocessors page.
7. Assistance
We help you respond to data subject requests, with the export and deletion tools and by email, and with security, breach notification, impact assessments and consultation with supervisory authorities.
8. Breaches
We notify you of a personal data breach without undue delay and within 72 hours of discovery, with the facts known, and update you as we learn more.
9. Deletion
You can export your data at any time. Deleting a page or the account removes it at once, bounced-mail records within 30 days and backups within 16 days. If we close your account or the service ends, you have 30 days to export before we delete. We keep only what the law requires.
10. Audits
We provide the information needed to show compliance: this agreement, the security page and answers to reasonable security questionnaires. An independent auditor bound by confidentiality may audit us once a year, at your cost, with 30 days notice.
11. Liability and law
Liability is limited as in the terms. Danish law applies. On personal data, this agreement prevails over the terms.