LEGAL

Auftragsverarbeitungsvertrag

Zuletzt aktualisiert: 15 June 2026

This data processing agreement (the "Agreement") is entered into between you as the customer ("Data Controller") and Calco ApS ("Data Processor") and forms an addendum to Calco's terms and conditions. The Agreement sets out the Data Processor's processing of personal data on behalf of the Data Controller in accordance with Article 28(3) of the General Data Protection Regulation (GDPR).

1. Subject matter and purpose

Calco processes personal data on behalf of the Data Controller for the purpose of delivering the Calco service, including offer generation and related features. The processing is carried out solely to make the features of the service available to the Data Controller and in accordance with the terms and this Agreement. The processing continues for as long as the Data Controller uses the service.

2. Categories of personal data and data subjects

  • Personal data of end customers and contacts: name, address and contact details (email, phone)
  • The content of offers, including task descriptions and images and PDF files uploaded by the Data Controller that may contain personal data
  • The Data Controller's own employees (users): name, email, phone and user activity in the service
  • API keys for the Data Controller's chosen order system (encrypted) - Apacta today (Minuba and Ordrestyring coming soon)

3. The Data Controller's instructions

Calco processes personal data only on documented instructions from the Data Controller, including with regard to transfers to third countries, unless required to do so by EU or Danish law. The instructions are constituted by this Agreement, the terms and the Data Controller's use of the service. Calco immediately informs the Data Controller if Calco considers that an instruction infringes data protection law.

4. Confidentiality

Calco ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is granted only to persons for whom it is necessary in order to fulfil Calco's obligations.

5. Security of processing

Calco implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32, including encryption in transit (TLS 1.2 or later), encryption of API keys and other sensitive credentials via AES-256 (pgcrypto), access control and row-level security in the database, and logging of access and events.

6. Sub-processors

The Data Controller hereby grants general authorisation for Calco to use the following sub-processors:

  • Supabase (database and authentication, EU)
  • Cloudflare (hosting and CDN, EU/global)
  • Anthropic PBC (AI generation of offers, USA)
  • Stripe (payment, EU/USA)
  • Resend (email delivery)
  • The order system that the Data Controller chooses to connect (Apacta, Minuba or Ordrestyring)

Calco gives at least 30 days' prior notice of changes to its use of sub-processors, and the Data Controller may object to the change. Transfers to the USA (Anthropic, Stripe) are made on the basis of the European Commission's Standard Contractual Clauses (SCC) and/or adherence to the EU-US Data Privacy Framework. Calco enters into a written agreement with each sub-processor imposing the same data protection obligations as set out in this Agreement, and Calco remains liable for the sub-processors' compliance with those obligations.

7. Assistance with data subjects' rights

Calco assists the Data Controller, insofar as this is possible, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights, including access, rectification, erasure, restriction, data portability and objection.

8. Assistance with security, breaches and impact assessments

Calco assists the Data Controller in ensuring compliance with the obligations under Articles 32-36, including security of processing, notification of personal data breaches to the supervisory authority and the data subjects, data protection impact assessments (DPIA) and prior consultation of the supervisory authority, taking into account the nature of the processing and the information available to Calco.

9. Personal data breach

Calco notifies the Data Controller without undue delay after becoming aware of a personal data breach. The notification contains the relevant information about the breach, including the nature of the breach, the categories of data and data subjects affected, the likely consequences and the measures taken or proposed to be taken.

10. Termination and deletion

On termination of the service, Calco, at the choice of the Data Controller, deletes or returns all personal data no later than 30 days after termination and deletes existing copies, unless EU or Danish law requires continued storage of the personal data.

11. Audit and inspection

Calco makes available to the Data Controller all information necessary to demonstrate compliance with the obligations in this Agreement and allows for and contributes to audits, including inspections, conducted by the Data Controller or another auditor mandated by the Data Controller.