Data processing agreement
HEADQUARTER data processing terms
Effective 21 September 2026
Position of the parties
HEADQUARTER is operated by Polymer Workshop ApS for its own business. The company is the data controller for the personal data the application processes, and there is no external customer on whose behalf it acts. In that ordinary case these terms have no counterparty and nothing below applies.
Where the company is nonetheless given access to personal data that another party controls, for example an accounting agreement whose data the company reads on that party’s instruction, the company acts as processor for that data and the following terms apply between that party as controller and Polymer Workshop ApS as processor.
Subject matter and duration
The company processes the controller’s personal data only to operate order fulfilment and to confirm the invoicing status of orders, for as long as the controller’s access grant remains in place. The categories of data and data subjects are those set out in the privacy policy published at /legal/privacy.
Instructions
The company processes the controller’s personal data only on the controller’s documented instructions, including on transfers to a third country, unless required to do otherwise by EU or member-state law, in which case it informs the controller before processing unless that law forbids it. Granting the application access to a system is an instruction to read and process the data needed for the purpose above. The company informs the controller if it considers an instruction to breach data protection law.
Confidentiality
Everyone authorised to process the controller’s personal data is bound by a duty of confidentiality, and access is limited to those who need it for the purpose above.
Security
- Credentials and API keys are held in a secrets store, never in application code or in a repository.
- Data is encrypted in transit and at rest by the underlying platform providers.
- Access to production systems requires an individual account with multi-factor authentication.
- Data belonging to one controller is isolated from any other, and access is enforced at the database level.
- Application and data-access changes are reviewed before release, and security reviews are run against the codebase on a recurring basis.
Sub-processors
The controller gives general authorisation for the sub-processors listed in the privacy policy at /legal/privacy. The company imposes the same data protection obligations on each sub-processor and remains liable for their performance. The company gives the controller notice of an intended addition or replacement, and the controller may object.
Assistance to the controller
Taking into account the nature of the processing, the company assists the controller with appropriate technical and organisational measures in answering requests from data subjects, and assists with data protection impact assessments and prior consultation where those are required.
Personal data breach
The company notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data, with the information the controller needs to meet its own notification obligations.
Return and deletion
On termination of the access grant the company deletes or returns the controller’s personal data, except where EU or member-state law requires it to be kept. Danish bookkeeping law requires accounting records to be kept for five years from the end of the financial year they belong to, and that data is retained for that period and no longer.
Audit
The company makes available the information needed to demonstrate compliance with these terms and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates.
Transfers
Processing takes place in the EU. Where a sub-processor processes personal data outside the EU and EEA, the transfer relies on the European Commission’s standard contractual clauses or an adequacy decision.
Contact
info@polymerworkshop.com