Data processing agreement
Last updated: 28 August 2026
This is a translation provided for convenience. If there is any discrepancy, the Danish version is the authoritative text. Read the Danish version.
This agreement is entered into between the customer (controller) and Kodebaze ApS, Vesterbrogade 74, 1620 København V, company reg. no. 45775976 (processor), and covers the processor's processing of personal data on behalf of the controller in the Kodeleads service.
1. Purpose and scope
The processor processes personal data solely on documented instruction from the controller, for the purpose of delivering Kodeleads: receiving leads, sending SMS and email, and handling the pipeline, bookings and newsletters.
2. Categories of data subjects and data
- Data subjects: the controller's leads, customers and staff with access to the system.
- Data: name, phone number, email address, company, job title, ad name, consent status, message content, call outcomes, meeting bookings and notes.
- No special categories of personal data (sensitive data) are processed.
3. The processor's obligations
- Processes only on instruction, and notifies the controller if an instruction is considered to conflict with data protection law.
- Ensures that persons with access are bound by confidentiality.
- Implements the technical and organisational security measures set out in section 5.
- Assists the controller in responding to requests from data subjects, and with security, breach notification and impact assessments.
- Notifies the controller without undue delay and no later than 24 hours after becoming aware of a security breach.
4. Sub-processors
The controller gives general authorisation for the use of sub-processors. Changes are announced with 30 days' notice, during which the controller may object. Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting provider | Running the application and database | EU |
| Supabase | Database hosting | EU |
| Postmark | Sending email | EU/USA (SCC) |
| GatewayAPI | Sending and receiving SMS | EU |
| Stripe | Payments and subscription | EU/USA (SCC) |
5. Security measures
- Encryption of data in transit (TLS) and of sensitive tokens at rest.
- Logical separation of each customer's data, enforced on every query.
- Access control with role based permissions and passwordless login (one time links).
- Logging of administrative and sensitive actions.
- Ongoing security patching of the platform and its dependencies.
- Daily backup with storage in the EU.
6. Transfer to third countries
Processing takes place in the EU and EEA as a starting point. Where a sub-processor processes data outside the EU and EEA, this takes place on the basis of the European Commission's standard contractual clauses (SCC) supplemented by relevant measures.
7. Assistance, audit and documentation
The processor makes available the information necessary to demonstrate compliance, and allows for an audit conducted by the controller or an independent auditor on reasonable notice. The controller bears the cost of the audit.
8. Deletion on termination
On termination of the agreement the processor deletes all personal data no later than 90 days after termination, unless legislation requires continued storage. The controller may export their data beforehand.
9. Signature
The agreement is accepted as part of the terms of service when a subscription is created. If you would like a signed copy, contact hi@kodeleads.com.