Legal
Data Processing Agreement
This Data Processing Agreement governs Sonardeck's processing of personal data on behalf of the company or organisation using the service as controller.
This agreement becomes binding when referenced in an order, subscription agreement or other written agreement between the parties. The customer's identity and contact details are those in that agreement or the Sonardeck workspace.
1. Parties and order of precedence
The processor is Redefine v/Morten Bang Justesen, Danish company registration no. 30270444, Denmark, which supplies Sonardeck. The controller is the customer identified in the agreement, order or workspace referring to this Data Processing Agreement.
This DPA supplements the parties' principal agreement for Sonardeck. If terms conflict, this DPA prevails for the processing of personal data. Changes must be in writing unless made under the agreed change mechanism.
2. Subject matter, duration and purpose
Sonardeck processes information to host, organise, display, search, export, secure and otherwise provide CRM, recruitment, time recording and related features selected and instructed by the customer.
Processing continues while the principal agreement is in force and during the subsequent period required to return or delete data. Annex A describes the nature, categories and data subjects in more detail.
3. Documented instructions
Sonardeck processes personal data only on the customer's documented instructions, including the customer's configuration and use of the service, unless EU or Danish law requires otherwise. In that event, Sonardeck informs the customer before processing unless prohibited by law.
If Sonardeck considers an instruction to infringe data protection law, it will notify the customer without undue delay and may suspend the instruction until clarified. The customer is responsible for the lawfulness of its instructions, notices to data subjects and a valid legal basis.
4. Confidentiality
Sonardeck ensures that people with access to the data are authorised, instructed and bound by contractual or statutory confidentiality. Access is limited to what each person's duties require.
5. Security of processing
Sonardeck implements and maintains technical and organisational measures appropriate under GDPR Article 32, considering the nature of processing, costs, state of the art and risks. Annex B describes the current principal measures.
The customer must use the service's access controls responsibly, keep user access current, protect credentials and avoid entering information the service is not agreed or suitable to process.
6. Subprocessors
The customer grants general written authorisation for subprocessors. Sonardeck ensures they are bound by data protection obligations substantially equivalent to this DPA and remains liable for their performance as required by the GDPR.
Sonardeck gives at least 30 days' notice of material additions or replacements, normally by email or through the service. The customer may object on reasonable data protection grounds before the change. The parties will seek a reasonable solution; if none is available, the customer may terminate the affected service under the principal agreement. Annex C contains the current list.
7. International transfers
Sonardeck transfers personal data outside the EU/EEA only on the customer's documented instruction and with a valid GDPR Chapter V mechanism. Where relevant, this includes the European Commission's Standard Contractual Clauses, a transfer assessment and supplementary safeguards.
The customer authorises Sonardeck to enter into any necessary Standard Contractual Clauses with an approved subprocessor on the customer's behalf.
8. Assistance to the customer
Taking account of the nature of processing, Sonardeck assists the customer through appropriate technical and organisational measures with requests to exercise data subject rights. Sonardeck forwards requests received directly and does not respond on the customer's behalf without instructions.
Sonardeck also provides reasonable assistance with security, breach notifications, impact assessments and prior consultation under GDPR Articles 32–36. Assistance beyond normal service features may be charged as agreed unless required because of Sonardeck's breach.
9. Personal data breaches
Sonardeck notifies the customer without undue delay after becoming aware of a personal data breach affecting data processed for that customer. The notice includes available information about the nature of the breach, affected categories and approximate numbers, likely consequences, contact point, and measures taken or proposed. Information may be provided in phases.
The customer is responsible for assessing and making any notification to a supervisory authority or communication to data subjects. Sonardeck documents breaches and cooperates with the customer's response.
10. Return and deletion
The customer may use the service's export features while the agreement is active. At termination and at the customer's choice, Sonardeck deletes or returns the customer's personal data and deletes existing copies unless applicable law requires continued storage.
Data in backups is isolated from ordinary operations and overwritten according to the backup schedule. Sonardeck may retain a limited audit trail where necessary to document security, deletion or legal claims, provided it remains protected and is not used for other purposes.
11. Documentation and audits
Sonardeck provides information necessary to demonstrate compliance with Article 28 and contributes to reasonable audits. The customer must first use available documentation and questionnaires.
Any further audit requires at least 30 days' notice, takes place during normal business hours, is limited to relevant systems and must not compromise other customers' data or security. The customer bears reasonable costs unless the audit shows a material breach. Regulatory requirements and serious incidents may justify shorter notice.
12. Liability and term
The parties' liability is governed by the GDPR and the liability limitations in the principal agreement to the extent those limitations lawfully apply. Sonardeck notifies the customer if it can no longer comply with this DPA and takes reasonable steps to remedy the issue.
This DPA remains effective for as long as Sonardeck processes personal data on the customer's behalf. Confidentiality, deletion, documentation and liability provisions survive where their nature requires. Danish law and the venue specified in the principal agreement apply.
13. Annexes: processing, security and providers
These tables form part of the DPA. Features the customer does not activate or use are excluded from actual processing. The provider list describes the planned production setup and is updated under clause 6.
| Area | Description |
|---|---|
| Data subjects | Customer users and employees; contacts at customer organisations; candidates, applicants and references; other people entered by the customer. |
| Data | Identity and contact data, organisation and job data, CVs and application materials, notes and assessments, communications, consent, activities and audit trails, time and call data, and technical identifiers. |
| Special categories | Not intended by default. They may be processed only where the customer has a lawful basis, provides documented instructions and applies suitable safeguards. The customer must not enter national identity numbers, payment card data or criminal-offence data without a separate written agreement. |
| Operations | Collection, recording, organisation, storage, search, display, alteration, sharing selected by the customer, export, restriction, encryption, anonymisation and deletion. |
| Frequency and duration | Continuously according to the customer's use during the principal agreement and until agreed return or deletion is complete. |
| Area | Measures |
|---|---|
| Access | Unique users, external authentication, role- and workspace-based authorisation, least privilege and the ability to remove access. |
| Encryption | TLS/HTTPS in transit; uploaded CVs encrypted using AES-256-GCM before object storage; secrets kept outside source code. |
| Isolation and traceability | Logical separation between workspaces, authorisation checks on API calls, audit logging and integrity protection for key audit information. |
| Availability | Controlled database and object-storage backups, recovery procedures, monitoring and operational incident handling. |
| Secure development | Version control, automated tests, dependency updates, restricted production access and vulnerability and incident handling. |
| Deletion | Anonymisation of candidate data, controlled deletion of objects and backup overwrite under the applicable backup schedule. |
| Provider | Purpose | Processing location / note |
|---|---|---|
| Hetzner | Server hosting, database, object storage and backups | EU/EEA; production data is placed in an agreed European region. |
| Logto | Authentication and user identity | Self-hosted in Sonardeck's European infrastructure where that setup is used. |
| Resend | Delivery of invitation, verification and consent emails | May involve processing outside the EU/EEA; a valid transfer mechanism is used. |
| Swetrix | Cookie-free, anonymised analytics and error events | Self-hosted in Sonardeck's European infrastructure; identifying customer data must not be sent. |
| ntfy | Internal operational notification when a workspace is created | Minimum information only, normally organisation name without the user's email; may be disabled or self-hosted. |