Back to Home

    Data Processing Agreement

    Lernaura ApS • CVR 46170164 • Denmark

    Version 1.0 • Effective: 29.04.2026

    These are the terms of the Data Processing Agreement between the Customer (Data Controller) and Lernaura ApS, CVR 46170164, Vesterbrogade 82 2 th, 1620 Copenhagen V, Denmark (Data Processor) as referenced in the Lernaura Seller Agreement (or applicable Master Services Agreement, the "Services Agreement") entered into by the Parties.

    1. Data Processing Agreement preamble

    1.1 This Data Processing Agreement sets out the rights and obligations that apply to the Data Processor's handling of personal data on behalf of the Data Controller.

    1.2 This Agreement has been designed to ensure the Parties' compliance with Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), which sets out specific requirements for the content of data processing agreements.

    1.3 The Data Processor's processing of personal data shall take place for the purposes of fulfilment of the Lernaura Services Agreement, accepted by the Customer by entering into the Services Agreement or by accessing or using the respective software or service.

    1.4 Scope. This Data Processing Agreement applies solely to the processing activities in which Lernaura acts as a processor on behalf of the Customer (the "Processor Activities"). Where Lernaura acts as an independent data controller in its capacity as Merchant of Record — including, without limitation, in respect of the sales transaction with the buyer, payment authorisation, tax determination and remittance, fraud and chargeback prevention, KYC/KYB and statutory records (accounting, tax, anti-money-laundering and sanctions compliance) — Lernaura's processing is governed by Lernaura's Privacy Statement and applicable law, and not by this Data Processing Agreement. Where Lernaura and the Customer are joint controllers in respect of a defined activity, the joint-controller arrangement is set out in the Services Agreement.

    1.5 This Data Processing Agreement remains in effect as long as the Customer has a valid Services Agreement with Lernaura. This Data Processing Agreement may, however, be replaced by an alternative valid data processing agreement that does not in any material way degrade the terms.

    1.6 This Data Processing Agreement shall take priority over any similar provisions contained in other agreements between the Parties.

    1.7 Three appendices are attached to this Data Processing Agreement. The Appendices form an integral part of this Data Processing Agreement.

    1.8 Appendix A of the Data Processing Agreement contains details about the processing as well as the purpose and nature of the processing, type of personal data, categories of data subject and duration of the processing.

    1.9 Appendix B of the Data Processing Agreement contains the Data Controller's terms and conditions that apply to the Data Processor's use of Sub-Processors and a list of Sub-Processors approved by the Data Controller.

    1.10 Appendix C of the Data Processing Agreement contains instructions on the processing that the Data Processor is to perform on behalf of the Data Controller (the subject of the processing), the minimum security measures that are to be implemented and how inspection of the Data Processor and any Sub-Processors is to be performed.

    1.11 The Data Processing Agreement and its associated Appendices shall be retained in writing, as well as electronically, by both Parties.

    1.12 This Data Processing Agreement shall not exempt the Data Processor from obligations to which the Data Processor is subject pursuant to the General Data Protection Regulation or other legislation.

    2. The rights and obligations of the Data Controller

    2.1 The Data Controller shall be responsible to the outside world (including the data subject) for ensuring that the processing of personal data takes place within the framework of the General Data Protection Regulation.

    2.2 The Data Controller shall therefore have both the right and obligation to make decisions about the purposes and means of the processing of personal data carried out by the Data Processor on its behalf under this Data Processing Agreement.

    2.3 The Data Controller shall be responsible for ensuring that the processing that the Data Processor is instructed to perform is authorised in law, including that the Data Controller has a valid legal basis under the GDPR for any personal data it makes available to the Data Processor through the Services and for any communications, marketing or other activity it instructs the Data Processor to perform.

    3. The Data Processor acts according to instructions

    3.1 The Data Processor shall solely be permitted to process personal data on documented instructions from the Data Controller unless processing is required under EU or Member State law to which the Data Processor is subject; in this case, the Data Processor shall inform the Data Controller of this legal requirement prior to processing unless that law prohibits such information on important grounds of public interest, cf. Article 28(3)(a). The Parties acknowledge that processing required of the Data Processor under applicable accounting, tax, anti-money-laundering, sanctions, payment-services or consumer-protection law in connection with the MoR role falls outside this Data Processing Agreement and is performed by the Data Processor as an independent controller.

    3.2 The Data Processor shall immediately inform the Data Controller if instructions, in the opinion of the Data Processor, contravene the General Data Protection Regulation or data protection provisions contained in other EU or Member State law.

    4. Confidentiality

    4.1 The Data Processor shall ensure that only those persons who are currently authorised to do so are able to access the personal data being processed on behalf of the Data Controller. Access to the data shall therefore without delay be denied if such authorisation is removed or expires.

    4.2 Only persons who require access to the personal data in order to fulfil the obligations of the Data Processor to the Data Controller shall be provided with authorisation.

    4.3 The Data Processor shall ensure that persons authorised to process personal data on behalf of the Data Controller have undertaken to observe confidentiality or are subject to a suitable statutory obligation of confidentiality.

    4.4 The Data Processor shall, at the request of the Data Controller, be able to demonstrate that the employees concerned are subject to the above confidentiality.

    5. Security of processing

    5.1 The Data Processor shall take all the measures required pursuant to Article 32 of the General Data Protection Regulation, which stipulates that, taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing and the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Data Controller and the Data Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

    5.2 The above obligation means that the Data Processor shall perform a risk assessment and thereafter implement measures to counter the identified risk. Depending on their relevance, the measures may include the following:

    a) Pseudonymisation and encryption of personal data.

    b) The ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services.

    c) The ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.

    d) A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

    5.3 The Data Processor shall, in ensuring the above, in all cases as a minimum implement the level of security and the measures specified in Appendix C to this Data Processing Agreement.

    6. Use of Sub-Processors

    6.1 The Data Processor shall meet the requirements specified in Article 28(2) and (4) of the General Data Protection Regulation in order to engage another processor (Sub-Processor).

    6.2 The Data Processor shall therefore not engage another processor (Sub-Processor) for the fulfilment of this Data Processing Agreement without the prior specific or general written consent of the Data Controller.

    6.3 In the event of general written consent, the Data Processor shall inform the Data Controller of any planned changes with regard to additions to, or replacement of, other data processors and thereby give the Data Controller the opportunity to object to such changes.

    6.4 The Data Controller's requirements for the Data Processor's engagement of other Sub-Processors shall be specified in Appendix B to this Data Processing Agreement.

    6.5 The Data Controller's consent to the engagement of specific Sub-Processors, if applicable, shall be specified in Appendix B to this Data Processing Agreement.

    6.6 When the Data Processor has the Data Controller's authorisation to use a Sub-Processor, the Data Processor shall ensure that the Sub-Processor is subject to the same data protection obligations as those specified in this Data Processing Agreement, on the basis of a contract or other legal document under EU law or the national law of the Member States, in particular providing the necessary guarantees that the Sub-Processor will implement the appropriate technical and organisational measures in such a way that the processing meets the requirements of the General Data Protection Regulation.

    The Data Processor shall therefore be responsible – on the basis of a sub-processor agreement – for requiring that the Sub-Processor at least comply with the obligations to which the Data Processor is subject pursuant to the requirements of the General Data Protection Regulation and this Data Processing Agreement and its associated Appendices.

    6.7 A copy of such a sub-processor agreement and subsequent amendments shall, at the Data Controller's request, be submitted to the Data Controller, who will thereby have the opportunity to ensure that a valid agreement has been entered into between the Data Processor and the Sub-Processor. Commercial terms and conditions, such as pricing, that do not affect the legal data protection content of the sub-processor agreement, shall not require submission to the Data Controller.

    6.8 The Data Processor shall, in its agreement with the Sub-Processor, include the Data Controller as a third party in the event of the bankruptcy of the Data Processor, to enable the Data Controller to assume the Data Processor's rights and invoke these as regards the Sub-Processor, e.g. so that the Data Controller is able to instruct the Sub-Processor to perform the erasure or return of data.

    6.9 If the Sub-Processor does not fulfil its data protection obligations, the Data Processor shall remain fully liable to the Data Controller as regards the fulfilment of the obligations of the Sub-Processor.

    7. Transfer of data to third countries or international organisations

    7.1 The Data Processor shall solely be permitted to process personal data on documented instructions from the Data Controller, including as regards transfer (assignment, disclosure and internal use) of personal data to third countries or international organisations, unless processing is required under EU or Member State law to which the Data Processor is subject; in such a case, the Data Processor shall inform the Data Controller of that legal requirement prior to processing unless that law prohibits such information on important grounds of public interest, cf. Article 28(3)(a).

    7.2 Without the instructions or approval of the Data Controller, the Data Processor therefore cannot – within the framework of this Data Processing Agreement:

    a) disclose personal data to a data controller in a third country or in an international organisation;

    b) assign the processing of personal data to a Sub-Processor in a third country;

    c) have the data processed in another of the Data Processor's divisions which is in a third country.

    7.3 The Data Controller's instructions or approval of the transfer of personal data to a third country, if applicable, shall be set out in Appendix C to this Data Processing Agreement.

    8. Assistance to the Data Controller

    8.1 The Data Processor, considering the nature of the processing, shall, as far as possible, assist the Data Controller with appropriate technical and organisational measures, in the fulfilment of the Data Controller's obligations to respond to requests for the exercise of the data subjects' rights pursuant to Chapter 3 of the General Data Protection Regulation.

    This entails that the Data Processor should, as far as possible, assist the Data Controller in the Data Controller's compliance with:

    a) notification obligation when collecting personal data from the data subject;

    b) notification obligation if personal data have not been obtained from the data subject;

    c) right of access by the data subject;

    d) the right to rectification;

    e) the right to erasure ('the right to be forgotten');

    f) the right to restrict processing;

    g) notification obligation regarding rectification or erasure of personal data or restriction of processing;

    h) the right to data portability;

    i) the right to object;

    j) the right to object to the result of automated individual decision-making, including profiling.

    8.2 The Data Processor shall assist the Data Controller in ensuring compliance with the Data Controller's obligations pursuant to Articles 32–36 of the General Data Protection Regulation, taking into account the nature of the processing and the data made available to the Data Processor, cf. Article 28(3)(f).

    This entails that the Data Processor should, taking into account the nature of the processing, as far as possible assist the Data Controller in the Data Controller's compliance with:

    a) the obligation to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk associated with the processing;

    b) the obligation to report personal data breaches to the supervisory authority without undue delay and, if possible, within 72 hours of the Data Controller discovering such breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons;

    c) the obligation, without undue delay, to communicate the personal data breach to the data subject when such breach is likely to result in a high risk to the rights and freedoms of natural persons;

    d) the obligation to carry out a data protection impact assessment if a type of processing is likely to result in a high risk to the rights and freedoms of natural persons;

    e) the obligation to consult with the supervisory authority prior to processing if a data protection impact assessment shows that the processing will lead to high risk in the absence of measures taken by the Data Controller to limit risk.

    8.3 The Parties' possible regulation/agreement on remuneration etc. for the Data Processor's assistance to the Data Controller shall be specified in the Services Agreement or in the applicable Order Form.

    9. Notification of personal data breach

    9.1 On discovery of a personal data breach at the Data Processor's facilities or a Sub-Processor's facilities affecting personal data processed under this Data Processing Agreement, the Data Processor shall, without undue delay, notify the Data Controller.

    The Data Processor's notification to the Data Controller shall, if possible, take place within 24 hours after the Data Processor has discovered the breach, to enable the Data Controller to comply with its obligation, if applicable, to report the breach to the supervisory authority within 72 hours.

    9.2 According to Clause 8.2(b) of this Data Processing Agreement, the Data Processor shall – taking into account the nature of the processing and the data available – assist the Data Controller in the reporting of the breach to the supervisory authority.

    This may mean that the Data Processor is required to assist in obtaining the information listed below which, pursuant to Article 33(3) of the General Data Protection Regulation, shall be stated in the Data Controller's report to the supervisory authority:

    a) the nature of the personal data breach, including, if possible, the categories and the approximate number of affected data subjects and the categories and the approximate number of affected personal data records;

    b) probable consequences of the personal data breach;

    c) measures which have been taken or are proposed to manage the personal data breach, including, if applicable, measures to limit its possible damage.

    10. Erasure and return of data

    10.1 On termination of the processing services, the Data Processor shall be under an obligation, at the Data Controller's discretion, to erase or return all the personal data processed under this Data Processing Agreement to the Data Controller and to erase existing copies, unless EU law or Member State law requires storage of the personal data. The Parties acknowledge that personal data which the Data Processor is required to retain in its capacity as Merchant of Record (including, without limitation, transaction, invoice, payment, KYC/KYB and AML records) is subject to statutory retention periods (including under the Danish Bookkeeping Act / Bogføringsloven and applicable AML legislation) and is not affected by this Clause 10.

    11. Inspection and audit

    11.1 The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with Article 28 of the General Data Protection Regulation and this Data Processing Agreement, and allow for and contribute to audits, including inspections performed by the Data Controller or another auditor mandated by the Data Controller.

    11.2 The procedures applicable to the Data Controller's inspection of the Data Processor are specified in Appendix C to this Data Processing Agreement.

    11.3 The Data Controller's inspection of Sub-Processors, if applicable, shall as a rule be performed through the Data Processor. The procedures for such inspection are specified in Appendix C to this Data Processing Agreement.

    11.4 The Data Processor shall be required to provide the supervisory authorities, which pursuant to applicable legislation have access to the Data Controller's and Data Processor's facilities, or representatives acting on behalf of such supervisory authorities, with access to the Data Processor's physical facilities on presentation of appropriate identification.

    12. Commencement and termination

    12.1 This Data Processing Agreement shall become effective on the date when the Customer accepts the Services Agreement (including by accessing or using the Services).

    12.2 The Data Controller shall be entitled to require this Data Processing Agreement to be renegotiated if changes to the law or inexpediency of the provisions contained herein should give rise to such renegotiation.

    12.3 This Data Processing Agreement is in effect as long as the Services Agreement is in effect, and as long as the Customer is using any software or service that falls under the agreement, irrespective of whether the Services Agreement has terminated while use has not.

    13. Data Controller and Data Processor contacts/contact points

    13.1 The Parties may contact each other using the following contacts/contact points:

    13.2 The Data Processor can be contacted by sending an email to privacy@lernaura.eu.

    13.3 The Data Controller can be contacted by any contact information provided to the Data Processor, and if no contact data specifically related to these terms is available, the Data Processor will contact the Admin users of the software and services in use.

    Appendix A — Information about the processing

    Purpose of the processing

    The purpose of the Data Processor's processing of personal data on behalf of the Data Controller is:

    Lernaura ApS provides a cloud-based Merchant of Record (MoR) platform that enables the Customer (the "Seller") to sell digital products, software, subscriptions and other goods and services to end buyers, with Lernaura acting as the seller of record. Most of Lernaura's processing takes place in Lernaura's capacity as an independent data controller for the MoR transaction (see scope note in the preamble) and is not covered by this Data Processing Agreement. Under this Data Processing Agreement, the Data Processor processes personal data on behalf of the Data Controller solely in connection with the limited Processor Activities, which include: (i) hosting and operating seller dashboards and back-office tools through which the Data Controller stores or manages personal data beyond what is necessary for the MoR role (e.g., custom customer attributes, segmentation data, support metadata, internal notes); (ii) sending transactional or marketing communications to the Data Controller's contacts on the Data Controller's documented instructions and using content supplied or configured by the Data Controller; (iii) hosting personal data the Data Controller uploads, imports or makes available through APIs for purposes other than the conclusion and performance of the MoR sale; and (iv) providing related support, maintenance, hosting, monitoring, backup and incident response in respect of the foregoing.

    Nature of the processing

    The Data Processor's processing of personal data on behalf of the Data Controller shall pertain to (the nature of the processing):

    The processing is performed on systems operated by, or on behalf of, the Data Processor (SaaS). Routine processing activities under this Data Processing Agreement include the collection, storage, structuring, retrieval, use, transmission and erasure of personal data in connection with: (i) the operation of seller dashboards and configuration tools used by the Data Controller; (ii) the sending of communications to the Data Controller's contacts on the Data Controller's instructions; (iii) the hosting of personal data uploaded or imported by the Data Controller for non-MoR purposes; and (iv) the provision of support, maintenance, hosting, monitoring, backup and incident response in respect of the foregoing. Activities performed by the Data Processor in its capacity as Merchant of Record (including payment authorisation and settlement, tax determination and remittance, fraud prevention, KYC/KYB, sanctions screening, statutory reporting and the handling of buyer-facing transactions) fall outside this Data Processing Agreement.

    Types of personal data

    The processing includes the following types of personal data about data subjects:

    The Data Controller determines which data are entered into the Services and the corresponding classification. Subject to the Data Controller's configuration and use, the processing under this Data Processing Agreement may include the following types of personal data: (i) identification and contact data of the Data Controller's contacts (e.g., name, email, phone number, country, company, role); (ii) seller-controlled customer attributes and segmentation data the Data Controller chooses to maintain in the Services beyond what is needed for the MoR role; (iii) marketing preferences, consents and engagement data uploaded or generated by the Data Controller; (iv) support and communication content the Data Controller stores in the Services (e.g., internal notes, attachments, ticket data); (v) account and authentication data of the Data Controller's users (e.g., user names, hashed credentials, role assignments, access logs); and (vi) technical and usage data generated when the Data Controller and its users access the Services (e.g., device and terminal identifiers, IP addresses, logs, telemetry). Categories of Article 9 (special) personal data are not intended to be processed under this Agreement; if the Data Controller nevertheless causes such data to be processed, it does so under its own responsibility and instruction. Personal data processed by the Data Processor in its MoR capacity (including transaction, billing, payment, tax, fraud and KYC data) are not covered by this Data Processing Agreement.

    Categories of data subject

    Typical categories include: the Data Controller's customers, prospects and leads (to the extent the Data Controller stores or manages personal data about them in the Services beyond what is needed for the MoR role); the Data Controller's employees, contractors and admin users (including users of the seller dashboard and back-office tools); and the Data Controller's suppliers and business contacts, together with any other individuals whose personal data are contained in the data the Data Controller uploads or configures in the Services.

    Duration of the processing

    The Data Processor's processing of personal data on behalf of the Data Controller may be performed when this Data Processing Agreement commences. Processing has the following duration:

    Processing shall not be time-limited and shall be performed until this Data Processing Agreement is terminated or cancelled by one of the Parties.

    Appendix B — Terms of the Data Processor's use of Sub-Processors and list of approved Sub-Processors

    B.1 Approved Sub-Processors

    On commencement of the Services Agreement, the Data Controller authorises the engagement of the Sub-Processors listed on the Lernaura website: www.lernaura.eu/compliance/sub-processors (or such other URL as Lernaura may notify). Typical categories of Sub-Processors engaged by Lernaura in connection with the Processor Activities include: cloud infrastructure and hosting providers, communication and notification providers (e.g., transactional email and SMS providers), customer support and ticketing tools, monitoring and logging tools, and backup providers.

    For information, Lernaura also engages additional categories of providers in its capacity as independent controller for the MoR role, including payment service providers and card networks, acquiring banks, tax determination and filing engines, KYC/KYB and identity verification providers, fraud and risk decisioning platforms, electronic invoicing platforms and accounting systems. Those providers are not Sub-Processors of the Data Controller under this Data Processing Agreement; they are listed on Lernaura's sub-processor page for transparency only and are governed by Lernaura's Privacy Statement and the Services Agreement.

    The Data Controller shall, on the commencement of the Services Agreement, authorise the use of the abovementioned Sub-Processors for the processing described under this Data Processing Agreement.

    B.2 Prior notice for the authorisation of Sub-Processors

    The Data Processor has the Data Controller's general authorisation for the engagement of Sub-Processors. The Data Processor shall inform the Data Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 30 days in advance, thereby giving the Data Controller the opportunity to object to such changes prior to the engagement of the concerned Sub-Processor(s).

    Future changes and amendments to the use of Sub-Processors will appear on the Data Processor's website: www.lernaura.eu.

    Appendix C — Instruction pertaining to the use of personal data

    C.1 The subject of/instruction for the processing

    The Data Processor's processing of personal data on behalf of the Data Controller shall be carried out by the Data Processor performing the following:

    Lernaura provides a SaaS Merchant of Record platform together with related hosting, maintenance, support and professional services. Under this Data Processing Agreement, the Data Processor processes personal data on the Data Controller's behalf in order to: (i) host and operate the Data Controller's seller dashboards and back-office tools; (ii) send communications to the Data Controller's contacts on the Data Controller's documented instructions; (iii) host personal data uploaded or imported by the Data Controller for non-MoR purposes; and (iv) provide support, troubleshooting, monitoring, backup and incident response in respect of the foregoing. All such processing is performed on the documented instructions of the Data Controller as set out in this Data Processing Agreement, the Services Agreement and the applicable Order Form. Activities performed by the Data Processor in its capacity as Merchant of Record fall outside this Data Processing Agreement and are not subject to the Data Controller's instructions.

    C.2 Security of processing

    The level of security shall reflect:

    That the processing is performed as a SaaS with internet-facing components, may involve substantial volumes of personal data across many of the Data Controller's contacts and users and is operated as part of a wider platform that also processes payment, fraud-prevention and KYC data in the Data Processor's MoR capacity; accordingly, a 'high' level of security shall be established. The Data Processor shall, where applicable, comply with the Payment Card Industry Data Security Standard (PCI-DSS) requirements relevant to its role in the payment flow, with full card data being handled by PCI-DSS-compliant payment service providers rather than stored in the Data Processor's systems. The Data Processor shall, as a minimum, implement: access controls and least-privilege provisioning; multi-factor authentication for administrative access; encryption of personal data in transit and at rest; segregation of customer environments; logging, monitoring and alerting; vulnerability management and regular penetration testing; secure software development practices; supplier security review; a documented incident response plan; and personnel screening, training and confidentiality obligations.

    The Data Processor shall hereafter be entitled and under obligation to make decisions about the technical and organisational security measures that are to be applied to create the necessary (and agreed) level of data security.

    C.3 Storage period / erasure procedures

    Personal data processed by the Data Processor on behalf of the Data Controller under this Data Processing Agreement are stored in the Data Processor's systems for the duration of the Data Controller's use of the Services. On the Data Controller's request, or on termination of the Services, the Data Processor shall erase or return all such personal data in accordance with Clause 10, except where EU or Member State law requires further storage. Backup copies are erased in accordance with the Data Processor's documented backup rotation. Personal data which the Data Processor processes in its capacity as Merchant of Record (including, without limitation, transaction, invoice, payment, KYC/KYB, AML and sanctions records) are retained as required by the Danish Bookkeeping Act (Bogføringsloven), applicable foreign tax law, applicable AML legislation and card-network rules; those retention periods are not affected by this Data Processing Agreement.

    C.4 Instruction for or approval of the transfer of personal data to third countries

    If the Data Controller does not, in this clause or by subsequent written notification, provide instructions or consent pertaining to the transfer of personal data to a third country, the Data Processor shall not be entitled, within the framework of this Data Processing Agreement, to perform such transfer. Where the Data Processor transfers personal data to a Sub-Processor outside the EU/EEA, the Data Processor shall rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) and carry out transfer impact assessments where required.

    C.5 Procedures for the Data Controller's inspection of the processing being performed by the Data Processor

    The Data Controller or the Data Controller's representative shall have access to inspect, including to physically inspect, the processing at the Data Processor's facilities when the Data Controller deems that this is required. Where the Data Processor maintains independent third-party assurance reports (e.g., ISO 27001, SOC 2 Type II) covering the relevant Processor Activities, the Data Controller shall accept such reports as primary means of demonstrating compliance and shall limit on-site inspections to issues that cannot reasonably be addressed through such reports.

    The Data Controller's costs, if applicable, relating to physical inspection shall be defrayed by the Data Controller. The Data Processor shall, however, be under an obligation to set aside the resources (mainly time) required for the Data Controller to be able to perform the inspection.

    The Data Processor must ensure logging. The log must be readable by the Data Controller. The log shall also be made available to the Data Controller. In addition, the log must be version controlled.

    — End of Agreement —

    Last Updated: April 29, 2026