Skip to content

1. Purpose and parties

This data processing agreement (DPA) is Windfeld Jensen Co.'s standard terms for processing personal data on behalf of the customer in connection with LCAB.

• Controller: the customer (the legal entity that contracts LCAB and determines purposes/means for the customer's content) • Processor: Windfeld Jensen Co., CVR 46591054, Lyngbyvej 83A, 2100 Copenhagen, Denmark

By accepting the LCAB terms, buying a subscription, or other written acceptance, the DPA is considered entered into between the parties, unless a separately signed DPA is agreed.

The DPA is prepared with GDPR Article 28 in mind.

2. Background and order of precedence

When the customer uploads personal data into LCAB (for example employee accounts, supplier contacts, documents, saved chats), Windfeld Jensen Co. typically processes that data as processor.

For Windfeld Jensen Co.'s own purposes (for example billing, account administration with us, security logging of the service), Windfeld Jensen Co. may be an independent controller. That is described in the privacy policy (/privacy).

If the DPA and the privacy policy conflict on processing on behalf of the customer, the DPA applies.

3. Subject matter and duration

The processor processes personal data to deliver LCAB, including hosting, storage, backup, access control, support, security, and, when the customer uses it, Haddock or other AI-assisted text.

Processing lasts while the customer has an active account/subscription, and for a reasonable period afterwards for deletion, export, or legally required retention.

4. Nature and purpose

Processing typically consists of:

• Storing and displaying the customer's content in LCAB • User administration and access control • Operations, monitoring, and debugging • Support at the customer's request • Backup and restore • Delivering reports/export after the customer's use • Processing chat and page context to produce a Haddock answer when the customer uses the feature

The processor does not use the customer's content for its own marketing, and does not use it to train an LCAB language model.

5. Types of personal data

Depending on the customer's use, the following types may occur:

• Name, email, phone, job title • User identifiers and role information • Supplier and partner contacts • Information in documents and free-text fields uploaded by the customer • Saved chat messages • Technical log data linked to users

The customer must not upload special categories of personal data (GDPR Article 9) or national identification numbers unless that is strictly necessary and agreed in writing.

6. Categories of data subjects

Data subjects may include:

• The customer's employees and partners with access to LCAB • Contact persons at suppliers and partners • Other people the customer chooses to enter data about

The customer is responsible for a lawful basis toward the data subjects.

7. Customer instructions

The processor processes personal data only on documented instructions from the customer, unless EU or Danish law requires otherwise.

Use of LCAB under these terms and the customer's configuration in the platform constitutes instructions on storage, access, deletion, and, when the customer opens Haddock, on sending necessary context to the connected language model.

If an instruction is, in the processor's assessment, contrary to the GDPR, the processor informs the customer.

8. Processor obligations

The processor shall:

• Process data confidentially and limit access to people who need it • Implement appropriate technical and organisational security measures • Assist the customer in fulfilling data subject rights, to the extent possible in LCAB • Notify the customer without undue delay of a personal data breach • Delete or return personal data at the end of the service at the customer's choice, unless law requires retention • Make information available to demonstrate compliance with Article 28 • Not engage sub-processors outside the framework described below

9. Sub-processors

The customer gives general authorisation for Windfeld Jensen Co. to use sub-processors to deliver LCAB.

Key sub-processors may include:

• Render (hosting and database) • Resend (email) • Google Gemini (cloud language model when the customer uses Haddock or other AI)

Stripe may process payment data as an independent controller.

For material changes in sub-processors, Windfeld Jensen Co. aims to inform the customer with reasonable notice so the customer can object on legitimate data protection grounds.

The processor enters into agreements with sub-processors that impose equivalent data protection obligations.

10. International transfers

If processing takes place outside the EU/EEA, the processor ensures a valid transfer basis (for example standard contractual clauses) when that is required.

Primary application hosting is aimed at the EU when practical. Use of Google Gemini may involve processing at that provider to produce an answer.

11. Security measures

The processor uses measures including:

• Encrypted transport (HTTPS) • Access control and organisation isolation • Authentication and session protection • CSRF protection, rate limiting, and security headers • Logging of relevant security events • Limited internal access on a need-to-know basis • Backup and restore procedures in the cloud environment

Further description: /security

12. Personal data breach

On a personal data breach, the processor notifies the customer without undue delay after becoming aware of the breach, with the information that can reasonably be given at the time (nature, possible consequences, measures).

The customer is responsible for any notification to the Danish Data Protection Agency and to data subjects, unless law or agreement says otherwise.

13. Assistance and audit

The processor assists the customer reasonably with information needed to comply with Articles 28 and 32-36, taking the nature of the processing into account.

The customer may at most once a year (or on reasoned suspicion of material breach) request documentation of security measures. A physical audit is agreed separately and may require a confidentiality agreement and coverage of reasonable costs if the audit goes beyond standard documentation.

14. Deletion and return

When the service ends, the processor deletes or anonymises personal data in the customer's LCAB environment after a reasonable period, unless the customer has exported data before then, or law requires longer retention.

Technical backups may exist for a limited period until they expire under normal backup cycles.

Saved Haddock conversations are deleted together with other account data. Temporary chat is not stored in the database.

15. Liability

Each party is responsible for its own obligations under the GDPR.

Liability limits in the LCAB terms (/terms) also apply to claims linked to this DPA, to the extent the law allows.

The processor is not liable for the customer's own unlawful instructions or for content the customer uploads in breach of law.

16. Governing law

This DPA is governed by Danish law. Disputes are decided as set out in the terms (/terms).

Questions about the DPA and processing can be sent to info@windfeldjensen.com

Windfeld Jensen Co. · CVR 46591054 · 23 97 94 91
Lyngbyvej 83A, 2100 København Ø