OpenAjan

Data processing agreement

Data processing agreement (GDPR art. 28) between the Merchant (controller) and Otonom, CVR 46779274 (processor). Accepted at shop sign-up.

1. Instruction and purpose

The processor processes personal data only on the Merchant's instruction: receiving and relaying orders/bookings, sending confirmations to the customer, showing orders in the order screen/panel, keeping order history for billing.

2. Data and data subjects

Customers' name, phone, email, order contents, requested time, note. Data subjects: the Merchant's customers.

3. Confidentiality and security

Access only for necessary persons under confidentiality. Technical measures: TLS, access control and 2FA on administration, signed webhooks, rate limiting, logging, daily backups, deletion after retention.

4. Sub-processors

Simply.com A/S (hosting, email, DK); GatewayAPI ApS (SMS, DK/EU) if enabled; Stripe Payments Europe Ltd. (payments, IE/EU) if enabled. New sub-processors are announced 30 days ahead; the Merchant may object and terminate.

5. Assistance

The processor assists with data-subject requests, security, breaches and impact assessments where relevant.

6. Breaches

Notified to the Merchant without undue delay and at the latest 48 hours after the processor became aware, with the information the Merchant needs for the supervisory authority.

7. Transfers

No transfers outside the EU/EEA without a valid basis.

8. Deletion and audit

On termination personal data is deleted or returned at the Merchant's choice unless law requires retention. The Merchant may request compliance documentation once a year.

9. Duration

While the shop exists on OpenAjan.

Version 17. september 2026. Based on the Danish DPA's standard template.