Data Processing Agreement
Last updated: 17 September 2026
This data processing agreement governs Storebook's processing of personal data on your behalf when you use the platform. It supplements the commercial agreement and meets the requirements of Article 28(3) of the GDPR. Annexes A-C form an integral part of the agreement.
Background and purpose
This data processing agreement is entered into between the company that uses the platform ("the Customer", "you") and Storebook ApS, Grønnegade 1, 1., 1107 København K, CVR 46721519 ("Storebook").
The agreement supplements the commercial agreement, the end user licence agreement and the terms of use, and governs the processing of personal data that Storebook carries out on your behalf as part of providing the platform.
The purpose of the agreement is to establish the rights and obligations that follow from Article 28 of the GDPR, including the framework for instructions, security, sub-processors, assistance, breaches, audit and deletion.
The agreement is entered into at the same time as you begin using the platform, and is a precondition for Storebook processing personal data on your behalf.
Roles of the parties
You are the data controller for the personal data contained in your accounting and bookkeeping material, including vouchers, bank transactions, commerce data and postings. You determine the purposes and means of the processing of that material.
Storebook is the data processor for that material and processes it exclusively on your documented instructions, see the section Instructions.
Storebook is an independent data controller for the data we process in order to operate and secure the platform: contact details for your users, login and security data, and log and usage data. The framework for this is set out in the privacy policy's section "Our two roles" and is not governed by this agreement.
The parties are not joint data controllers. Each party is responsible for complying with data protection law within its own role.
Scope and duration
The agreement covers the processing described in Annex A, which is necessary in order to provide the parts of the platform you have put into use.
The agreement enters into force when the processing begins, and applies for as long as Storebook processes personal data on your behalf.
The agreement terminates when the commercial agreement terminates and the wind-down under the section Deletion and return has been completed. The provisions on confidentiality and on statutory retention also apply thereafter.
Obligations of the data controller
You warrant that there is a valid legal basis for processing the personal data you make available to Storebook, and that the data subjects have received the information required by Articles 13-14 of the GDPR.
You warrant that your instructions to Storebook are lawful, and that processing in accordance with those instructions does not infringe data protection law or the rights of third parties.
You are responsible for ensuring that the material you upload or connect is accurate and up to date, and that it does not contain more personal data than the purpose requires. Storebook does not check the content of the material.
You must provide Storebook with the information necessary to perform this agreement, including information about any particular requirements arising from your industry or from a decision of a supervisory authority.
Instructions
Storebook processes personal data only on your documented instructions, including as regards transfers to third countries, unless EU or Danish law requires Storebook to process the data. In that case, Storebook informs you of the legal requirement before processing, unless that law prohibits such notification.
The documented instructions consist of this agreement with its annexes, the commercial agreement, the configuration you carry out in the portal — including which integrations and workflows you activate — and your and your users' actual use of the platform.
Additional or amended instructions are given to Storebook in writing. Where a new instruction requires development or changed operations, Storebook may make compliance conditional on a separate agreement on terms and fees.
If Storebook considers that an instruction infringes the GDPR, databeskyttelsesloven (the Danish Data Protection Act) or other EU or Member State data protection law, we will inform you immediately at the contact address you have provided, and may await your response before carrying out the instruction. Enquiries about this may be directed to philip@storebook.dk.
Confidentiality
Storebook ensures that the persons authorised to process personal data on your behalf have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Access to personal data is granted on a need-to-know basis: only the employees and sub-processors with a specific and legitimate need in order to provide the agreed services are given access, and access is limited to what is necessary.
Access is closed when the need ends, and access rights are reviewed as described in Annex B.
The confidentiality obligation also applies after termination of the agreement.
Security (Article 32)
Storebook implements the technical and organisational measures necessary to ensure a level of security appropriate to the risks presented by the processing, in accordance with Article 32 of the GDPR.
The measures implemented as at the date of this agreement are described in Annex B. The annex forms part of the agreement, and by reviewing it you have assessed that the level is appropriate for the processing you entrust to Storebook.
Storebook may change and further develop the measures, provided that the level of security is not reduced. Material changes are reflected in Annex B.
Sub-processors
You hereby give Storebook general written authorisation to engage sub-processors. The sub-processors approved as at the date of this agreement are listed in Annex C.
Storebook imposes on every sub-processor, by written agreement, the same data protection obligations as those set out in this agreement. Where a sub-processor fails to fulfil its obligations, Storebook remains fully liable to you for the performance of that sub-processor's obligations.
Storebook gives written notice of the addition or replacement of a sub-processor at least 30 days before the change takes effect. The notice states the sub-processor's name, the purpose of the processing, its location and the transfer basis.
You may object in writing to a notified change before the notice period expires. The objection must be reasoned on data protection grounds. In that case the parties will jointly seek a solution, for example an alternative sub-processor or an amended configuration.
If the objection cannot be resolved before the change takes effect, you may terminate the affected part of the service — and, where the service cannot be provided without the sub-processor in question, the commercial agreement — with effect from that date and without further payment for the period after termination.
Transfers to third countries
Storebook does not transfer personal data to a third country or an international organisation without a valid transfer basis under Chapter V of the GDPR and without your instructions.
The primary infrastructure is located in the EU, see Annex B. Where a sub-processor may involve processing outside the EU/EEA, the transfer takes place on the basis of the European Commission's standard contractual clauses (SCC) with the supplementary measures a prior assessment has shown to be necessary, supplemented by the EU-US Data Privacy Framework where the recipient is certified.
The transfer basis for each individual sub-processor is set out in Annex C.
A copy of the relevant safeguards, including the standard contractual clauses entered into, may be requested at philip@storebook.dk.
Assistance with data subject rights
Storebook assists you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests for exercising the data subject's rights under Chapter III of the GDPR, Articles 12-23, including access, rectification, erasure, restriction, data portability and objection.
Where Storebook receives a request directly from a data subject concerning data we process on your behalf, we do not answer the request ourselves. We forward it to you without undue delay and inform the data subject that the request must be directed to you as data controller.
Storebook responds to your requests for assistance within a reasonable time and in sufficient time for you to meet the response deadlines under the GDPR.
Assistance beyond what can be provided through the platform's ordinary functionality may be invoiced at Storebook's hourly rates in force at the time. We inform you in advance if a request will incur a fee.
Assistance under Articles 32-36
Storebook assists you in ensuring compliance with the obligations under Articles 32-36 of the GDPR, taking into account the nature of the processing and the information available to us.
The assistance covers security of processing under Article 32, including documentation of the measures described in Annex B.
The assistance covers the handling of personal data breaches under Articles 33-34, including the information you need in order to notify a breach and to communicate it to the affected data subjects.
The assistance covers data protection impact assessments under Article 35 and prior consultation of the supervisory authority under Article 36, to the extent the assessment or consultation concerns the processing Storebook carries out on your behalf.
Personal data breaches
If Storebook becomes aware of a personal data breach concerning personal data we process on your behalf, we notify you without undue delay after having become aware of the breach.
The notification contains the information available to us at the time: the nature of the breach, including where possible the categories and approximate number of data subjects concerned and of records concerned, the likely consequences of the breach, the measures we have taken or propose to take to address it and mitigate its possible adverse effects, and a point of contact at Storebook where more information can be obtained.
Where the information cannot be provided at the same time, it is provided in phases without undue further delay as the matter is clarified.
Storebook does not report the breach to Datatilsynet (the Danish Data Protection Agency) on your behalf and does not communicate it to the data subjects on your behalf. The assessment of whether a breach must be reported or communicated to data subjects, and the report and communication themselves, are your responsibility as data controller, unless otherwise separately agreed in writing.
Storebook's reporting of breaches concerning the processing for which we are ourselves the data controller falls outside this agreement.
Audit and inspection
On your written request, Storebook makes available all information necessary to demonstrate compliance with the obligations under Article 28 of the GDPR, including a description of the measures implemented and of the circle of sub-processors.
Storebook is not certified under a recognised security standard and does not currently hold an independent audit report. Should such a report become available at a later date, it will be made available on request and will replace a corresponding part of a physical inspection.
You may carry out a physical inspection at Storebook at most once a year. The inspection is notified in writing at least 30 days in advance, is carried out during normal working hours and is arranged so as to disturb Storebook's operations as little as possible.
The inspection must not extend to access to other customers' data or to information Storebook is obliged to keep secret. If you use an external auditor, that auditor must be independent of Storebook's competitors and must sign a confidentiality undertaking.
You bear your own and Storebook's costs of a physical inspection, including Storebook's time at the rates in force. An inspection prompted by an established breach at Storebook or by an order from a supervisory authority may be carried out without regard to the annual limit.
Datatilsynet (the Danish Data Protection Agency) has access to Storebook's premises and information to the extent the law provides authority for it, and Storebook is obliged to give the supervisory authority the necessary access.
Deletion and return
On termination of the agreement, Storebook deletes or returns, at your choice, all personal data processed on your behalf, and deletes existing copies.
You must notify us of your choice in writing no later than 30 days after termination. During that period we make an extract of the material available in a commonly used, machine-readable format. If we have not received a choice when the deadline expires, we delete the material.
Deletion is completed no later than 90 days after termination, once the wind-down has finished. Backups are deleted following the ordinary rotation cycle and are not reused in the meantime.
Deletion and return do not, however, take place to the extent EU or Danish law requires the personal data to be retained. This applies in particular to the requirement in bogføringsloven (the Danish Bookkeeping Act) that accounting material must be retained for five years from the end of the financial year to which the material relates.
Material retained under the preceding paragraph is processed solely for the purpose of meeting that legal obligation, remains covered by this agreement's provisions on security and confidentiality, and is deleted when the retention obligation ends.
Storebook confirms in writing on request that deletion has been completed, and states what material, if any, is retained under a legal requirement.
Liability
The parties' liability under this agreement follows the limitation of liability in the end user licence agreement's limitation-of-liability section and in the signed commercial agreement. This agreement does not establish independent monetary caps and neither expands nor narrows what follows from those documents.
Article 82 of the GDPR on liability for damage caused to data subjects applies between the parties. Where a party has paid full compensation for damage suffered, that party is entitled to claim back from the other party that part of the compensation corresponding to the other party's part of the responsibility for the damage.
Limitations of liability cannot be invoked where mandatory law precludes them, including as against data subjects and supervisory authorities.
A fine or an order imposed on one party by a supervisory authority because of the other party's circumstances is borne by the party whose circumstances gave rise to it, within the limits of the limitation of liability.
Duration, changes and order of precedence
The agreement applies for as long as Storebook processes personal data on your behalf, and cannot be terminated separately while the commercial agreement is running.
Storebook may amend the agreement where the law, the practice of a supervisory authority or the development of the platform so requires. Material changes are announced in writing with reasonable notice before they take effect. Changes to the circle of sub-processors, however, follow the notice and objection rules in the section Sub-processors.
The basis of agreement consists of the signed commercial agreement, this data processing agreement, the end user licence agreement, and the terms of use. In the event of a conflict, the documents apply in the order listed.
For the processing of personal data that Storebook carries out as data processor on your behalf, however, this agreement takes precedence over the end user licence agreement, the terms of use and the privacy policy.
The documents making up the basis of agreement are published in Danish and English. In the event of a discrepancy between the two language versions, the Danish version prevails.
Provisions in any document in the basis of agreement that conflict with mandatory requirements in Article 28 of the GDPR cannot be invoked to the extent of that conflict.
Annexes A, B and C form an integral part of the agreement.
Governing law and venue
The agreement is governed by Danish law, excluding conflict-of-law rules that would lead to the application of another body of law.
Disputes arising out of the agreement are first sought resolved by negotiation between the parties.
If a dispute cannot be resolved by negotiation, it is decided by Københavns Byret (the Copenhagen City Court) as the agreed venue at first instance.
Annex A — Description of the processing
Subject matter of the processing: Storebook's provision of the platform, including ingesting vouchers, bank transactions and commerce data, generating suggestions for account codes and VAT, human approval, and delivering the approved postings to the accounting system you use yourself.
Nature of the processing: collection, receipt, recording, storage, structuring, collation, machine reading, retrieval, use, disclosure to the accounting system you have connected, erasure and return.
Purpose of the processing: to prepare and carry out your bookkeeping, VAT handling and year-end closing in the workflows you have put into use, and to provide the support covered by the agreement.
Categories of data subjects: your employees and the users you create in the portal; your own customers; your suppliers; and other contact persons and business partners appearing in the accounting material you make available.
Categories of personal data: name and contact details, including email address and telephone number; information on employment and role; payment and account details, including account number and payment references; bank transaction data, including amount, date, text and counterparty; the content of vouchers, invoices and other documents you upload or connect, with whatever personal data that material may contain; commerce data from a connected webshop, but without the buyer's name, email, telephone number, address, IP address, notes and tracking number; and user, login and log data from the portal to the extent it relates to the processing of your material.
Special categories of personal data under Article 9 of the GDPR and data relating to criminal offences under Article 10 are not knowingly processed. The platform is not designed for it, and you must refrain from making such material available.
Duration of the processing: the processing runs for as long as the commercial agreement is in force, and is then wound down in accordance with the section Deletion and return, with the statutory retention under bogføringsloven (the Danish Bookkeeping Act) as the only exception.
Annex B — Technical and organisational measures
Location: Storebook's primary infrastructure and storage of your accounting material are located within the EU/EEA with established cloud providers. After activation and verification, the planned recovery configuration will store encrypted rotating backups of protected production data in a separate account in another EU region. AI models are run within the EU. A small number of sub-processors may process data outside the EU/EEA; which ones, and on what transfer basis, appears in Annex C.
Encryption at rest: all data is encrypted at rest. For the most sensitive categories — bank transactions, bank connections, booking cases, commerce data and exchange rates, connection and access data for the systems you connect, and the agents' shared knowledge base — we use keys to which Storebook controls access itself, so that a key can be revoked independently of the underlying storage. The platform's other data is encrypted with keys managed by the cloud provider. Voucher files are encrypted in object storage.
Execution history: the platform's automated workflows leave an execution history containing the data each individual run processed, which may therefore include bank and accounting data. The history sits in a private network with no access from the internet and is encrypted at rest. In production, execution history is deleted automatically after 30 days, and automated backups are taken with a retention of at least seven days.
Encryption in transit: all communication with the platform from outside takes place over TLS. Internal traffic between the platform's components runs within a private network with no access from the internet.
Separation of customer data: data is isolated per customer, and the interfaces enforce the separation, so that a user cannot access another company's material.
User authentication: user access is handled by a dedicated identity service with support for two-factor authentication (TOTP). Two-factor authentication is available to your users, but is enabled by you and is not enforced by the platform; we recommend turning it on for all users. Passwords are not stored in clear text.
Internal access control: each of the platform's components is granted its own permissions on the principle of least privilege, so that a component can read and write only the resources its task requires. Access to the production environment is restricted to named employees with an operational need.
Review of access rights: internal access rights are reviewed every quarter, and access no longer justified by an operational need is removed.
Secrets management: access keys, tokens and other secrets are held in a dedicated secret store and are never kept in ordinary application data or in source code.
Logging and monitoring: security-relevant events and operational data are logged. There is automatic alerting on any error or timeout in one of the platform's functions and on any 5xx error in the platform's interfaces. Alerts are sent to an internal operations team.
Log retention: log data in production is retained for three months.
Backup and recovery: for the production databases, continuous recovery is enabled with a recovery window of 35 days and a recovery point objective (RPO) of approximately five minutes. A prepared but not yet activated recovery configuration will copy protected database and object data daily to a separate account in another EU region, encrypt it and rotate the copies after 35 days. Once activated, that provides a nominal regional RPO of at most 24 hours plus copy completion time. Stateful production resources are protected against accidental deletion. A full recovery exercise has not yet been carried out, so Storebook does not state a tested recovery time objective (RTO).
Separation of environments: development, test and production environments are separated, and production data is not used in development or test environments.
Change management: changes are reviewed before being deployed to production, and automated checks run on every change.
Human control: automated suggestions for account codes and VAT are preparatory only. No posting is delivered to your accounting system before an employee has approved it, and no decision is therefore taken solely by automated processing.
Organisational measures: staff are subject to confidentiality, access is granted on a need-to-know basis, and there is an established procedure for handling security incidents covering containment, investigation, remediation and subsequent review.
Annex C — Approved sub-processors
The following sub-processors are approved as at the date of this agreement. For each, the name, the purpose of the processing, the location and the basis for any transfer to a third country are stated.
Amazon Web Services EMEA SARL — purpose: Cloud infrastructure, database, storage, authentication and the running of AI models. Location: EU — primary infrastructure and storage within the EU; after activation and verification, the planned recovery configuration will store encrypted rotating backups of protected production data in another EU region; AI models are run within the EU, distributed across several EU regions. Transfer basis: No transfer to a third country in normal operation.
Vercel Inc. — purpose: Hosting and delivery of the customer portal's frontend. Location: USA and a global delivery network; processing may take place outside the EU/EEA. Transfer basis: The European Commission's standard contractual clauses (SCC) with supplementary measures, supplemented by the EU-US Data Privacy Framework where the recipient is certified.
Resend (Plus Five Five, Inc.) — purpose: Sending transactional emails, including invitations and notifications. Location: USA; processing may take place outside the EU/EEA. Transfer basis: The European Commission's standard contractual clauses (SCC) with supplementary measures, supplemented by the EU-US Data Privacy Framework where the recipient is certified.
Microsoft Ireland Operations Ltd. — purpose: Machine reading of vouchers. Location: Contracting entity in Ireland; the service region used may involve processing outside the EU/EEA. Transfer basis: The European Commission's standard contractual clauses (SCC) with supplementary measures, supplemented by the EU-US Data Privacy Framework where the recipient is certified.
Enable Banking — purpose: Account information service under the Payment Services Directive (PSD2) — retrieval of account and bank transaction data from your bank on your authorisation. Location: Country of establishment and supervisory authority disclosed on request. Transfer basis: No data is transferred to a third country without a valid transfer basis; the specific basis is disclosed on request.
Nylas — purpose: Email integration — access to the Gmail or Outlook mailbox you connect yourself, and retrieval of attachments so they can be processed as vouchers. Location: Storebook uses the service's EU endpoint; contracting entity and country of establishment disclosed on request. Transfer basis: No data is transferred to a third country without a valid transfer basis; the specific basis is disclosed on request.
Slack — purpose: Delivery of notifications from the platform to the Slack workspace you connect. Location: Contracting entity and country of establishment disclosed on request. Transfer basis: No data is transferred to a third country without a valid transfer basis; the specific basis is disclosed on request.
The addition or replacement of a sub-processor is notified 30 days in advance and may be met with an objection, see the section Sub-processors.
The account information service in the table above is used to retrieve account and bank transaction data from your bank. The retrieval takes place on the basis of the authorisation you yourself give to the bank, and which you can withdraw by disconnecting the connection in the portal or with the bank. Storebook has itself entered into the agreement with that service provider, and the provider is therefore a sub-processor for Storebook.
Your own connected business systems, by contrast, are not sub-processors for Storebook. That applies to the accounting systems the platform can connect to, including e-conomic, and to the commerce platforms it can connect to, including Shopify. Such a system is your own, under your own agreement with the provider in question, and that provider processes your data on your behalf under that agreement — not under this one. Storebook accesses the system as your agent, on your instructions and only to the extent the workflows you have put into use require. You may withdraw that access at any time by disconnecting the connection in the portal. Storebook is neither a reseller of, nor an agent for, the provider in any other respect, and does not resell the provider's service or access to it.
The distinction follows from who holds the agreement with the provider. Where Storebook has itself entered into the agreement and uses the provider to deliver the platform, the provider is a sub-processor and appears in the table above. Where you hold the agreement with the provider yourself, the system is your own, and Storebook acts solely as your agent.