Data Processing Agreement (DPA)
Last revised: 27. Marts 2026
This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between:
Onlinereviews.dk/Trigalot.com (“Processor”)
and
the customer using the service (“Controller”).
1. Purpose of Processing
Processor provides a SaaS platform for sending review invitations by email and SMS following order fulfillment in the Controller’s webshop.
Processor processes personal data solely on behalf of the Controller and only according to documented instructions provided through the use of the service.
2. Categories of Personal Data
The Processor may process the following personal data:
- Name
- Email address
- Phone number
3. Categories of Data Subjects
The personal data concerns:
- Customers of the Controller
4. Nature of Processing
Processing includes:
- Storage
- Transmission
- Automated sending of review invitations
- Temporary access for troubleshooting integrations and technical support
5. Processor Obligations
Processor shall:
- process personal data only on documented instructions from Controller
- ensure confidentiality of persons authorized to process personal data
- implement appropriate technical and organizational security measures
- assist Controller where reasonably necessary to fulfill GDPR obligations
- notify Controller without undue delay in case of a personal data breach
6. Security Measures
Processor applies appropriate technical and organizational measures including:
- restricted access to production systems limited to authorized personnel only
- encrypted transmission of data using industry standard transport security
- server hosting within the European Union
- backup procedures with retention for 14 days
7. Subprocessors
Controller authorizes Processor to use the following subprocessors:
- Hetzner (hosting, EU infrastructure)
- Mailgun (email delivery, EU infrastructure)
- GatewayAPI (SMS delivery, EU infrastructure)
- Stripe (payment processing)
Processor shall ensure that subprocessors are subject to data protection obligations equivalent to those set out in this Agreement.
Processor remains responsible for the performance of subprocessors in relation to personal data processing.
8. International Transfers
Processor intends to process personal data within the European Union.
Where a subprocessor involves transfer outside the EU/EEA, Processor shall ensure lawful transfer safeguards in accordance with GDPR, including where relevant the European Commission’s Standard Contractual Clauses.
9. Support Access
Processor may access personal data only when necessary for troubleshooting, support, maintenance, or integration assistance requested by Controller.
Such access shall be limited to what is necessary for the relevant support task.
10. Deletion
Upon termination of the service, personal data is deleted without undue delay unless retention is required by law.
Backup copies are automatically deleted after 14 days.
11. Audit
Controller may request reasonable written information demonstrating Processor’s compliance with this Agreement.
On-site audits are not required unless mandated by applicable law.
12. Liability
Liability under this Agreement follows the liability provisions of the Terms of Service unless mandatory GDPR law requires otherwise.
13. Governing Law
This Agreement is governed by Danish law.
