Data Processing Agreement (DPA)

Last revised: 27. Marts 2026

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between:

Onlinereviews.dk/Trigalot.com (“Processor”)

and

the customer using the service (“Controller”).

1. Purpose of Processing

Processor provides a SaaS platform for sending review invitations by email and SMS following order fulfillment in the Controller’s webshop.

Processor processes personal data solely on behalf of the Controller and only according to documented instructions provided through the use of the service.

2. Categories of Personal Data

The Processor may process the following personal data:

  • Name
  • Email address
  • Phone number

3. Categories of Data Subjects

The personal data concerns:

  • Customers of the Controller

4. Nature of Processing

Processing includes:

  • Storage
  • Transmission
  • Automated sending of review invitations
  • Temporary access for troubleshooting integrations and technical support

5. Processor Obligations

Processor shall:

  • process personal data only on documented instructions from Controller
  • ensure confidentiality of persons authorized to process personal data
  • implement appropriate technical and organizational security measures
  • assist Controller where reasonably necessary to fulfill GDPR obligations
  • notify Controller without undue delay in case of a personal data breach

6. Security Measures

Processor applies appropriate technical and organizational measures including:

  • restricted access to production systems limited to authorized personnel only
  • encrypted transmission of data using industry standard transport security
  • server hosting within the European Union
  • backup procedures with retention for 14 days

7. Subprocessors

Controller authorizes Processor to use the following subprocessors:

  • Hetzner (hosting, EU infrastructure)
  • Mailgun (email delivery, EU infrastructure)
  • GatewayAPI (SMS delivery, EU infrastructure)
  • Stripe (payment processing)

Processor shall ensure that subprocessors are subject to data protection obligations equivalent to those set out in this Agreement.

Processor remains responsible for the performance of subprocessors in relation to personal data processing.

8. International Transfers

Processor intends to process personal data within the European Union.

Where a subprocessor involves transfer outside the EU/EEA, Processor shall ensure lawful transfer safeguards in accordance with GDPR, including where relevant the European Commission’s Standard Contractual Clauses.

9. Support Access

Processor may access personal data only when necessary for troubleshooting, support, maintenance, or integration assistance requested by Controller.

Such access shall be limited to what is necessary for the relevant support task.

10. Deletion

Upon termination of the service, personal data is deleted without undue delay unless retention is required by law.

Backup copies are automatically deleted after 14 days.

11. Audit

Controller may request reasonable written information demonstrating Processor’s compliance with this Agreement.

On-site audits are not required unless mandated by applicable law.

12. Liability

Liability under this Agreement follows the liability provisions of the Terms of Service unless mandatory GDPR law requires otherwise.

13. Governing Law

This Agreement is governed by Danish law.