Data Processing Agreement
1 Scope and interpretation of this DPA
1.1 This Data Processing Agreement (“DPA”) is entered between Queue-it ApS (“Queue-it” or “Data Processor”) and the legal entity entering into the Main Agreement (the “Customer”, “Data Controller”). The Parties have entered into an agreement (the “Main Agreement”) concerning Queue-it’s provision to the Customer of Queue-it’s cloud-based platform and services, delivered as software-as-a-service (“Services”). This DPA forms part of the Main Agreement and applies to Queue-it’s Processing of Personal Data on behalf of the Customer in connection with the Services.
1.2 In the event of a contradiction between this DPA and the provisions of related agreements between the parties existing at the time when this DPA is agreed or entered into thereafter, this DPA shall prevail.
2 Agreed terms, Definitions and Application
2.1 In this DPA the following terms have the meaning set out below:
“Data Security Incident” a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
“Data Subject” End-users of the Customer’s websites and applications on which
the Services are deployed.
“Personal Data” any information relating to an identified or identifiable natural
person that is passed from the Data Controller to the Data Processor and processed by the Data Processor on behalf of the Data Controller. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data or an online identifier.
“Processing” means any operation or set of operations which is performed on
Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Data Controller” means the natural or legal person, public authority, agency or
other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. Under this DPA, Customer is identified as the Data Controller.
“Data Processor” means a natural or legal person, public authority, agency or
other body, which processes personal data on behalf of the controller. Under this DPA, Queue-it is identified as Data Processor.
“Data Protection Legislation” shall mean all mandatory applicable laws relating to
Personal Data protection, the processing of Personal Data and privacy including: The Danish Data Protection Act 2018. The General Data Protection Regulation (EU) 2016/679 from 25th May 2018 including the Commission Implementation Decision of 10th July 2023; the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as may be amended by the proposed Regulation on Privacy and Electronic Communications); and any legislation that, in respect of the United Kingdom, replaces such legislation as a consequence of the United Kingdom leaving the European Union; the California Consumer Privacy Act, CCPA (Assembly Bill No. 375); and any other applicable legislation and regulations in any other country and any modification or re-enactment of such legislation or regulations from time to time.
“Standard Contractual Clauses” the standard contractual clauses for the transfer
of personal data to third countries under Commission Implementing Decision (EU) 2021/914 and, for transfers subject to the UK GDPR, the UK International Data Transfer Addendum.
“Supervisory Authority” the competent supervisory authority under the Data Protection Legislation; for Denmark, the Danish Data Protection Agency (Datatilsynet).
3 Rights and obligations of the Data Controller
3.1 Queue-it acts as a Data Processor under the GDPR and, for Data Controllers established in the United Kingdom, under the UK GDPR. Queue-it acts as a “service provider” under the CCPA. Any reference in this DPA to the obligations of the Data Processor shall, where applicable, be read as a reference to the obligations of a service provider under the CCPA.
3.2 Where the Data Processor processes Personal Data as a service provider under the CCPA, it shall not: (i) sell or share such personal data; (ii) retain, use or disclose it for any purpose other than performing the Services, or as otherwise permitted by the CCPA; or (iii) retain, use or disclose it outside the direct business relationship between the parties.
3.3 The Data Controller is responsible for ensuring that the Processing of Personal Data takes place in compliance with the Data Protection Legislation (see Article 24 GDPR) and this DPA.
3.4 The Data Controller has the right and the obligation to make decisions about the purposes and means of the Processing of Personal Data.
3.5 The Data Controller is responsible, among other things, for ensuring that there is a legal basis for the Processing that the Data Processor is instructed to perform, and for fulfilling the rights of data subjects under the Data Protection Legislation.
3.6 The Data Controller warrants that its instructions to the Data Processor comply with the Data Protection Legislation.
4 Instructions for Data Processing
4.1 The Data Processor shall process Personal Data only on documented instructions from the Data Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Member State- or other applicable law. In that case, the Data Processor shall inform the Data Controller of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4.2 The Data Controller’s instructions at the time of entering into this DPA are set out in the Main Agreement, this DPA and Appendices 1 (Data Processing Terms). Subsequent instructions may be given by the Data Controller throughout the duration of the Processing, but shall always be documented and kept in writing.
4.3 The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction infringes the Data Protection Legislation.
4.4 Processing by the Data Processor as an independent controller. In addition to the Processing as Data Processor under this DPA, Queue-it processes certain personal data as an independent data controller for its own purposes, including account administration and customer-relationship management, billing and financial administration, securing and improving the Services, product and performance analytics, and compliance with its legal obligations. Such processing is determined by Queue-it (not by the Data Controller’s instructions), is not carried out on behalf of the Data Controller, and is outside the scope of this DPA. It is governed by Queue-it’s Privacy Policy, available at https://queue-it.com/privacy-policy/.
4.5 The Data Processor may, where necessary to document the provision of the Services to the Data Controller or to defend itself against legal claims, retain a copy of the Personal Data processed on behalf of the Data Controller. In such cases the Personal Data may be processed only for those purposes.
5 Processing Standards
5.1 The Data Processor shall carry out the processing in compliance with the applicable Data Protection Legislation.
5.2 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Data Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
5.3 The Data Processor shall ensure that appropriate and adequate technical and organizational measures to safeguard the Personal Data from unauthorized or unlawful Processing or accidental loss, destruction, or damage are implemented.
5.4 Details about Queue-it’s data protection measures can be found in the Trust Center here https://trust.queue-it.com/ and in Appendix 3 (Security Measures).
5.5 The Data Processor shall ensure that each of its employees, agents or subcontractors are made aware of its obligations with regard to the security and protection of the Personal Data and shall require that they:
- shall only grant access to the personal data being processed on behalf of the Data Controller to persons under the Data Processor’s authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and only on a need to know basis. The list of persons to whom access has been granted shall be kept under periodic review. On the basis of this review, such access to Personal Data can be withdrawn, if access is no longer necessary, and Personal Data shall consequently not be accessible anymore to those persons.
- Process the Personal Data solely on instructions from Customer; and
- Is appropriately reliable, qualified and trained in relation to their Processing of Personal Data.
6 Use of Sub processors
6.1 The Data Controller gives the Data Processor a general authorisation to engage Sub-processors, subject to this Clause 6.
6.2 If Queue-it subcontracts any part of the data processing to a third party, Queue-it shall ensure that a written contract on the same terms as this DPA is entered into by the Sub-processor and that any Sub-processor provides Queueit with assurance of the technical and organizational means it has adopted to prevent unauthorized or unlawful processing or accidental loss or destruction of the data. Queue-it will remain responsible for all acts and omissions of Sub-processors as if they were its own.
6.3 The current list of authorised Sub-processors is available at https://queueit.com/data-processing-agreement-sub-processors/ (“Sub-processor”). The parties agree that this online list forms part of this DPA and is updated on an ongoing basis, and the Customer authorises the use of the Sub-processors on the list as a general authorisation. The Data Processor shall provide the Customer with at least 60 days’ advance notice of any intended addition or replacement of subprocessors (including by updating the online sub-processor list already referenced in this DPA). If the Customer objects in writing on reasonable data protection grounds within the notice period, the parties will cooperate in good faith to address the objection. If no commercially reasonable alternative is available, Queue-it may discontinue the affected feature/service, or the Customer may terminate the affected service(s) on written notice.
6.4 Where the Data Processor engages a Sub-processor to carry out specific Processing activities on behalf of the Data Controller, it shall impose on that Subprocessor, by way of a contract or other legal act, the same data protection obligations as set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures so that the Processing meets the requirements of the Data Protection Legislation. The Data Processor shall be responsible for ensuring that the Sub-processor at least complies with the obligations to which the Data Processor is subject under this DPA.
6.5 The Data Processor remains fully liable to the Data Controller for the performance of each Sub-processor’s data protection obligations. If a Sub-processor fails to fulfil its data protection obligations, the Data Processor remains fully liable to the Data Controller for the fulfilment of those obligations. This does not affect the rights of data subjects under the Data Protection Legislation, in particular Articles 79 and 82 GDPR.
7 International transfers
7.1 Any transfer of Personal Data outside the EEA will take place only on the Controller’s documented instructions and in compliance with Chapter V GDPR. The Data Controller’s instructions regarding transfers, including the applicable Chapter V transfer tool, are set out in Clause C.6 of Appendix 4.
7.2 Where the recipient is in a country, or the transfer otherwise benefits from an adequacy decision of the European Commission under Article 45 GDPR (including the EU–US Data Privacy Framework), the parties shall rely on that adequacy decision. For all other transfers, the parties shall rely on the Standard Contractual Clauses, which are deemed entered into and completed as set out in Appendix 5 (Cross-Border Transfer Mechanism), together with any supplementary measures required under the Data Protection Legislation.
7.3 If an adequacy decision (including the EU–US Data Privacy Framework) is amended, replaced, invalidated or becomes inapplicable to a particular transfer, the parties shall, without undue delay, rely on the Standard Contractual Clauses, as completed in Appendix 5, which shall automatically apply to the affected transfers without further action by the parties, together with any required supplementary measures.
7.4 As regards onward transfers by Sub-processors located outside the EEA, the Data Controller instructs the Data Processor to enter into the Standard Contractual Clauses (or another valid Chapter V transfer mechanism) with such Sub-processors on the Data Controller’s behalf.
8 Incident management
8.1 The Data Processor shall notify the Customer without undue delay and in any event no later than 72 hours after becoming aware of a Data Security Incident affecting Personal Data.
8.2 Where, and in so far as, it is not possible to provide all relevant information at the same time, the information may be provided in phases without undue further delay, but the Data Processor may not delay notification on the basis that an investigation is incomplete or ongoing.
8.3 Notifications will include, to the extent available, the information required under Article 33(3) GDPR (nature of the incident, categories/approximate number of Data Subjects and records concerned, likely consequences, measures taken/proposed, and a contact point for further information).
8.4 Notices under this Clause 8 shall be sent to the email address designated by the Data Controller (the Controller Notification Address), being the address specified in the Main Agreement or otherwise notified by the Data Controller to the Data Processor in writing. The Data Controller shall ensure the Controller Notification Address is monitored at all times and shall promptly notify the Data Processor in writing of any change. Privacy enquiries and notices to the Data Processor under this DPA may be sent to privacy@queue-it.com, unless the Data Processor designates another address in writing.
8.5 The Data Processor shall not, and shall procure that its Sub-processors shall not, make any public announcement regarding a Data Security Incident that refers to the Data Controller without the Data Controller’s prior written consent, unless required by applicable law.
9 Confidentiality
9.1 The Data Processor shall grant access to the Personal Data processed on behalf of the Data Controller only to persons under its authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only on a need-to-know basis. The list of persons granted access shall be kept under periodic review and, on the basis of that review, access shall be withdrawn where it is no longer necessary.
9.2 The Data Processor shall, at the Data Controller’s request, demonstrate that the persons concerned are subject to the confidentiality obligations described above.
9.3 The Data Processor’s obligations under this Clause 9 are not limited by, nor contingent upon, the continuation or discontinuation of the parties’ cooperation.
10 Assistance to the data controller
10.1 The Data Processor shall (if applicable) promptly notify the Customer of and assist the Customer in relation to:
- Any request for disclosure of the Data by a law enforcement authority unless otherwise prohibited from so notifying;
- Documenting, reporting or taking measures to address or mitigate any Data Security Incident;
- Any request received seeking to exercise a Data Subject’s rights under the Data Protection Legislation;
10.2 In addition to the data processor’s obligation to assist the Data Controller pursuant to the preceding clause, the Data Processor shall furthermore, taking into account the nature of the Processing and the information available to the Data Processor, assist the Data Controller in ensuring compliance with:
- The Data Controller’s obligation to without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the competent Supervisory Authority of a personal data breach;
- the Data Controller’s obligation to without undue delay communicate a personal data breach to the Data Subject, the Data Controller’s obligation to carry out an assessment of the impact of the envisaged Processing operations on the protection of Personal Data (a data protection impact assessment);
10.3 the Data Controller’s obligation to consult the competent supervisory authority prior to processing. If the Data Processor receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Data Controller, it shall, unless prohibited by law, without undue delay forward the request to the Data Controller and shall not respond to the request itself except on the Data Controller’s documented instructions.
10.4 The Data Processor will (i) make available to the Customer all information necessary to demonstrate compliance with this DPA and Article 28 GDPR and (ii) allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, in each case subject to the terms below. As the default method for audits/inspections, the Data Processor will, upon request, provide its then-current independent third-party assurance reports and certifications and related summaries needed for the Customer’s compliance assessment. Where such materials are insufficient for a specific, justified purpose (e.g., material security incident impacting the Customer, or a competent Supervisory Authority request), the Customer may conduct an audit/inspection (itself or via a mandated independent auditor) subject to the Audit Procedures set out in Appendix 2 (Audit Procedures).
11 Liability
11.1 Each party is liable to the other party under the general rules of the law and the limitations of liability as set out in the Main Agreement.
11.2 In addition to any limitations of liabilities set out in the Main Agreement and Subject to Clause 11.3, neither party shall be liable to the other for any indirect or consequential loss or damage, or for any loss of profits, revenue, anticipated savings, goodwill or business, or for operating losses, in each case arising out of or in connection with this DPA, whether in contract, tort (including negligence) or otherwise.
11.3 Nothing in this DPA limits or excludes either party’s liability to the extent it cannot be limited or excluded under applicable law, and nothing in this DPA limits or affects: (a) the rights of a Data Subject, or either party’s liability towards Data Subjects or a Supervisory Authority, under the Data Protection Legislation (including Article 82 GDPR); or (b) either party’s liability for death or personal injury caused by its negligence.
12 Erasure and return of data
12.1 In case of termination or expiration of this Agreement, regardless of the reason, the Supplier must, at the Customer’s sole discretion, either delete or return to the Customer all Personal Data and delete any existing copies, unless this DPA or the Data Protection Legislation prescribes storing of the Personal Data.
12.2 Until the Personal Data is deleted or returned, the Data Processor shall continue to ensure compliance with this DPA.
12.3 Where law applicable to the Data Processor prevents it from deleting all or part of the Personal Data, the Data Processor shall guarantee the confidentiality and security of that Personal Data, shall process it only for the purposes and duration mandated by that law and under the applicable conditions, and shall not otherwise actively process it.
12.4 The Data Processor is not entitled to exercise any right of retention over the Personal Data in respect of any claim it may have against the Data Controller (for example, for payment of invoices).
13 Commencement and termination
13.1 This DPA takes effect on the date of acceptance or signature of the Main Agreement (or, if later, of this DPA) and remains in force for the duration of the Data Processor’s provision of the Services, plus the period from termination of the Main Agreement until the Data Processor ceases to process Personal Data on behalf of the Data Controller in accordance with Clause 12.
13.2 The Data Controller may terminate this DPA, and the Main Agreement insofar as it concerns the Processing of Personal Data, if: (a) the Data Processor is in substantial or persistent breach of this DPA or its obligations under the Data Protection Legislation; or (b) the Data Processor fails to comply with a binding decision of a competent court or Supervisory Authority regarding its obligations under this DPA or the Data Protection Legislation.
13.3 The Data Processor may terminate this DPA, and the Main Agreement insofar as it concerns the Processing of Personal Data, where, after the Data Processor has informed the Data Controller that an instruction infringes the Data Protection Legislation, the Data Controller insists on compliance with that instruction.
13.4 On termination, the Data Processor shall delete or return the Personal Data and certify deletion in accordance with Clause 12. Clauses 9 (Confidentiality), 11 (Liability), 12 (Erasure and return of data) and this Clause 13.4 survive termination and continue in full force and effect until the Data Processor has complied in full with Clause 12.
14 Miscellaneous
14.1 Governing law and jurisdiction. This DPA is governed by the law governing the Main Agreement and, in the absence of such a choice, by the laws of Denmark. Any dispute arising out of or in connection with this DPA shall be resolved by the courts having jurisdiction under the Main Agreement and, in the absence of such a choice, by the Danish courts.
14.2 Other terms. The parties may agree other terms concerning the provision of the Services, including on liability, provided they do not contradict, directly or indirectly, this DPA or prejudice the fundamental rights or freedoms of data subjects or the protection afforded by the Data Protection Legislation.
14.3 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force and effect, and the parties shall replace the invalid provision with a valid one that most closely reflects its purpose.
15 Appendix 1 - Data Processing Terms
15.1 Background:
- These Data Processing Terms set out contractual provisions to ensure the protection and security of Personal Data passed from the Customer to the Data Processor for Processing.
- This Appendix sets out the details of the Processing of Personal Data carried out by the Data Processor on behalf of the Data Controller under this DPA. The Data Processor’s separate Processing as an independent controller is described in Clause 4.4 and is outside the scope of this DPA.
- The Data Protection Legislation place certain obligations upon a Data Controller to ensure that any Data Processor it engages provides sufficient guarantees to ensure that the Processing of the Personal Data carried out on its behalf is secure and legal.
- These Data Processing Terms exists to ensure that there are sufficient security guarantees in place and that the Processing complies with the Data Protection Legislation.
15.2 The Processing consists of the collection, recording, storage, organisation, consultation, use, transmission, restriction, erasure and destruction of Personal Data, by automated means, as necessary to operate the Services, manage enduser traffic and online queues, protect the Services against abuse, and below the relevant type of Personal Data is listed:
| Type of Personal Data | Purpose/use | Retention |
|---|---|---|
| IP address and user agent of the end-user’s device / browser | Logging; preventing unauthorised access and malicious code distribution; mitigating denial-of-service attacks; operating the built-in functionality that prevents malicious activity from individual IP addresses (e.g. bots). | Deleted after 13 months |
| Email address of the end-user — optional Identity feature | Processed by the Data Processor on behalf of the Data Controller only where the Data Controller enables the optional Identity feature. | Deleted after 12 months |
| Email address of the end-user — optional Notification feature | Processed where the Data Controller enables the optional Notification feature. An end-user’s email address is disclosed to the Data Controller only where the end-user has given consent. | Deleted after 3 months |
15.3 The Data will be processed in connection with the processing operations during the term of this DPA or such shorter period where the Processing is no longer authorized, and in respect of any post-termination Processing activities permitted by the Customer from time to time.
15.4 The Data Processor will not store sensitive Personal Data (cf. Article 9 of the General Data Protection Regulation):
- Racial or ethnic origin
- Political opinions
- Religious beliefs
- Philosophical beliefs
- Trade union membership
- Data concerning health including abuse of medicine, narcotics, alcohol etc.
- Data concerning sex life or sexual orientation
15.5 The Data Processor will not store Data on purely private matters of individuals (cf. section 8 of the Danish Personal Data Act, as of 25 May 2018, cf. Articles 6 and 9 of the General Data Protection Regulation):
- Criminal offences
- Significant social problems
- Other purely private matters, which are not mentioned above.
The Data Processor processes the Personal Data for the term of the Main Agreement and for any short period thereafter required to delete or return the Personal Data in accordance with Clause 12. The retention periods for specific data types are set out in Appendix 1. On termination, Personal Data is deleted and deletion certified, within 60 days in accordance with Clause 12.
16 Appendix 2 - Audit Procedures
16.1 Notice: The Controller shall provide reasonable prior written notice of an onsite audit/inspection (e.g., at least 30 days), except where earlier access is required due to a material Data Security Incident affecting the Controller or a request from a competent supervisory authority.
- Scope limitation: Audits/inspections shall be limited to information, systems, facilities, and records relevant to the Services and the Controller’s data processed under this DPA.
- Reports-first approach: The Controller agrees that up-to-date ISO reports/certifications (and related summaries) will be the primary evidence for routine compliance verification.
- Confidentiality: The Controller and any mandated auditor shall be bound by confidentiality obligations and may not disclose audit outputs except as required by law or to the competent Supervisory Authority.
- Minimal disruption: Audits shall be conducted in a manner that avoids unnecessary disruption to Queue-it’s operations and maintains the security and confidentiality of other customers’ Personal Data.
- Frequency limit: Routine audits are limited to once per year. Additional audits may be performed if reasonably necessary due to a material incident or regulatory/Supervisory Authority requirement.
- Cost allocation: The Controller shall bear its own costs and the fees of any mandated auditor. Queue-it will bear its internal costs of cooperation during a routine audit. If an audit reveals a material breach of this DPA by Queue-it, the parties will discuss reasonable remediation and cost allocation in good faith.
- Use of third parties: Any mandated auditor must be independent, not a competitor of Queue-it, and acceptable to Queue-it acting reasonably.
Where Queue-it uses third-party cloud or hosting providers to deliver the Services, Queue-it relies on those providers’ physical and platform security controls as part of the overall TOMs, and ensures that appropriate contractual and organisational measures are in place (including sub-processor obligations under this DPA). Where relevant, provider security measures and assurance documentation may be referenced in the Trust Center and/or made available under the audit clause.
Appendix 3 - Security Measures
This Appendix 3 describes the baseline technical and organisational security measures implemented by Queue-it to protect Personal Data processed under this DPA. These measures cover physical, technical and organisational security. Supporting detail (including applicable third-party assurance) is available via Queue-it’s Trust Center referenced in Clause 5.3.
Physical safety
- Fire, power failure, flooding etc. Production services are hosted in professional data centre and/or cloud environments designed for resilience; incidents affecting Queue-it’s office locations do not, by themselves, interrupt delivery of the Services.
- Hosting facilities. Physical and environmental security controls for hosting facilities are primarily provided by Queue-it’s cloud and data centre providers (as applicable), including access controls and environmental safeguards.
Access control
- Access to systems used to provide the Services is restricted to authorised personnel with unique user accounts.
- Access is granted on a need-to-know basis and is kept under periodic review; access is removed when no longer required.
- Multi-factor authentication (MFA) is used for administrative access and remote access to production environments where applicable.
Technical safety
- Firewalls and malware protection. Systems are protected using security controls appropriate to the environment, including malware protection and network security controls.
- Administrative access. Administrative access to production systems is restricted and secured (including least privilege principles and secure remote access mechanisms where applicable).
- Vulnerability management and patching. Queue-it maintains processes to identify, assess, prioritise and remediate vulnerabilities and to apply security updates in a timely manner based on severity and risk.
Encryption
- External communications to and from the Services use encrypted transport (e.g., HTTPS/TLS) where applicable.
- Support and administrative access to systems is performed via encrypted channels where applicable (e.g., TLS, VPN).
- Where appropriate for the relevant storage systems and managed services, encryption at rest is used and keys/secrets are protected by access controls.
Storing of data and backup
- Customer Personal Data is stored in hosted infrastructure used to deliver the Services (including cloud infrastructure and storage systems as applicable).
- Backups and recovery capabilities are maintained as appropriate to support availability and integrity.
- Restore/recovery procedures are tested periodically where appropriate.
Organizational safety
- Access rights. Access to systems is controlled via personal logins; generic administrative logins are not permitted where feasible; access is reviewed periodically.
- Security awareness. Personnel with access to systems used to provide the Services receive security awareness training appropriate to their role.
- Incident response. Queue-it maintains an incident response process for security incidents, including investigation, mitigation and corrective actions, aligned with the DPA’s breach notification obligations.
Deletion and discarding
- Storing media. Devices and storage media are handled using secure disposal processes when no longer in use, appropriate to the medium and risk.
- End of services. Deletion and deletion certification are handled in accordance with the DPA’s end-of-services provisions, including the default 60-day deletion/certification timeline.
Appendix 4 — Instruction pertaining to the use of Personal Data
C.1 The subject of / instruction for the processing
The Data Processor processes Personal Data on behalf of the Data Controller only to provide the Services described in the Main Agreement and Appendix 1, and only on the Data Controller’s documented instructions.
C.2 Security of processing
The Personal Data consists of ordinary Personal Data and does not include special categories of data (see Appendix 1). Given the volume of end-user traffic processed, an appropriate level of security shall be maintained, with particular attention to the availability and resilience of the Services. The Data Processor is entitled and obliged to determine the technical and organisational measures required to achieve the agreed level of security, and shall at a minimum maintain the measures described in Appendix 3 (Security Measures).
C.3 Assistance to the Data Controller
Insofar as this is possible, the Data Processor shall assist the Data Controller in accordance with Clauses 8 and 10, including assistance with Data Subject requests, notification of a Data Security Incident (including the Article 33(3) elements listed in Clause 8.3), data protection impact assessments and prior consultation, taking into account the nature of the Processing and the information available to the Data Processor.
C.4 Storage period / erasure
The retention periods for specific data types are set out in Appendix 1 (IP address and user agent: 13 months; Identity-feature email: 12 months; Notification-feature email: 3 months). On termination of the provision of the Services, the Data Processor shall delete or return the Personal Data and certify deletion within 60 days, in accordance with Clause 12, unless the Data Controller has modified its original choice in a documented instruction.
C.5 Processing locations
Processing takes place at the Data Processor’s facilities and at the facilities of the Subprocessors set out on the Sub-processor list. Processing shall not be performed at other locations without the Data Controller’s prior written authorisation.
C.6 Instruction on transfers to third countries
The Data Controller instructs the Data Processor to carry out transfers of Personal Data to third countries only in accordance with Clause 7 — relying on an applicable adequacy decision (including the EU–US Data Privacy Framework) where available, and otherwise on the Standard Contractual Clauses, as deemed entered into and completed in Appendix 5 (Cross-Border Transfer Mechanism), together with any required supplementary measures. Absent documented instructions, the Data Processor shall not be entitled to transfer Personal Data to a third country.
C.7 Procedures for the Data Controller’s audits and inspections
The following procedures apply to audits and inspections under Clause 10.4:
- Notice. The Data Controller shall give reasonable prior written notice of an on-site audit or inspection (at least 30 days), except where earlier access is required due to a material Data Security Incident affecting the Data Controller or a request from a competent Supervisory Authority.
- Scope. Audits and inspections are limited to information, systems, facilities and records relevant to the Services and the Data Controller’s Personal Data processed under this DPA.
- Confidentiality. The Data Controller and any mandated auditor shall be bound by confidentiality obligations and shall not disclose audit outputs except as required by law or to a competent Supervisory Authority.
- Minimal disruption. Audits shall be conducted in a manner that avoids unnecessary disruption to the Data Processor’s operations and maintains the security and confidentiality of other customers’ data.
- Frequency. Routine audits are limited to once per year; additional audits may be performed where reasonably necessary due to a material incident or a regulatory or Supervisory Authority requirement.
- Cost. The Data Controller bears its own costs and the fees of any mandated auditor; the Data Processor bears its internal cost of cooperation during a routine audit. Where an audit reveals a material breach of this DPA by the Data Processor, the parties will discuss reasonable remediation and cost allocation in good faith.
- Auditor. Any mandated auditor must be independent, must not be a competitor of the Data Processor, and must be acceptable to the Data Processor acting reasonably.
C.8 Sub-processor audits
Where the Data Processor uses third-party cloud or hosting providers to deliver the Services, it relies on those providers’ physical and platform security controls as part of its overall technical and organisational measures, and ensures that appropriate contractual and organisational measures are in place (including the Sub-processor obligations under Clause 6). Relevant provider security measures and assurance documentation may be referenced via the Trust Center and/or made available under Clause 10.4. The Data Controller’s participation in any inspection of a Sub-processor does not alter the fact that the Data Processor continues to bear full responsibility for the Subprocessor’s compliance with the Data Protection Legislation and this DPA.
Appendix 5 — Cross-Border Transfer Mechanism
This Appendix 5 sets out the Chapter V transfer mechanisms referred to in Clause 7 and Clause C.6 of Appendix 4. Where a transfer benefits from an adequacy decision under Article 45 GDPR (including the EU–US Data Privacy Framework), the parties rely on that adequacy decision and this Appendix 5 applies only as the fallback mechanism described in Clause 7.4. The mechanisms below are deemed entered into (and incorporated into this DPA by this reference) upon acceptance or signature of this DPA and do not require separate signature. If Standard Contractual Clauses other than those listed in this Appendix are adopted by a Supervisory Authority or other body of competent jurisdiction to govern a cross-border transfer of Personal Data under the Data Protection Legislation, the parties agree to incorporate them in accordance with their respective roles.
I. EU Data Transfers
Transfers of Personal Data originating from the EU/EEA that are not covered by an adequacy decision are made pursuant to the EU SCCs (Commission Implementing Decision (EU) 2021/914), which are completed as follows:
- Applicable Modules: Module Two (Controller to Processor) applies where the Customer is a controller and the Data Processor processes Personal Data as its processor. Module Three (Processor to Processor) applies where the Customer is itself a processor and the Data Processor processes Personal Data as its sub-processor.
- For each applicable Module: (a) the optional Docking Clause in Clause 7 applies; (b) in Clause 9, Option 2 (general written authorisation) applies, with the minimum notice period for Sub-processor changes as set out in Clause 6.3 of this DPA (60 days); (c) in Clause 11, the optional language does not apply; (d) all square brackets in Clause 13 are removed; (e) in Clause 17 (Option 1), the EU SCCs are governed by Danish law; and (f) in Clause 18(b), disputes will be resolved by the courts of Denmark.
- Annex I.A of the EU SCCs is completed with the parties’ details as set out in this DPA and the Main Agreement (data exporter: the Customer; data importer: Queue-it ApS, Skelbækgade 4, 1., 1717 Copenhagen V, Denmark, privacy@queueit.com). Annex I.B is completed with the description of the Processing set out in Appendix 1 and Appendix 4 (data subjects: end-users of the Customer’s websites and applications; categories of data: IP address and user agent, and — where the optional Identity or Notification features are enabled — end-user email addresses; no special categories; frequency: continuous; retention: as set out in Appendix 1). Annex I.C: the competent supervisory authority is the Danish Data Protection Agency (Datatilsynet), or the Supervisory Authority competent for the data exporter as determined under Clause 13 of the EU SCCs.
- Annex II of the EU SCCs is completed with the technical and organisational measures set out in Appendix 3 (Security Measures). In the case of transfers to Sub-processors, the related details are set out in the data importer’s sub-processing documentation referenced in Clause 6.
II. UK Data Transfers
Transfers of Personal Data subject to the UK GDPR are made pursuant to the UK International Data Transfer Addendum to the EU SCCs (version B.1.0), issued by the Information Commissioner’s Office under s.119A of the Data Protection Act 2018 (the “UK Addendum”), which is completed as follows: for Tables 1 and 3 of Part 1 of the UK Addendum, the information set out in Section I above applies; for Table 2, the version of the approved EU SCCs with the Modules as set out in Section I applies; and for Table 4, both “Importer” and “Exporter” are selected. Alternatively, the parties may execute the UK IDTA where required.
III. Swiss Data Transfers
Transfers of Personal Data originating from Switzerland are made pursuant to the EU SCCs as completed in Section I above, with the following modifications: (1) references to Regulation (EU) 2016/679 (GDPR) in the EU SCCs are interpreted to include the Swiss Federal Act on Data Protection of 25 September 2020 (“FADP”) with respect to transfers subject to the FADP; (2) Clause 13 of the EU SCCs is modified so that the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) has authority over transfers governed by the FADP; (3) Clauses 17 and 18 are governed by the law of Switzerland and the parties agree to the jurisdiction of the courts of Switzerland with regard to disputes arising from those clauses, in respect of such transfers; and (4) the term “EU Member State” shall not be interpreted so as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs.
IV. Brazil Data Transfers
Transfers of Personal Data originating from Brazil and subject to the Brazilian General Data Protection Law (Law No. 13,709/2018, “LGPD”) are made pursuant to the standard contractual clauses approved by the Brazilian data protection authority (ANPD) and attached as Annex II to ANPD Resolution No. 19/2024 (the “Brazil SCCs”), which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows:
- Section I – Clause 1.1 (identification of the parties) is completed with the parties’ details as set out in this DPA and the Main Agreement (exporter: the Customer; importer: Queue-it ApS).
- Section I – Clause 2.1 (description of the transfer) is completed with the description of the Processing set out in Appendix 1 and Appendix 4, corresponding to Annex I.B as completed in Section I above.
- Section I – Clause 3: Option B (transfer between a controller as exporter and a processor/operator as importer) is selected and completed by reference to Appendix 1 and Appendix 4.
- Section I – Clause 4: Option A is selected, and “Exporter” is selected in items (a), (b) and (c) of Clause 4.1, where the Customer is a controller and the Data Processor processes Personal Data as its processor. Option B is selected where the Customer is itself a processor/operator and the Data Processor processes Personal Data as its sub-processor; in that case the third-party controller is the Customer’s relevant customer or affiliate as identified by the Customer on a case-by-case basis.
- Section III (security measures) is completed with the technical and organisational measures set out in Appendix 3 (Security Measures).
- Section IV – not applicable.
For the avoidance of doubt, nothing in this Section IV requires the Data Processor to carry out a transfer originating from Brazil absent the Data Controller’s documented instructions in accordance with Clause 7.1.
Download the Data Processing Agreement
Revised: September 9, 2026.