Legal
Data Processing Agreement
This Data Processing Agreement governs Tradebird's processing of personal data on behalf of customers using the service.
- Effective date:
- 7 September 2026
- Version:
- 2026-09-07
This Data Processing Agreement (DPA) forms part of the agreement between the customer organization that accepts or otherwise agrees to Tradebird's Terms of Service (Customer) and the Tradebird legal entity identified below (Tradebird). It applies where Tradebird processes personal data on behalf of Customer in providing the service.
1. Relationship to the agreement
This DPA is incorporated into the Terms of Service when Customer creates an organization or otherwise agrees to the Terms. The person accepting represents that they are authorized to bind Customer.
If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. The Terms otherwise continue to apply, including their governing-law, liability, and dispute provisions.
2. Definitions and roles
Terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meanings given in applicable data protection law, including the GDPR.
Customer Personal Data means personal data contained in information submitted to the service by or for Customer that Tradebird processes on Customer's behalf.
Customer is the controller, or a processor acting for another controller, of Customer Personal Data. Tradebird is Customer's processor or subprocessor. Each party remains independently responsible for personal data it processes as a controller, as described in the Privacy Policy.
3. Processing instructions
Tradebird will process Customer Personal Data only:
- to provide, secure, support, and maintain the service;
- as configured, submitted, or instructed through Customer's authorized use of the service;
- as stated in the agreement; or
- where required by applicable law, in which case Tradebird will inform Customer before processing unless the law prohibits that notice.
The agreement, Customer's use and configuration of the service, and documented support requests are Customer's complete documented instructions. Additional instructions require mutual written agreement and may be subject to reasonable fees where they materially exceed the service's ordinary operation.
Tradebird will notify Customer if, in Tradebird's opinion, an instruction infringes applicable data protection law. Tradebird may suspend the affected processing while the parties address the instruction.
4. Customer responsibilities
Customer will:
- have a lawful basis and provide required notices for Customer Personal Data;
- give lawful, documented instructions and use the service in accordance with applicable law;
- configure access and sharing appropriately and ensure authorized users follow Customer's instructions;
- respond to data subjects and regulators unless the DPA assigns assistance to Tradebird; and
- avoid submitting information that the service is not designed to process, including the restricted data described in the Terms, unless Tradebird has expressly agreed otherwise in writing.
Customer is responsible for determining whether the service and the safeguards described here are appropriate for its processing.
5. Confidentiality and personnel
Tradebird will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where needed for their work.
6. Security
Tradebird will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Schedule 2.
Customer acknowledges that security depends on the nature and configuration of the service, Customer's use, and the sensitivity of the data submitted. Tradebird may update its measures as technology and risks evolve, provided the overall level of protection is not materially reduced.
7. Personal data breaches
Tradebird will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available to Tradebird that Customer needs to meet its notification obligations. Tradebird may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the breach.
A notice is not an admission of fault or liability. Customer is responsible for notifying data subjects or authorities where required, with Tradebird's reasonable assistance.
8. Data-subject requests and compliance assistance
Taking into account the nature of the processing, Tradebird will provide reasonable assistance through available product functionality and, where necessary, appropriate technical or organizational measures so Customer can respond to requests to exercise data-subject rights.
If Tradebird receives a request concerning Customer Personal Data directly, it will ordinarily direct the requester to Customer and will not respond on Customer's behalf unless legally required or authorized by Customer.
Taking into account the nature of the processing and information available to Tradebird, Tradebird will also provide reasonable assistance with Customer's security obligations, breach assessments, data-protection impact assessments, and prior consultations with authorities.
9. Subprocessors
Customer gives Tradebird general authorization to use subprocessors. Tradebird will:
- impose data-protection obligations on each subprocessor that provide substantially equivalent protection for Customer Personal Data;
- remain responsible for the subprocessor's performance of its obligations to the extent required by applicable law; and
- maintain a current Subprocessor List.
Tradebird will give at least 30 days' notice before a new subprocessor begins processing Customer Personal Data, normally by email to the organization's account contact or through the service. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable resolution. If no resolution is possible, Customer may stop using and terminate the affected part of the service before the new subprocessor begins processing, or the agreement if the affected processing cannot reasonably be separated. This is Customer's sole remedy for the objection.
10. International transfers
Tradebird will ensure that transfers of Customer Personal Data outside the European Economic Area are covered by a lawful transfer mechanism and supplementary measures where required. Where the European Commission's Standard Contractual Clauses are needed, the then-current controller-to-processor or processor-to-processor modules, as applicable, are incorporated by reference. This DPA and its schedules complete the relevant annexes. The optional docking clause applies; optional redress wording does not; the supervisory authority and governing law are determined by applicable data protection law and, where permitted, Denmark.
Tradebird will use reasonable efforts to challenge unlawful or disproportionate government demands and notify Customer unless legally prohibited.
11. Information and audits
Tradebird will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. On reasonable written request, Tradebird will first provide available independent reports, certifications, security documentation, and written responses.
If that information is insufficient, Customer may conduct an audit no more than once per year, and additionally after a substantiated personal data breach or where required by a supervisory authority. Audits must be arranged in advance, occur during normal business hours, avoid unreasonable disruption, protect other customers and Tradebird's confidential information, and be performed by Customer or an independent auditor that is not a competitor. Customer bears its audit costs and Tradebird may charge reasonable costs for assistance beyond ordinary documentation, unless the audit identifies a material breach by Tradebird.
12. Return and deletion
During the term, Customer may use available functionality to access or export Customer Personal Data. When the agreement ends, Tradebird will delete or return Customer Personal Data in accordance with Customer's documented instruction, unless applicable law requires retention.
Deletion may occur through Tradebird's normal retention, recovery, backup, and secure-deletion cycles. Data retained in protected backups will remain isolated from ordinary use until overwritten. Tradebird may retain information that has been irreversibly anonymized so it is no longer personal data.
13. Duration and changes
This DPA remains effective while Tradebird processes Customer Personal Data. Tradebird may update it as described in the Terms. A material reduction in Customer's data-protection rights will be notified in advance, and Tradebird will request renewed acceptance where legally or contractually required.
Schedule 1 — Processing details
| Detail | Description |
|---|---|
| Subject matter | Provision, security, support, and maintenance of the service under Customer's instructions. |
| Duration | The agreement term plus the limited retention and deletion periods described in the agreement and Privacy Policy. |
| Nature and purpose | Hosting, organizing, retrieving, transmitting, analyzing, and otherwise processing information submitted or configured by Customer to provide the service. |
| Data subjects | Customer's authorized users and the individuals whose information Customer or its users submit, such as employees, representatives, suppliers, customers, prospects, and counterparties. |
| Personal-data types | Account and business contact details; communications; uploaded documents and their contents; usage and support data; and other personal data Customer elects to submit. The service is not designed for restricted data identified in the Terms unless expressly agreed. |
| Processing frequency | Continuous or as initiated by Customer and its authorized users during the agreement. |
| Controller rights | Customer may issue instructions and exercise its rights through the service and the contact details in this DPA. |
Schedule 2 — Technical and organizational measures
Tradebird's measures are designed to include, as appropriate to risk:
- encryption of data in transit and at rest using current industry-standard provider capabilities;
- authenticated access, role-based authorization, least-privilege administrative access, and tenant-boundary controls;
- logging, monitoring, alerting, and procedures for investigating suspected security events;
- resilience, backup, recovery, and continuity controls appropriate to the hosted service;
- secure development practices, code review, dependency maintenance, change control, and separation of environments;
- confidentiality obligations and access management for personnel;
- due diligence and contractual safeguards for relevant service providers;
- vulnerability, patch, and incident-management processes; and
- periodic review and improvement of safeguards as threats, processing, and technology change.
Tradebird will not disclose security details where doing so would materially weaken the service or expose another customer's information, but will provide reasonable assurance information under Section 11.
Contact
Contact us about this Data Processing Agreement, data protection, audits, security, or subprocessors.
Tradebird ApS
Company registration number: 46753313
Overgaden Oven Vandet 58A, 2. 1415 København K Danmark