Data Processing Agreement

Version 1.0 · Last updated: 3 July 2026

Læs på dansk

This Data Processing Agreement (the "Agreement") forms an integral part of the terms and conditions between the customer (the "controller") and Verkta (the "processor") and applies automatically to all customers. If you would like a signed copy including your company details, please write to hej@verkta.com.

1. Background and purpose

The Agreement sets out the rights and obligations that apply when the processor processes personal data on behalf of the controller, cf. Article 28(3) of the General Data Protection Regulation (GDPR). The processing is carried out for the purpose of delivering the Verkta platform: digital workplace risk assessment (APV), registration of occupational accidents and incidents, whistleblower scheme, GDPR documentation and digital signature.

2. Instructions

The processor shall process personal data only on documented instructions from the controller. Use of the platform constitutes the complete set of instructions. The processor shall notify the controller if, in the processor's opinion, an instruction infringes the GDPR or other data protection law.

3. Nature of the processing and categories of data

  • Data subjects: the controller's employees, managers and any external reporters.
  • Ordinary personal data: name and email address of the platform's users; content of action plans.
  • Workplace assessment (APV) responses: collected and stored anonymously without name, email address or IP address and cannot be attributed to individuals.
  • Whistleblower reports: may contain sensitive data and data relating to criminal offences. The reporter's identity is processed only if provided voluntarily, and access is restricted to the whistleblower unit designated by the controller.

4. Confidentiality

The processor shall ensure that only persons with a work-related need have access to the personal data, and that such persons are subject to an obligation of confidentiality. Access to whistleblower cases is technically restricted to the users whom the controller itself has designated as responsible for the whistleblower scheme.

5. Security of processing

  • All traffic is encrypted with TLS; data is encrypted at rest with the hosting provider.
  • Passwords are hashed with bcrypt; access keys and tokens are stored only as SHA-256 hash values.
  • Role-based access control and an audit-proof activity log on whistleblower cases.
  • Ongoing security updates of the platform's components and dependencies.

6. Sub-processors

The controller grants a general authorisation for the use of sub-processors. In the event of planned changes, the controller will be notified by email at least 30 days in advance. Current sub-processors:

ProviderServiceLocation
Vercel Inc.Hosting and operations (incl. file storage)EU (Frankfurt) · EU-U.S. DPF
Neon Inc.DatabaseEU (Frankfurt)
Resend Inc.Transactional emailsEU/US · SCCs
Stripe Payments Europe Ltd.Payment processing (independent controller for card data)EU (Ireland)

7. Assistance to the controller

The processor shall, to a reasonable extent, assist the controller in fulfilling its obligations concerning the rights of data subjects (Chapter III of the GDPR) as well as Articles 32-36, including in connection with requests for access, erasure and data portability.

8. Personal data breaches

The processor shall notify the controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach, providing the information necessary for the controller's notification to the Danish Data Protection Agency.

9. Deletion and return of data

Upon termination of the subscription, the controller may export its data for 90 days, after which all personal data is deleted or anonymised, unless legislation requires continued storage.

10. Audits and inspections

Upon request, the processor shall make available the information necessary to demonstrate compliance with Article 28, and shall allow for and contribute to audits conducted by the controller or an auditor mandated by the controller: subject to reasonable notice and no more than once per year, unless there is a specific reason.

11. Duration

The Agreement applies for as long as the processor processes personal data on behalf of the controller, and is replaced by or lapses together with the main agreement (the terms and conditions).