Data Processing Agreement

Version 1.0 · Effective from September 29, 2026

Public version. Customers download a copy filled in with their company details and connected systems in Alunta under Settings → Master Data.

Controller

Name
[Company name]
Address
[Address]
[Postal code] [City]
[Country]
CVR
[CVR number]

Processor

Name
Boligforeningsweb ApS (trading as Alunta ApS)
Address
Aalborg Syndikatet, Møllegade 11A
9000 Aalborg
Denmark
CVR
33643284

1. Purpose, nature and duration

The processor provides Alunta, a platform for subscriptions, invoicing and payment collection with a customer portal where the controller's customers can view and pay their invoices. The processor processes personal data on behalf of the controller solely to provide Alunta. The processing includes storing and displaying data, generating invoices and other documents, and transferring data to the systems the controller has connected itself (Annex 2), and lasts for as long as is necessary to provide Alunta.

2. Data subjects and personal data

The data subjects are the controller's customers (private individuals and sole traders), contact persons at the controller's business customers, the controller's own users of Alunta, and payers who pay on behalf of the controller's customers.

The personal data comprises name, address, email address, phone number, CVR/VAT number, customer number, subscription, invoicing and payment history, IP address and activity in checkout and the customer portal, the content of emails sent to customers, bank registration and account numbers and direct debit mandates (Leverandørservice), EAN/GLN number and order references, and masked card details held by the payment provider. The processor does not intend to process sensitive data (special categories of personal data).

3. Instructions

The processor may only process personal data on documented instructions from the controller, unless EU or member state law requires otherwise. In that case the processor informs the controller of the requirement before processing, unless that law prohibits it. The instructions include transfers to the systems the controller has connected to its Alunta account itself (Annex 2).

If the processor considers that an instruction infringes the General Data Protection Regulation or other data protection law, the processor immediately informs the controller.

4. Confidentiality and security

Persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality. The processor implements the technical and organisational measures required by Article 32 of the General Data Protection Regulation. The current measures are set out in Annex 3.

5. Sub-processors and third countries

The processor has the controller's general authorisation to engage sub-processors. The current list is set out in Annex 1. The processor imposes the same data protection obligations on its sub-processors as in this agreement and remains fully liable for their performance, cf. Article 28(4).

Additions or replacements of sub-processors are announced at least 30 days in advance in Alunta's in-product changelog. The controller may object on reasonable grounds.

Personal data is only transferred to countries outside the EU/EEA where a valid transfer basis exists, such as the EU-US Data Privacy Framework or the European Commission's standard contractual clauses (SCCs). The basis for each sub-processor is set out in Annex 1.

6. Assistance and personal data breaches

Insofar as possible, the processor assists the controller in responding to requests from data subjects exercising their rights and in complying with Articles 32-36 (security, breach notification, impact assessments and prior consultation).

The processor notifies the controller without undue delay after becoming aware of a personal data breach concerning the controller's personal data.

7. Deletion and return

When the agreement ends, the processor deletes the personal data unless retention is required by law (for example bookkeeping law). If the controller requests it before the agreement ends, the processor instead returns the data in a commonly used format.

Data transferred to the controller's own systems (Annex 2) is the controller's own copy and is not covered by the processor's deletion.

8. Supervision and audit

The controller may supervise the processor's compliance with this agreement, primarily through documentation and statements the processor provides on request. A physical audit at the processor or its sub-processors requires reasonable justification and must be agreed in writing with reasonable notice. The controller bears the costs.

9. Liability

The processor's liability is limited to direct losses and cannot exceed the amount the controller has paid for Alunta in the preceding 12 months. The processor is not liable for indirect losses, including loss of operation, loss of data, loss of profit or goodwill.

10. Term and amendments

This agreement applies for as long as the processor processes personal data for the controller. The processor may amend the agreement with at least 30 days' notice in writing, by email or in Alunta's in-product changelog. If the controller cannot accept the amendments, it may terminate the cooperation. Continued use of Alunta after the amendments take effect is deemed acceptance.

11. Contact and acceptance

Questions about this agreement and data protection may be sent to kontakt@alunta.com. By creating and using Alunta, the controller accepts this data processing agreement.

Annex 1 - Sub-processors

Sub-processors marked as conditional are only used when the controller uses the relevant feature.

Sub-processor Purpose Location and transfer basis
Hetzner
Hetzner Online GmbH
Hosting of servers, database, backups and files. Germany (EU)
Mailgun
Mailgun Technologies, Inc.
Sending emails, including invoices. EU (Germany and Belgium); US company
EU-US Data Privacy Framework and SCCs
Slack (Alunta's internal workspace)
Slack Technologies, LLC
Alunta's internal operational and error alerts, which may contain customer names. USA
EU-US Data Privacy Framework and SCCs
cvr.dev Lookup and monitoring of CVR details for business customers. Germany (EU), AWS Frankfurt
VatCheckAPI
Everapi GmbH
Validation of EU VAT numbers. Austria (EU)
ip-api.com
Artia International S.R.L.
Determining country from IP address at checkout. Romania (EU)
Scalar
API Documentation Inc. (dba Scalar)
The test feature in the API documentation, when a user tests an API call. Canada
SCCs
Google Fonts
Google Ireland Limited
Web fonts on checkout and customer portal (IP address). Ireland (EU) and USA
EU-US Data Privacy Framework and SCCs
Bunny Fonts
BunnyWay d.o.o.
Web fonts on checkout and payment-error pages (IP address). Slovenia (EU)
Sproom
Visma e-conomic A/S (driver Sproom / sproom.net)
(conditional)
Sending e-invoices via EAN/NemHandel. Denmark (EU)
Mastercard Leverandørservice
Mastercard Payment Services Denmark A/S
(conditional)
Collection via Leverandørservice, with Alunta as data supplier. Denmark (EU)
Vipps MobilePay
Vipps MobilePay AS
(conditional)
Payments via Vipps MobilePay through Alunta's partner agreement. Norway (EEA)

Annex 2 - Systems the controller has connected itself

The systems below are not sub-processors. The controller has connected them with its own account and its own agreement with the provider, and the processor only transfers data to them because the controller has instructed it to by connecting the system.

The systems the controller has connected are listed in the filled-in agreement, which is downloaded in Alunta under Settings → Master Data.

Annex 3 - Security measures