BankConnectorData Processing Agreement · v1.0

Data Processing Agreement (DPA)

v1.0Last updated 8 July 2026. This DPA forms part of the BankConnector Customer Agreement, Platform Agreement, or Connected Company Agreement (the "Agreement") between BankConnector ApS ("BankConnector", the "Processor") and the customer entity that owns the company workspace (the "Controller"). It governs processing of personal data in Customer Data under Article 28 GDPR. In case of conflict with the Agreement, this DPA prevails for its subject matter.

1Roles and scope

1.1

The Controller is the company whose workspace the personal data belongs to. BankConnector processes personal data in Customer Data as Processor, on the Controller's behalf.

1.2

For Usage Data (technical logs, metrics, and de-identified aggregated data), BankConnector is an independent controller for the purposes of service operation, security, fraud and abuse prevention, and service improvement, as described in the Agreement.

1.3

Where the Controller's access is provided through a Platform, the Platform's access to and processing of the Controller's data takes place under the Controller's authorisation in its own agreement with the Platform; the Platform is not a subprocessor of BankConnector.

2Processing details (Article 28(3))

3Processor obligations

3.1

Instructions. BankConnector processes personal data only on the Controller's documented instructions (the Agreement, this DPA, and the Controller's configuration and use of the services), unless required by EU or Member State law, in which case BankConnector informs the Controller before processing unless that law prohibits it. BankConnector will inform the Controller if, in its opinion, an instruction infringes the GDPR.

3.2

Confidentiality. Persons authorised to process personal data are bound by confidentiality obligations and receive access only as needed for their role.

3.3

Security. BankConnector implements the technical and organisational measures in Annex II and the Security Policy, including field-level encryption at rest, TLS in transit, tenant isolation enforced at the database layer, role-based access control, multi-factor authentication, and a tamper-evident audit trail. Measures may be updated provided the overall level of protection is not materially reduced.

3.4

Assistance. Taking into account the nature of processing, BankConnector assists the Controller with appropriate technical and organisational measures in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection), including through the built-in export and erasure functions, and, insofar as information is available to BankConnector, with the Controller's obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation).

3.5

Personal-data breach. BankConnector notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting Customer Data, providing (as information becomes available) the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. BankConnector documents breaches and remediation.

3.6

Deletion and return. During the term, the Controller can export its data at any time using the export functions. On termination and expiry of the wind-down period, BankConnector deletes or anonymises personal data in Customer Data in accordance with the retention schedule in the Service Description (journal documents 90 days; audit records 5 years; usage events 365 days; idempotency records 24 hours), except where EU or Member State law requires longer storage or a documented legal hold applies. The Controller's per-user and company-level erasure functions are described in the Documentation.

3.7

Audits. BankConnector makes available the information reasonably necessary to demonstrate compliance with Article 28, including summaries of security assessments and, once achieved, certification reports (available on request under NDA), and allows and contributes to audits. Audits beyond documentation review (including on-site inspections) are limited to once per 12 months, on at least 30 days' notice, during business hours, at the Controller's cost, under confidentiality, and must not compromise the security or data of other customers; an additional audit is permitted where required by a supervisory authority or following a material breach.

4Subprocessors

4.1

The Controller grants a general authorisation for the subprocessors listed in Annex III (also published at bankconnector.com/legal). BankConnector will give at least 30 days' notice before adding or replacing a subprocessor; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected services with a pro-rata refund of prepaid unused fees.

4.2

BankConnector imposes data-protection obligations on subprocessors equivalent to this DPA and remains fully liable for their performance.

5Transfers

Customer Data is stored and processed within the EU/EEA. Personal data is not transferred outside the EEA unless the transfer is protected by a Chapter V GDPR mechanism (adequacy decision or Standard Contractual Clauses, with supplementary measures where needed), and any such subprocessor is identified in Annex III.

6General

6.1

This DPA lasts as long as BankConnector processes personal data in Customer Data. Liability under this DPA is subject to the Agreement's liability provisions. This DPA is governed by the law and venue of the Agreement.


Annex IProcessing details

As set out in Section 2.

Annex IITechnical and organisational measures (summary; detail in the Security Policy)

Annex IIISubprocessors

SubprocessorPurposeLocation
Amazon Web Services EMEA SARLCloud infrastructure and database hostingEU regions

The current list is maintained at bankconnector.com/legal; changes are notified per Section 4.1.

BankConnector ApS · bankconnector.com/legalBC-LGL-DPA-1.0