# Data Processing Agreement (DPA) — Platforma

**Version:** 1.1  •  **Effective:** 2026-09-01

Between **Platforma ApS** (CVR 46274814, Kærbyvej 131, 2610 Rødovre, Denmark; 'Processor') and **the Tenant** ('Controller'), per Regulation (EU) 2016/679 (GDPR) Article 28. This DPA prevails over any conflicting data-processing terms in the underlying subscription agreement.

## 1. Subject matter and duration

The Processor will process personal data on behalf of the Controller as part of the Platforma SaaS service for the duration of the subscription term. This DPA terminates automatically when the subscription ends (see §10).

## 2. Nature, purpose and instructions

Storage, retrieval, hosting, backup, and operational support of the Controller's tenant data on Microsoft Azure (Sweden Central region, EU).

The Processor processes personal data only on documented instructions from the Controller — including through the Controller's own use and configuration of the service — unless required to do so by EU or Danish law to which the Processor is subject (Article 28(3)(a)); in that case the Processor informs the Controller of the legal requirement before processing, unless that law prohibits such notice on important grounds of public interest. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other EU/national data-protection law (Article 28(3), final paragraph).

## 3. Categories of data subjects

Tenant administrators, tenant staff, tenant members (residents), and any contact persons recorded by the Controller.

## 4. Categories of personal data

Identity data (name, email, phone), authentication data (password hash, MFA tokens, session tokens), tenant content data (bookings, messages, documents, profile photos), audit logs. No special categories (Article 9) are processed as an intended part of the service.

## 5. Confidentiality

The Processor ensures that persons authorised to process the Controller's personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b)). Access is granted only to staff who need it to perform the Processor's obligations under this DPA, and such access is recorded in the audit trail.

## 6. Sub-processors

See https://platforma.nu/processors for the active register (GDPR Article 28). The Controller gives general written authorisation to these sub-processors and is informed of intended additions or replacements with at least 30 days' notice and may object in writing. The Processor imposes the same data-protection obligations set out in this DPA on any sub-processor by contract (Article 28(4)); where a sub-processor fails to meet its obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor's obligations.

## 7. Security measures

Encryption in transit (TLS 1.2+) and at rest (Azure SQL TDE). Per-tenant logical isolation via global query filters. ASP.NET Core Identity password hashing (PBKDF2). MFA available for all admin roles. Centralised audit logs with 5-year retention. See the /status and /processors pages for the operational posture.

## 8. Assistance to the Controller

The Processor assists the Controller in fulfilling data-subject rights (Articles 15-22) via the in-product Data Subject Request queue (/admin/gdpr/dsr) and self-service data export (/gdpr/download-my-data). Taking into account the nature of processing and the information available to it, the Processor also assists the Controller with security of processing (Article 32), personal-data-breach notification (Articles 33-34), data protection impact assessments (Article 35) and prior consultation of the supervisory authority (Article 36).

## 9. Personal data breaches

The Processor notifies the Controller without undue delay (and at the latest within 48 hours) of becoming aware of a personal data breach affecting the Controller's tenant data.

## 10. Return or deletion

On termination, the Processor shall — at the Controller's choice — either delete or return all personal data to the Controller and delete existing copies, unless EU or Danish law requires continued storage (Article 28(3)(g)). The Controller may export its data via the standard export endpoints at any time before termination; profile data is thereafter deleted or anonymised via the Processor's Article 17 erasure flow. Data under statutory retention (e.g. the Danish Bookkeeping Act — 5 years; security audit logs — 5 years) is kept for its legal period and deleted afterwards.

## 11. Audit

The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by it. On-site inspections are subject to reasonable notice (as a rule at least 30 days) and are conducted without undue disruption to the Processor's operations.

---

Signed electronically on subscription, or by physical signature returned to dpa@platforma.nu.
