Agreements

Data processing agreement

Last updated 4 October 2026 · Version 1.1 of 4 October 2026

How to accept the agreement. An administrator at your company accepts it in Adea under Organisation and Agreements. We then record name, title and time, and you get a signed copy as a PDF with your company number and address. The text below is the same as in the PDF; fields in square brackets are filled with your details.

Data Processing Agreement

Version 1.1 of 4 October 2026. This agreement is based on the Danish Data Protection Agency's standard contractual clauses under Article 28(3) of the GDPR, adapted to Adea.

1. The parties

The controller: [Customer name], company reg. no. [reg. no.], [address] (the "Customer").

The processor: Marcus Wilstrup, VAT no. PT310292522, Rua da Fonte 85 B, Capride, 2785-371 São Domingos de Rana, Portugal ("Adea").

The parties have entered into this agreement about Adea's processing of personal data on behalf of the Customer. It forms part of the Customer's agreement to use Adea, including Adea's terms of service, and applies for as long as Adea processes personal data for the Customer.

2. Purpose and background

Adea is a service where the Customer's staff ask questions about the Customer's business. Adea answers by reading the Customer's code and running read-only queries against the Customer's database. In doing so, Adea may process personal data found in the Customer's database, code or questions.

This agreement ensures that Adea complies with the General Data Protection Regulation (EU 2016/679) and the Danish Data Protection Act when processing personal data for the Customer. Appendix A describes the processing, appendix B the sub-processors and appendix C the Customer's instructions and the security measures.

3. The Customer's rights and obligations

The Customer is responsible for the processing complying with data protection law, including having a lawful basis for it and giving data subjects the information they are entitled to.

The Customer decides the purposes and means of the processing. The Customer controls which databases and repositories Adea can access, and which tables and columns are restricted for which roles.

The Customer warrants that it has the right to give Adea access to the code and data it connects. The Customer makes sure that Adea does not use special categories of personal data (Article 9), data on criminal offences (Article 10) or national identification numbers in answers, for example by restricting the tables and columns where they are found, unless the parties have agreed otherwise in writing.

4. Adea acts on instructions

Adea processes personal data only on documented instructions from the Customer. The instructions are set out in this agreement, appendix C and the choices the Customer makes in Adea. Adea informs the Customer immediately if, in Adea's opinion, an instruction infringes data protection law.

If EU law or national law to which Adea is subject requires Adea to process the data otherwise, Adea informs the Customer beforehand, unless the law prohibits it.

5. Confidentiality

Adea gives access to the personal data only to people who need it to deliver the service and who have committed to confidentiality or are under a statutory duty of confidentiality. Access is removed when the need ends.

6. Security of processing

Adea implements the technical and organisational measures required by Article 32, appropriate to the risk to data subjects. The measures are described in appendix C. Adea assesses the risk on an ongoing basis and improves the measures when needed.

7. Sub-processors

With this agreement the Customer gives general authorisation for Adea to use the sub-processors listed in appendix B.

Adea notifies the Customer in writing at least 30 days before adding or replacing a sub-processor. The Customer may object within those 30 days. If the parties can't find a solution, the Customer may end the subscription before the change takes effect and get a refund of prepaid fees for the remaining period.

Adea imposes the same data protection obligations as in this agreement on each sub-processor and remains liable to the Customer for their compliance.

8. Transfers to third countries

Adea transfers personal data to countries outside the EU/EEA only on the Customer's instructions as set out in appendices B and C, and only with a valid transfer mechanism under Chapter V of the GDPR, such as the EU-US Data Privacy Framework or the EU Standard Contractual Clauses.

If Adea is or becomes established in a country outside the EU/EEA, for example because this agreement is assigned under clause 14, the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor), apply between the Customer as data exporter and Adea as data importer. They are incorporated into this agreement by reference, without the parties having to sign anything. For them:

  • Annex I.A is completed with the parties' details in clause 1, Annex I.B with appendix A, Annex II with appendix C and Annex III with appendix B.
  • The optional Clause 7 does not apply. Under Clause 9(a), Option 2 (general written authorisation) applies, with the notice period set out in clause 7.
  • The competent supervisory authority under Clause 13 is the supervisory authority of the EU/EEA country where the Customer is established. If the Customer is not established in the EU/EEA, it is the authority designated by Clause 13.
  • Under Clause 17 the clauses are governed by Danish law, and under Clause 18 disputes are resolved by the Danish courts, with the City Court of Copenhagen (Københavns Byret) as the court of first instance. Where this cannot be agreed, the clauses' own defaults apply.

If Adea uses a sub-processor outside the EU/EEA, Adea ensures that the transfer has a valid basis. If Adea itself is established in the EU/EEA, this is done for example by entering into Module Three (processor to processor) of the Standard Contractual Clauses with the sub-processor. If Adea is established outside the EU/EEA, Adea imposes on the sub-processor the same obligations Adea has under Module Two.

If the Standard Contractual Clauses conflict with the rest of this agreement, the Standard Contractual Clauses prevail.

9. Assistance to the Customer

Adea helps the Customer respond to data subjects' rights (access, rectification, erasure, restriction, portability and objection) as far as possible, taking the nature of the processing into account.

Adea also helps the Customer with security under Article 32, breach notification under Articles 33 and 34, impact assessments under Article 35 and prior consultation under Article 36.

10. Personal data breaches

Adea notifies the Customer without undue delay and no later than 48 hours after becoming aware of a personal data breach. The notice describes, as far as possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.

11. Deletion and return

When the agreement to use Adea ends, or the Customer deletes its organisation in Adea, Adea deletes the Customer's personal data, including copies of the Customer's code, within 30 days. Backups are deleted with the normal rotation and no later than 35 days after that deletion. Adea keeps only what the law requires, such as accounting records.

Before the end, the Customer can download its questions and answers through the export in Adea.

12. Audits and inspections

Adea makes available all information necessary to demonstrate compliance with this agreement. Adea allows for and contributes to audits and inspections by the Customer or an independent auditor appointed by the Customer, with reasonable notice and at most once a year, unless a breach or an authority gives cause for more.

13. Liability

The limitation of liability in Adea's terms of service also applies to this agreement. The amount cap is shared between the terms of service and this agreement, so it cannot be used twice.

The limitation applies only between the Customer and Adea. It does not change data subjects' rights under the GDPR, including the right to compensation under Article 82, and it does not apply where the Standard Contractual Clauses or mandatory law do not allow a limitation.

14. Assignment

Adea may assign this agreement together with the terms of service to a company that Adea or Adea's owner owns or controls, including a company established outside the EU/EEA. Adea notifies the Customer in writing at least 30 days before. The new company takes over all of Adea's rights and obligations under the agreement and becomes the processor in Adea's place. If the company is established outside the EU/EEA, clause 8 on the Standard Contractual Clauses applies from the assignment.

If the Customer does not want to continue with the new company, the Customer may end the subscription before the assignment takes effect and get a refund of prepaid fees for the remaining period.

15. Term

The agreement takes effect when the Customer accepts it in Adea and applies for as long as Adea processes personal data for the Customer. If data protection law changes, either party may require the agreement to be updated.

If this agreement conflicts with Adea's other terms, this agreement prevails as regards the processing of personal data. The agreement is governed by Danish law, and disputes are resolved under the rules on governing law and venue in the terms of service, unless clause 8 says otherwise.

Appendix A: The processing

Purpose: to answer the Customer's staff's questions about the Customer's business, keep questions and answers, send the notifications and reports the Customer asked for, and show insights from the Customer's own numbers.

Nature of the processing: read-only queries against the Customer's database, reading the Customer's code, storing questions, answers and summarised results, and sending email and notifications.

Types of personal data: the data in the Customer's database and code that ends up in an answer, typically names, contact details, customer and order numbers and transaction data. The Customer can restrict tables and columns. Also the name, email and role of the Customer's Adea users.

Categories of data subjects: the Customer's customers, partners and staff who appear in the Customer's data, and the Customer's Adea users.

Duration: for as long as the Customer uses Adea, and then until deletion under clause 11.

Appendix B: Sub-processors

The Customer has approved these sub-processors:

  • Hetzner Online GmbH: Servers and databases. EU (Germany). No transfer outside the EU.
  • Anthropic PBC: The AI model that reads code and writes SQL (Claude). Data is not used for training. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
  • Cloudflare, Inc.: Network and encrypted connection to the Adea service. Storage of encrypted backups of Adea's database (R2 with EU jurisdiction). EU and USA. The backups are stored only in the EU. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
  • Resend (Plus Five Five, Inc.): Sending email (sign-in, notifications, reports). USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
  • Stripe Payments Europe, Ltd.: Payments and invoicing. Ireland and USA. EU Standard Contractual Clauses.
  • GitHub, Inc.: Read access to the customer's code through the GitHub App. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
  • Slack Technologies, LLC: Questions and answers in Slack, only when the customer connects Slack. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
  • Functional Software, Inc. (Sentry): Error monitoring: technical error reports from Adea, without the content of your data, code, questions or answers. EU (Germany). Data is stored in the EU. Any access from the USA relies on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.

Appendix C: Instructions and security

Instructions: Adea processes data only to deliver the service described in appendix A. The AI model does not use the Customer's data for training. Data is never shared with other customers.

Usage data: Adea may produce anonymised, aggregated statistics on how the service is used, such as the number of questions, response times and errors, and use them to run and improve the service. The statistics never contain the content of the Customer's data, code, questions or answers, cannot be traced back to a person and are never used to train AI models.

Retention: raw result rows from the Customer's database are deleted after 30 days. Questions, SQL and summarised numbers are kept for as long as the Customer uses Adea. The audit log is kept for as long as the organisation exists.

Location: the Customer's data is stored on servers in the EU, and backups are stored encrypted in the EU. Questions and excerpts of code and data are sent to the AI model at Anthropic in the USA under the transfer mechanism in appendix B.

Security measures:

  • Adea connects to the Customer's database with a read-only user, with a time limit and a row limit per query.
  • Every query is checked before it runs: read-only, no restricted tables or columns.
  • The Customer's data is separated from other customers' by row-level security in the database and separate connections per customer.
  • The AI model cannot run code or commands. All access goes through controlled functions bound to the Customer.
  • Connection details and keys are encrypted. All traffic is encrypted with TLS.
  • Sign-in uses one-time links or Google, never passwords.
  • Every question is logged with the user, the time and the tables and code used. The Customer's administrators can see the log.
  • Copies of the Customer's code are deleted when the repository is removed or the organisation is deleted.