Data Processing Agreement
Version: 2026-06-02-v1
This Data Processing Agreement ("DPA") is entered into between the Customer Organisation ("Controller") and Allegro IT ApS, CVR 34593701, Fyrrelien 8, 8920 Randers NV, Denmark ("Processor"), which operates the DonorLink service. The DPA governs the Processor's processing of personal data on behalf of the Controller in accordance with Article 28 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
1. Subject and duration. The Processor processes personal data on behalf of the Controller for as long as the Controller maintains an active account on the DonorLink service. The DPA takes effect on signing and terminates when the Controller's account is closed.
2. Nature and purpose. The processing consists of storing, organising, retrieving, and transmitting transaction records (donations and payments), related personal data, and identifying information for the purpose of donor and transaction management, tax reporting, transaction matching, and financial record-keeping on behalf of the Controller.
3. Categories of personal data. Names, email addresses, telephone numbers, postal addresses, national identification numbers (where provided), transaction amounts, transaction dates, payment methods, bank references, and organisation administrator roles. In this agreement, "transaction" means any financial record managed through the service — typically a donation, but also a payment or other transfer.
4. Categories of data subjects. Individuals whose transactions are recorded by the Controller — typically donors, but also payers or other parties to a financial transfer; administrators, staff, and invited users of the Controller's organisation on the DonorLink service.
5. Controller instructions. The Processor processes personal data only on the documented instructions of the Controller, including as set out in the DonorLink service interface and the DonorLink Terms of Service. The Processor notifies the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.
6. Confidentiality. The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7. Security measures (Article 32). The Processor applies: encryption at rest for national identification numbers; HTTPS in transit for all client connections; role-based access control; structured audit logging of all data-subject-affecting actions; SHA-256 duplicate detection on imported data; regular backups; physical and network security provided by the hosting sub-processor (Hetzner Cloud, Finland, EU).
8. Sub-processors. The Processor currently engages: Hetzner Online GmbH (hosting, Finland, EU); Stripe Payments Europe, Ltd. (payment processing for platform billing — used only when the Controller pays for the DonorLink service); and the Controller's configured SMTP provider (email delivery). The Controller grants general authorisation for these sub-processors. The Processor notifies the Controller in advance of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object.
9. Data subject rights. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests for exercising data-subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).
10. Breach notification. The Processor notifies the Controller without undue delay, and at the latest within 72 hours, of becoming aware of a personal data breach affecting the Controller's data. The notification contains at minimum the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed.
11. Return or deletion on termination. At the choice of the Controller, on termination of the service agreement the Processor deletes or returns all personal data processed on behalf of the Controller, and deletes existing copies, unless retention is required by Union or Member State law (including Bogføringsloven's 5-year retention of accounting records). Deletion is completed within 30 days of termination.
12. Audit rights. The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, on reasonable notice and during normal business hours.