Spring til indhold
NordicWeb
Forside
Priser
Priser Besparelse
Vores arbejde Om os Kontakt
Få et tilbud

Databehandleraftale

Databehandleraftale

Sidst opdateret: 01-09-2026

Denne databehandleraftale er et standarddokument, der udgør en del af aftalegrundlaget mellem NordicWeb og kunden. En underskrevet udgave udleveres på anmodning. Dokumentet bør gennemgås af en juridisk rådgiver inden endelig anvendelse.

1. Parter og roller

Denne databehandleraftale ("Aftalen") supplerer NordicWebs handelsbetingelser og regulerer NordicWebs behandling af personoplysninger på vegne af kunden. Kunden er dataansvarlig. NordicWeb, CVR-nr. 46643429, er databehandler. Aftalen indgås som en del af kundens accept af et konkret tilbud og handelsbetingelserne.

2. Genstand, varighed, karakter og formål

NordicWeb behandler personoplysninger med det formål at levere og drifte kundens hjemmeside eller webshop, herunder hosting, sikkerhedsopdateringer, fejlretning, backup, e-mailudsendelse fra formularer og support. Behandlingen varer, så længe NordicWeb leverer ydelser til kunden.

3. Typer af personoplysninger og kategorier af registrerede

Behandlingen omfatter de personoplysninger, som kundens hjemmeside indsamler og lagrer – typisk navn, e-mail, telefonnummer, virksomhedsnavn, beskedindhold samt tekniske data som IP-adresse, log- og cookieoplysninger – for kundens besøgende, kunder og kontaktpersoner. Kunden fastlægger og dokumenterer de konkrete kategorier. NordicWeb behandler ikke bevidst særlige kategorier af personoplysninger, medmindre det er aftalt skriftligt.

4. Instruks

NordicWeb behandler kun personoplysninger efter dokumenteret instruks fra kunden, herunder denne Aftale og de aftalte ydelser. NordicWeb underretter kunden, hvis en instruks efter NordicWebs vurdering strider mod databeskyttelsesreglerne.

5. Fortrolighed

NordicWeb sikrer, at personer, der er autoriseret til at behandle personoplysningerne, har forpligtet sig til fortrolighed eller er underlagt en passende lovbestemt tavshedspligt.

6. Behandlingssikkerhed (artikel 32)

NordicWeb gennemfører passende tekniske og organisatoriske foranstaltninger, herunder kryptering under overførsel (HTTPS/TLS), adgangsbegrænsning efter "need to know", en streng indholdssikkerhedspolitik (CSP) og sikkerhedsheaders, adskillelse af hemmeligheder (API-nøgler m.v.) fra kildekoden samt løbende fejl- og driftsovervågning.

7. Underdatabehandlere

Kunden giver NordicWeb en generel skriftlig godkendelse til at anvende underdatabehandlere. NordicWeb anvender aktuelt følgende:

  • Cloudflare, Inc. – hosting, CDN, DNS og edge-sikkerhed
  • Supabase – database (EU-region)
  • Resend – udsendelse af e-mail fra kontaktformularer
  • Functional Software, Inc. (Sentry) – fejlovervågning af hjemmesiden
  • GitHub, Inc. – opbevaring af kildekode og projektdata

NordicWeb har indgået databehandleraftaler med hver underdatabehandler med databeskyttelsesforpligtelser svarende til denne Aftale. NordicWeb underretter kunden om planlagte ændringer vedrørende tilføjelse eller udskiftning af underdatabehandlere med rimeligt varsel, så kunden har mulighed for at gøre indsigelse.

8. Overførsel til tredjelande

Visse underdatabehandlere er etableret uden for EU/EØS. Overførsler sker på grundlag af EU-Kommissionens standardkontraktbestemmelser (SCC) og supplerende foranstaltninger, hvor det er relevant. Supabase-databasen driftes i en EU-region.

9. Bistand til kunden

NordicWeb bistår så vidt muligt kunden – under hensyntagen til behandlingens karakter og de oplysninger, der er tilgængelige for NordicWeb – med at besvare anmodninger fra registrerede, med at sikre behandlingssikkerheden, med anmeldelse af brud på persondatasikkerheden til tilsynsmyndigheden og de registrerede samt med konsekvensanalyser vedrørende databeskyttelse (DPIA) og forudgående høring.

10. Brud på persondatasikkerheden

NordicWeb underretter kunden uden unødig forsinkelse, efter at NordicWeb er blevet opmærksom på et brud på persondatasikkerheden, og bistår kunden med de oplysninger, der er nødvendige for, at kunden kan opfylde sin anmeldelses- og underretningspligt.

11. Sletning og tilbagelevering

Ved ophør af ydelserne, eller på kundens anmodning, sletter NordicWeb personoplysningerne og eksisterende kopier eller tilbageleverer dem til kunden efter kundens valg, medmindre lovgivning kræver fortsat opbevaring. Ved en buyout af hjemmeside og kode udleveres al kildekode og domænet til kunden, og NordicWebs hosting og behandling ophører. Ved opsigelse af den løbende plan stopper hostingen, og alle relevante data slettes, medmindre bogføringsloven eller anden lovgivning kræver fortsat opbevaring i en periode.

12. Revision og tilsyn

NordicWeb stiller alle oplysninger, der er nødvendige for at påvise overholdelse af databeskyttelsesforordningens artikel 28, til rådighed for kunden og giver mulighed for og bidrager til revisioner, herunder inspektioner, der gennemføres af kunden eller en revisor bemyndiget af kunden, med rimeligt varsel og under fortrolighed.

13. Ansvar og lovvalg

Parternes erstatningsansvar følger handelsbetingelserne. Aftalen er underlagt dansk ret, og eventuelle tvister afgøres ved de danske domstole.

14. Ikrafttræden

Aftalen træder i kraft samtidig med aftalen om ydelserne og gælder, så længe NordicWeb behandler personoplysninger på vegne af kunden. Ved uoverensstemmelse mellem denne Aftale og handelsbetingelserne har denne Aftale forrang for så vidt angår behandling af personoplysninger.

15. Kontakt

Spørgsmål til denne databehandleraftale kan rettes til support@nordicweb.net.

Last updated: 01-09-2026

This Data Processing Agreement is a standard document forming part of the agreement between NordicWeb and the customer. A signed version is provided on request. The document should be reviewed by a legal adviser before final use.

1. Parties and roles

This Data Processing Agreement (the "Agreement") supplements NordicWeb's terms of business and governs NordicWeb's processing of personal data on behalf of the customer. The customer is the controller. NordicWeb, CVR no. 46643429, is the processor. The Agreement is entered into as part of the customer's acceptance of a concrete quote and the terms of business.

2. Subject matter, duration, nature and purpose

NordicWeb processes personal data for the purpose of delivering and operating the customer's website or webshop, including hosting, security updates, bug fixing, backups, sending email from forms and support. Processing lasts for as long as NordicWeb provides services to the customer.

3. Types of personal data and categories of data subjects

Processing covers the personal data that the customer's website collects and stores – typically name, email, phone number, company name, message content and technical data such as IP address, log and cookie data – relating to the customer's visitors, customers and contacts. The customer determines and documents the specific categories. NordicWeb does not knowingly process special categories of personal data unless agreed in writing.

4. Instructions

NordicWeb processes personal data only on documented instructions from the customer, including this Agreement and the agreed services. NordicWeb informs the customer if, in NordicWeb's opinion, an instruction infringes data protection law.

5. Confidentiality

NordicWeb ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security of processing (Article 32)

NordicWeb implements appropriate technical and organisational measures, including encryption in transit (HTTPS/TLS), need-to-know access control, a strict Content Security Policy and security headers, separation of secrets (API keys etc.) from the source code, and ongoing error and uptime monitoring.

7. Sub-processors

The customer gives NordicWeb general written authorisation to use sub-processors. NordicWeb currently uses:

  • Cloudflare, Inc. – hosting, CDN, DNS and edge security
  • Supabase – database (EU region)
  • Resend – sending email from contact forms
  • Functional Software, Inc. (Sentry) – website error monitoring
  • GitHub, Inc. – storage of source code and project data

NordicWeb has entered into data processing agreements with each sub-processor imposing data protection obligations equivalent to this Agreement. NordicWeb informs the customer of intended changes concerning the addition or replacement of sub-processors with reasonable notice, giving the customer the opportunity to object.

8. Transfers to third countries

Some sub-processors are established outside the EU/EEA. Transfers take place on the basis of the European Commission's Standard Contractual Clauses (SCCs) and supplementary measures where relevant. The Supabase database is operated in an EU region.

9. Assistance to the customer

Taking into account the nature of the processing and the information available to it, NordicWeb assists the customer as far as possible in responding to data subject requests, in ensuring the security of processing, in notifying personal data breaches to the supervisory authority and data subjects, and with data protection impact assessments (DPIAs) and prior consultation.

10. Personal data breaches

NordicWeb notifies the customer without undue delay after becoming aware of a personal data breach and assists the customer with the information needed for the customer to meet its notification obligations.

11. Deletion and return

On termination of the services, or at the customer's request, NordicWeb deletes the personal data and existing copies or returns them to the customer at the customer's choice, unless law requires continued storage. On a buyout of the website and code, all source code and the domain are handed over to the customer, and NordicWeb's hosting and processing cease. On cancellation of the ongoing plan, hosting stops and all relevant data is deleted, unless bookkeeping legislation or other law requires continued storage for a period.

12. Audit

NordicWeb makes available to the customer all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the customer or an auditor mandated by the customer, on reasonable notice and subject to confidentiality.

13. Liability and governing law

The parties' liability follows the terms of business. The Agreement is governed by Danish law, and any disputes are settled by the Danish courts.

14. Entry into force

The Agreement enters into force at the same time as the agreement on the services and applies for as long as NordicWeb processes personal data on behalf of the customer. In the event of a conflict between this Agreement and the terms of business, this Agreement prevails in respect of the processing of personal data.

15. Contact

Questions about this Data Processing Agreement can be directed to support@nordicweb.net.

Ostatnia aktualizacja: 01-09-2026

Niniejsza umowa powierzenia przetwarzania danych jest dokumentem standardowym stanowiącym część umowy między NordicWeb a klientem. Podpisana wersja jest udostępniana na żądanie. Dokument powinien zostać sprawdzony przez doradcę prawnego przed ostatecznym użyciem.

1. Strony i role

Niniejsza umowa powierzenia przetwarzania danych („Umowa”) uzupełnia warunki współpracy NordicWeb i reguluje przetwarzanie danych osobowych przez NordicWeb w imieniu klienta. Klient jest administratorem. NordicWeb, nr CVR 46643429, jest podmiotem przetwarzającym. Umowa zostaje zawarta w ramach akceptacji przez klienta konkretnej oferty i warunków współpracy.

2. Przedmiot, czas trwania, charakter i cel

NordicWeb przetwarza dane osobowe w celu dostarczania i utrzymania strony internetowej lub sklepu klienta, w tym hostingu, aktualizacji bezpieczeństwa, usuwania błędów, kopii zapasowych, wysyłania e-maili z formularzy oraz wsparcia. Przetwarzanie trwa tak długo, jak NordicWeb świadczy usługi na rzecz klienta.

3. Rodzaje danych osobowych i kategorie osób, których dane dotyczą

Przetwarzanie obejmuje dane osobowe, które strona klienta zbiera i przechowuje – zwykle imię i nazwisko, e-mail, numer telefonu, nazwę firmy, treść wiadomości oraz dane techniczne, takie jak adres IP, dane z logów i plików cookie – dotyczące odwiedzających, klientów i osób kontaktowych klienta. Klient określa i dokumentuje konkretne kategorie. NordicWeb nie przetwarza świadomie szczególnych kategorii danych osobowych, chyba że uzgodniono to na piśmie.

4. Polecenia

NordicWeb przetwarza dane osobowe wyłącznie na udokumentowane polecenie klienta, w tym niniejszą Umowę oraz uzgodnione usługi. NordicWeb informuje klienta, jeśli w opinii NordicWeb polecenie narusza przepisy o ochronie danych.

5. Poufność

NordicWeb zapewnia, że osoby upoważnione do przetwarzania danych osobowych zobowiązały się do zachowania poufności lub podlegają odpowiedniemu ustawowemu obowiązkowi zachowania tajemnicy.

6. Bezpieczeństwo przetwarzania (art. 32)

NordicWeb wdraża odpowiednie środki techniczne i organizacyjne, w tym szyfrowanie podczas przesyłania (HTTPS/TLS), kontrolę dostępu w oparciu o zasadę wiedzy koniecznej, rygorystyczną politykę bezpieczeństwa treści (CSP) i nagłówki bezpieczeństwa, oddzielenie sekretów (kluczy API itp.) od kodu źródłowego oraz bieżące monitorowanie błędów i dostępności.

7. Podmioty podprzetwarzające

Klient udziela NordicWeb ogólnej pisemnej zgody na korzystanie z podmiotów podprzetwarzających. NordicWeb korzysta obecnie z:

  • Cloudflare, Inc. – hosting, CDN, DNS i bezpieczeństwo brzegowe
  • Supabase – baza danych (region UE)
  • Resend – wysyłanie e-maili z formularzy kontaktowych
  • Functional Software, Inc. (Sentry) – monitorowanie błędów strony
  • GitHub, Inc. – przechowywanie kodu źródłowego i danych projektu

NordicWeb zawarł umowy powierzenia z każdym podmiotem podprzetwarzającym, nakładające obowiązki w zakresie ochrony danych odpowiadające niniejszej Umowie. NordicWeb informuje klienta o zamierzonych zmianach dotyczących dodania lub zastąpienia podmiotów podprzetwarzających z rozsądnym wyprzedzeniem, umożliwiając klientowi wniesienie sprzeciwu.

8. Przekazywanie do państw trzecich

Niektóre podmioty podprzetwarzające mają siedzibę poza UE/EOG. Przekazywanie odbywa się na podstawie standardowych klauzul umownych Komisji Europejskiej (SCC) oraz środków uzupełniających, gdy jest to istotne. Baza danych Supabase działa w regionie UE.

9. Pomoc dla klienta

Uwzględniając charakter przetwarzania oraz dostępne mu informacje, NordicWeb w miarę możliwości pomaga klientowi w odpowiadaniu na żądania osób, których dane dotyczą, w zapewnieniu bezpieczeństwa przetwarzania, w zgłaszaniu naruszeń ochrony danych organowi nadzorczemu i osobom, których dane dotyczą, a także w ocenach skutków dla ochrony danych (DPIA) i uprzednich konsultacjach.

10. Naruszenia ochrony danych osobowych

NordicWeb zawiadamia klienta bez zbędnej zwłoki po stwierdzeniu naruszenia ochrony danych osobowych i pomaga klientowi, dostarczając informacje niezbędne do wypełnienia przez klienta obowiązków w zakresie zgłaszania.

11. Usunięcie i zwrot

Po zakończeniu usług lub na żądanie klienta NordicWeb usuwa dane osobowe i istniejące kopie albo zwraca je klientowi zgodnie z wyborem klienta, chyba że prawo wymaga dalszego przechowywania. W przypadku wykupu strony i kodu cały kod źródłowy oraz domena są przekazywane klientowi, a hosting i przetwarzanie przez NordicWeb ustają. W przypadku wypowiedzenia planu miesięcznego hosting zostaje wstrzymany, a wszystkie istotne dane są usuwane, chyba że przepisy o rachunkowości lub inne przepisy wymagają dalszego przechowywania przez pewien okres.

12. Audyt

NordicWeb udostępnia klientowi wszelkie informacje niezbędne do wykazania zgodności z art. 28 RODO oraz umożliwia audyty, w tym inspekcje, przeprowadzane przez klienta lub audytora upoważnionego przez klienta, i przyczynia się do nich, z rozsądnym wyprzedzeniem i z zachowaniem poufności.

13. Odpowiedzialność i prawo właściwe

Odpowiedzialność stron wynika z warunków współpracy. Umowa podlega prawu duńskiemu, a wszelkie spory rozstrzygają sądy duńskie.

14. Wejście w życie

Umowa wchodzi w życie jednocześnie z umową o świadczenie usług i obowiązuje tak długo, jak NordicWeb przetwarza dane osobowe w imieniu klienta. W przypadku sprzeczności między niniejszą Umową a warunkami współpracy niniejsza Umowa ma pierwszeństwo w zakresie przetwarzania danych osobowych.

15. Kontakt

Pytania dotyczące niniejszej umowy powierzenia można kierować na adres support@nordicweb.net.

NordicWebNordicWeb

Hjemmesider, der arbejder for din forretning.

Virksomhed

CVR: 46643429

3600 Frederikssund

Juridisk

Privatlivspolitik Handelsbetingelser Databehandleraftale

NordicWeb · CVR 46643429

Alle rettigheder forbeholdes.

Vi bruger kun nødvendige cookies til at huske dit sprogvalg. Læs mere i vores privatlivspolitik.