Data Processing Agreement
fermt ApS · Concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 (GDPR) · Effective 20 September 2026
This Data Processing Agreement is entered into between the customer of the fermt platform (the "Controller") and fermt ApS, Åløkkevej 1, 2720 Vanløse, Denmark ("fermt", the "Processor"), each a "party" and together the "parties".
It forms an integral part of the Terms of Service. By accepting the Terms of Service, the Controller accepts this agreement. It is concluded in electronic form as permitted by Article 28(9) GDPR, and no separate signature is required.
1. Background and scope
1.1The Processor provides the Controller with access to the fermt platform, a subscription-based ERP service, under the Terms of Service between the parties (the "Main Agreement").
1.2In providing the Service, the Processor processes personal data on behalf of the Controller. This Data Processing Agreement ("DPA") sets out the terms of that processing, as required by Article 28(3) GDPR.
1.3The DPA applies for as long as the Processor processes personal data on behalf of the Controller. In the event of conflict, this DPA prevails over the Main Agreement in respect of the processing of personal data.
1.4The DPA does not apply to personal data for which the Processor is itself the controller, including account, billing, support and technical data relating to the Controller’s use of the Service. That processing is described in the Processor’s privacy policy.
1.5The details of the processing — subject matter, duration, nature and purpose, types of personal data and categories of data subjects — are set out in Annex A.
2. Instructions
2.1The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which the Processor is subject. In such a case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
2.2This DPA, the Main Agreement and the Controller’s configuration and use of the Service constitute the Controller’s documented instructions. Further instructions must be given in writing to info@fermt.com.
2.3The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
2.4The Processor may charge for work arising from instructions that go beyond the standard functionality of the Service, at its then-current hourly rate, after informing the Controller.
2.5The Controller warrants that it has a valid legal basis for the processing it instructs, that it has provided the required information to data subjects, and that the personal data it enters into the Service is limited to what is necessary.
2.6The Controller shall not enter special categories of personal data within the meaning of Article 9 GDPR, or personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR, into the Service. The Service is not designed or assessed for such data.
3. Confidentiality
3.1The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2Access to personal data is limited to those persons for whom access is necessary in order to fulfil the Processor’s obligations.
4. Security of processing
4.1The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.
4.2The measures currently implemented are described in Annex C. The Processor may update the measures provided the level of security is not reduced.
4.3The Controller has assessed the measures in Annex C and considers them appropriate to the risk presented by the processing it instructs.
5. Sub-processors
5.1The Controller grants the Processor general written authorisation to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex B.
5.2The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the Controller’s registered address.
5.3The Controller may object to the change on reasonable, documented data protection grounds within 30 days of the notice. If the parties cannot resolve the objection, the Controller may terminate the affected part of the Service with effect from the date the change takes effect, without further liability on either side other than the refund of any prepaid fees for the unused period.
5.4The Processor shall impose on each sub-processor, by contract, the same data protection obligations as are set out in this DPA, and remains fully liable to the Controller for the performance of the sub-processor’s obligations.
6. Transfers to third countries
6.1Processing takes place within the EU/EEA, except as stated in Annex B.
6.2Any transfer to a third country shall take place only on the basis of an adequacy decision, the European Commission’s Standard Contractual Clauses, or another valid transfer mechanism under Chapter V GDPR, and only after the Processor has assessed whether supplementary measures are required.
7. Assistance to the Controller
7.1Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR.
7.2Where a data subject contacts the Processor directly in respect of personal data processed on the Controller’s behalf, the Processor shall not respond substantively, shall refer the data subject to the Controller, and shall inform the Controller without undue delay.
7.3The Processor shall assist the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor.
7.4Assistance is provided primarily through the self-service functionality of the Service. Assistance requiring manual work beyond that may be charged at the Processor’s then-current hourly rate, after the Processor has informed the Controller of the expected cost.
8. Personal data breach
8.1The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf.
8.2The notification shall, to the extent available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not available at once, it shall be provided in phases without undue further delay.
8.3Notification to the supervisory authority and to data subjects is the responsibility of the Controller. The Processor shall not notify on the Controller’s behalf unless expressly instructed to do so.
8.4Notifications under this clause are sent to the contact point stated in Annex A. The Controller is responsible for keeping that contact point current.
9. Documentation and audit
9.1The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations in Article 28 GDPR.
9.2Compliance is documented in the first instance by the Processor’s written description of its measures (Annex C), by the sub-processors’ own certifications and audit reports where available, and by the Processor’s written answers to the Controller’s questions.
9.3The Controller may carry out or mandate an audit, including inspection, of the processing. Such an audit may be carried out once per calendar year, on at least 30 days’ written notice, during normal business hours, and without unreasonable disruption to the Processor’s operations. The auditor must not be a competitor of the Processor and must sign a confidentiality undertaking.
9.4The Controller bears its own costs and the Processor’s documented time spent on the audit, except where the audit establishes a material breach of this DPA by the Processor, in which case the Processor bears its own costs.
9.5Where a supervisory authority requires an inspection, the Processor shall cooperate and the limitations in clause 9.3 do not apply.
10. Deletion and return of personal data
10.1On termination of the Main Agreement, the Controller retains access to export personal data from the Service for 30 days from the effective date of termination.
10.2After that period, the Processor shall delete the personal data from production systems within 30 days, unless Union or Member State law requires continued storage.
10.3Personal data contained in backups is deleted as part of the ordinary backup rotation. The production database is backed up with a retention period of 7 days, so backup copies containing the Controller’s personal data cease to exist no later than 7 days after deletion from production systems. Until deleted, backup copies remain subject to this DPA.
10.4The Processor shall confirm deletion in writing on request.
11. Liability
11.1Each party is liable in accordance with Article 82 GDPR towards data subjects. Nothing in this DPA limits a data subject’s rights or either party’s liability under Article 82.
11.2As between the parties, liability under this DPA is subject to the limitations and the cap set out in the Main Agreement, except in respect of wilful misconduct or gross negligence.
11.3Where one party has paid compensation or an administrative fine attributable in whole or in part to the other party’s breach, it may claim back from that party the share corresponding to that party’s responsibility.
12. Term, changes and governing law
12.1This DPA enters into force at the same time as the Main Agreement, on the Controller’s acceptance of the Terms of Service, and remains in force for as long as the Processor processes personal data on behalf of the Controller. It is concluded in electronic form as permitted by Article 28(9) GDPR.
12.2Changes required by amendments to applicable data protection law, or by decisions or guidance of a supervisory authority, take effect on 30 days’ written notice.
12.3This DPA is governed by Danish law. Disputes are settled in accordance with the venue clause of the Main Agreement.
Annex A — Details of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of the fermt ERP platform to the Controller as a subscription service. |
| Duration | For the term of the Main Agreement, plus the export and deletion periods in clause 10. |
| Nature of the processing | Collection, recording, structuring, storage, retrieval, alteration, use, backup, export and erasure, carried out by automated means in the Service. |
| Purpose | To enable the Controller to plan, record and document its production, recipes, batches, inventory, orders and traceability, and to administer users of the Service. |
| Categories of data subjects | The Controller’s employees and other users of the Service; the Controller’s contact persons at suppliers and business customers; any individual whose details the Controller enters into free-text fields. |
| Types of personal data | Name, job title, work email address, work telephone number, employer, user name, user role and permissions, activity and audit log entries (who did what and when), and any personal data the Controller chooses to enter into free-text fields, notes or attachments. |
| Special categories | None. The Controller is not permitted to enter special categories of personal data or criminal conviction data into the Service (clause 2.6). |
| Frequency of transfer | Continuous, for the duration of the Main Agreement. |
| Controller’s contact point for data protection and breach notification | The administrative email address registered on the Controller’s account. The Controller is responsible for keeping it current, and may nominate a different address by writing to info@fermt.com. |
| Processor’s contact point | info@fermt.com |
Annex B — Approved sub-processors
The following sub-processors are approved at the date of this DPA.
| Sub-processor | Registered office | Processing activity | Location | Transfer basis |
|---|---|---|---|---|
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Dublin, Ireland | Hosting of the application and database, storage, backup, platform infrastructure, operational logging | EU/EEA — Azure West Europe (Netherlands) | Not applicable — processing within the EU/EEA |
| Microsoft Ireland Operations Ltd. (Microsoft Entra External ID) | Dublin, Ireland | Authentication of users. Credentials are handled entirely by this service; the fermt application never receives or stores a password. | EU/EEA — European directory location | Not applicable — processing within the EU/EEA |
| Microsoft Ireland Operations Ltd. (Azure OpenAI Service) | Dublin, Ireland | Optional assistance features. Where the Controller uses them, the text submitted — a goods receipt description, a product or recipe description — is sent to the service to produce a suggestion. Prompts are not used to train models. | EU/EEA — Azure West Europe (Netherlands) | Not applicable — processing within the EU/EEA |
| Microsoft Ireland Operations Ltd. (Azure Application Insights) | Dublin, Ireland | Error tracking and usage telemetry: request paths, timings, error traces and a pseudonymous user reference. Free-text content and identifying values are removed before transmission. | EU/EEA — Azure West Europe and North Europe | Not applicable — processing within the EU/EEA |
| Proton AG | Geneva, Switzerland | Transactional email — user invitations, account notifications. Recipient name and email address. | Switzerland | European Commission adequacy decision for Switzerland |
| Stripe Payments Europe, Ltd. | Dublin, Ireland | Subscription administration and payment processing. Stripe acts as an independent controller for card and payment data. | Ireland, with onward transfers to Stripe group companies | Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework |
Annex C — Technical and organisational measures
The Processor has implemented the following measures pursuant to Article 32 GDPR. The description is kept current, and describes the measures actually in place rather than measures intended.
| Area | Measures |
|---|---|
| Authentication | Authentication is provided by Microsoft Entra External ID. The fermt application never receives or stores a password: it validates a signed token issued by that service. Multi-factor authentication is available and is configured in the identity service by the Controller. |
| Access control — users | Individual user accounts. Role-based permissions, set by the Controller for its own organisation. Session expiry. A user can see data belonging only to the organisations they are a member of. |
| Access control — administrative | Administrative access to production infrastructure is limited to one named person and requires Microsoft Entra authentication. There are no shared accounts. Access to the production database is additionally restricted by IP firewall rule. |
| Encryption | TLS 1.2 or higher for all traffic in transit. Encryption at rest for the database, storage and backups, using the platform encryption provided by Microsoft Azure. |
| Segregation | Every record in the application carries the identifier of the organisation that owns it, and every query is scoped to it. Development is carried out against local databases containing generated data; production data is not copied into development environments. |
| Logging and monitoring | Application and infrastructure logging of access and changes. An audit trail of user actions within the Service, retained with the record it belongs to. Platform telemetry retained 90 days; infrastructure logs 30 days. Automated alerting on server error rates and on repeated container restarts. |
| Backup and restoration | Continuous backup of the production database with point-in-time restore over a 7-day retention window. Backups are encrypted at rest and stored within the EU/EEA (Azure West Europe); geo-redundant backup is not enabled, so backup copies do not leave the region. |
| Availability and resilience | Hosting on Microsoft Azure managed services. The database runs on a single server instance without high-availability failover, and the Service is provided without a guaranteed level of availability (clause 5.1 of the Terms of Service). |
| Change management | All source code under version control. Changes deployed through an automated pipeline that runs the full automated test suite and applies database migrations against a disposable database before release. Dependencies monitored for known vulnerabilities. |
| Personnel | One person has access to production. That person is bound by confidentiality. Any future personnel with access will be bound equivalently before access is granted. |
| Sub-processor management | Written data processing terms with all sub-processors. Selection based on documented security measures and certifications. The current list is Annex B. |
| Deletion | Deletion from production within 30 days of the end of the export period. Deletion from backups by expiry of the 7-day backup retention window. |
| Incident handling | Documented procedure for detecting, assessing and reporting personal data breaches, including notification to the Controller within 48 hours. Automated alerting routes production errors to a monitored address. |
| Physical security | Handled by Microsoft Azure at data centre level, covered by that provider’s certifications, including ISO 27001 and SOC 2. |
