This DPA must be approved together with the order and documented customer instructions. The Danish version prevails in case of conflict.
Roles and instructions
The customer is controller and Moselstudio ApS is processor. Processing follows documented instructions for hosting, analytics, generation, reporting, support and customer-approved actions.
People and data
Data subjects may include users, staff, leads, visitors and end customers. Data may include identity, contact, online, traffic, order, conversion and content data. Special-category or criminal-offence data requires a separate written agreement.
Security and confidentiality
Access is need- and role-based and subject to confidentiality. Controls include tenant isolation, server-side authorisation, AES-GCM credential encryption, TLS, logs, rate limits, SSRF defences, approvals and revocation.
Subprocessors and incidents
Conditional subprocessors include Vercel, Cloudflare, Resend and the selected AI provider. Stripe processes payment data separately under its payment terms. Only activated vendors receive data. Material changes are notified and personal-data breaches are reported without undue delay.
Assistance, deletion and audit
Vækstværk reasonably assists with rights, risk assessments and authority requests. On termination, data is returned or deleted as instructed and legally required. Compliance evidence and reasonable audits are supported without exposing other customers.
