The company details are still missing. The marked fields are filled in before the page is used.
Version 1.0 · effective 29 September 2026
Standard contractual clauses under Article 28(3) of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) for the processing of personal data by the processor. The structure follows the standard contractual clauses of the Danish Data Protection Agency (Datatilsynet, January 2020). The Danish version prevails over this translation.
between
the Customer, as stated when the account was created in Tracepas (the "controller")
and
[TODO: COMPANY DETAILS: legal name], CVR [TODO: CVR], [TODO: COMPANY DETAILS: address], Denmark (the "processor")
each a "party" and together the "parties".
The parties have agreed the following clauses (the "Clauses") in order to comply with the GDPR and to ensure the protection of privacy and the fundamental rights and freedoms of natural persons. The Clauses form part of the terms of business and are accepted together with them.
1. Table of contents
- Preamble · 3. The rights and obligations of the controller · 4. The processor acts according to instructions · 5. Confidentiality · 6. Security of processing · 7. Use of sub-processors · 8. Transfer of data to third countries or international organisations · 9. Assistance to the controller · 10. Notification of personal data breach · 11. Erasure and return of data · 12. Audit and inspection · 13. The parties' agreement on other terms · 14. Commencement and termination · 15. Contacts · Appendices A–D
2. Preamble
2.1 These Clauses set out the rights and obligations of the processor when processing personal data on behalf of the controller.
2.2 The Clauses are designed to ensure the parties' compliance with Article 28(3) GDPR.
2.3 The processor processes personal data on behalf of the controller in connection with the provision of the platform Tracepas and the add-on service Assisted onboarding under the terms of business (the "main agreement").
2.4 The Clauses take priority over any similar provisions in other agreements between the parties, including the main agreement.
2.5 Appendices A–D form an integral part of the Clauses. Appendix A describes the processing. Appendix B contains the conditions for the use of sub-processors and the list of approved sub-processors. Appendix C contains the instructions, the security measures and the supervision. Appendix D contains the parties' provisions on other matters.
2.6 Both parties keep the Clauses and appendices electronically. The processor makes the current version available on its website and in the Platform.
2.7 The Clauses do not release the processor from obligations under the GDPR or other legislation.
3. The rights and obligations of the controller
3.1 The controller is responsible for ensuring that the processing complies with the GDPR (Article 24), data protection provisions in other Union or Member State law, and these Clauses.
3.2 The controller has the right and obligation to decide the purposes and means of the processing.
3.3 The controller is responsible, among other things, for ensuring a legal basis for the processing the processor is instructed to carry out, and for informing data subjects about the processing, including suppliers' staff whose data is entered in the Platform.
4. The processor acts according to instructions
4.1 The processor processes personal data only on documented instructions from the controller, unless required to do so by Union or Member State law to which the processor is subject. The instructions are set out in Appendices A and C. The controller may give further instructions while the processing takes place. Actions that Users take in the Platform, such as uploading, approving, publishing or setting up webhooks, are documented instructions.
4.2 The processor immediately informs the controller if, in the processor's opinion, an instruction infringes the GDPR or data protection provisions in other Union or Member State law.
5. Confidentiality
5.1 The processor only grants access to the personal data to persons under its authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only to the extent necessary. The list of persons with access is reviewed on an ongoing basis, and access is withdrawn when no longer necessary.
5.2 On request, the processor must be able to demonstrate that these persons are subject to confidentiality.
6. Security of processing
6.1 Under Article 32 GDPR, the controller and the processor implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These may include pseudonymisation and encryption, the ability to ensure ongoing confidentiality, integrity, availability and resilience, the ability to restore availability in a timely manner after an incident, and a process for regularly testing and evaluating the measures.
6.2 The processor assesses the risks of the processing independently of the controller and implements measures to address them. The controller provides the information needed for that assessment.
6.3 The processor assists the controller in complying with Article 32, among other things by providing information about the measures described in Appendix C.2. If the controller's risk assessment requires further measures, they are agreed in writing and added to Appendix C.
7. Use of sub-processors
7.1 The processor meets the conditions of Article 28(2) and (4) GDPR for engaging another processor (a sub-processor).
7.2 The processor has the controller's general authorisation to engage sub-processors. The processor informs the controller in writing of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance, giving the controller the opportunity to object, see Appendix B.2. The list of approved sub-processors is in Appendix B.1.
7.3 The processor imposes on each sub-processor, by contract, the same data protection obligations as in these Clauses, including sufficient guarantees of appropriate technical and organisational measures. Where a sub-processor only offers its own standard terms, the processor assesses before engaging it that those terms provide an equivalent level of protection, and says so in Appendix B.
7.4 On request, the processor sends a copy of the sub-processor agreement, excluding commercial terms that do not affect its data protection content.
7.5 Where possible, the processor ensures that the controller can step into the processor's rights against the sub-processor in the event of the processor's bankruptcy.
7.6 The processor remains fully liable to the controller for sub-processors' performance of their obligations. This does not affect the rights of data subjects under the GDPR, in particular Articles 79 and 82.
8. Transfer of data to third countries or international organisations
8.1 Transfers of personal data to third countries or international organisations take place only on documented instructions from the controller and always in accordance with Chapter V GDPR.
8.2 If a transfer is required by Union or Member State law to which the processor is subject, the processor informs the controller before processing, unless that law prohibits this on important grounds of public interest.
8.3 Without documented instructions, the processor may not transfer personal data to a controller or processor in a third country, engage a sub-processor in a third country, or process the data in a third country.
8.4 The controller's instructions on transfers, including the transfer tool, are in Appendix C.6.
8.5 These Clauses are not standard contractual clauses under Article 46(2)(c) or (d) and cannot by themselves be a basis for transfers under Chapter V.
9. Assistance to the controller
9.1 Taking into account the nature of the processing, the processor assists the controller as far as possible, by appropriate technical and organisational measures, in responding to requests to exercise data subjects' rights under Chapter III, including information, access, rectification, erasure, restriction, notification, portability, objection and the right not to be subject to an automated decision.
9.2 Taking into account the nature of the processing and the information available to it, the processor also assists the controller with:
a) notifying personal data breaches to Datatilsynet without undue delay and, where feasible, within 72 hours after the controller became aware of the breach, unless the breach is unlikely to result in a risk to the rights of natural persons; b) communicating breaches to data subjects where the breach is likely to result in a high risk; c) carrying out a data protection impact assessment where required; d) consulting Datatilsynet where an impact assessment indicates a high risk.
9.3 The scope of the assistance is set out in Appendix C.3.
10. Notification of personal data breach
10.1 The processor notifies the controller without undue delay after becoming aware of a personal data breach.
10.2 Where possible, the notification is given within 48 hours after the processor became aware of the breach, so that the controller can meet its obligation under Article 33.
10.3 The processor assists with the information that must be included in the notification under Article 33(3): the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. The information may be provided in phases where it cannot all be provided at once.
11. Erasure and return of data
11.1 On termination of the services, the processor erases all personal data processed on behalf of the controller and confirms to the controller that it has been erased, unless Union or Member State law requires storage. Before erasure, the controller can export the data under Appendix C.4.
11.2 Personal data contained in published product passports and the declarations shown in them is not erased on termination but remains available under clause 14.3 of the terms of business, which the controller hereby instructs. The reason is that Battery Regulation (EU) 2023/1542 Art. 78(e) and Ecodesign Regulation (EU) 2024/1781 Art. 11(e) require product passports to remain available even after the responsible economic operator has ceased to exist.
12. Audit and inspection
12.1 The processor makes available all information necessary to demonstrate compliance with Article 28 and these Clauses, and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by the controller.
12.2 The procedures are set out in Appendices C.7 and C.8.
12.3 The processor gives supervisory authorities that by law have access to the controller's or processor's facilities access on presentation of appropriate identification.
13. The parties' agreement on other terms
The parties may agree other provisions, for example on liability, provided they do not directly or indirectly contradict the Clauses or prejudice the fundamental rights of data subjects. Such provisions are set out in Appendix D.
14. Commencement and termination
14.1 The Clauses take effect when the Customer accepts the terms of business.
14.2 Either party may require the Clauses to be renegotiated if changes in law or shortcomings in the Clauses give reason to do so.
14.3 The Clauses apply for as long as the processor processes personal data on behalf of the controller, including during the periods in Appendix C.4. During that time the Clauses cannot be terminated separately.
14.4 When the processing has ended and the personal data has been erased or returned under clause 11 and Appendix C.4, either party may terminate the Clauses in writing.
15. Contacts
15.1 The controller's contact is the User with the Owner role in the Platform, unless the Customer names another contact in Settings or in writing.
15.2 The processor's contact: [TODO: name, position, email, phone].
15.3 The parties keep each other informed of changes of contact.
Appendix A · Information about the processing
A.1 Purpose
The processor processes personal data to provide the Platform and the services under the main agreement:
- receiving and storing documents from the controller and its suppliers;
- automatic document reading with AI and manual review, so that values can be proposed with a source;
- approval of values and production of declarations, technical documentation and reports;
- publishing and displaying product passports, including access links to restricted information;
- the supplier portal, where suppliers upload documents through a link;
- scan statistics for the controller's product passports;
- API and webhooks as set up by the controller;
- support and Assisted onboarding, including contacting suppliers under Appendix C.1;
- operation, backup and security.
A.2 Nature of the processing
Collection through upload, API and supplier links, storage, structuring, machine reading, display to the controller's Users, publication in product passports when the controller publishes them, disclosure to the addresses the controller specifies (webhooks), backup and erasure.
A.3 Types of personal data
| Data subjects | Data |
|---|---|
| The controller's Users | Name, email, role, language, actions in the activity log (what, when), messages in service requests, the name of whoever approved a value |
| Contact persons at suppliers | Name, email, phone, company, country; comments given in the supplier portal |
| People named in documents | Whatever the documents contain, typically name, position, signature and contact details of staff at suppliers, laboratories and certification bodies |
| Signatories of declarations | Name, position, place and date. Published when a declaration is shown in a product passport |
| Contact for access to restricted information | The email address the controller enters for product passports. Published in product passports |
| Visitors to product passports | IP address, used only in memory to look up the country and not stored; the browser's user agent, used only to determine the device type. Only country, device type, language and date are stored |
The processing does not include special categories of personal data (Article 9) or data relating to criminal convictions (Article 10). The controller must not upload such data. If a document nevertheless contains it, the controller must redact it before uploading.
A.4 Categories of data subjects
The controller's Users; contact persons and staff at the controller's suppliers, laboratories and others named in documents; signatories of declarations; visitors to the controller's product passports.
A.5 Duration
Processing may start when the Clauses take effect and lasts for as long as the main agreement runs, and afterwards for the periods set out in Appendix C.4.
Appendix B · Sub-processors
B.1 Approved sub-processors
When the Clauses take effect, the controller has approved the following sub-processors:
| Name | Registration | Address | Processing | Location |
|---|---|---|---|---|
| Simply.com A/S | CVR 29412006 | Højvangen 4, 8660 Skanderborg, Denmark | Hosting of the system, database, documents, backups and product passports | Denmark |
| Google Cloud EMEA Limited | Ireland | 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Automatic document reading with [TODO: Google's API (paid tier) or Google Vertex AI in the EU] | [TODO: see Appendices C.5 and C.6] |
| [TODO: email provider] | [TODO] | [TODO] | Sending emails to Users, such as invitations and status messages | [TODO] |
Simply.com A/S itself uses sub-processors for, among other things, backup and hardware destruction, as stated at simply.com/compliance. Google Cloud EMEA Limited uses Google LLC and other group companies as sub-processors under Google's data processing terms.
Without the controller's approval under B.2, the processor may not use a sub-processor for a processing activity other than the one described, or use another sub-processor for that activity.
B.2 Notice and objection
The processor informs the controller of any addition or replacement of sub-processors at least 30 days in advance, by email to the controller's contact and by updating the list on the website. The controller may object in writing within 14 days of the notice if it has reasonable, specific grounds. If the parties cannot find a solution, the controller may terminate the affected part of the main agreement with effect before the change takes effect and receive a refund of prepaid fees for the remaining period.
Where a change is necessary to avert an acute security breach or an outage, the notice may be shorter. The processor then informs the controller as soon as possible and gives reasons.
Appendix C · Instructions for the processing of personal data
C.1 Subject matter and instructions
The processor processes personal data by providing the Platform and the services described in Appendix A. In addition:
a) Automatic document reading. Documents are only sent to the sub-processor listed in Appendix B.1 for this purpose, and only on a paid tier where the provider, under its terms, does not use the content to improve its products. The processor does not use the personal data for training AI.
b) Manual review. The processor's staff may read documents and enter proposals when the controller has ordered Assisted onboarding, when automatic reading is not possible, or when necessary to resolve a support case.
c) Access to the account. The processor's staff may open the controller's account with read-only access when necessary for support, a service request, troubleshooting or security. The access is recorded in the controller's activity log.
d) Contacting suppliers. The processor only contacts suppliers that the controller has named in writing in a service request, and only about what is stated there. The contact is made in the controller's name.
e) Product passports. Personal data is published in product passports when a User publishes the passport. Restricted information is only shown through access links the controller issues.
f) Scan statistics. When a product passport is displayed, the IP address is used only in memory to look up the country. It is not stored in the database. Only country, device type, language and date are stored.
g) Webhooks and API. Data is sent to the addresses the controller specifies and fetched with the API keys the controller creates.
h) The processor does not sell, re-use or process personal data or product passport data for its own purposes.
C.2 Security of processing
The level of security reflects that the processing mainly concerns ordinary contact details and product documentation on a limited scale, and that some data is published on the controller's instructions. The processor has implemented at least the following:
- Hosting with Simply.com A/S in data centres in Denmark.
- Encrypted connection (HTTPS) between browser and server.
- Passwords are stored only as hashes. Two-step verification can be switched on for every User.
- Access control with the roles owner, admin, editor and viewer. Data is separated per customer in the application.
- Rate limiting of login attempts, two-step verification, uploads in the supplier portal and the contact form.
- API keys, supplier portal links and product passport access links are stored only as hashes and can be revoked. Webhook secrets and the document-reading key are stored encrypted.
- Documents are stored outside the web server's public folder and only served to Users with access.
- Activity log of approvals, exports, API calls and staff access to the account, which the controller can view and export.
- Daily backup of the database and documents. The latest 7 copies are kept on the server, and one copy is kept off the server in the EU: [TODO: backup location].
- Staff access is granted on a need-to-know basis and removed when no longer needed. Staff are bound by confidentiality.
- Security updates for PHP, Laravel and dependencies are installed on an ongoing basis.
C.3 Assistance to the controller
- The controller can view, correct and export most data itself in the Platform. Data that cannot be handled in the Platform, such as deleting individual documents or a User's account, is handled by the processor on written request within 14 days.
- Requests from data subjects that the processor receives directly are forwarded without undue delay to the controller's contact.
- In the event of a breach, the processor provides the information listed in clause 10.3.
- Assistance is free of charge within reason. If assistance requires extensive work not caused by the processor, the price is agreed in advance.
C.4 Storage period and erasure
- Personal data is stored while the main agreement runs, until the controller or a User deletes it where the Platform allows this.
- After termination, the controller has read-only access and can export the data for 30 days. No later than 90 days after termination, the processor erases the personal data, except data in published product passports and their declarations, see clause 11.2.
- Backups are erased on a rolling basis as they expire, no later than 30 days after the data was deleted in the Platform.
- At the sub-processor for automatic document reading, content is kept according to its terms, see Appendix C.6. The processor switches off optional request logging.
C.5 Location of processing
Processing may not take place at other locations than the following without the controller's prior written approval:
- Simply.com A/S: data centres in Denmark.
- The processor's staff: [TODO: COMPANY DETAILS: address] and remote work from EU/EEA countries over encrypted connections.
- Google Cloud EMEA Limited: [TODO: choose one of the following and delete the other]
- Google's API, paid tier: Google may process the data in any country where Google or its sub-processors maintain facilities.
- Google Vertex AI with an EU endpoint: processing and storage in the EU.
- [TODO: email provider and location]
C.6 Instructions on transfers to third countries
The controller instructs the processor to use the sub-processors listed in Appendix B.1. Transfers to third countries take place only to the extent that follows from those sub-processors' terms, on the following basis:
- For Google: the Commission's adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) for Google LLC, and the Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) included in Google's data processing terms where the adequacy decision does not apply.
- Simply.com A/S processes the data in Denmark.
Unless the controller gives other documented instructions, the processor may not make any other transfers.
C.7 Audit and inspection procedure
- Once a year, on request, the processor provides a written account of how the Clauses are complied with, including an overview of security measures and sub-processors.
- The controller, or an independent auditor bound by confidentiality, may carry out an inspection at the processor once a year on 30 days' written notice, and in addition after a personal data breach. The controller bears its own costs and the processor's reasonable costs, unless the inspection reveals material breaches.
C.8 Supervision of sub-processors
The processor supervises sub-processors by reviewing their data processing terms and available audit reports or certifications at least once a year and whenever they change. The result is included in the account under C.7.
Appendix D · The parties' provisions on other matters
D.1 Liability and limitation of liability under clause 15 of the main agreement also apply to the Clauses, to the extent this does not prejudice data subjects' rights under the GDPR.
D.2 If the main agreement ends, the Clauses apply until the personal data has been erased or returned under clause 11, and for data in product passports under clause 11.2.
D.3 If the list of sub-processors or the security measures change, the processor publishes a new version of the Clauses with a new version date.