# Data Processing Agreement (DPA) — DRAFT TEMPLATE

> **⚠️ DRAFT — NOT LEGALLY BINDING.** This is a working template prepared as a
> starting point for counsel. It has **not** been reviewed or approved by a
> qualified lawyer and must not be presented to customers or signed in this
> state. Every `[bracketed]` item requires legal input. Publishing or executing
> a binding DPA is a project STOP condition pending legal review.
>
> Version: v0.1 (draft) · Prepared: 2026 · Owner: legal@remitto.io

This Data Processing Agreement ("DPA") forms part of the Agreement between
**Remitto ApS** ("Processor") and the customer identified in the Agreement
("Controller") and reflects the parties' agreement on the Processing of Personal
Data in compliance with Regulation (EU) 2016/679 ("GDPR").

---

## 1. Definitions

Terms not defined here have the meaning given in the GDPR. "Personal Data",
"Processing", "Controller", "Processor", "Data Subject", "Sub-processor", and
"Personal Data Breach" carry their GDPR meanings. "Agreement" means the Remitto
customer terms of service. `[Counsel: confirm full definitions list and align
with the Agreement's defined terms.]`

## 2. Roles and scope

The Controller determines the purposes and means of Processing. The Processor
Processes Personal Data only on the Controller's documented instructions
(including those in the Agreement and this DPA), solely to provide the refund
detection and recovery service.

## 3. Subject-matter and details of Processing (Annex I)

- **Nature and purpose:** auditing carrier shipment and invoice data to detect
  recoverable charges and, where the Controller approves, filing recovery claims
  with carriers on the Controller's behalf.
- **Duration:** the term of the Agreement plus any retention required by law.
- **Categories of Data Subjects:** the Controller's personnel and authorised
  users; recipients/senders referenced in shipment and invoice records.
- **Categories of Personal Data:** account and contact details; shipment,
  invoice, and limited recipient data necessary for claims.
  `[Counsel: confirm no special-category data is in scope; if it can be, add
  Article 9 handling.]`

## 4. Processor obligations

The Processor shall: (a) Process only on documented instructions; (b) ensure
persons authorised to Process are bound by confidentiality; (c) implement the
technical and organisational measures in Annex II; (d) respect the conditions in
Section 5 for engaging Sub-processors; (e) assist the Controller per Sections 6–7;
(f) at the Controller's choice, delete or return Personal Data per Section 9; and
(g) make available information necessary to demonstrate compliance and allow for
audits per Section 8.

## 5. Sub-processors

The Controller provides general authorisation for the Processor to engage the
Sub-processors listed in the Trust Center (`/resources/trust-center`). The
Processor shall impose data-protection obligations equivalent to this DPA on each
Sub-processor and shall give the Controller `[notice period, e.g. 30 days]` notice
of intended additions or replacements, allowing the Controller to object on
reasonable data-protection grounds.

## 6. Assistance with Data Subject rights

Taking into account the nature of the Processing, the Processor shall assist the
Controller by appropriate technical and organisational measures, insofar as
possible, to respond to Data Subject requests under Chapter III of the GDPR.

## 7. Personal Data Breach

The Processor shall notify the Controller **without undue delay** and in any event
within `[e.g. 48 hours]` after becoming aware of a Personal Data Breach, and shall
provide information reasonably required for the Controller to meet its Article 33
and 34 obligations.

## 8. Audits and inspections

The Processor shall make available information necessary to demonstrate compliance
with Article 28 and allow for and contribute to audits, including inspections,
conducted by the Controller or an auditor it mandates, subject to
`[reasonable notice, confidentiality, and frequency limits — counsel to set]`.

## 9. Return or deletion

On termination of the Services, the Processor shall, at the Controller's choice,
delete or return all Personal Data and delete existing copies unless EU or Member
State law requires storage. `[Counsel: define retention exceptions and timelines.]`

## 10. International transfers

The Processor stores and Processes Personal Data within the EU and does not
transfer Personal Data outside the EU/EEA. If any transfer becomes necessary, the
parties shall implement an appropriate Article 46 transfer mechanism (e.g.,
Standard Contractual Clauses) before any such transfer. `[Counsel: confirm; attach
SCCs if applicable.]`

## 11. Liability, term, and governing law

Liability, term, and termination follow the Agreement. This DPA is governed by
`[governing law — e.g. the laws of Denmark]` and the parties submit to
`[jurisdiction]`. `[Counsel to complete and reconcile with the Agreement.]`

---

## Annex I — Description of Processing

`[Counsel/Remitto to finalise the table: categories of data subjects, categories
of personal data, special categories (if any), frequency, nature, purpose,
duration, and the identity of Sub-processors.]`

## Annex II — Technical and organisational measures

Summary of current measures (see the Trust Center and Security page for detail):

- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-based access control with least-privilege defaults; immutable audit logs.
- EU-only data residency across database, object storage, and workflow
  orchestration; single-tenant isolation per organisation at the data layer.
- `[Counsel/Security: expand into the full Article 32 measures inventory —
  pseudonymisation, resilience, backup/restore testing, vulnerability management,
  personnel security, etc.]`

---

*End of draft template. Do not distribute.*
