Data processing agreement
This is a translation of the Danish original. In case of discrepancy, the Danish version is the binding one.
Last updated: July 6, 2026
See also the list of sub-processors.
1. Introduction and scope
1.1 This data processing agreement (“DPA”) forms part of Doclane’s terms of service or another agreement between the parties concerning the customer’s use of the service (“the main agreement”). By using the service the customer accepts this DPA.
1.2 In the event of any conflict between this DPA and the main agreement regarding the processing of personal data, this DPA prevails.
1.3 This DPA applies where the customer is the data controller (or a processor on behalf of another controller) and Doclane processes personal data on the customer’s behalf in connection with the delivery of the service.
2. Parties and roles
2.1 Supplier (processor): Doclane, company reg. no. 35682821, Åbogade 15, 8200 Aarhus N, Denmark (“Doclane” or “the processor”).
2.2 The customer (controller): the legal entity identified as the customer in the main agreement.
2.3 The parties agree that the customer is the data controller and Doclane is the data processor in the sense in which the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) uses those terms.
3. Subject matter and duration
3.1 Subject matter. Doclane processes personal data on the customer’s behalf in order to deliver the Doclane platform and related services as described in the main agreement.
3.2 Duration. This DPA applies for as long as Doclane processes personal data on the customer’s behalf under the main agreement, and until all personal data has been deleted or returned in accordance with this DPA.
4. Nature and purpose of the processing
4.1 Doclane processes personal data for the following purposes:
- receipt, storage and processing of documents (orders, invoices, claims, product data and customer details) and related communication;
- running AI models and workflows to read, classify and extract data from documents;
- creation of the corresponding records in the customer’s business system, currently Microsoft Dynamics 365 Business Central, Uniconta or e-conomic;
- operation of logs, analytics and monitoring for performance, security and product improvement purposes (as configured by the customer and permitted by law);
- support and maintenance of the service; and
- fulfilment of other documented instructions from the customer in accordance with the main agreement.
4.2 Depending on the circumstances, the nature of the processing includes: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure by transmission (for example to sub-processors), alignment, restriction, erasure or destruction.
5. Types of personal data and data subjects
5.1 Types of personal data. Depending on the customer’s configuration and use, the following may be processed:
- contact details (for example names, email addresses, telephone numbers);
- order and transaction data;
- the content of documents and communication (free text);
- technical data such as IP addresses and device and usage data;
- other personal data that the customer chooses to send to the service.
5.2 Special categories. The service is not intended for the processing of special categories of personal data under GDPR art. 9 (for example health, political opinions, religion) or data relating to criminal convictions. The customer must ensure that such data is not knowingly sent to the service.
5.3 Data subjects. Data subjects may include: the customer’s end customers and suppliers; the customer’s employees, consultants and agents; and other individuals whose personal data forms part of the customer’s data.
6. Instructions and responsibility
6.1 Doclane processes personal data only on documented instructions from the customer, including with regard to transfers to third countries, unless required otherwise by EU or member state law. In that case Doclane informs the customer of the legal requirement before processing, unless the law prohibits it.
6.2 The main agreement (including this DPA) together with the customer’s configuration and use of the service constitute the customer’s complete and final instruction to Doclane.
6.3 If Doclane reasonably believes an instruction infringes the GDPR or other applicable data protection law, Doclane informs the customer without undue delay.
6.4 The customer is responsible for: the lawfulness of the processing; providing appropriate information to data subjects; obtaining any necessary consents; and ensuring that the personal data sent to the service is adequate, relevant and limited to what is necessary.
7. Confidentiality
7.1 Doclane ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
8. Security of processing
8.1 Taking into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing, as well as the risks to data subjects, Doclane implements appropriate technical and organisational measures, including as appropriate:
- pseudonymisation and encryption of personal data;
- the ability to ensure ongoing confidentiality, integrity, availability and resilience;
- the ability to restore availability and access in a timely manner after an incident;
- processes for regularly testing and evaluating the effectiveness of the measures.
8.2 Doclane may implement specific measures through its infrastructure suppliers and sub-processors (for example data centre security, network security, backup). The entire infrastructure is hosted in the EU.
8.3 The customer is responsible for appropriate security in its own environment, including secure use of the service (for example account management, access control, configuration).
9. Sub-processors
9.1 The customer authorises Doclane to engage other processors (“sub-processors”) for the processing described in this DPA.
9.2 Doclane ensures that every sub-processor is bound by written data protection obligations no less protective than those in this DPA.
9.3 The current list of sub-processors is published at sub-processors and may be updated from time to time.
9.4 Doclane notifies the customer of intended changes by email (to the registered billing address) with at least 30 days’ notice and gives the customer the opportunity to object on reasonable data protection grounds. If the parties cannot agree on an alternative, the customer may terminate the affected part of the service on 30 days’ written notice.
10. International transfers
10.1 The customer’s data is stored within the European Economic Area (EEA).
10.2 Doclane’s entire technology stack, including AI processing, is located in the EU/EEA. No personal data is transferred to third countries outside the EEA. Should such a transfer exceptionally become necessary, it will take place only with appropriate safeguards under GDPR chapter V (for example Standard Contractual Clauses).
11. Data subject rights
11.1 Taking into account the nature of the processing, Doclane assists the customer with appropriate technical and organisational measures in fulfilling the customer’s obligation to respond to requests from data subjects (for example access, rectification, erasure, restriction, portability, objection).
11.2 If Doclane receives a request directly from a data subject concerning personal data processed on the customer’s behalf, Doclane forwards the request to the customer without undue delay (unless prohibited by law) and does not respond directly unless the customer has approved it or the law requires it.
12. Personal data breaches
12.1 In the event of a personal data breach affecting personal data processed on the customer’s behalf, Doclane notifies the customer without undue delay after becoming aware of the breach.
12.2 The notification includes the information reasonably available to Doclane, including the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
12.3 Where all information cannot be provided at the same time, it may be provided in phases without undue delay.
12.4 The customer is responsible for determining whether the supervisory authority or data subjects must be notified, and for making such notifications, unless otherwise agreed.
13. Impact assessments and prior consultations
13.1 Taking into account the nature of the processing and the information available to Doclane, Doclane assists the customer (for reasonable remuneration where relevant) with data protection impact assessments (DPIAs) concerning the service and with prior consultations of supervisory authorities where required.
14. Audit and compliance
14.1 Doclane makes available all information reasonably necessary to demonstrate compliance with the obligations in GDPR art. 28.
14.2 This may take the form of documentation of security and data protection measures, external audit reports or certifications (where available) and responses to reasonable written questionnaires.
14.3 On reasonable prior notice and no more than once per 12 months (unless required by an authority, or following a security breach), the customer or an independent auditor may audit Doclane’s practices concerning the service. Any such audit is limited to relevant systems, is subject to Doclane’s confidentiality and security policies, is carried out during normal business hours and may be subject to a reasonable fee.
15. Return and deletion of data
15.1 On termination of the service Doclane will, at the customer’s choice and subject to applicable law, delete all personal data processed on the customer’s behalf, or return it to the customer and then delete existing copies.
15.2 Unless the customer requests earlier deletion or return, Doclane may retain personal data for up to 30 days after termination so that the customer can export data. After that, Doclane may delete or anonymise the data, subject to any statutory retention requirements.
15.3 Doclane may retain copies where required by law, or in backup systems for a limited period until they are overwritten in the ordinary course of operations. Such data remains covered by the protections in this DPA.
15.4 Exceptions. The following may be retained for longer where necessary and proportionate: data that must be retained by law; information necessary to establish or defend legal claims; security logs for fraud and abuse monitoring; and accounting, tax and payment data.
16. Liability
16.1 The limitations of liability set out in the main agreement also apply to this DPA to the extent permitted by law.
16.2 Nothing in this DPA limits any liability under the GDPR that may not be limited.
17. Governing law and venue
17.1 This DPA is governed by the same law as the main agreement, namely Danish law, without regard to conflict of law rules.
17.2 Any dispute shall be settled at the same venue as the main agreement (the Danish courts, with the City Court of Aarhus as the court of first instance, unless mandatory law provides otherwise).
18. Other provisions
18.1 This DPA forms part of the main agreement and does not alter its general commercial terms, fees or limitations of liability beyond what is stated here.
18.2 If a provision is invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision is replaced by a valid one that best reflects the intention of the parties.
18.3 Doclane may update this DPA on at least 30 days’ notice (by email or in the product). Material changes are clearly identified. Continued use after the notice period constitutes acceptance of the updated DPA.
19. AI processing
19.1 Use of AI models. Doclane uses language models and related AI models through an EU based supplier, see the list of sub-processors, to deliver the AI functionality in the service, including reading, classifying and extracting data from documents.
19.2 Categories of data processed by AI models. Depending on the customer’s configuration, personal data sent to AI models may include identifiers (name, email, order number), document content, order and transaction details and limited technical metadata for context.
19.3 AI sub-processors are listed in the sub-processors list and are covered by the same notification and objection mechanism as other sub-processors (section 9).
19.4 Limited retention. AI sub-processors retain data only to the extent and for the short period technically necessary for the processing, and never for other purposes. Processing takes place in the EU.
19.5 No training. Customer data is not used to train or improve the underlying AI models, whether by Doclane, AI sub-processors or the underlying model providers. This applies on all plans.
19.6 Customer specific improvement. Doclane may store the customer’s own corrections and document templates in order to improve extraction from that customer’s future documents. This data is kept isolated per customer, is not shared across customers and is not used to train underlying AI models.
19.7 The EU AI Act. Doclane designs and operates the AI functionality so that end users are informed where required under the EU AI Act. The customer remains responsible for its own obligations as a deployer, including appropriate human oversight.
Contact
Questions about this data processing agreement? Write to hello@doclane.ai or Doclane, Åbogade 15, 8200 Aarhus N, Denmark. Company reg. no. 35682821.