Data processing agreement.
Last updated: 13 August 2026 · Forms part of the terms of service
This agreement is between you (the controller) and AddonNordic ApS, CVR 46495985, Denmark (the processor). It applies whenever we process personal data on your behalf, and it takes effect when you create an account. It is written to satisfy Article 28(3) of the GDPR, and the sections below follow that article’s requirements in order.
1. Subject matter, duration, nature and purpose
Subject matter: retrieving and storing information published by official business registers about the competitor companies you select, and matching those companies to public contract-award notices published on TED and Doffin.
Duration: for as long as you have an account, plus the deletion period in section 10.
Nature and purpose: automated retrieval of registry data, assembly into supplier dossiers, and email alerts when a company you track is named winner on a public contract award, so that you can follow your competitors in public procurement.
2. Categories of data and data subjects
Data subjects: individuals named in public business registers in connection with the companies you track — typically directors and other officers, and beneficial owners where a register publishes them.
Categories of data: name, role, appointment and resignation dates, registered address, and where published, nationality, year of birth and extent of ownership or control.
We do not process special categories of data under Article 9. The risk flags a dossier shows — insolvency proceedings, liquidation, deregistration — are facts a register published about the company, not assessments of individuals. Where a register restricts access to ownership data, we respect the restriction; we only show what is legally available.
3. Processing only on your instructions
We process personal data only on your documented instructions. Your use of the service — the competitors you track, the alerts you enable — constitutes those instructions. We will tell you if we believe an instruction breaches data protection law. If we are required by EU or member-state law to process data otherwise, we will inform you first unless that law prohibits it.
We do not use your data for our own purposes, do not sell it, and do not use it to train machine-learning models.
4. Confidentiality
Everyone we authorise to process your data is bound by confidentiality and only has access where it is necessary for their work.
5. Security measures
We take appropriate technical and organisational measures under Article 32, including: data transmitted over encrypted connections and stored on encrypted storage; access to production data restricted to those who need it; credentials for upstream registries held server-side only and never present in any client; each customer’s data separated and access checked on the server for every request; and logging that lets us investigate an incident.
We hold no security certification, and our security page states that plainly rather than leaving you to discover it.
6. Assisting you
We will help you respond to requests from data subjects exercising their rights, and assist with your obligations under Articles 32 to 36 — security, breach notification, and data protection impact assessments — taking into account the nature of the processing and the information available to us. If a data subject contacts us directly about data you track, we will pass it to you rather than acting on it ourselves.
7. Subprocessors
You give general authorisation for us to engage the subprocessors listed at /subprocessors. That page is part of this agreement. We impose data protection obligations on each of them no less protective than those in this agreement, and we remain fully liable to you for their performance.
We will publish an intended addition or replacement on that page and notify account holders by email before it takes effect. If you object on reasonable data protection grounds, tell us; if we cannot resolve it, you may terminate the affected part of the service and receive a refund for the unused period.
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and give you the information you need to meet your own notification obligations: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. We will not wait until we have a complete picture before telling you.
9. International transfers
Tracking data and account records are processed and stored in the EU. One subprocessor — our email provider — sends from EU infrastructure but stores its delivery logs in the United States; that transfer is covered by the European Commission’s standard contractual clauses and is recorded on the subprocessors page. Any future transfer outside the EU or EEA will be handled the same way: an appropriate mechanism in place, and named on that page before it takes effect.
10. Deletion and return
While your account is open, your tracked-competitor list is visible in the product, and you can ask us at any time for a copy of the personal data we process on your behalf. When your account ends, we delete that data within 30 days, except where EU or member-state law requires us to keep it, such as invoicing records under accounting rules.
11. Audits
We will make available the information needed to demonstrate compliance with Article 28 and allow for audits by you or an auditor you mandate. In practice we ask that you write to us first: most questions are answered by this agreement, the security page and the subprocessor list, and an on-site audit of a company of our size is rarely the fastest route to the answer you need.
12. Contact and changes
Write to contact@addonnordic.dk for anything under this agreement, including a countersigned copy if your procurement process requires one. If we change this agreement in a way that affects you, we will notify account holders by email and update the date at the top.