Data Processing Agreement
Last updated 6 August 2026.
This is the agreement required by article 28 of the GDPR between your agency, as the data controller, and Thomas Løvring, CVR 33220510, A. F. Beyers Vej 3, 2. tv., 2720 Vanløse, Denmark, as the processor.
You do not need to sign it. It is part of the terms of service and applies from the moment you have an account. Ask at hello@excubia.dk if your own compliance work needs a signed copy on paper; you will get one, and it will say what this page says.
1. What is being processed, and for whom
We process personal data on your instruction, for one purpose: to provide Excubia to you. That means monitoring the sites you connect, holding the work you record about them, and preparing invoice drafts from it.
Categories of data subjects:
- The people at your agency who hold an Excubia login.
- The contact people at your clients, as you record them.
- Anyone else who appears in something you write or upload — a name in a task, a person in a screenshot.
Categories of personal data:
- Names, email addresses, phone numbers and job titles, as you enter them.
- Free text: task descriptions, comments, notes on an agreement.
- Files you attach to a task, and whatever they happen to contain.
- Hours logged against a task, and who logged them.
We do not ask for special categories of data — health, beliefs, union membership and the rest of article 9 — and Excubia has no field for them. If you put them into a free-text field anyway, that is your instruction and your responsibility, and you should tell us first so we can say whether the setup is fit for it.
The processing lasts as long as your organisation has an account.
2. Our instructions come from you
We process personal data only on your documented instructions. Using the product is an instruction: when you connect a site, we check it; when you write a comment, we store it; when you press Generate invoices, we send lines to your Dinero account.
Beyond that we access your data in three situations, and no others:
- To help you when you have asked us to.
- To keep the service running — a failing job, a migration, a bug that has to be reproduced.
- Where Danish or EU law requires it, in which case we tell you first unless the law forbids it.
We do not sell your data, and we do not train anything on it.
If we think an instruction from you breaks data protection law, we say so before carrying it out.
3. Confidentiality
Excubia is run by one person. That person is bound by confidentiality about everything in the system, and it does not lapse when the agreement ends. If that ever changes — an employee, a contractor — anyone with access will be bound in writing before they get it, and this page will say so.
4. Security
The measures that are actually in place:
- Traffic is encrypted in transit, everywhere.
- Your data is separated from other agencies' data in the database itself, by row-level security in Postgres, not by a filter in the application. A query that forgets the condition returns nothing rather than someone else's rows.
- There are no passwords to lose. Logging in uses a one-time code sent by email.
- Credentials for your connected sites are held in Supabase Vault, which stores them encrypted, and they are deleted when a site is disconnected.
- Backups are taken by our database supplier and are held in the same region as the database.
We review this list when the system changes, and the page says when it last did.
5. Subprocessors
You give us general authorisation to use subprocessors. The current list, what each of them touches, and where the data sits, is at subprocessors.
We tell you before a new one starts processing anything, and you have 30 days to object. If we cannot find a way around your objection, you can end the agreement for the part of the service it affects.
Each subprocessor is bound by terms no weaker than these. If one of them fails to meet its data protection obligations, we remain liable to you for that failure — article 28(4) puts it there, and it means your claim is against us rather than against a supplier you never chose.
6. Transfers out of the EU
Everything in Excubia is stored in the EU, with one exception: Resend keeps the log of sent mail — recipient address, subject, time — in the United States for 30 days. That transfer rests on the EU-US Data Privacy Framework and on the standard contractual clauses in our agreement with them.
Our other suppliers store in the EU but are US companies whose staff can reach the data while supporting the service. Each of those relationships carries the standard contractual clauses. The detail is on the subprocessors page, per supplier.
7. Helping you with the people whose data it is
If someone asks you for access, correction, deletion, portability, or objects to the processing, we help you answer within your deadline. In practice that means we get you the data, or make the change, or delete it — you decide what the answer is.
If someone comes to us directly, we do not answer for you. We point them to you and tell you they asked.
We also help you with your obligations under articles 32 to 36: security, breach notification, and an impact assessment if you have to make one, to the extent the information is ours to give.
8. If something goes wrong
We tell you about a personal data breach without undue delay and no later than 24 hours after we become aware of it, so your own 72-hour deadline to Datatilsynet is not spent waiting for us.
The notification says what we know: what happened, which data and roughly how many people are affected, what we are doing about it, and what we do not know yet. We do not wait for a complete picture before the first message.
9. When it ends
When your agreement with us ends, you choose: we send you a copy of your data, or we delete it. Say which within 30 days. If you say nothing, we delete it after 30 days.
What we have to keep for accounting stays, and nothing else. Deletion covers backups as they age out on their normal schedule, which is the only way deletion from a backup can honestly be promised.
10. Showing that this is true
We give you the information you need to demonstrate that we meet article 28, on request.
You may audit us, or have someone audit us on your behalf, once a year and after a breach. Give us 30 days' notice. We answer a written questionnaire at no cost; an on-site audit is at your expense, unless it finds something material, in which case it is at ours.
11. Law
Danish law applies, and disputes go to the courts of Copenhagen — the same as the terms of service.
Where this page and the terms of service disagree about the processing of personal data, this page wins.