Legal
Data processing agreement
Last updated: 26 July 2026
This data processing agreement (the “Agreement”) governs Ciento Finans’ processing of personal data on behalf of the Customer in connection with the services provided. The Customer is the data controller and Ciento Finans is the data processor.
1. Background and scope
When Ciento Finans delivers e.g. bookkeeping and payroll, personal data is processed on behalf of and on the instructions of the Customer. The Agreement has the same duration as the underlying service agreement.
2. Instructions
Ciento Finans processes personal data only on documented instructions from the Customer, unless processing is required by EU or Danish law. The Customer’s instructions consist of the service agreement and this Agreement.
3. Categories of data subjects and personal data
The processing typically covers:
- The Customer’s employees for payroll: name, address, civil registration (CPR) number, bank account number and salary details.
- The Customer’s customers and suppliers: name, contact details and payment and invoice details.
4. Confidentiality
Ciento Finans ensures that persons processing the data have committed to confidentiality or are under an appropriate statutory duty of confidentiality.
5. Security of processing
Ciento Finans implements the technical and organisational measures required under GDPR art. 32, including access management, secure storage and encryption where relevant.
6. Sub-processors
The Customer gives a general authorisation for Ciento Finans to use sub-processors, including the hosting provider (Simply.com), a payroll system (e.g. Danløn and Visma) and a bookkeeping system (e.g. e-conomic, Billy and Dinero). Ciento Finans concludes agreements with sub-processors imposing equivalent obligations and notifies the Customer of intended changes so that objections can be raised.
7. Transfers to third countries
Personal data is transferred to countries outside the EU/EEA only where a valid transfer basis exists. Where we use Google Workspace, data is transferred to the USA under the EU-US Data Privacy Framework.
8. Assistance to the controller
Ciento Finans assists the Customer, to a reasonable extent, in responding to requests from data subjects, with security of processing, with breach notification and with impact assessments (DPIA).
9. Personal data breaches
Ciento Finans notifies the Customer without undue delay after becoming aware of a personal data breach and provides the necessary information.
10. Termination - erasure and return
On termination of the Agreement, Ciento Finans, at the Customer’s choice, deletes or returns all personal data, unless storage is required by law, e.g. the Danish Bookkeeping Act.
11. Audit and inspection
Ciento Finans makes available the information necessary to demonstrate compliance with art. 28 and allows for and contributes to audits as further agreed.
12. Liability and term
The Agreement takes effect on the parties’ acceptance and applies for as long as Ciento Finans processes personal data for the Customer. The parties’ liability follows the GDPR and the underlying service agreement.
13. Contact
Enquiries about this Agreement can be sent to Ciento Finans at info@cientofinans.dk.