Data processing agreement
Last updated: 21. April, 2026
This data processing agreement (the "DPA") governs the processing of Personal Data in the course of the provision of the Services provided by Spaak Technologies ApS or its Affiliates to the Customer and forms part of the Agreement between the Parties.
Introduction
1.1 This DPA shall be deemed to be part of the Agreement between the Parties.
1.2 This DPA regulates the Customer's rights and obligations in its capacity as data controller or processor as well as Spaak Technologies ApS's rights and obligations in its capacity as data processor or sub-processor when Spaak Technologies ApS processes Personal Data on behalf of the Customer under the Agreement.
1.3 The purpose of this DPA is to regulate the processing of Personal Data in accordance with the requirements set forth by Applicable Data Protection Laws. Concepts, terms, and expressions in this DPA shall be interpreted in accordance with Applicable Data Protection Laws (as defined below).
1.4 In case of any conflict between the rest of the Agreement and this DPA (including its appendices), the wording of this DPA shall prevail.
1.5 The following appendices shall form part of the DPA:
a) Appendix A – Specification of data processing
b) Appendix B – Sub-processors
c) Appendix C – Security measures
1.6 Capitalized terms that are used but not defined in this document shall have the meaning set out in the Agreement Order Form or the Terms of Service of Spaak Technologies ApS.
Definitions
2.1 "Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement and this DPA, including but not limited to: (i) the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); (ii) the UK GDPR as defined in section 3 of the UK Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection; (iv) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"); and (v) any other applicable data protection or privacy law in force in any jurisdiction where the Services are provided.
2.2 "Controller" means the entity which determines the purposes and means of the Processing of Personal Data.
2.3 "Data Subject" means an identified or identifiable natural person whose Personal Data is Processed.
2.4 "Personal Data" means any Customer Content that (i) relates to an identified or identifiable natural person, or (ii) constitutes “personal data”, “personal information” or any similar term within the meaning of Applicable Data Protection Laws.
2.5 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed.
2.6 "Process", "Processing", "Processed" shall have the meaning as defined in Applicable Data Protection Laws.
2.7 "Restricted Transfer" means a transfer of Personal Data to a country or territory that is not subject to an adequacy decision under the Applicable Data Protection Laws.
2.8 "Standard Contractual Clauses" or "SCCs" means: (i) the standard contractual clauses approved by the European Commission in Commission Decision (EU) 2021/914 dated 4 June 2021; and/or (ii) the UK International Data Transfer Addendum to the EU SCCs ("UK Addendum"), as applicable.
2.9 "Sub-processor" means any person or entity engaged by the Processor to Process Personal Data on behalf of the Controller in connection with the provision of the Services.
2.10 "Input" means the data, software, documents, third-party services, and other content (including prompts) uploaded, accessed, stored, or submitted by any means for the use in the Services by or on behalf of the Customer.
2.11 "Output" means the output generated and returned by the Services, by or on behalf of the Customer, based on the Input.
2.12 "Customer Content" means both Input and Output collectively.
The terms “data controller” and “data processor” have the meanings accorded to them under Applicable Data Protection Laws.
Processing of personal data
3.1 Spaak Technologies ApS undertakes to Process Personal Data for purposes set forth in this DPA (including Appendix A) and in accordance with the Customer's written instructions, unless otherwise required by Applicable Data Protection Laws. The Customer's instructions to Spaak Technologies ApS regarding the subject-matter and duration of the processing, the nature and purpose of the processing, the type of Personal Data and categories of data subjects, and the rights and obligations of both Parties are set forth in this DPA and in Appendix A.
3.2 As data processor, Spaak Technologies ApS undertakes to:
a) Comply with all Applicable Data Protection Laws that are applicable to it as a processor of the Personal Data;
b) Cooperate with audits conducted by the Customer; and
c) Inform the Customer promptly if Spaak Technologies ApS determines that an instruction from the Customer violates Applicable Data Protection Laws.
3.3 Any transfer of Personal Data to Spaak Technologies ApS using the Services shall be made using secure, reasonable, and appropriate mechanisms for data transfers.
3.4 Spaak Technologies ApS shall, without undue delay, inform the Customer of any communication with any Data Protection Authority that relates to Spaak Technologies ApS's Processing of Personal Data under this DPA.
3.5 Spaak Technologies ApS shall provide reasonable assistance to the Customer, through appropriate technical and organizational measures, with the Customer's compliance obligations to implement reasonable security procedures and practices appropriate to the nature of the Personal Data.
3.6 Spaak Technologies ApS certifies that it will not:
a) retain, use, or disclose Personal Data outside the context of the relationship between Spaak Technologies ApS and the Customer, other than to provide the Services in accordance with the Agreement and this DPA, or as otherwise permitted by Applicable Data Protection Laws;
b) sell or share Personal Data; or
c) combine Personal Data Spaak Technologies ApS obtains in the performance of the Services with any personal information that Spaak Technologies ApS collects from other sources, except as permitted by Applicable Data Protection Laws.
3.7 Spaak Technologies ApS's assistance to the Customer under this DPA will be provided at the Customer's reasonable expense, unless the reason for the assistance is a direct result of an act or omission by Spaak Technologies ApS or its Affiliates.
Obligations of the customer
4.1 The Customer shall ensure that it has a valid legal basis, and all necessary rights, consents, and authorizations, to provide the Personal Data to Spaak Technologies ApS and to authorize Spaak Technologies ApS to Process the Personal Data in accordance with this DPA, the Agreement, and/or other processing instructions provided by the Customer.
4.2 The Customer shall comply with all Applicable Data Protection Laws that are applicable to it as controller of the Personal Data.
4.3 The Customer shall limit the provision of Personal Data to Spaak Technologies ApS to what is necessary for the purpose of the Agreement.
Sub-processors
5.1 Spaak Technologies ApS is entitled to engage subcontractors acting as sub-processors, under the condition that they are bound by a written agreement which imposes on them materially the same data processing obligations as the obligations under this DPA in respect of data protection.
5.2 Spaak Technologies ApS shall inform the Customer of any new subprocessors by updating the sub-processor list on https://trust.spaak.ai/ and give the Customer the opportunity to object to such changes. Such objections by the Customer shall be based on grounds regarding the new sub-processor's ability to comply with Applicable Data Protection Laws and be made in writing within 30 days from posting. Spaak Technologies ApS may not engage a new sub-processor before the 30-day period has ended.
5.3 If Spaak Technologies ApS, despite the Customer's objection, wishes to engage the sub-processor, the Parties shall in good faith discuss and try to find an alternative solution which is reasonably acceptable to both Parties. If the Parties cannot find an alternative solution and the Customer still objects to the appointment of the sub-processor, and if the Customer’s objection would result in additional costs or expenses for Spaak Technologies ApS, then Spaak Technologies ApS is entitled to adjust its fees under the Agreement to ensure that Spaak Technologies ApS is compensated for such additional and/or increased costs or expenses. Notwithstanding the previous sentence, if the Customer’s objection would result in costs or operational consequences which, in Spaak Technologies ApS’s opinion, would not be commercially reasonable, Spaak Technologies ApS may terminate the Agreement upon reasonable written notice.
5.4 The current list of sub-processors is set out in Appendix B.
International data transfers
6.1 The Customer acknowledges that Spaak Technologies ApS may transfer Personal Data or make Personal Data available by remote access to
Spaak Technologies ApS in order to provide the Services. Spaak Technologies ApS shall ensure that any such transfer complies with Applicable Data Protection Laws.
6.2 To the extent any transfer constitutes a Restricted Transfer, Spaak Technologies ApS shall upon request provide all reasonably relevant information regarding the Restricted Transfer to enable the Customer to make an informed decision, including details of the country or territory to which the Personal Data will be transferred.
6.3 Where a transfer of Personal Data to Spaak Technologies ApS or to a sub-processor constitutes a Restricted Transfer, Spaak Technologies ApS shall apply an appropriate transfer mechanism, in the following order of priority:
a) where the destination jurisdiction benefits from an adequacy decision under Article 45 of the EU GDPR (or the equivalent decision under the UK GDPR or the Swiss Federal Act on Data Protection, as applicable), Spaak Technologies ApS relies on that adequacy decision;
b) otherwise, where Spaak Technologies ApS or the relevant sub-processor maintains a valid certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework (as applicable to the originating jurisdiction of the Personal Data), Spaak Technologies ApS relies on that framework as the transfer mechanism for so long as the certification remains valid and the framework remains in force;
c) in all other cases — including where a certification under (b) lapses or is withdrawn or where the relevant framework is invalidated by a competent authority — Spaak Technologies ApS relies on the Standard Contractual Clauses, implemented as follows:
(i) For transfers subject to the EU GDPR, the EU Commission SCCs shall apply, with Module 2 (controller-to-processor) applying where the Customer acts as a Controller and Module 3 (processor-to-processor) applying where the Customer acts as a Processor. The Parties further agree that: (A) under Clause 7, the docking clause is incorporated; (B) under Clause 9(a), Option 2 (general written authorisation) applies, with the notice period set out in Clause 5.2 of this DPA; (C) the optional redress clause in Clause 11(a) does not apply; (D) under Clause 17, the SCCs are governed by the laws of Denmark; (E) under Clause 18, disputes are resolved by the courts of Denmark; and (F) Appendix A of this DPA serves as Annex I, Appendix C as Annex II, and Appendix B as Annex III to the SCCs;
(ii) For transfers subject to the UK GDPR, the UK Addendum to the EU SCCs shall apply, incorporating the elections made in (i) above to the extent applicable;
(iii) For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs shall apply with the modifications required under Swiss law, including in particular references to the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority and the inclusion of legal entities within the scope of protection where required.
6.4 In each case under Clause 6.3, Spaak Technologies ApS shall apply supplementary technical, organisational and contractual measures appropriate to the transfer, including (i) encryption of Personal Data in transit and at rest; (ii) least-privilege and role-based access controls in accordance with Appendix C; (iii) maintaining records of any binding requests for disclosure of Personal Data received from public authorities; and (iv) a contractual commitment to challenge any such request that appears unlawful under Applicable Data Protection Laws, to the extent legally permitted.
6.5 Spaak Technologies ApS represents and warrants that it has no reason to believe that legislation or practices applicable to it or its subprocessors prevent it from fulfilling its obligations under Applicable Data Protection Laws, this DPA, or the Standard Contractual Clauses. In the event Spaak Technologies ApS is unable to fulfill its obligations, it agrees to immediately notify the Customer.
US-specific provisions
7.1 To the extent that the CCPA/CPRA or other US state privacy laws apply to the Processing of Personal Data under this DPA, Spaak Technologies ApS acts as a "Service Provider" (as defined under the CCPA) or equivalent role under other applicable US state privacy laws.
7.2 In its capacity as Service Provider, Spaak Technologies ApS shall not: (i) sell, rent, release, disclose, or otherwise make available Personal Data to third parties for monetary or other valuable consideration; (ii) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement or this DPA; or (iii) retain, use, or disclose Personal Data outside of the direct business relationship between Spaak Technologies ApS and the Customer.
7.3 Spaak Technologies ApS shall assist the Customer in responding to verifiable consumer requests under Applicable Data Protection Laws, including requests for access, deletion, or correction of Personal Data.
Information security and confidentially
8.1 To maintain an adequate level of security for the protection of Personal Data, Spaak Technologies ApS commits to the appropriate technical and organizational measures described in Appendix C.
8.2 Spaak Technologies ApS shall protect the Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed.
8.3 Spaak Technologies ApS shall ensure that only staff and other representatives who require access to Personal Data to fulfill Spaak Technologies ApS's obligations under the Agreement have access to such information. Spaak Technologies ApS shall guarantee that all persons authorized to Process Personal Data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
Data breach notifications
9.1 Spaak Technologies ApS shall inform the Customer without undue delay and at the latest within 72 hours from becoming aware of a Personal Data Breach.
9.2 Spaak Technologies ApS shall assist the Customer with any information reasonably required to fulfill the Customer's data breach notification requirements under Applicable Data Protection Laws. Any costs associated with such assistance will be subject to the limitations of liability in the Terms of Service.
Data protection impact assessments and prior consultations
10.1 Spaak Technologies ApS shall, at the Customer's reasonable expense, considering the nature of the processing and the information available to Spaak Technologies ApS, assist the Customer in fulfilling the Customer's obligation to, when applicable, carry out data protection impact assessments and prior consultations with the Data Protection Authority.
Audit rights
11.1 Customer shall have the right to perform audits of Spaak Technologies
ApS's Processing of Customer's Personal Data to verify Spaak Technologies ApS's compliance with this DPA and Applicable Data Protection Laws. This audit right is limited to once per 12-month period unless the Customer has clear reasons to believe that Spaak Technologies ApS has materially breached its obligations under this DPA.
11.2 Spaak Technologies ApS undertakes to make available to the Customer all information and other assistance necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including on-site inspections, conducted by an authorized and reputable auditor mandated by the Customer, provided that the individuals performing the audits enter into confidentiality agreements.
11.3 It is noted that among Spaak Technologies ApS's customers there may
be entities which are subject to statutory, regulatory, or professional confidentiality obligations in relation to their stakeholders, members, clients, or advocacy matters. Hence, the Customer acknowledges that audits under this DPA shall not include access to information pertaining or belonging to Spaak Technologies ApS's other customers.
11.4 The Customer is responsible for all costs associated with audits, save for when an audit concludes a material breach of Spaak Technologies ApS's undertakings in violation of the Agreement. If so, Spaak Technologies ApS shall compensate the Customer for reasonable and verified costs associated with the audit.
Term of agreement
12.1 The provisions of this DPA shall apply as long as Spaak Technologies ApS Processes Personal Data for which the Customer is data controller or until such time this DPA is replaced with another data processing agreement.
Measures upon completion of processing of personal data
13.1 Before the expiration of this DPA, Spaak Technologies ApS shall, at the choice and instruction of the Customer, securely delete or return all Personal Data to the Customer, unless Applicable Data Protection Laws require Spaak Technologies ApS to store the Personal Data in which case the obligations set out in Clause 13.4(a)–(c) shall apply.
13.2 If return or destruction is impracticable or prohibited by law, Spaak Technologies ApS shall take measures to inform the Customer and block such Personal Data from any further Processing (except to the extent necessary for its continued hosting or processing required under applicable law) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control.
13.3 Upon request by the Customer, Spaak Technologies ApS shall provide a written notice of the measures taken regarding the Personal Data upon completion of the processing.
13.4 If Spaak Technologies ApS is legally required to retain archival copies of any specific data belonging to the Customer for tax or similar regulatory purposes, Spaak Technologies ApS shall:
a) inform the Customer thereof in writing specifying the legal obligation and the affected Customer data;
b) not use the archived information for any purpose other than to strictly comply with the applicable legal obligation; and
c) remain bound by its obligations under the Agreement, including this DPA, including its confidentiality and security obligations under the Agreement and the obligations under this DPA to protect the information using appropriate safeguards and to notify the Customer of any security incident involving the information.
Amendments
14.1 Any substantial amendments to this DPA shall, to be valid, be communicated to the Customer in writing and the Customer shall be given the opportunity to object to the proposed amendments. An objection shall be made in writing within thirty (30) days from receipt of the proposed amendments. If Spaak Technologies ApS, despite the Customer’s objection, wishes to continue with the proposed amendments, the Customer is entitled to terminate the Agreement at no extra cost.
14.2 Notwithstanding Clause 14.1, the Customer is entitled to make updates to its written instructions regarding the processing set out in Appendix A. Spaak Technologies ApS shall be entitled to remuneration for any reasonable and verified additional costs that Spaak Technologies ApS incurs due to the Customer having made amendments to its written instructions regarding the processing. Notwithstanding the aforesaid, no remuneration shall be payable due to amendments in the written instructions directly due to, or directly based on, regulatory requirements.
Liabiliy
15.1 Subject to Clauses 15.2 and 15.3, the liability provisions and limitations thereof set out in the Terms of Service of Spaak Technologies ApS shall apply to this DPA.
15.2 Notwithstanding any aggregate liability cap set out in the Terms of Service, each Party’s aggregate liability arising out of or in connection with breach of this DPA shall not exceed two (2) times the total fees paid or payable by the Customer to Spaak Technologies ApS under the Agreement in the twelve (12) months immediately preceding the event giving rise to the claim. shall apply to this DPA.
15.3 Nothing in this DPA or the Terms of Service shall limit or exclude either Party’s statutory liability to data subjects under Article 82 of the EU GDPR (or equivalent provisions of Applicable Data Protection Laws), or any other liability which by Applicable Data Protection Laws cannot be limited or excluded.
Liabiliy
16.1 Except as otherwise required by Applicable Data Protection Laws, this DPA shall be governed by and construed in accordance with the laws of Denmark.
16.2 Any dispute, controversy, or claim arising out of or in connection with this DPA shall be finally settled in accordance with the dispute resolution provision set out in the Terms of Service of Spaak Technologies ApS.
Appendix A - SPECIFICATION OF DATA PROCESSING
Subject matter and purposes of the processing
Spaak provides teams with an AI workspace for public affairs knowledge work through a SaaS solution.
The Services are defined in the Agreement and include, among other things, an AI chat interface to interact with public policy and legislative sources, as well as organizational and Customer data.
Spaak shall process Personal Data on behalf of the Customer for the purpose of providing the Services under the Agreement. Spaak's processing of Personal Data on behalf of the Customer will be as necessary to perform the Services, and as otherwise required by applicable law.
Nature of Processing
The nature of Spaak's processing includes collection, storage, retrieval, organization, analysis (including through large language models), and erasure of Personal Data as required to deliver the Services.
Duration of Processing
For the duration of the Agreement, plus any retention period required by Applicable Data Protection Laws or as otherwise agreed between the Parties.
Categories of Data Subjects
Personal Data included in Customer Content, i.e. natural persons who are mentioned or otherwise included in the Customer’s input data submitted to the Spaak Platform.
Personal Data
Name, title, email or other personal data submitted in search queries, prompt queries or documents uploaded into the Services.
Appendix B - SUB-PROCESSORS
Please see: trust.spaak.ai
Appendix C - SECURITY MEASURES
Spaak Technologies ApS has implemented the following technical and organizational security measures to protect Personal Data and ensure a continuous high quality delivery of our services.
Spaak Technologies ApS reserves the right to revise these technical and organizational measures at any time, without notice unless required under applicable laws, so long as any such revisions will not materially reduce or weaken the protection provided for Personal Data that Spaak Technologies ApS processes in providing its products and services.
Sub-processors
Spaak Technologies ApS engages with sub-processors of for specific purposes to enhance the Services provided to the Customer. Please see Appendix B for the list of sub-processors.
Access Control
Measures that prevent unauthorized persons from using IT systems and processes:
a) When provisioning access, Spaak adheres to the principle of least privilege and role-based access control (RBAC) — meaning employees are only authorized to access data they reasonably must handle to fulfill their job responsibilities.
b) Spaak enforces multi-factor authentication (MFA) for all employees accessing systems with confidential data, including the production environment that houses Personal Data.
c) Access rights are reviewed quarterly, and access is revoked immediately upon termination of employment or change of role.
d) Automatic session expiry and account lockout policies are enforced on production systems.
Measures to prevent physical access of unauthorized persons to IT systems that handle Personal Data:
e) Spaak hosts its services on Google Cloud Platform ("GCP"). Access to GCP data centers is strictly controlled. All data centers are equipped with 24x7x365 surveillance and biometric access control systems.
f) Spaak ensures that only authorized persons can access physical office locations.
g) Spaak operates onboarding and offboarding procedures for employees including the provision of relevant security training and the immediate return and/or destruction of sensitive documents and access credentials upon termination.
Incident Response
a) Spaak maintains a documented incident response plan with defined roles and escalation procedures.
b) Post-incident reviews are conducted for all material incidents, with documented findings and remediation actions.
