Data processing agreement
Version 2026-08-13 · effective from 13 August 2026
1. Parties and status of the agreement
The controller is the company, authority or organisation represented by the account holder that determines the purposes and means of processing personal data in the transferred files. The organisation's name and contact person are those registered on the SikkerFTP.dk account.
The processor is Rasmus Jensen, who operates SikkerFTP.dk in Denmark. Contact: privacy@sikkerftp.dk.
This agreement supplements SikkerFTP.dk's terms of use. It becomes binding when an account holder accepts it during onboarding and uses the service on behalf of a controller. In the event of a conflict concerning personal data processing, this agreement takes precedence.
2. Purpose, nature and duration
The processor provides isolated SFTP endpoints and web-based file access solely to receive, temporarily store and deliver files according to the controller's documented instructions.
Processing includes receipt, transmission, temporary storage, display, download, deletion, access management, security logging and necessary troubleshooting. The agreement applies while the account or an endpoint is active and during the subsequent deletion period.
3. Data and data subjects
Permitted categories
Ordinary personal data with a low potential for harm, such as names, work contact details, customer or order numbers, delivery details and similar administrative information.
Categories of data subjects
The controller's employees, customers, suppliers, contacts and other people whose ordinary information lawfully forms part of the specific file transfer.
Prohibited categories
Special categories of data under GDPR Article 9, criminal offence data under Article 10, Danish CPR numbers, patient information, payment card data, authentication secrets and other content where loss, alteration or unauthorised access could create a high risk.
4. Instructions
- The processor may process data only on documented instructions from the controller, unless EU or Danish law requires otherwise. In that case, the controller is informed before processing unless the law prohibits this.
- Uploads, endpoint configuration, access assignments, deletion, this agreement and the terms of use constitute the documented instructions.
- The processor does not use file contents for its own purposes, advertising, profiling or product training.
- If the processor considers an instruction contrary to data protection rules, the controller is informed without undue delay and the affected processing may be paused.
- The controller is responsible for the legal basis, information obligations, data minimisation, accuracy, recipients and ensuring that the chosen security profile is appropriate based on its own risk assessment.
5. Confidentiality and access
People with access to personal data are subject to confidentiality obligations and may process it only on instructions. Access is limited to the operator with a specific operational, security or support need. Administrative access uses individual SSH keys and a separate restricted management network.
6. Security measures
The processor implements the measures described in Annex B and maintains a security level appropriate to the agreed low-risk, short-term processing. The controller must not increase the processing risk without a new written agreement.
Customer data backups and encryption at rest are planned improvements. They are not part of the current service or agreement until Annex B has been updated, the change implemented and the new version brought into effect.
7. Sub-processors and transfers
- The controller grants general authorisation for the sub-processors listed in Annex C.
- The processor gives at least 30 days' notice before using a new or replacement sub-processor when practically possible. The controller may raise a reasoned objection and stop using the service before the change.
- A sub-processor is subject to at least the same data protection obligations for the relevant processing.
- Customer SFTP file contents are stored in Denmark and are not intentionally transferred to third countries. Any processing of web connection data outside the EEA takes place only on a valid transfer basis.
8. Assistance to the controller
Taking into account the nature of processing and available information, the processor assists with:
- requests for access, rectification, erasure, restriction and data portability;
- security, breach notifications and communication to data subjects;
- impact assessments and any prior consultation;
- information necessary to demonstrate compliance with Article 28.
Enquiries should be sent to privacy@sikkerftp.dk. The processor does not respond to data subjects on the controller's behalf without instructions, but forwards relevant enquiries.
9. Personal data breaches
The processor informs the controller without undue delay after becoming aware of a breach affecting its data. As information becomes available, the notice includes the nature of the incident, affected categories, likely consequences, measures taken or proposed and a contact point. The controller is responsible for any notification to the Danish Data Protection Agency and communication to data subjects.
10. Deletion and return
- The controller may download and delete files through the service at any time and must do so once the transfer purpose has been fulfilled.
- When an endpoint is deleted, external access is removed immediately. The isolated folder is permanently deleted within 30 days, or earlier following verified written instructions, unless retention is required by law.
- Before termination, the controller must download any required files. The processor then deletes remaining personal data and copies, except information that must lawfully be retained.
- Customer files are not included in backups. Control-plane backups may contain account and endpoint metadata and rotate after 30 days.
11. Inspection and audit
The processor makes relevant information about security measures and compliance available and permits reasonable audits by the controller, an independent auditor or a competent authority. Ordinary audits require at least 30 days' notice and are conducted without access to other customers' data or compromising security. This restriction does not apply to security breaches, specifically justified suspicion or requirements from an authority.
12. Liability, duration and governing law
The parties' liability follows the GDPR, Danish data protection law and the terms of use. This agreement does not limit the rights of data subjects or authorities. The agreement ends when the processor has deleted or lawfully returned all data. Danish law applies, and the Danish Data Protection Agency is the competent supervisory authority for the processor's processing.
Annex A — Processing instructions
- Purpose: Short-term, user-initiated file transfers through SFTP and the web client.
- Frequency: As needed by the controller within the account's quotas.
- Geography: SFTP file storage and application database in Denmark.
- Duration: Active endpoint plus up to 30 days of isolated retention pending deletion.
- Special instructions: No high-risk data, no permanent storage and no third-country transfers of file contents.
Annex B — Technical and organisational measures
- Encrypted transport through SFTP/SSH and HTTPS/TLS.
- Separate technical user, UUID-based folder and quota per endpoint.
- Strong, cryptographically generated passwords, one-time display and secure rotation.
- Brute-force protection, rate limiting, firewall and restricted API source networks.
- Web administration only through an SSH tunnel and private administrative access.
- When antivirus is enabled, files are received in a restricted intake folder and scanned locally before publication for download. Rejected or unscannable files are not published. File isolation, antivirus and encrypted transport do not guarantee that received files are harmless.
- Security updates, service health checks and tenant-isolated SFTP hook events covering authentication, IP addresses, protocols, virtual file paths, file sizes and results. Session IDs are available for file events but not sign-in/disconnect hooks. Asynchronous hooks do not guarantee complete or lossless audit.
- SFTP audit is pruned daily with a limit of 90 days. Technical log files are rotated. Application security events and permanent endpoint deletion metadata are automatically pruned after 90 days.
- Daily local control-plane backups with integrity checks; customer files are explicitly excluded.
- Not yet implemented: customer file backups and encryption at rest.
- Manual, verified access for support and incidents; no routine reading of file contents.
Annex C — Approved sub-processors
- Cloudflare, Inc. — DNS and optional proxy/security for web traffic. May process IP addresses and connection metadata globally under its applicable data protection and transfer framework. Does not receive SFTP file contents as part of the described architecture.
The self-hosted portal, database, file transfer service and storage run on the operator's own equipment in Denmark and are not sub-processors.
Annex D — Acceptance and contact
Acceptance is recorded on the account with the user, timestamp and agreement version. The accepting user confirms that they are authorised to enter into the agreement for the controller. Changes that materially reduce data protection require new notice or acceptance under applicable law.