Data Processing Addendum (DPA)
Effective Date: 7 October 2025
Version: 1.0
This Data Processing Addendum (“DPA”) forms part of the Proactivox Terms of Service (“Agreement”) between:
Proactivox (“Processor”, “we”, “our”, or “us”), a company registered in Denmark, and
The Customer (“Controller”, “you”, or “your”) who has entered into the Agreement for use of the Proactivox Services.
1. Purpose and Scope
1.1 This DPA governs Proactivox’s processing of personal data on behalf of the Customer in connection with the provision of the Services.
1.2 The DPA ensures compliance with Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent data protection laws applicable to the Customer’s use of the Services.
1.3 In case of conflict between this DPA and the Agreement, this DPA shall prevail to the extent of the inconsistency relating to data protection obligations.
2. Definitions
Data Protection Laws: All laws and regulations relating to data protection and privacy, including GDPR, UK GDPR, and the Danish Data Protection Act.
Personal Data: Any information relating to an identified or identifiable individual that is processed by Proactivox on behalf of the Customer.
Processing / Process: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
Subprocessor: Any third party engaged by Proactivox to process personal data on behalf of the Customer.
EEA: European Economic Area.
3. Roles of the Parties
3.1 The Customer acts as the Data Controller, determining the purpose and means of processing personal data.
3.2 Proactivox acts as the Data Processor, processing personal data only on behalf of and under the documented instructions of the Customer.
4. Duration of Processing
This DPA applies for the duration of the Agreement and continues until all Customer Data and personal data processed under it are deleted or returned to the Customer in accordance with Section 11.
5. Nature and Purpose of Processing
Proactivox processes personal data solely for the purpose of delivering and maintaining the Services, which may include:
Providing access to the Proactivox SaaS platform;
Managing integrations with third-party systems (e.g., Salesforce or marketing automation tools);
Performing analytics, diagnostics, and technical support;
Securing, maintaining, and improving service performance; and
Complying with applicable legal obligations.
No personal data is processed beyond these purposes unless required by law or explicitly authorized by the Customer.
6. Types of Personal Data and Data Subjects
Types of data: contact details, account credentials, activity logs, integration metadata, or customer-submitted contact information.
Data subjects: employees, end users, subscribers, or other individuals whose data the Customer transmits through the Services.
Proactivox does not intentionally collect or process special categories of data (sensitive data) unless explicitly agreed.
7. Processor Obligations
Proactivox shall:
Process personal data only on documented instructions from the Customer;
Ensure all personnel authorized to process personal data are bound by confidentiality;
Implement appropriate technical and organizational measures to protect personal data as described in Appendix 1 (Security Measures);
Assist the Customer in fulfilling its obligations regarding data subject rights, data protection impact assessments, and breach notifications;
Maintain records of processing activities; and
Notify the Customer without undue delay after becoming aware of a personal data breach.
8. Subprocessing
8.1 The Customer authorizes Proactivox to engage subprocessors necessary for providing the Services.
8.2 Proactivox will ensure subprocessors are bound by written agreements imposing data protection obligations no less protective than those in this DPA.
8.3 A current list of subprocessors is available upon request or at proactivox.com/subprocessors.
8.4 The Customer may object to a new subprocessor for reasonable data protection grounds. If the objection cannot be resolved, either party may terminate the affected Services.
9. International Data Transfers
9.1 Proactivox may transfer personal data outside the EEA or UK where necessary for service delivery.
9.2 Any such transfer will comply with Data Protection Laws and include adequate safeguards, such as:
Standard Contractual Clauses (SCCs) approved by the European Commission; or
Other lawful transfer mechanisms recognized under GDPR.
Proactivox ensures all subprocessors outside the EEA maintain equivalent protection levels.
10. Assistance to Controller
Proactivox will, as far as reasonably possible:
Assist the Customer in responding to data subject access requests;
Provide information needed for data protection impact assessments;
Support cooperation with supervisory authorities.
Any such assistance may be subject to reasonable fees if it requires substantial resources beyond standard support.
11. Deletion or Return of Data
Upon termination or expiration of the Agreement, Proactivox shall:
Delete or return all personal data within 30 days, unless retention is required by law;
Delete backup copies within a commercially reasonable period thereafter;
Provide written confirmation of deletion upon request.
12. Audits and Certifications
12.1 Proactivox maintains internal documentation to demonstrate compliance with this DPA.
12.2 Upon written request, Proactivox will provide available audit summaries or third-party certifications (e.g., ISO 27001 or SOC 2 reports, if applicable).
12.3 Physical audits or on-site inspections by the Customer may be requested only if required by law and subject to confidentiality and prior written agreement.
13. Data Breach Notification
In the event of a confirmed personal data breach, Proactivox will:
Notify the Customer without undue delay;
Provide relevant details, including the nature of the breach, affected data, and mitigation steps;
Cooperate fully with the Customer and authorities to address the incident.
14. Liability
Each party’s liability under this DPA is subject to the limitations set forth in the main Agreement.
Proactivox shall not be liable for data loss or damages resulting from actions or omissions of the Customer or third-party systems under the Customer’s control.
15. Governing Law and Jurisdiction
This DPA is governed by the laws of Denmark, and any dispute arising in connection with it shall be resolved by the courts of Copenhagen, Denmark, unless otherwise required by applicable mandatory law.
16. Miscellaneous
Any amendment to this DPA must be in writing and mutually agreed.
If any provision is found invalid, the remaining provisions remain in effect.
This DPA supersedes any prior data processing agreements between the parties.
Appendix 1 – Security Measures
Proactivox implements appropriate technical and organizational security measures, including but not limited to:
Encryption: TLS encryption for data in transit and AES-256 encryption for data at rest.
Access Controls: Role-based access and multi-factor authentication for internal systems.
Data Minimization: Limiting collection and retention to necessary data only.
Monitoring: Logging and intrusion detection systems for anomaly monitoring.
Backup & Recovery: Regular encrypted backups and tested recovery procedures.
Employee Training: Security and privacy awareness training for all personnel.
Vendor Management: Due diligence and contractual safeguards for all subprocessors.
Appendix 2 – Contact Details
Proactivox
CVR-nr 32434355
Email: privacy@proactivox.com
Website: www.proactivox.com
Address: Østre Havnevej 2, 5700 Svendborg, Denmark