Data Processing Agreement

Last updated: 15 August 2026

1. The parties and their roles

This data processing agreement (DPA) forms part of the Terms & Conditions between you ("the Company") and Throughline, CVR number 32861326, Würglersvej 3, 8870 Langå, Denmark. For the contact, event, and consent data your Company uploads to or generates in the platform, your Company is the data controller and Throughline is the data processor, acting only on your documented instructions. For your own user accounts and billing data, Throughline is the controller — that processing is described in the Privacy Policy, not here.

2. Subject matter, duration, and scope

Subject matter: processing of personal data on behalf of the Company in order to provide the Throughline customer-lifecycle platform. Duration: for as long as the Company's subscription is active, plus the deletion period in section 9. Nature and purpose: storage, organisation, segmentation, journey execution, message delivery over email and SMS, AI-assisted drafting of content and journeys, and the related logging and analytics. Categories of data subjects: the Company's contacts — typically its leads, customers, and their employees. Categories of personal data: identifiers and contact details (name, email address, phone number), company affiliation, custom fields defined by the Company, behavioural events, consent records, and message engagement data. The Company must not upload special categories of personal data under GDPR art. 9 to the platform.

3. Processing on instructions

Throughline processes personal data only on the Company's documented instructions, including with regard to transfers, unless required otherwise by EU or Danish law — in which case Throughline informs the Company before processing, unless that law prohibits it. Use of the platform's features, including AI-assisted drafting, constitutes the Company's instruction. Throughline will inform the Company if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality

Throughline ensures that every person authorised to process personal data under this DPA is bound by confidentiality and processes the data only as needed to deliver the service.

5. Security of processing

Throughline implements appropriate technical and organisational measures under GDPR art. 32, including encryption in transit and at rest, tenant isolation enforced in the database, role-based access control, password hashing, audit logging of administrative actions and AI invocations, backups, and monitoring. Measures are reviewed as the service evolves and may be updated, provided the level of security is not reduced.

6. Sub-processors

The Company gives general authorisation for Throughline to engage sub-processors. Current sub-processors are Scaleway SAS (hosting, EU data centres) and Mollie B.V. (payments, the Netherlands — billing data only). Message delivery and AI processing run on EU-based providers. Throughline imposes the same data protection obligations on each sub-processor by contract and remains fully liable for their performance. Throughline gives the Company at least 30 days' notice before adding or replacing a sub-processor; if the Company objects on reasonable data protection grounds, it may terminate the subscription with effect from the change.

7. Assistance with data subject rights

Taking the nature of the processing into account, Throughline assists the Company with appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights — access, rectification, erasure, restriction, portability, and objection. The platform provides self-service export and erasure so the Company can handle most requests itself. If a data subject contacts Throughline directly, Throughline forwards the request to the Company and does not respond on its behalf.

8. Personal data breaches

Throughline notifies the Company without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Company's data, and provides the information the Company needs to meet its own notification obligations under GDPR art. 33 and 34. Throughline also assists the Company with data protection impact assessments and prior consultations under art. 35 and 36 where relevant.

9. Return and deletion of data

While the subscription is active, the Company can export individual contact records from the platform and can request a full export of its data from us. On termination, the Company has 30 days to request an export; after that, Throughline deletes the Company's personal data from active systems, and from backups within a further 90 days as backups roll over — unless EU or Danish law requires longer retention.

10. Audits and international transfers

Throughline makes available the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Company or an auditor it mandates, on reasonable notice and no more than once per year unless a breach or a supervisory authority requires otherwise. Personal data is processed exclusively within the EU/EEA. Throughline does not transfer the Company's personal data to a third country, and no sub-processor is authorised to do so.

11. Term and precedence

This DPA takes effect when the Company starts using the service and remains in force for as long as Throughline processes personal data on the Company's behalf. In the event of a conflict between this DPA and the Terms & Conditions regarding the processing of personal data, this DPA prevails.