CyberSkjold

Data Processing Agreement

This is an AI-generated draft based on standard Danish and GDPR practice — it is not legal advice, and should be reviewed by a lawyer before use with real customers.

This Data Processing Agreement ("DPA") forms part of the agreement between the customer (data controller) and CyberSkjold ApS (data processor), and applies to CyberSkjold's processing of personal data on the customer's behalf, per GDPR Article 28.

1. Subject matter and instructions

CyberSkjold processes employee personal data (name, work email, course/quiz results, phishing-simulation results) solely to deliver the training platform, and only on the customer's documented instructions, including as set out in these terms.

2. Confidentiality

Persons authorised to process the data are bound by confidentiality, whether through contract or statutory obligation.

3. Security measures

CyberSkjold implements appropriate technical and organisational measures, including encrypted transport (HTTPS), access control per company account, and hashed/salted password storage, taking into account the state of the art and the risk to the rights of data subjects.

4. Sub-processors

CyberSkjold may engage sub-processors (e.g. hosting providers) under equivalent data protection obligations, and will inform the customer of any intended changes, giving the customer an opportunity to object.

5. Assistance to the controller

CyberSkjold will assist the customer, as reasonably required, in responding to data subject rights requests and in fulfilling obligations under GDPR Articles 32–36 (security, breach notification, impact assessments).

6. Deletion or return of data

At the end of the subscription, CyberSkjold will, at the customer's choice, delete or return all personal data, unless EU or Danish law requires continued storage.

7. Audit

The customer may request reasonable evidence of CyberSkjold's compliance with this DPA, including relevant documentation of the security measures in place.

8. International transfers

Personal data is processed within the EU/EEA. Any transfer outside the EU/EEA will only take place under an adequate safeguard recognised by GDPR Chapter V.

9. Effective date

This DPA takes effect when the customer creates an account and remains in effect for as long as CyberSkjold processes personal data on the customer's behalf.

Back to homepage