Data Processing Agreement (DPA)

DRAFT — this data processing agreement is pending legal review. Contact us at support@followmeup.dk for a signed version.

Version 0.9 (draft) — 5 July 2026

This data processing agreement (the "Agreement") is entered into between the customer (the "Controller") and FollowMeUp, Ølandsgade 1, 2300 Copenhagen, Denmark (the "Processor"), and forms an annex to the Terms of Service. The Agreement governs the Processor's processing of personal data on behalf of the Controller pursuant to GDPR art. 28.

1. Nature and purpose of the processing

The Processor provides a service that monitors the Controller's Outlook mailbox(es) for unanswered requests, analyses email content with a language model, and generates reminders and drafts. The processing comprises reading email content and metadata via Microsoft Graph (read-only Mail.Read), storing derived records (threads, statuses, excerpts), and sending service emails.

2. Categories of data subjects and data

  • Data subjects: the Controller's users and their correspondents (senders/recipients of emails).
  • Data: identity data (name, email), email content and metadata (subject, sender, timestamps, text excerpts), app settings, billing and usage data.
  • No special categories of data (art. 9) are intentionally processed; such data may however occur in email content, which the Controller controls.

3. Instructions

The Processor processes personal data only on documented instructions from the Controller — constituted by this Agreement, the Terms, and the user's configuration of the service — unless processing is required under EU or Danish law. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality and security (TOMs)

The Processor implements appropriate technical and organisational measures, including:

  • Encryption in transit (TLS) and at rest; OAuth tokens are additionally encrypted at the application level (Fernet) with key rotation.
  • Tenant isolation enforced in the database (row-level security, fail-closed).
  • Access control: superadmin access is bound to named, immutable identities; all administrative actions are logged in a hash-chained, tamper-evident audit trail.
  • Data minimisation towards the AI provider: only minimised excerpts are sent, under zero-retention and no-training terms in an EU region.
  • Daily encrypted backups with an offsite copy; documented restore procedure.
  • Persons with access to the data are subject to confidentiality obligations.

5. Sub-processors

The Controller grants general authorisation to the use of sub-processors. The current list appears in the Privacy Policy §5 (Microsoft, OpenAI, Stripe, Euronodes, Google — the latter only with consent). The Processor gives reasonable prior notice of material changes so the Controller may object. Sub-processors are bound by data protection obligations equivalent to this Agreement.

6. Third-country transfers

Processing takes place in the EU by default. Where transfers to third countries occur (e.g. Stripe/Google), they rely on the EU Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework.

7. Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller in fulfilling its obligations regarding data subjects' rights (access, erasure, portability — the service includes self-service export and deletion), security, breach notification, and impact assessments.

8. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a breach, providing the information required under art. 33(3) to the extent available.

9. Deletion and return

Upon termination of the service, the Processor deletes all personal data after a 14-day grace period, unless EU or Danish law requires retention (e.g. bookkeeping-law requirements for transaction data, which is stored separately and minimised). The Controller may export its data via the service's export function beforehand.

10. Audits

The Processor makes available the information necessary to demonstrate compliance with art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it, with reasonable notice and at most once per year unless a breach warrants otherwise.

11. Duration and governing law

The Agreement applies for as long as the Processor processes personal data for the Controller. The Agreement is governed by Danish law; venue follows the Terms.


Contact: support@followmeup.dk · FollowMeUp, Ølandsgade 1, 2300 Copenhagen, Denmark

Data Processing Agreement