Legal
Data Processing Agreement.
Version 1.3 · Last updated 5 September 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Staygood ApS, CVR no. 46639081, Rytterkær 2, DK-4000 Roskilde, Denmark (“Staygood”) and the customer identified in an order for the Staygood service (the “Customer”). It applies automatically when Staygood processes personal data on the Customer’s behalf.
1. Definitions
“Controller”, “processor”, “processing”, “personal data”, “data subject” and “personal data breach” have the meanings given in Regulation (EU) 2016/679 (the “GDPR”). “Customer Personal Data” means personal data in Customer Data that Staygood processes on the Customer’s behalf. Other capitalised terms have the meanings given in the Agreement.
2. Roles and scope
2.1 The Customer is the controller and Staygood is the processor of Customer Personal Data. If the Customer is itself a processor, Staygood acts as its sub-processor and the Customer confirms that it may appoint Staygood on these terms.
2.2 Staygood acts as an independent controller for its own account, billing and support records, security and abuse-prevention records, and aggregated information that identifies no person or Customer. Staygood’s Privacy Policy governs that processing.
3. Instructions
3.1 Staygood will process Customer Personal Data only on documented instructions from the Customer, including for transfers outside the EEA, unless EU or Member State law requires otherwise. Where legally permitted, Staygood will inform the Customer before carrying out such legally required processing.
3.2 The Customer’s documented instructions are the Agreement, its configuration and use of the Service, actions by its Users, and any further written instructions agreed by the parties.
3.3 Staygood will inform the Customer if it believes an instruction infringes applicable data protection law. Staygood may suspend the affected processing until the instruction is confirmed, amended or withdrawn and is not required to perform a general legal review of the Customer’s instructions.
4. Confidentiality
Staygood will ensure that people authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and have access only as needed for their role.
5. Security
Staygood will maintain the technical and organisational measures in Annex C, taking account of the matters listed in Article 32 GDPR. Staygood may update those measures without materially reducing the overall level of protection.
6. Sub-processors
6.1 The Customer gives Staygood general written authorisation to use sub-processors. The current list at staygood.ai/legal/subprocessors is Annex B to this DPA.
6.2 Staygood will give at least 30 days’ notice before a new or replacement sub-processor starts processing Customer Personal Data, by updating the list and notifying the Customer’s designated contact by email or in the Service.
6.3 The Customer may object during the notice period on reasonable data-protection grounds. The parties will try in good faith to resolve the issue. If they cannot, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.
6.4 Staygood will impose substantially equivalent data-protection obligations on its sub-processors and remains responsible to the Customer for their performance.
7. Data subject requests
7.1 If Staygood receives a request concerning Customer Personal Data, it will forward it to the Customer without undue delay and will not respond on the merits unless instructed or legally required.
7.2 Taking account of the nature of the processing, Staygood will assist the Customer with its obligations under Chapter III GDPR through available Service functionality and reasonable further assistance where needed.
8. Personal data breaches
8.1 Staygood will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and, where reasonably possible, within 48 hours after becoming aware of it.
8.2 The notice will include available information about the nature and likely consequences of the breach, affected data and data subjects, and measures taken or proposed. Information may be provided in phases.
8.3 Staygood will provide reasonable assistance with the Customer’s obligations under Articles 33 and 34 GDPR. A notification is not an admission of fault or liability.
9. Compliance assistance
Taking account of the nature of the processing and information available to it, Staygood will provide reasonable assistance with the Customer’s obligations under Articles 32–36 GDPR, including data-protection impact assessments and prior consultations relating to the Service. Staygood may charge reasonable fees for assistance under Sections 7 and 9 that goes materially beyond the Service’s functionality and Staygood’s existing documentation.
10. Return and deletion
10.1 During the term, the Customer may retrieve Customer Personal Data using available Service functionality and API access.
10.2 At the Customer’s choice, Staygood will return or delete Customer Personal Data after the Agreement ends. A request for return must be made within 30 days after termination. Staygood will complete return or deletion within 90 days after termination, except for data that EU or Member State law requires it to retain.
10.3 Residual copies in backups are protected from ordinary access and deleted through the applicable backup cycle. If a backup is restored, Staygood will reapply outstanding deletion requirements before resuming ordinary processing.
11. Information and audits
11.1 Staygood will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, its Annexes and relevant security documentation.
11.2 If that information is insufficient, the Customer or an independent auditor bound by confidentiality may audit Staygood’s compliance once in a 12-month period on at least 30 days’ notice, during business hours, without access to other customers’ data and subject to reasonable security requirements. These limits do not apply to an audit required by a supervisory authority or reasonably triggered by a personal data breach.
11.3 Each party bears its own audit costs. Staygood may charge reasonable fees for assistance exceeding two person-days, unless the audit identifies a material breach by Staygood.
12. International transfers
12.1 Current processing locations and transfer safeguards are stated in Annex B. Staygood will transfer Customer Personal Data outside the EEA only under a safeguard permitted by Chapter V GDPR, including an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, or the Standard Contractual Clauses in Commission Decision (EU) 2021/914, using the appropriate module and supplementary measures where required.
12.2 On request, Staygood will provide information reasonably necessary for the Customer to assess a transfer, including relevant portions of the applicable transfer terms.
13. Liability
Liability under this DPA is subject to the Agreement’s limitations and exclusions and is counted together with liability under the rest of the Agreement. This does not limit any rights or liability of data subjects or supervisory authorities under the GDPR.
14. Term and precedence
This DPA applies for as long as Staygood processes Customer Personal Data. It prevails over the rest of the Agreement on the processing of personal data. The DPA is governed by the same law and courts as the Agreement.
Annex A — Description of processing
Subject matter and duration. Provision of the Staygood receivables platform for the term of the Agreement, followed by the return and deletion period in Section 10.
Nature and purposes. Hosting, structuring and managing receivables; importing invoice and customer data; sending payment communications on the Customer’s behalf; receiving and classifying replies; operating payment and self-service features; payment reconciliation; document extraction; reporting, security and support.
Categories of data subjects.
- Debtors of the Customer, including sole proprietors
- Contact people at corporate debtors
- Guardians or other representatives recorded by the Customer
- The Customer’s Users
Categories of personal data.
- Identity, contact, language and customer-reference data
- Invoice, claim, line-item, payment and instalment information
- Communication content and metadata across enabled channels
- Service and payment-portal security data, including IP address, browser information and agreement evidence
- Structured call outcomes
- Voice-call recordings and transcripts, held for a limited period (recordings by the voice sub-processor only)
- Operational prioritisation and contact-handling indicators
- Public company-register information used for enrichment
Potentially sensitive data. The Service is not intended for unrestricted special-category data under Article 9 GDPR. Contact restrictions, guardianship or vulnerability indicators entered by the Customer may reveal such data. The Customer must use those fields only where it has an applicable Article 6 basis and Article 9 condition, and must limit the content to what is necessary. The Service does not store Danish CPR numbers.
Customer rights and obligations. The Customer determines the purposes of processing and is responsible for lawful instructions, the accuracy and necessity of Customer Personal Data, transparency to data subjects, and responding to their requests. The Customer may access, correct, export and give instructions concerning Customer Personal Data using the Service and the assistance mechanisms in this DPA.
Annex B — Sub-processors
The current list at staygood.ai/legal/subprocessors, including roles, locations and transfer safeguards, forms part of this DPA. Changes are governed by Section 6.
Annex C — Technical and organisational measures
Access and isolation
- Logical tenant isolation at both application and database layers
- Role-based access and least-privilege administrative access
- Separate controls and logging for internal administrative access
Encryption and credentials
- TLS for data in transit and infrastructure-level encryption at rest
- Passwords, session tokens and API keys stored using one-way cryptographic protection
- Integration credentials encrypted at the application layer
- Mutual TLS for the digital-post channel
Auditability and minimisation
- Tenant and administrative audit logs for security-relevant actions
- No storage of payment card details or Danish CPR numbers
- Structured voice-call outcomes retained in the Service; call transcripts and the assistant’s instructions retained in the Service, and call recordings and transcripts at the voice sub-processor, for 90 days for quality review and complaint handling, then deleted automatically, or earlier on Customer instruction or a data-subject erasure request
- No third-party advertising or behavioural-tracking SDKs in the platform
Environment and operational security
- Separation of production and non-production environments
- Masking required before production personal data is used in non-production
- Non-production outbound communications restricted by allow-lists or simulation
- Input validation, rate limiting, monitored background processing and controlled deployment procedures
- Managed backups and recovery procedures, subject to verified provider settings and retention periods
Staygood ApS · CVR 46639081 · Rytterkær 2, DK-4000 Roskilde, Denmark · legal@staygood.ai