Legal

Data Processing Agreement.

Version 1.3 · Last updated 5 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Staygood ApS, CVR no. 46639081, Rytterkær 2, DK-4000 Roskilde, Denmark (“Staygood”) and the customer identified in an order for the Staygood service (the “Customer”). It applies automatically when Staygood processes personal data on the Customer’s behalf.

1. Definitions

“Controller”, “processor”, “processing”, “personal data”, “data subject” and “personal data breach” have the meanings given in Regulation (EU) 2016/679 (the “GDPR”). “Customer Personal Data” means personal data in Customer Data that Staygood processes on the Customer’s behalf. Other capitalised terms have the meanings given in the Agreement.

2. Roles and scope

2.1 The Customer is the controller and Staygood is the processor of Customer Personal Data. If the Customer is itself a processor, Staygood acts as its sub-processor and the Customer confirms that it may appoint Staygood on these terms.

2.2 Staygood acts as an independent controller for its own account, billing and support records, security and abuse-prevention records, and aggregated information that identifies no person or Customer. Staygood’s Privacy Policy governs that processing.

3. Instructions

3.1 Staygood will process Customer Personal Data only on documented instructions from the Customer, including for transfers outside the EEA, unless EU or Member State law requires otherwise. Where legally permitted, Staygood will inform the Customer before carrying out such legally required processing.

3.2 The Customer’s documented instructions are the Agreement, its configuration and use of the Service, actions by its Users, and any further written instructions agreed by the parties.

3.3 Staygood will inform the Customer if it believes an instruction infringes applicable data protection law. Staygood may suspend the affected processing until the instruction is confirmed, amended or withdrawn and is not required to perform a general legal review of the Customer’s instructions.

4. Confidentiality

Staygood will ensure that people authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and have access only as needed for their role.

5. Security

Staygood will maintain the technical and organisational measures in Annex C, taking account of the matters listed in Article 32 GDPR. Staygood may update those measures without materially reducing the overall level of protection.

6. Sub-processors

6.1 The Customer gives Staygood general written authorisation to use sub-processors. The current list at staygood.ai/legal/subprocessors is Annex B to this DPA.

6.2 Staygood will give at least 30 days’ notice before a new or replacement sub-processor starts processing Customer Personal Data, by updating the list and notifying the Customer’s designated contact by email or in the Service.

6.3 The Customer may object during the notice period on reasonable data-protection grounds. The parties will try in good faith to resolve the issue. If they cannot, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.

6.4 Staygood will impose substantially equivalent data-protection obligations on its sub-processors and remains responsible to the Customer for their performance.

7. Data subject requests

7.1 If Staygood receives a request concerning Customer Personal Data, it will forward it to the Customer without undue delay and will not respond on the merits unless instructed or legally required.

7.2 Taking account of the nature of the processing, Staygood will assist the Customer with its obligations under Chapter III GDPR through available Service functionality and reasonable further assistance where needed.

8. Personal data breaches

8.1 Staygood will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and, where reasonably possible, within 48 hours after becoming aware of it.

8.2 The notice will include available information about the nature and likely consequences of the breach, affected data and data subjects, and measures taken or proposed. Information may be provided in phases.

8.3 Staygood will provide reasonable assistance with the Customer’s obligations under Articles 33 and 34 GDPR. A notification is not an admission of fault or liability.

9. Compliance assistance

Taking account of the nature of the processing and information available to it, Staygood will provide reasonable assistance with the Customer’s obligations under Articles 32–36 GDPR, including data-protection impact assessments and prior consultations relating to the Service. Staygood may charge reasonable fees for assistance under Sections 7 and 9 that goes materially beyond the Service’s functionality and Staygood’s existing documentation.

10. Return and deletion

10.1 During the term, the Customer may retrieve Customer Personal Data using available Service functionality and API access.

10.2 At the Customer’s choice, Staygood will return or delete Customer Personal Data after the Agreement ends. A request for return must be made within 30 days after termination. Staygood will complete return or deletion within 90 days after termination, except for data that EU or Member State law requires it to retain.

10.3 Residual copies in backups are protected from ordinary access and deleted through the applicable backup cycle. If a backup is restored, Staygood will reapply outstanding deletion requirements before resuming ordinary processing.

11. Information and audits

11.1 Staygood will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, its Annexes and relevant security documentation.

11.2 If that information is insufficient, the Customer or an independent auditor bound by confidentiality may audit Staygood’s compliance once in a 12-month period on at least 30 days’ notice, during business hours, without access to other customers’ data and subject to reasonable security requirements. These limits do not apply to an audit required by a supervisory authority or reasonably triggered by a personal data breach.

11.3 Each party bears its own audit costs. Staygood may charge reasonable fees for assistance exceeding two person-days, unless the audit identifies a material breach by Staygood.

12. International transfers

12.1 Current processing locations and transfer safeguards are stated in Annex B. Staygood will transfer Customer Personal Data outside the EEA only under a safeguard permitted by Chapter V GDPR, including an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, or the Standard Contractual Clauses in Commission Decision (EU) 2021/914, using the appropriate module and supplementary measures where required.

12.2 On request, Staygood will provide information reasonably necessary for the Customer to assess a transfer, including relevant portions of the applicable transfer terms.

13. Liability

Liability under this DPA is subject to the Agreement’s limitations and exclusions and is counted together with liability under the rest of the Agreement. This does not limit any rights or liability of data subjects or supervisory authorities under the GDPR.

14. Term and precedence

This DPA applies for as long as Staygood processes Customer Personal Data. It prevails over the rest of the Agreement on the processing of personal data. The DPA is governed by the same law and courts as the Agreement.


Annex A — Description of processing

Subject matter and duration. Provision of the Staygood receivables platform for the term of the Agreement, followed by the return and deletion period in Section 10.

Nature and purposes. Hosting, structuring and managing receivables; importing invoice and customer data; sending payment communications on the Customer’s behalf; receiving and classifying replies; operating payment and self-service features; payment reconciliation; document extraction; reporting, security and support.

Categories of data subjects.

Categories of personal data.

Potentially sensitive data. The Service is not intended for unrestricted special-category data under Article 9 GDPR. Contact restrictions, guardianship or vulnerability indicators entered by the Customer may reveal such data. The Customer must use those fields only where it has an applicable Article 6 basis and Article 9 condition, and must limit the content to what is necessary. The Service does not store Danish CPR numbers.

Customer rights and obligations. The Customer determines the purposes of processing and is responsible for lawful instructions, the accuracy and necessity of Customer Personal Data, transparency to data subjects, and responding to their requests. The Customer may access, correct, export and give instructions concerning Customer Personal Data using the Service and the assistance mechanisms in this DPA.

Annex B — Sub-processors

The current list at staygood.ai/legal/subprocessors, including roles, locations and transfer safeguards, forms part of this DPA. Changes are governed by Section 6.

Annex C — Technical and organisational measures

Access and isolation

Encryption and credentials

Auditability and minimisation

Environment and operational security


Staygood ApS · CVR 46639081 · Rytterkær 2, DK-4000 Roskilde, Denmark · legal@staygood.ai