GDPR and Data Protection
Our obligations under the General Data Protection Regulation
As a business that handles documents and archives for other organizations, we take data protection very seriously. This page describes how we comply with the requirements of the EU General Data Protection Regulation (GDPR).
Our Role as Data Processor
When we provide archiving and document management services, we often act as a data processor on behalf of our customers. This means that we only process personal data in accordance with the customer's instructions and applicable legislation.
Data Processing Agreements
For all assignments where we handle documents containing personal data, we enter into a written data processing agreement. This agreement sets out:
- The purpose and duration of the processing
- The type of personal data being processed
- Categories of data subjects
- The customer's rights and obligations
- Our obligations as a data processor
Technical and Organizational Security Measures
We have implemented appropriate security measures to protect the personal data we process:
Physical Security
- Access control to premises where documents are stored
- Locked filing cabinets and security rooms
- Surveillance systems and alarms
Digital Security
- Encrypted data transfer and storage
- Regular backup
- Strong passwords and two-factor authentication
- Updated systems and antivirus software
Organizational Measures
- Employees bound by confidentiality
- Regular training in data protection
- Documented procedures for handling personal data
- Need-to-know principle for access to information
Sub-processors
We only use sub-processors with prior approval from the customer. All sub-processors are subject to the same data protection requirements as ourselves.
Security Breaches
In the event of a personal data breach, we have procedures in place to:
- Identify and contain the breach quickly
- Notify the data controller customer without undue delay
- Document the breach and the measures taken
- Assist the customer with any notification to the Danish Data Protection Agency (Datatilsynet)
Deletion and Return of Data
Upon termination of the collaboration, we delete or return all personal data at the customer's choice, unless legislation requires continued storage. Deletion is documented in writing.
Audit and Control
Customers have the right to audit our processing of personal data. We make the necessary documentation available and provide access to relevant systems and premises by agreement.
Contact Regarding Data Protection
If you have questions about our processing of personal data or wish to exercise your rights, you are welcome to contact us:
- E-mail: [email protected]
- Address: Strandvejen 142, 2900 Hellerup, Denmark