Contents
Data Processing Agreement Version: 1 Last Updated: September 5, 2026
This Data Processing Agreement ("DPA") governs Assembley's processing of personal data on behalf of the Customer in connection with the Services.
This DPA forms part of, and is incorporated into, the Assembley Terms of Service ("Terms"). It is concluded between the parties on the Customer's acceptance of the Terms, without further action. No separate signature is required, and no Customer is without a DPA.
Where the Customer requires an individually negotiated data processing agreement, it may be agreed in an Order or separately signed agreement.
Capitalised terms not defined in this DPA have the meaning given to them in the Terms.
Data processor: Assembley ApS Vesterbrogade 13, 4. th, 1620 København V, Denmark CVR no.: [•] Contact: privacy@assembley.dk
Data controller: The Customer, as identified in the Customer's Account and in the applicable Order.
Each a "party" and together the "parties".
"Applicable Data means Regulation (EU) 2016/679 ("GDPR"), the Danish Data Protection Act Protection Law" (databeskyttelsesloven), and any other data protection legislation applicable to a party's processing under this DPA.
"Customer means personal data within Customer Data that Assembley processes on behalf Personal Data" of the Customer under this DPA.
"Data Subject" has the meaning given in the GDPR. The terms "controller", "processor", "processing", "personal data", "personal data breach" and "supervisory authority" likewise have the meanings given in the GDPR.
"Sub-processor" means a third party engaged by Assembley to process Customer Personal Data.
"Standard means the standard contractual clauses for the transfer of personal data to third Contractual countries adopted by the European Commission in Implementing Decision (EU) Clauses" or 2021/914. "SCCs"
The following terms have the meaning given in the Terms and are used here with that meaning: Assembly, Attestation, Authorised User, Calculation, Configured Parameter, Customer Data, Determination, Evidence Package, Outcome Declaration, Participant, Record, Services.
For Customer Personal Data, the Customer is the controller and Assembley is the processor.
Where the Customer is itself a processor acting on behalf of a third-party controller — for example, a law firm or administrator conducting an Assembly on behalf of a client organisation — Assembley acts as sub-processor. In that case the Customer warrants that it has the third-party controller's authorisation to engage Assembley on the terms of this DPA, and references to the Customer's instructions mean instructions consistent with those of the underlying controller.
This DPA does not apply to processing for which Assembley is an independent controller, including Account registration, billing, security and access logs, service administration, support correspondence and direct marketing to Assembley's own business contacts. That processing is described in the Assembley Privacy Policy.
The parties record that, as set out in section 3 of the Terms, the Services perform Recording, Calculation and Attestation, and do not make Determinations.
Assembley therefore does not determine the purposes of the processing, does not decide which individuals are entitled to participate or vote, does not decide the rules applied to Records, and does not evaluate the lawfulness or validity of any Assembly. Those decisions are the Customer's and constitute part of its instructions under section 4.
Assembley shall process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which Assembley is subject. In such a case, Assembley shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Customer's documented instructions consist of:
-
this DPA;
-
the Terms;
-
the applicable Order;
-
the Configured Parameters and other configuration made by the Customer or its Authorised Users through the Services; and
-
any further written instruction agreed by the parties.
The Customer acknowledges that each Configured Parameter is its own declaration of its own rules (section 5 of the Terms) and constitutes an instruction to Assembley to record, calculate and attest in accordance with it. Assembley does not verify, validate or evaluate a Configured Parameter.
Within these instructions, Assembley processes Customer Personal Data to:
-
(a) provide, maintain, secure and support the Services;
-
(b) create and maintain Records and Attestation material;
-
(c) perform Calculations in accordance with Configured Parameters;
-
(d) generate Evidence Packages and draft documents;
-
(e) dispatch invitations, credentials and Assembly-related messages;
-
(f) prevent and investigate fraud, abuse and security incidents;
-
(g) comply with legal obligations applicable to Assembley; and
-
(h) establish, exercise or defend legal claims.
The Customer instructs Assembley to generate aggregated statistics concerning use of the Services, on condition that such statistics are irreversibly anonymised, cannot be attributed to the Customer, any Assembly or any individual, and are not derived from voting choices.
Assembley shall not use Customer Personal Data to train generally available artificial intelligence models.
Assembley shall immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Assembley may suspend performance of the affected instruction until it is confirmed, withdrawn or amended.
Assembley shall not process Customer Personal Data for its own purposes, shall not sell Customer Personal Data, and shall not use it for advertising or profiling.
The Customer shall:
- (a) ensure that it has a valid legal basis for the processing and for providing Customer Personal
Data to Assembley;
- (b) provide Participants and other Data Subjects with the information required by Articles 13 and
14 GDPR, including information about the retention of Records under section 11 of this DPA;
-
(c) ensure that Customer Personal Data is accurate, relevant and limited to what is necessary;
-
(d) comply with section 17.4 of the Terms concerning data minimisation and prohibited
categories of data;
- (e) configure the Services, including access rights and ballot settings, in a manner appropriate
to the sensitivity of the processing; and
- (f) respond to Data Subject requests concerning Customer Personal Data as controller.
Except as provided in section 6.2, the Customer shall not submit to the Services special categories of personal data within the meaning of Article 9(1) GDPR, personal data relating to criminal convictions and offences, national identification numbers, or payment card data.
Where the Customer is an association, trade union, religious community, political party or similar body whose purpose is itself of a nature referred to in Article 9(1) GDPR, the fact of membership may constitute special category data.
The parties record that such membership data may be processed through the Services, and the Customer instructs Assembley to process it, on condition that:
-
the Customer relies on Article 9(2)(d) GDPR (processing carried out by a not-for-profit body with a political, philosophical, religious or trade-union aim, in the course of its legitimate activities, relating solely to members or former members, and without disclosure outside that body without consent) or another applicable exception under Article 9(2);
-
the Customer does not submit any further special category data beyond what follows from membership itself; and
-
the Customer applies appropriate access restrictions within the Services.
Assembley applies the security measures in Annex II to such data without distinction.
Assembley may, without liability to the Customer, decline to process, or require the removal of, data submitted in breach of this section, and shall inform the Customer.
This DPA takes effect on the Customer's acceptance of the Terms and continues for as long as Assembley processes Customer Personal Data on behalf of the Customer.
Sections 8, 11, 13, 17 and 18 survive termination for as long as Assembley holds Customer Personal Data or is subject to obligations relating to it.
Assembley shall ensure that persons authorised to process Customer Personal Data are subject to an appropriate obligation of confidentiality, whether contractual or statutory, and that the obligation survives the end of their engagement.
Access to Customer Personal Data is limited to personnel who require it to perform Assembley's obligations, and is subject to the access controls described in Annex II.
Assembley shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.
The measures in force are set out in Annex II.
Assembley may update the measures in Annex II to reflect technical developments, provided that the level of protection is not materially reduced. Material changes are notified in accordance with section 20.
The Customer is responsible for assessing whether the measures in Annex II are appropriate for its own processing, and for the security of its own systems, devices, Accounts and credentials.
Assembley describes the measures it applies. Assembley does not represent that Customer Personal Data is secure against all forms of attack, unauthorised access or compromise.
The Customer gives Assembley general written authorisation to engage Sub-processors, subject to this section.
The Sub-processors engaged as at the date of this DPA are listed in Annex III. The current list is maintained at assembley.dk/subprocessors.
Assembley shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA, and shall remain fully liable to the Customer for the performance of that Sub-processor's obligations.
Assembley shall give the Customer at least 30 days' notice before adding or replacing a Sub- processor. Notice is given by email to the Customer's registered contact address and by updating the list referred to in section 10.1. The Customer may subscribe to notifications at the same address.
The Customer may object to a change on reasonable grounds relating to data protection by giving written notice within the notice period. The parties shall discuss the objection in good faith. If no reasonable solution is found, the Customer may terminate the affected Services with effect from the date the change takes effect, and receive a pro-rata refund of prepaid fees for the unused portion of the Subscription Term.
Where a Sub-processor must be replaced urgently for security, legal or continuity reasons, Assembley may do so with shorter notice and shall inform the Customer without undue delay. The Customer's objection right under section 10.3 applies from the date of that notice.
Unless otherwise agreed in an Order, or required by Applicable Data Protection Law or other legislation applicable to a party:
Category Retention period
Deleted or anonymised within 90 days after the end of Customer Personal Data other than the Subscription Term or closure of the Account, Records whichever is earlier Records and Attestation material for a 5 years from the date the Assembly ended, then deleted completed Assembly or reduced to non-personal form 90 days, unless longer retention is necessary for security, Email dispatch and delivery records troubleshooting or legal claims 90 days; logs relating to an identified security incident Technical and authentication logs may be retained for up to 12 months Backups Rolling maximum of 35 days, then overwritten
At the Customer's choice, Assembley shall delete or return Customer Personal Data at the end of the provision of the Services, and delete existing copies, unless Union or Member State law requires storage of the personal data.
The Customer may export Customer Data, Records and available Evidence Packages using the export functionality included in its plan, before termination takes effect and, where practicable, for 30 days afterwards. If the Customer has not made a choice within that period, Assembley proceeds to deletion in accordance with section 11.1.
Certain Records are designed to be append-only and tamper-evident. Modification or deletion of such a Record is detectable and renders the associated Attestation material inconsistent.
The Customer instructs Assembley to maintain Records in append-only form for the period stated in section 11.1. The parties record that this constitutes a documented limitation on erasure, applied for the purpose of establishing, exercising or defending legal claims within the meaning of Article 17(3)(e) GDPR.
Where a request for erasure concerns data within an append-only Record, Assembley will, on the Customer's instruction and to the extent technically possible:
-
delete or anonymise associated data held outside the append-only structure;
-
suppress display of the identifying data in the user interface; and
-
retain within the append-only structure only the minimum required to preserve the integrity of the Attestation material.
The Customer is responsible for informing Data Subjects of this limitation in the information it provides under Articles 13 and 14 GDPR.
Data deleted from active systems may persist in backups until the backup cycle expires. Such data is not restored to active use, and is deleted on expiry of the cycle.
Taking into account the nature of the processing, Assembley shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests for exercising Data Subject rights under Chapter III GDPR.
The Services provide functionality enabling the Customer to access, correct, export and delete Customer Personal Data. Where that functionality is sufficient to respond to a request, the Customer shall use it.
If Assembley receives a request directly from a Data Subject concerning Customer Personal Data, Assembley shall not respond to the substance of the request, shall inform the Data Subject that the request must be directed to the Customer, and shall forward or refer the request to the Customer without undue delay.
Assistance beyond the functionality included in the Customer's plan, and beyond what is reasonably necessary, may be charged at Assembley's applicable rates, notified in advance.
Assembley shall notify the Customer without undue delay and in any event within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data.
The notification shall include, to the extent known at the time and supplemented as further information becomes available:
- the nature of the breach, including where possible the categories and approximate number
of Data Subjects and records concerned;
-
the likely consequences;
-
the measures taken or proposed to address the breach and mitigate its effects; and
-
the contact point for further information.
Assembley shall assist the Customer in meeting its obligations under Articles 33 and 34 GDPR, and shall document breaches and the remedial action taken.
Notification of a breach does not constitute an admission of fault or liability.
Assembley shall not notify a supervisory authority or Data Subjects on the Customer's behalf unless required by law or expressly instructed by the Customer in writing.
Taking into account the nature of the processing and the information available to it, Assembley shall assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments and prior consultation.
Assembley makes available documentation describing the Services, the categories of data processed and the measures in Annex II, for use by the Customer in preparing a data protection impact assessment. Assistance beyond that documentation may be charged at Assembley's applicable rates, notified in advance.
Assembley shall make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Audit rights are exercised as follows:
-
Documentation first. Assembley shall respond to reasonable written information requests, and shall make available any certifications, audit reports or security documentation it holds. Where these answer the Customer's request, no on-site audit is required.
-
Frequency. On-site audits may be conducted no more than once in any 12-month period, except where required by a supervisory authority or following a personal data breach affecting the Customer.
-
Notice. At least 30 days' written notice, with scope agreed in advance.
-
Conduct. Audits take place during business hours, with minimal disruption, and subject to confidentiality obligations. The auditor must not be a competitor of Assembley.
-
Cost. The Customer bears its own costs and Assembley's reasonable costs of assisting, except where the audit reveals material non-compliance by Assembley.
-
Limits. Audit rights do not extend to source code, security credentials, other customers' data, or information the disclosure of which would compromise the security of the Services or Assembley's obligations to third parties.
Customer Personal Data is processed within the European Economic Area ("EEA"), except as stated in Annex III.
Where processing of Customer Personal Data outside the EEA is necessary — including access by support personnel or corporate entities of a Sub-processor established outside the EEA — Assembley shall ensure that a valid transfer mechanism under Chapter V GDPR is in place, being an adequacy decision, the Standard Contractual Clauses with any necessary supplementary measures, or another legally recognised mechanism.
Where a transfer requires them, the Standard Contractual Clauses are incorporated into this DPA and apply as follows:
- (a) Module Three (processor to processor) where Assembley transfers Customer Personal
Data to a Sub-processor outside the EEA;
-
(b) Module Four (processor to controller) where the Customer is established outside the EEA;
-
(c) Clause 7 (docking clause) applies;
-
(d) Clause 9, Option 2 (general written authorisation) applies, with the notice period in section
10.3;
-
(e) Clause 11(a) — the optional independent dispute resolution provision does not apply;
-
(f) Clause 17 — the Clauses are governed by Danish law;
-
(g) Clause 18(b) — disputes are resolved before the Danish courts;
-
(h) Annex I, Annex II and Annex III of this DPA populate the corresponding annexes of the
Clauses. Where the UK GDPR applies to a transfer, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with Assembley as exporter and the relevant Sub-processor as importer.
In the event of conflict between the Standard Contractual Clauses and any other provision of this DPA, the Terms or an Order, the Standard Contractual Clauses prevail in respect of the transfer to which they apply.
Each party shall maintain records of processing activities as required by Article 30 GDPR.
Assembley shall make its records relating to processing on behalf of the Customer available to the Customer or to a supervisory authority on request, to the extent required by Article 30(4) GDPR.
Liability under this DPA is subject to section 44 of the Terms, including the limitation of liability in section 44.2 and the data protection provisions in section 44.4.
For the avoidance of doubt:
- nothing in this DPA affects a Data Subject's rights under Article 82 GDPR against either
party;
- each party bears administrative fines imposed on it under Article 83 GDPR, except to the
extent the fine results from the other party's breach of this DPA, the Terms or Applicable Data Protection Law, in which case recourse is subject to section 44.2 of the Terms;
- a party that has paid full compensation under Article 82(4) GDPR may claim back from the
other party that part of the compensation corresponding to that party's responsibility, subject to section 44.2 of the Terms.
In the event of conflict, the following order applies:
-
mandatory applicable law;
-
the Standard Contractual Clauses, in respect of transfers to which they apply;
-
this DPA;
-
a separately signed agreement between the parties;
-
the applicable Order;
-
the Terms.
In matters of data protection, this DPA prevails over the Terms.
Assembley may update this DPA where necessary to reflect changes in Applicable Data Protection Law, guidance from supervisory authorities, changes to the Services, or changes to Sub-processors or security measures.
Material changes are notified to the Customer's registered contact address at least 30 days before they take effect. Where a material change adversely affects the Customer, the Customer may object in accordance with the procedure in section 10.3.
Changes required by law take effect on the date required by that law.
Data protection enquiries under this DPA: privacy@assembley.dk
Security incidents: security@assembley.dk
Assembley has assessed that it is not required to appoint a data protection officer under Article 37 GDPR. The contact point for data protection matters is the address above.
This DPA is governed by Danish law and is subject to the dispute resolution and jurisdiction provisions in section 61 of the Terms, save as provided in section 16.3 in respect of the Standard Contractual Clauses.
Annex I — Description of the processing A. List of parties
Data exporter / controller: the Customer, as identified in the Customer's Account and the applicable Order. Contact details are those registered by the Customer. Role: controller (or, where section 3.1 applies, processor).
Data importer / processor: Assembley ApS, Vesterbrogade 13, 4. th, 1620 København V, Denmark, CVR no. [•]. Contact: privacy@assembley.dk. Role: processor.
B. Description of the processing
Subject matter: Provision of the Assembley platform for recording, calculating and attesting governance processes.
Duration: For the duration of the Subscription Term, plus the retention periods in section 11.1.
Nature of the processing: Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, restriction, erasure and destruction, by automated means.
Purpose of the processing: To provide the Services in accordance with the Customer's instructions, comprising Recording, Calculation and Attestation as described in section 3 of the Terms; dispatch of Assembly-related communications; generation of Evidence Packages and draft documents; security and abuse prevention; and support.
Categories of Data Subjects:
-
Participants, including shareholders, members and voters
-
Proxy holders and persons granting proxies
-
Candidates in elections
-
Chairs and other persons recording Outcome Declarations
-
Authorised Users and administrators of the Customer
-
Persons included in a participant register uploaded by the Customer
Categories of personal data:
Category Examples
Identification and contact Name, email address
Membership, shareholder status, eligibility to vote, presence Participation status registration, proxy relationships, candidate status
Voting entitlement Voting weight, share class, number of votes
Agenda item, option selected, weight allocated, split allocations, time of Voting data submission, Assembly and participant identifiers
Category Examples
Configuration changes, acknowledgements of observations under section 7.2 of the Terms (identity and time), Outcome Declarations Governance actions (identity of the declaring individual, time, and the Calculation and Configured Parameters presented)
Access credential references, session identifiers, authentication Access and security timestamps, IP address, browser and device characteristics, failed access attempts, security events
Attestation Hashes, chain references, Merkle roots, timestamps
Message content dispatched through the Services, dispatch and Communications delivery status
Content supplied by the Agenda text, candidate descriptions, meeting materials and other Customer content uploaded by the Customer
Special categories of personal data: Not processed, except membership data under section 6.2 of this DPA.
Frequency of processing: Continuous for the duration of the Subscription Term.
Retention: As set out in section 11.1 of this DPA.
Transfers to Sub-processors: Subject matter, nature and duration as set out in Annex III.
C. Competent supervisory authority
Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — as the supervisory authority of Assembley's place of establishment. Where the Customer is established in another EEA state, the supervisory authority of that state is competent in respect of the Customer.
Annex II — Technical and organisational measures The following measures are in force as at the date of this DPA. Assembley may update them provided the level of protection is not materially reduced.
- Encryption
-
Encryption in transit using TLS for all connections to the Services
-
Encryption at rest for the production database and backups
-
Passwords, where used, stored only as salted hashes; never in plaintext
- Access control — data
-
Row-level security policies enforced at database level, isolating each organisation's data
-
Role-based permissions within the Services, configured by the Customer
-
Server-side sessions using signed tokens in httpOnly cookies
-
Single-use, time-limited access links for Participants
-
Rate limiting on authentication endpoints
- Access control — systems
-
Access to production systems restricted to authorised personnel who require it
-
Administrative access uses separate credentials and is logged
-
Access reviewed on change of role and on termination of engagement
- Integrity
-
Vote Records protected against modification by database-level constraints and triggers
-
Vote submission and the corresponding audit entry written in a single atomic transaction
-
Hash-chained event store with per-agenda-item Merkle roots, recomputed on submission
-
Frozen snapshots of Configured Parameters at the point an Assembly opens
-
Evidence Packages permitting independent recomputation of the chain
- Logging and monitoring
-
Logging of authentication events, administrative actions and governance events
-
Logging of access to Records and generation of Evidence Packages
-
Monitoring for anomalous and potentially abusive activity
- Availability and resilience
-
Managed database infrastructure with automated backups
-
Rolling backup retention as set out in section 11.1
-
Infrastructure hosted with providers offering redundancy within the region
- Secure development
-
Version-controlled source code with reviewed changes
-
Separation of development and production environments
-
Production credentials not present in development environments or client-side bundles
-
Dependency and vulnerability monitoring
- Data minimisation
-
The Services are designed to operate on name, email address and voting entitlement
-
Prohibited categories of data as set out in section 17.4 of the Terms and section 6 of this
DPA
- Retention limits applied automatically in accordance with section 11.1
- Organisational measures
-
Confidentiality obligations for all personnel with access to Customer Personal Data
-
Documented incident response procedure, including the notification timeline in section 13
-
Sub-processor assessment before engagement
-
Responsible disclosure process published at assembley.dk/security
- Statement of scope
Assembley holds no third-party security certification as at the date of this DPA. The measures above are described as implemented; they are not certified by an external auditor, and Assembley makes no representation that they render Customer Personal Data secure against all forms of attack or compromise.
Annex III — Sub-processors The current list is maintained at assembley.dk/subprocessors. Changes are notified in accordance with section 10.3.
Categories of Transfer Sub-processor Purpose Location of processing data mechanism
Production data hosted Supabase in the EU (AWS eu- Database, (Supabase Inc. / central-1, Frankfurt). SCCs where authentication All Customer Supabase Pte. Support and applicable and backend Personal Data Ltd.) [entity to administrative access [confirm] infrastructure confirm] may occur from outside the EEA. [confirm]
Amazon Web Services (as N/A — Underlying cloud All Customer eu-central-1, Frankfurt, infrastructure processing infrastructure Personal Data Germany provider to within the EEA Supabase)
Data processed [confirm: region Application transiently in Vercel (Vercel configuration, edge hosting and requests and [confirm] Inc.) network locations, log delivery responses; access storage location] and technical logs
Transactional Recipient name email dispatch — and email address; Resend [confirm: processing and invitations, message content; [confirm] (Resend, Inc.) log storage location] credentials, dispatch and notices delivery status
End of Data Processing Agreement
Data Processing Agreement · version 1 · in effect from 7 September 2026