Data Processing Agreement
Last updated: 17 September 2026
Items in [brackets] are being finalised and will be replaced before this page is published.
Between the customer (the "Controller") and BestSecurity ApS, CVR 38821148, Denmark (the "Processor"), under GDPR art. 28. This agreement is part of the PastWP Terms of Service and applies from the date the Controller orders a PastWP package.
1. Subject matter and duration
The Processor hosts, maintains and supports the Controller's website(s) and related services under the ordered package. Processing lasts as long as the subscription runs, plus the deletion period in section 9.
2. Nature and purpose
Hosting, backup, maintenance, security monitoring, updates, analytics and tracking set-up, form and booking handling, and support, all to run the Controller's website.
3. Categories of data subjects and personal data
Data subjects: visitors to the Controller's website, the Controller's customers and leads, the Controller's staff who use the site or its admin. Personal data: names, e-mail addresses, phone numbers, addresses, messages sent through forms, booking details, IP addresses, browser and device data, cookie and tracking identifiers, and anything else the Controller chooses to collect through the site. No special categories (art. 9) unless agreed in writing.
4. Instructions
The Processor processes personal data only on documented instructions from the Controller. These terms, the package description and written requests through the support channel are the instructions. The Processor tells the Controller if an instruction in its view breaks the GDPR.
5. Confidentiality
Persons authorised by the Processor to process personal data are bound by confidentiality.
6. Security (art. 32)
The Processor keeps appropriate technical and organisational measures, including: EU hosting, encryption in transit (TLS) and at rest, access control with multi-factor authentication for administrative access, least-privilege access, logging, patch management, regular automated backups with tested restore, and separation of customer environments. The Processor may update the measures as long as the security level is not reduced.
7. Sub-processors
The Controller gives general authorisation to the sub-processors listed below. The Processor informs the Controller by e-mail at least 30 days before adding or replacing a sub-processor; the Controller may object on reasonable grounds within that period, and if no solution is found may terminate the affected service.
Current sub-processors: [hosting provider, country] · [e-mail/transactional provider, country] · [backup provider, country] · [analytics provider, country].
8. Transfers outside the EU/EEA
Personal data is processed within the EU/EEA. Where a sub-processor is outside the EU/EEA, transfer is based on an EU adequacy decision, the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses, as noted in the sub-processor list.
9. Deletion and return
At the end of the service the Processor returns the Controller's data (site content and exports) and deletes remaining copies within 30 days, unless EU or Danish law requires storage. Backups are overwritten within the normal backup cycle of [30] days.
10. Assistance
The Processor assists the Controller with data subject requests, security, breach notification, data protection impact assessments and consultation with the supervisory authority, to the extent possible given the nature of processing. Assistance beyond what the package includes is invoiced at the Processor's hourly rate.
11. Personal data breaches
The Processor notifies the Controller without undue delay and no later than 36 hours after becoming aware of a personal data breach, with the information the Controller needs for its own notification under art. 33.
12. Audit
The Processor makes available the information necessary to demonstrate compliance with art. 28 and allows for and contributes to audits, including inspections, by the Controller or an auditor mandated by the Controller, with reasonable notice and at most once a year unless a breach has occurred. The Controller bears the cost of audits beyond written documentation.
13. Liability and law
Liability follows the Terms of Service. Danish law applies; disputes go to the courts of Aarhus, Denmark.