STRAKS InvoiceSTRAKS Invoice
Effective August 7, 2026

Data Processing Addendum

Legal review required: This DPA is an operational draft that must be reviewed by qualified legal counsel before STRAKS claims full compliance with GDPR, Greenlandic, Danish or other applicable data-protection law.

This Data Processing Addendum (“DPA”) supplements the agreement for STRAKS Invoice where STRAKS SERVICES processes personal data on behalf of a customer. The customer is the controller or processor giving documented instructions; STRAKS is the processor or subprocessor for that processing.

1. Parties and operator

The service operator and processor is STRAKS SERVICES, CVR 39734915, Quassunnguaq 24 B-216, 3900 Nuuk, Greenland. The other party is the customer identified in the STRAKS Invoice account or order.

2. Subject matter and duration

The processing concerns provision, hosting, security, support, maintenance, communication and termination of STRAKS Invoice. Processing continues for the customer relationship and any documented transition, backup, security, claim or lawful-retention period.

3. Nature and purpose

  • Hosting, organizing, retrieving and displaying customer-entered business data.
  • Generating and preserving invoices, credit notes, reminders and associated audit history.
  • Authenticating users, delivering emails and files, providing support and preventing misuse.
  • Creating, updating, exporting or deleting data only where permitted by the service, documented instructions and applicable law.

4. Categories of data and data subjects

Data may include account identifiers, names, contact information, company details, customer and supplier information, service descriptions, invoice and credit-note information, payment status, communications, attachments, usage, audit and security metadata. Data subjects may include customer personnel, the customer’s customers and contacts, invoice recipients, suppliers, contractors and other persons whose information the customer enters.

5. Documented customer instructions

STRAKS processes customer data only on documented instructions in the agreement, application settings, supported workflows and written communications, unless law requires otherwise. STRAKS will inform the customer if an instruction appears unlawful where legally permitted.

6. Confidentiality and personnel

Access to customer data is limited to individually authorized STRAKS personnel who have a work-related need and are bound by confidentiality obligations. STRAKS does not currently provide personnel with interactive access to a customer’s live company workspace; support is provided through the customer’s own use of the service and documented written instructions.

7. Technical and organizational measures

  • Tenant-scoped authorization and row-level database controls.
  • Individual authenticated accounts and server-side authorization checks.
  • Encryption in transit and provider-managed infrastructure security controls.
  • Logging, backup, change control, dependency management and incident-response procedures appropriate to the service.

8. Subprocessors

STRAKS may use subprocessors for hosting, databases, authentication, storage, email delivery, monitoring, payments and related infrastructure. STRAKS will maintain appropriate contractual protections and provide a procedure for material subprocessor changes and objections where required.

9. Data-subject requests

Taking account of the nature of processing, STRAKS will reasonably assist the customer with access, correction, deletion, restriction, portability, objection and related requests. STRAKS will not independently decide the merits of requests concerning data controlled by the customer unless required by law.

10. Security incidents

STRAKS will investigate confirmed personal-data incidents and notify the customer without undue delay where required, providing information reasonably available about the nature, affected data, likely consequences and mitigation. Notification does not by itself constitute an admission of fault.

11. Deletion or return

After termination, STRAKS will delete or return customer personal data according to documented procedures and the customer’s lawful request, except where retention is required by law, necessary to preserve issued accounting records or required for limited security, backup or claim purposes. Retained data remains protected and is not used for unrelated purposes.

12. Audit and compliance information

STRAKS will provide information reasonably necessary to demonstrate the controls described in this DPA and may satisfy audit requests through documentation, independent reports, security summaries or a proportionate supervised review. Audits must protect other tenants, security information and subprocessors.

13. International processing

Where personal data is transferred internationally, STRAKS will use an applicable legal transfer mechanism and supplementary measures when required. The customer authorizes processing locations disclosed in the service and subprocessor information subject to those safeguards.

14. Contact procedure

Privacy, security and data-processing requests should be sent to jd@jdscs.com with the customer identity, tenant, request type, relevant dates and an authorized contact. Passwords, authentication codes and secret keys must not be included.

Terms of Service →Privacy Policy →Support →
Data Processing Addendum — STRAKS Invoice