Data Processing Agreement
Last updated: March 23, 2026
1. Parties
Customer (Data Controller) and New Strategy Model ApS (Data Processor).
2. Scope
This DPA governs processing of personal data in the Service.
3. Processing Details
- Subject: SaaS platform delivery
- Duration: Agreement period
- Nature: Storage and processing of customer data
4. Processor Obligations
We will:
- Process data only on instructions
- Ensure confidentiality
- Apply appropriate security measures
5. Security Measures
We implement:
- Row-level security (tenant isolation)
- Email-based authentication
- EU-based hosting
6. Sub-processors
We use:
- Supabase (database) - https://supabase.com/legal/dpa
- Vercel (hosting) - https://vercel.com/legal/dpa
- Brevo (email) - https://www.brevo.com/legal/
7. Data Subject Rights
We assist the Customer in responding to requests.
8. Data Breach
We notify Customers without undue delay in case of breach.
9. Data Deletion
Upon termination:
- Data is retained for 120 days
- Data is then permanently deleted
10. Governing Law
This DPA is governed by Danish law.