Last updated
Data Processing Agreement
The Article 28 GDPR terms under which we process personal data on your behalf. It applies to every customer on every plan, takes effect when you accept the Terms of Service, and needs no signature — but we will sign a copy if your process requires one.
1. Parties and role
This agreement is between you — the organization holding a StandardOS subscription, acting as controller — and RMS Systems (CVR 34282668, VAT DK34282668), Nyvangsvej 29, 1. tv., 5000 Odense C, Denmark, acting as processor. Privacy questions and any request under this agreement: privacy@getstandardos.com.
It forms part of the Terms of Service and applies automatically. There is no separate negotiation, no enterprise tier that unlocks it, and no sales call. Where it conflicts with the Terms on the processing of personal data, this agreement wins.
For our own account data — the name and email of the people who sign in, and billing records — we are the controller, not your processor. That processing is described in the Privacy Policy and is outside this agreement.
2. Subject matter, duration, nature and purpose
We process personal data only to provide the StandardOS service to you: storing and making available the management-system records your organization creates, rendering them into documents and exports, sending the notifications your members have asked for, and keeping the tamper-evident audit trail that records who changed what.
Processing lasts for as long as your subscription runs, plus the retention window in section 9.
3. Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Your members — the people you invite into your workspace | Name, email address, role, sign-in metadata, and the record of every change they make inside your management system |
| People named inside your records | Whatever you choose to write: risk and control owners, training and competence records, audit findings, nonconformity and corrective-action entries, and the contents of evidence you upload |
| Your suppliers' and interested parties' contacts | Names and contact details you record in the supplier and interested-party registers |
StandardOS is not designed for special categories of personal data under Article 9, and nothing in the product asks for them. You control what goes into free-text fields and uploaded evidence; please do not put special-category data there.
4. Our instructions (Art. 28(3)(a))
We process personal data only on your documented instructions. Your use of the service, together with this agreement and the Terms, is that instruction; further instructions can be sent to privacy@getstandardos.com.
We do not sell personal data, do not use it to train AI models, and do not use it for our own purposes. Where the product offers AI-assisted drafting, the text you send is processed to return that draft and is not retained for training by us or by our model provider. If EU or Danish law ever requires us to process beyond your instructions, we will tell you before doing so unless that law forbids it.
5. Confidentiality (Art. 28(3)(b))
Everyone we authorise to process personal data is bound by a duty of confidentiality and holds least-privilege access. Every operator action on a customer organization is written to an append-only ledger we cannot edit or delete, and each customer can read that ledger for their own organization on their Audit trail page.
6. Security (Art. 28(3)(c), Art. 32)
The measures are described in full and kept current on our Trust page, which is part of this agreement by reference. In summary:
- Encryption in transit (TLS 1.2+, HSTS) and at rest.
- Tenant isolation enforced by row-level security in the database itself rather than in application code, and asserted against a live Postgres on every change.
- A tamper-evident, hash-chained audit trail. Each day's chain head is emailed to your owners and admins and the daily roots are published openly, so a later rewrite is detectable by you rather than only by us.
- Managed daily backups held in the EU, with alerting if a scheduled backup does not appear, plus a weekly encrypted copy held outside the database provider.
- Diagnostics stripped of email addresses, IP addresses and record identifiers before they leave our servers.
- We run our own ISO 27001 management system inside StandardOS.
7. Subprocessors (Art. 28(2), 28(3)(d))
You give general authorisation for the subprocessors below. This is the same list published on our Trust page and in the Privacy Policy — one source rendered in three places, last changed 2026-07-28.
| Subprocessor | Role | Location of processing |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland) |
| Vercel | Application hosting & delivery; cookieless traffic analytics (no cookies, no cross-site identifiers) | EU serving; global CDN for static assets |
| Sentry | Error monitoring — diagnostics only; email addresses, IP addresses and record identifiers are stripped before events leave our servers | EU region (Frankfurt) |
| Paddle | Merchant of record — checkout, payment, VAT & invoicing (card data never touches our servers) | UK — EU adequacy decision |
| Resend | Transactional email | EU region |
Each is bound by written terms no less protective than these. We announce additions or replacements on the Trust page with prior notice; if you object on reasonable data protection grounds you may terminate the affected service and receive a pro-rata refund of the unused period.
8. International transfers (Chapter V)
Customer records are stored in the EU. We choose EU regions wherever a service touches them. Where a subprocessor processes data outside the EU/EEA, the transfer rests on an adequacy decision — Paddle operates from the UK, which holds one — or on Standard Contractual Clauses, supplemented where required.
9. Deletion and return (Art. 28(3)(g))
You can export everything at any time, in open formats, in one click — during the trial, while subscribed, and after cancellation. The export carries the hashes and the content they cover, so it can be verified without us.
After a subscription ends your workspace stays readable and exportable for 90 days. We email your owners and admins before the window closes. At the end of it we delete the organization and everything belonging to it — records, uploaded evidence, and the audit chain itself — and keep a record that the deletion happened, its date, and how much was removed. Deletion is permanent and covers backups as they age out of their rotation.
Invoices and accounting records are kept for 5 years as Danish law requires. That retention is ours as controller and is not affected by this section.
10. Helping you meet your own obligations (Art. 28(3)(e), (f))
Most data subject requests you can answer yourself: the product lets you read, correct, export and delete the records you hold. Where you need us, we will assist — write to privacy@getstandardos.com and we will respond within 5 working days. If a data subject contacts us directly about your records, we will not answer them on your behalf; we will forward the request to you.
We will help with your data protection impact assessments and prior consultations to the extent the information is ours to give.
11. Personal data breaches (Art. 33(2))
We will notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data, by email to your owners and admins. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, and what we are doing about it — and we will keep sending updates as we learn more rather than waiting until we know everything.
12. Audits and information (Art. 28(3)(h))
We make available everything needed to demonstrate compliance with Article 28. In practice most of it is already published — the Trust page, the subprocessor list, the verification specification and the script that checks your chain without us. Ask and we will complete a reasonable security questionnaire.
You may audit our compliance, or appoint an independent auditor to do so, once per year and on 30 days' written notice — or sooner following a breach affecting your data. Audits happen during business hours, must not compromise other customers' confidentiality, and each party bears its own costs.
13. Liability, law and jurisdiction
Liability under this agreement is governed by the limitations in the Terms of Service. This agreement is governed by Danish law, and the courts of Denmark have jurisdiction — without prejudice to any mandatory right you or a data subject has to bring proceedings elsewhere under the GDPR.
14. Changes
We will give at least 30 days' notice of a material change to this agreement, by email to your owners and admins. The date at the top of this page is authoritative.