---
title: "Data processing agreement · Adea"
description: "Adea's data processing agreement, based on the Danish Data Protection Agency's standard terms."
url: https://adea.app/dpa
---

# The data processing agreement, signed in Adea.

An administrator accepts it in Settings, and you get a signed copy as a PDF with your company's details. If you want to change something in it, write to us and a person will answer.

[Log in](https://adea.app/login) [Write to us about the agreement](mailto:privacy@adea.app)

## How to accept it

1. 1

Sign in to Adea as an administrator.

2. 2

Open Settings, then Data processing agreement.

3. 3

Read it, add your name and title, and accept.

4. 4

Download the signed PDF for your files.

## The agreement

This is the text you accept. Fields in square brackets are filled in with your company's details in the signed copy.

Adea is provided by Marcus Wilstrup, Rua da Fonte 85 B, Capride, 2785-371 São Domingos de Rana, Portugal. VAT no. PT310292522.

Version 2.0 of 6 October 2026

Version 2.0 of 6 October 2026. This agreement is based on the Danish Data Protection Agency's standard contractual clauses under Article 28(3) of the GDPR, adapted to Adea.

## 1. The parties

**The controller:** [Customer name], company reg. no. [reg. no.], [address] (the "Customer").

**The processor:** Marcus Wilstrup, VAT no. PT310292522, Rua da Fonte 85 B, Capride, 2785-371 São Domingos de Rana, Portugal ("Adea").

The parties have entered into this agreement about Adea's processing of personal data on behalf of the Customer. It forms part of the Customer's agreement to use Adea, including Adea's terms of service, and applies for as long as Adea processes personal data for the Customer.

## 2. Purpose and background

Adea is a service that keeps a company informed about its own business. The Customer connects its databases, its code and the services it uses, such as a payment provider, a webshop or a spreadsheet. Adea then watches the Customer's numbers, notices when something changes, finds out why, answers the questions the Customer's staff ask, and keeps lists, dashboards and reports for them. Adea only reads from what the Customer connects. It never writes to the Customer's systems.

To do this, Adea processes personal data found in the Customer's data, code, files and questions, and personal data about the Customer's own users of Adea.

This agreement ensures that Adea complies with the General Data Protection Regulation (EU 2016/679) and the Danish Data Protection Act when processing personal data for the Customer. Appendix A describes the processing, appendix B the sub-processors and appendix C the Customer's instructions and the security measures.

## 3. The Customer's rights and obligations

The Customer is responsible for the processing complying with data protection law, including having a lawful basis for it and giving data subjects the information they are entitled to.

The Customer decides the purposes and means of the processing. In Adea, the Customer decides which sources Adea may read, which people may use Adea and what each of them may see, which tables and columns are hidden or masked, what Guardian holds for approval, and whether anything is shared outside the company.

The Customer warrants that it has the right to give Adea access to the code and data it connects. The Customer makes sure that Adea does not use special categories of personal data (Article 9), data on criminal offences (Article 10) or national identification numbers in answers, for example by hiding the tables and columns where they are found, unless the parties have agreed otherwise in writing.

## 4. Adea acts on instructions

Adea processes personal data only on documented instructions from the Customer. The instructions are set out in this agreement, appendix C and the choices the Customer and its users make in Adea, including choices made through an AI assistant or agent that a user has connected to Adea. Adea informs the Customer immediately if, in Adea's opinion, an instruction infringes data protection law.

If EU law or national law to which Adea is subject requires Adea to process the data otherwise, Adea informs the Customer beforehand, unless the law prohibits it.

## 5. Confidentiality

Adea gives access to the personal data only to people who need it to deliver the service and who have committed to confidentiality or are under a statutory duty of confidentiality. Access is removed when the need ends.

Adea's staff do not look at the Customer's data, questions or answers in the ordinary course of running the service. They do so only when an administrator of the Customer has given access for a specific case, for example a support request, for the time that case needs, or when it is needed to stop a security incident or to restore a deleted organisation at the Customer's request. Each access is recorded in the Customer's security log, which the Customer's administrators can read.

## 6. Security of processing

Adea implements the technical and organisational measures required by Article 32, appropriate to the risk to data subjects. The measures are described in appendix C. Adea assesses the risk on an ongoing basis and improves the measures when needed.

## 7. Sub-processors

With this agreement the Customer gives general authorisation for Adea to use the sub-processors listed in appendix B. Some of them are used only when the Customer or its users use the feature or connect the service that the sub-processor provides, as appendix B says.

Adea notifies the Customer at least 30 days before adding or replacing a sub-processor, by email to the Customer's administrators and on the sub-processors page at adea.app, where anyone can also sign up for the notices. The Customer may object within those 30 days. If the parties can't find a solution, the Customer may end the subscription before the change takes effect and get a refund of prepaid fees for the remaining period.

Adea imposes the same data protection obligations as in this agreement on each sub-processor and remains liable to the Customer for their compliance.

## 8. Transfers to third countries

Adea transfers personal data to countries outside the EU/EEA only on the Customer's instructions as set out in appendices B and C, and only with a valid transfer mechanism under Chapter V of the GDPR, such as the EU-US Data Privacy Framework or the EU Standard Contractual Clauses.

If Adea is or becomes established in a country outside the EU/EEA, for example because this agreement is assigned under clause 14, the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor), apply between the Customer as data exporter and Adea as data importer. They are incorporated into this agreement by reference, without the parties having to sign anything. For them:

- Annex I.A is completed with the parties' details in clause 1, Annex I.B with appendix A, Annex II with appendix C and Annex III with appendix B.
- The optional Clause 7 does not apply. Under Clause 9(a), Option 2 (general written authorisation) applies, with the notice period set out in clause 7.
- The competent supervisory authority under Clause 13 is the supervisory authority of the EU/EEA country where the Customer is established. If the Customer is not established in the EU/EEA, it is the authority designated by Clause 13.
- Under Clause 17 the clauses are governed by Danish law, and under Clause 18 disputes are resolved by the Danish courts, with the City Court of Copenhagen (Københavns Byret) as the court of first instance. Where this cannot be agreed, the clauses' own defaults apply.

If Adea uses a sub-processor outside the EU/EEA, Adea ensures that the transfer has a valid basis. If Adea itself is established in the EU/EEA, this is done for example by entering into Module Three (processor to processor) of the Standard Contractual Clauses with the sub-processor. If Adea is established outside the EU/EEA, Adea imposes on the sub-processor the same obligations Adea has under Module Two.

If the Standard Contractual Clauses conflict with the rest of this agreement, the Standard Contractual Clauses prevail.

## 9. Assistance to the Customer

Adea helps the Customer respond to data subjects' rights (access, rectification, erasure, restriction, portability and objection) as far as possible, taking the nature of the processing into account. Most requests the Customer can handle itself in Adea: an administrator can remove a person, delete answers, lists and dashboards, and export everything Adea holds for the Customer. Personal data that Adea reads from the Customer's own systems is corrected or erased in those systems, and Adea follows the change the next time it reads them.

Adea also helps the Customer with security under Article 32, breach notification under Articles 33 and 34, impact assessments under Article 35 and prior consultation under Article 36.

## 10. Personal data breaches

Adea notifies the Customer without undue delay and no later than 48 hours after becoming aware of a personal data breach. The notice describes, as far as possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.

## 11. Deletion and return

Before the end, an administrator can export everything Adea holds for the Customer in Adea: questions and answers, dashboards, lists, insights, the team and the security log. The Customer's own data stays in the Customer's own systems.

When an administrator deletes the Customer's organisation in Adea, or the agreement to use Adea ends:

- At once, nobody can sign in, the subscription ends, all sessions, keys, AI assistant connections and connections to the Customer's systems are revoked, and scheduled work stops.
- For 30 days the data is kept unchanged and encrypted, so an administrator can restore the organisation with the link Adea mails them.
- On day 30, Adea deletes all of the Customer's data, including copies of the Customer's code and data, and destroys the Customer's encryption key. Without the key, the Customer's data can't be read, even in backups made before the deletion. The backups themselves are deleted with the normal rotation and no later than 35 days later.

Adea keeps only what it needs to meet the law and to keep its own books: invoices and payment records for as long as accounting law requires, and a short record that the Customer was a customer (company name, website domain, country, industry, plan and payment history, the dates of signup and deletion, and the reason given for leaving, if any). That record holds no names or email addresses of people and none of the Customer's data, questions or answers.

## 12. Audits and inspections

Adea makes available all information necessary to demonstrate compliance with this agreement. Adea allows for and contributes to audits and inspections by the Customer or an independent auditor appointed by the Customer, with reasonable notice and at most once a year, unless a breach or an authority gives cause for more.

## 13. Liability

The limitation of liability in Adea's terms of service also applies to this agreement. The amount cap is shared between the terms of service and this agreement, so it cannot be used twice.

The limitation applies only between the Customer and Adea. It does not change data subjects' rights under the GDPR, including the right to compensation under Article 82, and it does not apply where the Standard Contractual Clauses or mandatory law do not allow a limitation.

## 14. Assignment

Adea may assign this agreement together with the terms of service to a company that Adea or Adea's owner owns or controls, including a company established outside the EU/EEA. Adea notifies the Customer in writing at least 30 days before. The new company takes over all of Adea's rights and obligations under the agreement and becomes the processor in Adea's place. If the company is established outside the EU/EEA, clause 8 on the Standard Contractual Clauses applies from the assignment.

If the Customer does not want to continue with the new company, the Customer may end the subscription before the assignment takes effect and get a refund of prepaid fees for the remaining period.

## 15. Term

The agreement takes effect when the Customer accepts it in Adea and applies for as long as Adea processes personal data for the Customer. If data protection law changes, either party may require the agreement to be updated.

If this agreement conflicts with Adea's other terms, this agreement prevails as regards the processing of personal data. The agreement is governed by Danish law, and disputes are resolved under the rules on governing law and venue in the terms of service, unless clause 8 says otherwise.

## Appendix A: The processing

**Purpose:** to keep the Customer informed about its own business: to watch the Customer's numbers and notice changes, find out why they happened, answer the questions the Customer's users ask, keep the lists, dashboards, reports and presentations they make, share what they choose to share, and send the notifications, briefs and reports they asked for.

**Nature of the processing:**

- Read-only queries against the Customer's databases and data warehouses.
- Reading the Customer's code, its history and its changes.
- Fetching data from the services the Customer connects (for example a payment provider, a webshop, accounting, Google Sheets, Search Console or Google Ads), and reading files the Customer uploads or mails to Adea, into a separate store for the Customer at Adea.
- Storing questions, answers, the queries behind them, summarised results, insights, lists, dashboards and the measurements of the numbers Adea watches.
- Reading screenshots the Customer's users upload to rebuild a report.
- Turning a user's speech into text, and answers into speech, when the user uses their voice.
- Sending email, push notifications, text messages, phone calls and messages in Slack or Microsoft Teams, as the Customer and its users have chosen.
- Showing what a user shares with a public link to anyone who has the link.

**Types of personal data:**

- The data in the Customer's databases, code, connected services and files that ends up in an answer, a list or a watched number, typically names, contact details, customer, member and order numbers, bookings, subscriptions and transactions. The Customer can hide and mask tables and columns.
- Names and email addresses in the code's history (the authors of changes).
- About the Customer's users of Adea: name, email address, role, language, the location or team they may see, phone number if they add one, how they sign in (for passkeys only the public key), the time and network address of sign-ins, and what they ask and do in Adea.
- Voice recordings and screenshots, only for as long as it takes to turn them into text or a dashboard.

**Categories of data subjects:** the Customer's customers, members, partners and staff who appear in the Customer's data and code, and the Customer's users of Adea.

**Duration:** for as long as the Customer uses Adea, and then until deletion under clause 11.

## Appendix B: Sub-processors

The Customer has approved these sub-processors:

- **Hetzner Online GmbH**: The servers Adea runs on: the application, its databases, the copies of connected data and code, and files. EU (Germany). No transfer outside the EU.
- **Cloudflare, Inc.**: The network and encrypted connection to Adea. Encrypted backups of Adea's databases (R2, stored in the EU). Reading code in a short-lived, isolated sandbox. Turning reports and dashboards into PDF files (Browser Rendering). Speech to text and text to speech when a person uses their voice (Workers AI). EU and USA. Backups are stored only in the EU. The sandbox, PDF files and speech run on Cloudflare's global network, not necessarily in the EU, and nothing is kept there after the job. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Anthropic PBC**: The AI model (Claude) that understands questions, writes queries, reads code and screenshots and writes answers. Anthropic does not use the data to train its models. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Resend (Plus Five Five, Inc.)**: Sending email (sign-in links, notifications, reports and briefs) and receiving files that a company's approved senders mail to Adea. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Stripe Payments Europe, Ltd.**: Payments, invoices, receipts and VAT. Only Stripe handles card details. Ireland and USA. EU Standard Contractual Clauses.
- **Functional Software, Inc. (Sentry)**: Error monitoring: technical error reports from Adea, without the content of your data, code, questions or answers. EU (Germany). Data is stored in the EU. Any access from the USA relies on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Twilio Inc.**: Text messages and phone calls about urgent findings, only to people who have added their phone number and turned this on. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Google Ireland Limited**: Sign-in with Google, and reading Google Sheets, BigQuery, Search Console and Google Ads, only when a person signs in with Google or the customer connects one of them. Ireland and USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Microsoft Ireland Operations Ltd.**: Sign-in with Microsoft, and questions and answers in Microsoft Teams, only when a person signs in with Microsoft or the customer connects Teams. Ireland and USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **Slack Technologies, LLC**: Questions, answers and notifications in Slack, only when the customer connects Slack. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- **GitHub, Inc.**: Read access to the customer's code through the GitHub App, only when the customer connects GitHub. USA. EU-US Data Privacy Framework and the EU Standard Contractual Clauses.

## Appendix C: Instructions and security

**Instructions:** Adea processes data only to deliver the service described in appendix A. Neither Adea nor its AI providers use the Customer's data to train AI models. The Customer's data is never shared with other customers.

**Usage data:** Adea may produce anonymised, aggregated statistics on how the service is used, such as the number of questions, response times, costs and errors, and use them to run and improve the service. The statistics never contain the content of the Customer's data, code, questions or answers, cannot be traced back to a person and are never used to train AI models.

**What goes to the AI model:** the question, the names and descriptions of the Customer's tables and columns, the excerpts of code and the result rows needed to answer, and uploaded screenshots. Columns the Customer has hidden are never sent. Speech goes to the speech service in appendix B together with the Customer's own words and names, so they are spelled right.

**Retention:**

- Answers made of numbers, series, breakdowns and explanations are kept for as long as the Customer uses Adea. Result rows that hold personal data are deleted after 30 days. The answer then still shows its numbers and the query behind it, and can be run again.
- Copies of the Customer's code are kept while the repository is connected and deleted when it is removed.
- Data fetched from connected services and files is kept while the source is connected and deleted when it is removed.
- Voice recordings are deleted as soon as they are turned into text. Screenshots are deleted when the dashboard is built.
- Guardian's decision log is kept for 90 days. The security log is kept for as long as the organisation exists.
- On the Free plan, when nobody has opened Adea for 90 days, the connection details for the Customer's sources are deleted.

**Location:** the Customer's data is stored on servers in the EU, and backups are stored encrypted in the EU. The sub-processors in appendix B process data outside the EU only as appendix B says, under the transfer mechanism stated there.

**Security measures:**

- Adea connects to the Customer's databases with a user that can only read, checks that before it connects, and refuses a user that can write. Each query has a time limit and a row limit.
- Every query is checked before it runs: read-only, and no hidden tables or columns.
- Guardian looks at every pull of data, whoever asks, including scheduled work and AI assistants: how much personal data, how many rows, and how unusual the request is. It flags what looks unusual and, on the plans that include it, holds a request until an administrator approves it. Lowering a protection needs a second administrator or waits 24 hours. If Guardian can't run, requests for personal data and exports wait.
- Each company's data is separated from other companies' by row-level security in the database and a separate encryption key per company. Each job runs in its own short-lived process.
- Code is read in a short-lived, isolated sandbox that is gone when the job ends. The AI model cannot run code or commands. All access goes through controlled functions bound to the Customer.
- Connection details, keys and tokens are encrypted. All traffic is encrypted with TLS.
- Sign-in uses one-time links by email, Google, Microsoft or passkeys, never passwords. The Customer can require passkeys or single sign-on.
- A public link shows only what the user chose to share, has an address that cannot be guessed, can have a last day, and can be switched off at any time.
- Every question and every pull of data is logged with the person, the time and the tables and code used. The security log can't be changed without it showing, and the Customer's administrators can read it.

[See the sub-processors](https://adea.app/subprocessors)
