Data Processing Agreement
Last updated: 30 September 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Vionord Technology ApS (“Vionord”, “we”, “us” or “Processor”) and the customer using Vionord services (“Customer”, “you” or “Controller”).
This DPA governs the processing of personal data by Vionord on behalf of the Customer in connection with Vionord's services, including Vionord Cashbox, Vio-conomic and related POS, ordering, cloud and integration services.
This DPA is intended to comply with Article 28 of the EU General Data Protection Regulation (GDPR).
1. Definitions
For purposes of this DPA:
- “Controller” means the party determining the purposes and means of processing personal data.
- “Processor” means Vionord Technology ApS where Vionord processes personal data on behalf of the Customer.
- “Personal Data” means personal data processed under the GDPR.
- “Processing” has the meaning given to it under the GDPR.
- “Data Subject” means an identified or identifiable individual whose personal data is processed.
- “Subprocessor” means a third party appointed by Vionord to process personal data on behalf of the Customer.
2. Scope and Roles
The Customer remains responsible for determining the purposes and lawful basis for processing personal data within its business.
Where Vionord processes personal data on behalf of the Customer, Vionord acts as a data processor and processes such personal data only in accordance with the Customer's documented instructions and the applicable agreement.
Vionord may also process certain information as an independent data controller where required for operating, securing, supporting and legally administering its own services. Such processing is governed by Vionord's applicable privacy policy.
For the Vio-conomic integration, Vionord processes relevant POS and business information in order to transfer and synchronize information between Vionord Cashbox and the Customer's e-conomic account.
3. Subject Matter and Duration
The subject matter of processing is the provision and operation of Vionord's services and integrations.
Processing may include:
- Synchronizing sales and invoice information;
- Synchronizing customer information;
- Synchronizing product information;
- Processing order information;
- Processing VAT and tax-related information;
- Processing discounts and product/add-on information;
- Maintaining synchronization queues and integration records;
- Providing technical support;
- Monitoring and securing the services.
Personal data will be processed for the duration of the Customer's use of the applicable Vionord service and for any additional period required by law or necessary for legitimate operational purposes.
4. Categories of Personal Data
Depending on how the Customer uses the services, the following categories of personal data may be processed:
Customer information
- Name;
- Company name;
- Business registration/VAT number where applicable;
- Address;
- Email address;
- Telephone number;
- Customer identification/reference information.
Transaction information
- Orders;
- Products purchased;
- Quantities;
- Prices;
- Discounts;
- VAT/tax information;
- Invoice information;
- Payment-related transaction references where applicable.
Technical information
- Account and integration identifiers;
- Authentication and authorization information;
- System logs;
- Error and synchronization logs;
- API/integration metadata.
Vionord does not intentionally request special categories of personal data through the Vio-conomic integration.
5. Processing Instructions
Vionord shall process Personal Data only:
- To provide the contracted services;
- To perform the Customer's requested integrations;
- To maintain and secure the services;
- To provide technical support;
- As otherwise instructed by the Customer; or
- Where required by applicable EU or Member State law.
Vionord shall inform the Customer if it believes that an instruction violates applicable data protection law, unless prohibited by law from doing so.
6. Confidentiality
Vionord shall ensure that persons authorized to process Personal Data:
- Are subject to appropriate confidentiality obligations;
- Have access only to information necessary for their role; and
- Receive appropriate instructions regarding the protection of Personal Data.
7. Security Measures
Vionord shall implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access.
Depending on the service and environment, these measures may include:
- Encryption of data in transit;
- Access controls and least-privilege principles;
- Secure authentication mechanisms;
- Administrative access controls;
- System and application logging;
- Security monitoring;
- Software and dependency updates;
- Backup and recovery procedures;
- Environment and customer data separation;
- Secure API communication;
- Incident response procedures.
Vionord periodically reviews its technical and organizational security measures and may update them as appropriate to address changes in technology, threats and regulatory requirements.
8. Subprocessors
Vionord may use carefully selected third-party service providers to support the delivery, hosting, security, monitoring and operation of its services.
Where a third party processes Personal Data on behalf of Vionord, Vionord will require the Subprocessor to provide appropriate data protection and security commitments consistent with the requirements applicable to Vionord.
Vionord remains responsible for the processing carried out by its authorized Subprocessors to the extent required by applicable law.
A current list of relevant Subprocessors may be made available by Vionord upon request or through the applicable service documentation.
9. International Transfers
Where Personal Data is transferred outside the European Economic Area (“EEA”), Vionord shall ensure that the transfer is carried out in accordance with applicable GDPR requirements.
Where required, Vionord may rely on an applicable adequacy decision, Standard Contractual Clauses (“SCCs”), or another lawful transfer mechanism recognized under applicable data protection law.
10. Assistance with Data Subject Rights
Taking into account the nature of the processing, Vionord shall provide reasonable assistance to the Customer in responding to requests from Data Subjects concerning their rights under the GDPR.
These rights may include:
- Access;
- Rectification;
- Erasure;
- Restriction of processing;
- Data portability;
- Objection to processing.
Where technically available, Vionord may provide functionality allowing the Customer to access, correct or delete relevant information directly.
11. Personal Data Breaches
Vionord shall maintain procedures designed to detect, investigate and respond to Personal Data breaches.
Where Vionord becomes aware of a Personal Data breach affecting Personal Data processed on behalf of the Customer, Vionord shall notify the Customer without undue delay, where required by applicable law.
Where reasonably available, the notification will include information concerning:
- The nature of the incident;
- The categories of data affected;
- The likely consequences;
- Measures taken or proposed to address the incident.
Vionord shall provide reasonable cooperation to assist the Customer in meeting its obligations under applicable data protection law.
12. Data Protection Impact Assessments
Taking into account the nature of the processing and information available to Vionord, Vionord shall provide reasonable assistance to the Customer with data protection impact assessments where required under applicable GDPR requirements.
13. Audits and Compliance Information
Vionord shall make available information reasonably necessary to demonstrate compliance with the obligations applicable to processors under Article 28 GDPR.
Where legally required and subject to reasonable confidentiality and security requirements, Vionord shall cooperate with reasonable audits or inspections conducted by the Customer or an authorized auditor.
Audits shall be conducted in a manner that does not unnecessarily disrupt Vionord's business operations or compromise the security or confidentiality of other customers' information.
14. Return and Deletion of Data
Upon termination of the applicable services, Vionord shall, subject to applicable legal retention requirements, delete or return Personal Data processed on behalf of the Customer in accordance with the Customer's instructions.
Certain information may need to be retained where required by law, for the establishment, exercise or defense of legal claims, or where otherwise permitted under applicable law.
Where data is retained for such purposes, it shall continue to be protected in accordance with applicable data protection requirements.
15. Customer Responsibilities
The Customer is responsible for:
- Ensuring that it has a lawful basis for processing Personal Data;
- Providing appropriate privacy information to Data Subjects;
- Ensuring that information supplied to Vionord is accurate and lawful;
- Providing lawful instructions to Vionord;
- Managing user access to its Vionord and e-conomic accounts;
- Protecting its credentials and authentication mechanisms;
- Complying with applicable data protection legislation.
16. Data Minimization
Vionord is designed to process information necessary to provide the relevant services and integrations.
The Customer should avoid providing Personal Data that is unnecessary for the operation of the applicable service.
17. No AI/ML Training Using Customer Data
Vionord does not use Personal Data received through the e-conomic integration for training general-purpose artificial intelligence or machine-learning models.
Any future use of Customer Personal Data for AI/ML training would require an appropriate legal basis and, where applicable, explicit contractual authorization.
18. Conflict with the Main Agreement
If there is a conflict between this DPA and another agreement between Vionord and the Customer concerning the processing of Personal Data, this DPA shall prevail to the extent necessary to comply with applicable data protection law.
19. Changes to this DPA
Vionord may update this DPA from time to time to reflect changes in applicable law, technology, security practices or its services.
Where a material change affects the Customer's rights or obligations, Vionord will provide appropriate notice where required.
20. Contact
For questions concerning this Data Processing Agreement or data protection matters, please contact:
Grenåvej 122
8240 Risskov
Denmark
CVR: 45021769
Email: business@vionord.com
Website: www.vionord.com