Data Processing Agreement
Last updated: 30 July 2026
This Data Processing Agreement (the "Agreement") is entered into between the Customer (controller — the company name and registration number are filled in on sign-up) and WEAKESTLINK ApS (CVR 46614011), which operates weakestlink (the "Supplier", processor). The Agreement is accepted electronically when the account is created and governs the Supplier's processing of personal data on behalf of the Customer in connection with security-awareness training and phishing simulation. On matters of data processing, this Agreement takes precedence over the terms of service; on all other matters, the terms of service apply.
1. Subject matter and instructions
The Supplier processes personal data only on the Customer's documented instructions — this Agreement with its appendices and the ongoing use of the service (Appendix A) — unless EU or Danish law requires otherwise; in that case the Supplier will inform the Customer of that legal requirement before processing, unless the law prohibits this. The instructions also permit the Supplier to compile statistics in anonymised and aggregated form as described in the terms of service; once anonymised, the information is no longer personal data. The Supplier will inform the Customer if, in its assessment, an instruction infringes data protection law, and will not transfer data to third countries beyond those listed in Appendix B without a valid transfer mechanism.
2. Confidentiality
The Supplier ensures that persons authorised to process the data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality.
3. Security (art. 32)
The Supplier implements appropriate technical and organisational measures (Appendix C). A core principle is data minimisation: in phishing simulations, only the fact that an event occurred (opened/clicked/entered data) is recorded, along with field names — never the values an employee enters.
4. Sub-processors
The Customer grants general prior authorisation for the sub-processors listed in Appendix B. The Supplier imposes on each sub-processor the same data protection obligations as set out in this Agreement, and gives notice of planned changes by email with at least 30 days' notice so the Customer can object. If an objection cannot be resolved with a reasonable solution, the Customer may terminate the customer relationship with effect from the date the change takes effect. The Supplier remains fully liable for sub-processors' compliance.
5. Assistance to the Customer
Taking into account the nature of the processing and through appropriate technical and organisational measures, the Supplier assists the Customer in responding to requests to exercise data subjects' rights (art. 12–23) and in meeting the Customer's obligations under art. 32–36 (security, breach notification, data protection impact assessment and prior consultation). The service includes a ready-made legitimate interest assessment and a transparency notice for employees, which the Customer can use directly. Assistance that goes substantially beyond what the service normally involves may be invoiced on a time-spent basis at a reasonable rate.
6. Personal data breaches
The Supplier notifies the Customer without undue delay and no later than 48 hours after becoming aware of a breach affecting the Customer's data — describing the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed. The assessment of whether the breach must be reported to the Danish Data Protection Agency (Datatilsynet) (the 72-hour deadline) is the Customer's responsibility as controller.
7. Deletion and return
On termination of the Agreement, the Supplier deletes or returns all personal data, at the Customer's choice. Return is provided as a structured, commonly used, machine-readable export (e.g. CSV). If the Customer does not indicate a choice by the time of termination, the data is deleted. Deletion is carried out no later than 90 days after termination and is final; if the customer relationship ends because the account has been in restricted status (see section 4 of the terms of service), deletion is announced by email at least 30 days in advance, and the Customer may choose to have the data returned at any point before deletion. Personal data in backups is deleted through the ordinary backup rotation, no later than 90 days after deletion in the production environment. Data that legislation requires to be retained (e.g. bookkeeping records under the Danish Bookkeeping Act) is retained only for as long as that obligation applies.
8. Audit and supervision
The Supplier makes available to the Customer all information necessary to demonstrate compliance with art. 28, and enables and contributes to audits, including inspections, conducted by the Customer or an auditor authorised by the Customer. Current security descriptions and reports may substitute for a physical inspection where reasonable. Physical audits are carried out with reasonable notice, no more than once a year — unless a breach or a regulatory requirement gives specific cause — and at the Customer's expense.
9. Duration and termination
The Agreement applies for as long as the Supplier processes personal data on behalf of the Customer and terminates automatically when the customer relationship ends — including when a customer relationship is deemed to have ended following prolonged restricted status, as set out in the terms of service — after which section 7 applies.
10. Liability and governing law
Towards data subjects, the parties' liability is governed by art. 82 of the GDPR. In the relationship between the parties, the liability provisions of the terms of service apply, to the extent permitted by applicable law. The Agreement is governed by Danish law, with venue as set out in the terms of service.
Appendix A — Nature of the processing
| Subject matter | Security training (nano-lessons + quizzes) and authorised internal phishing simulation of the Customer's employees |
| Duration | The duration of the customer relationship (see section 9) |
| Nature and purpose | Training in security behaviour; measurement of human risk at an aggregated level |
| Categories of data | Name, email, department/job title; training and simulation events (opened/clicked/reported), timestamp, IP address, user agent; values entered in simulations are not stored (field names only) |
| Categories of data subjects | The Customer's employees (and any external users with an account) |
| Special categories of data (art. 9) | None — the service is designed so that none arise (no storage of entered values) |
Appendix B — Sub-processors
| Sub-processor | Service | Country | Transfer mechanism |
|---|---|---|---|
| Brevo (Sendinblue SAS) | Outgoing transactional and notification email | France | — (EU/EEA) |
| Cloudflare, Inc. | Network, TLS, DDoS protection | USA | DPF/SCC |
Hosting takes place on the Supplier's own infrastructure in Denmark. Simulation emails are sent from the Supplier's own systems without any additional sub-processors.
For clarity: AI-generated training and simulation content is authored without the use of personal data — the AI provider is therefore not a sub-processor. Payment processing is handled by Revolut as an independent controller (payment institution) and is described in the privacy policy.
Annex C — Technical and organisational security measures (art. 32)
- Per-customer separation (multi-tenancy): strict tenant isolation at the application layer; one customer's data is inaccessible to other customers.
- Access control: role-based access (RBAC) on a least-privilege basis; individual accounts; no shared logins.
- Encryption: TLS in transit; encryption of backups.
- Data minimisation: simulations store only the event and field names, never entered values; reporting is aggregated only (minimum group size, k ≥ 5).
- Logging and auditing: event log for security-relevant actions; append-only audit trail.
- Security headers/CSP: strict Content-Security-Policy and other security headers on all pages.
- Incident response: breach procedure with notification to the Customer within 48 hours (section 6).
- Deletion: automated process upon termination — notice after 60 days in restricted mode, deletion after 90 days, never without at least 30 days' prior notice; otherwise deletion/return no later than 90 days after termination (section 7).
If you need a signed copy for your own records, please write to info@weakestlink.io.