Customer GDPR Data Processing Agreement

This Customer Data Processing Agreement ("DPA") sets out the terms governing HubBroker ApS's processing of Personal Data on behalf of Customer in accordance with applicable Data Protection Laws, including Regulation (EU) 2016/679 ("GDPR").
This Data Processing Agreement (“DPA”) is an addendum to Your – as Customer - contract with HubBroker ApS, (“HubBroker ApS”). All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement. Customer enters into this DPA on behalf of itself and, to the extent required under Data Protection Laws, in the name and on behalf of its Authorized Affiliates (defined below).
The parties agree as follows:
1. Definitions
“Controller” means an entity that determines the purposes and means of the processing of Personal Data.
“Customer Data” means any data that HubBroker ApS and/or its Affiliates processes on behalf of Customer in the course of providing the Services under the Agreement.
“Data Protection Laws” means all data protection and privacy laws and regulations applicable to the processing of Personal Data under the Agreement, including, where applicable, EU Data Protection Law.
"EU Data Protection Law" means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation or "GDPR"), as applicable in the EU, EEA, and Switzerland; (ii) Directive 2002/58/EC concerning the processing of Personal Data and the protection of privacy in the electronic communications sector (ePrivacy Directive) and applicable national implementations thereof; iii) Any amendments, supersessions or replacements of the above as may be enacted.
“Personal Data” means any Customer Data relating to an identified or identifiable natural person to the extent that such information is protected as personal data under applicable Data Protection Law.
“Processor” means an entity that processes Personal Data on behalf of the Controller.
“Processing” has the meaning given to it in the GDPR and “process”, “processes” and “processed” shall be interpreted accordingly.
“Security Incident” means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data.
"Services" means the integration, iPaaS, EDI, e-invoicing, document exchange, transformation, validation, routing, monitoring, API, storage, support and related services provided by HubBroker under the applicable agreement.
"Subprocessor" means a third party engaged by HubBroker to process Personal Data on behalf of Customer in connection with provision of the Services.
2. Roles and Scope
2.1 Roles
For Personal Data processed by HubBroker on behalf of Customer:
Customer is the Controller and HubBroker is the Processor.
Where Customer itself acts as a processor for another controller, HubBroker may act as a Subprocessor in relation to such Personal Data.
Nothing in this DPA changes the allocation of roles established by Applicable Data Protection Laws.
2.2 Customer Instructions
HubBroker shall process Personal Data only:
- on documented instructions from Customer;
- as necessary to provide the Services;
- as otherwise documented in the applicable agreement; or
- where required by applicable law.
Where applicable law requires HubBroker to process Personal Data other than on Customer's documented instructions, HubBroker shall inform Customer of that legal requirement before processing unless prohibited by applicable law.
2.3 Unlawful Instructions
HubBroker shall inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws.
3. Customer Responsibilities
Customer is responsible for:
- determining the purposes and lawful basis of processing;
- ensuring that its instructions comply with Applicable Data Protection Laws;
- ensuring that Personal Data provided to HubBroker has been collected and disclosed lawfully;
- providing required privacy information to Data Subjects;
- responding to Data Subject requests as Controller;
- determining appropriate retention periods for Customer Data;
- determining whether special categories of Personal Data may be processed through the Services; and
- configuring and using the Services in accordance with applicable security requirements.
Customer shall not instruct HubBroker to process Personal Data in violation of Applicable Data Protection Laws.
4. HubBroker Processing Obligations
4.1 Confidentiality
HubBroker shall ensure that persons authorised to process Personal Data:
- are subject to appropriate confidentiality obligations;
- receive appropriate security and data protection awareness training; and
- process Personal Data only as necessary to perform their authorised responsibilities.
4.2 Security
HubBroker shall implement and maintain appropriate technical and organisational measures designed to protect Personal Data against:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure; and
- unauthorised access.
The principal technical and organisational measures are described in Annex B.
Security measures shall be appropriate to the nature, scope, context and purposes of processing and the risks presented by the processing.
4.3 Data Protection by Design and Default
Where applicable to the Services and taking into account the nature of processing, HubBroker shall implement appropriate technical and organisational measures designed to support data protection principles.
5. Personal Data Breaches
5.1 Notification
HubBroker shall notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Personal Data processed on behalf of Customer.
Where reasonably practicable, HubBroker shall provide an initial notification within 24 hours after becoming aware of such confirmed Personal Data Breach.
5.2 Information
To the extent information is reasonably available, HubBroker shall provide Customer with relevant information concerning:
- the nature of the Personal Data Breach;
- affected categories of Personal Data;
- affected categories of Data Subjects;
- approximate number of affected records or Data Subjects, where known;
- likely consequences;
- containment or mitigation measures taken or proposed; and
- appropriate contact information for further communication.
Information may be provided in phases as the investigation progresses.
5.3 Cooperation
HubBroker shall provide reasonable assistance to Customer in meeting Customer's applicable Personal Data Breach notification obligations.
HubBroker's notification of a Personal Data Breach shall not constitute an admission of fault or liability.
6. Subprocessors
6.1 General Authorisation
Customer provides HubBroker with general written authorisation to engage Subprocessors for processing necessary to provide the Services.
Relevant Subprocessors are identified in Annex A or HubBroker's applicable published Subprocessor list.
6.2 Subprocessor Obligations
HubBroker shall impose appropriate data protection obligations on each Subprocessor where required by Applicable Data Protection Laws.
Such obligations shall provide an appropriate level of protection having regard to the processing performed by the Subprocessor.
6.3 Responsibility
Where required under GDPR, HubBroker shall remain responsible to Customer for the performance of its Subprocessors' applicable data protection obligations.
6.4 Changes
HubBroker shall provide reasonable advance notice of intended material additions or replacements of Subprocessors that process Customer Personal Data.
Customer may object to a new Subprocessor on reasonable and documented data protection grounds.
The Parties shall cooperate in good faith to seek a commercially reasonable resolution.
Where no reasonable resolution is available, the Parties shall address the affected Services in accordance with the applicable agreement.
7. International Transfers and Processing Locations
7.1 Processing Locations
Personal Data may be processed:
- within the EU/EEA;
- in the United Kingdom;
- in jurisdictions recognised by the European Commission as providing an adequate level of protection; and
- in other jurisdictions where an appropriate transfer mechanism is available as required under Applicable Data Protection Laws.
HubBroker shall maintain reasonable transparency regarding material processing locations and relevant Subprocessors.
7.2 United Kingdom
Where Personal Data is transferred from the EEA to the United Kingdom and a valid European Commission adequacy decision applicable to the relevant transfer remains in force, the transfer may rely upon that adequacy decision.
No additional Chapter V transfer mechanism shall be required solely because Personal Data is transferred from the EEA to the United Kingdom while such adequacy decision remains applicable.
7.3 Loss or Change of Adequacy
If an adequacy decision relied upon for a transfer is repealed, suspended, invalidated or otherwise ceases to provide a lawful basis for that transfer, HubBroker shall implement an appropriate alternative transfer mechanism where required by Applicable Data Protection Laws.
Such mechanisms may include, where applicable:
- Standard Contractual Clauses adopted by the European Commission;
- Binding Corporate Rules where duly approved and applicable; or
- another legally recognised transfer mechanism.
7.4 Standard Contractual Clauses
Where required for an international transfer, the Parties shall implement the applicable European Commission Standard Contractual Clauses for transfers of Personal Data to third countries, including the applicable module and annexes.
Where required by Applicable Data Protection Laws or the applicable transfer mechanism, HubBroker shall cooperate in completing an appropriate transfer assessment and implementing supplementary measures.
7.5 Onward Transfers
HubBroker shall ensure that onward transfers by relevant Subprocessors are subject to a lawful transfer mechanism where required under Applicable Data Protection Laws.
Remote access to Personal Data from another jurisdiction shall be handled as an international transfer where Applicable Data Protection Laws require such treatment.
8. Data Subject Rights
Taking into account the nature of processing, HubBroker shall provide reasonable assistance to Customer through appropriate technical and organisational measures for responding to requests concerning:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection; and
- other applicable Data Subject rights.
Where HubBroker receives a request directly from a Data Subject concerning Personal Data processed on Customer's behalf, HubBroker shall, where legally permitted, direct the Data Subject to Customer or notify Customer.
HubBroker shall not independently respond to such request except:
- on Customer's documented instructions; or
- where required by applicable law.
9. DPIAs and Regulatory Assistance
Taking into account the nature of processing and information available to HubBroker, HubBroker shall provide reasonable assistance to Customer with:
- security obligations;
- Personal Data Breach obligations;
- Data Protection Impact Assessments;
- prior consultation with Supervisory Authorities; and
- other obligations under Articles 32–36 GDPR where applicable.
Customer remains responsible for determining whether a DPIA or prior consultation is legally required.
10. Audit and Compliance Information
10.1 Compliance Evidence
Upon reasonable written request, HubBroker shall make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.
Such information may include, where applicable:
- security documentation;
- descriptions of technical and organisational measures;
- relevant certifications;
- third-party assessment information;
- Subprocessor information; and
- security or audit summaries.
10.2 Audits
Customer may conduct or appoint an independent auditor to conduct an audit where reasonably necessary to demonstrate HubBroker's compliance with Article 28 GDPR.
Audits shall normally:
- be conducted during normal business hours;
- be subject to reasonable advance written notice;
- avoid unreasonable disruption to HubBroker's operations;
- comply with appropriate confidentiality and security requirements; and
- avoid access to information concerning other customers.
Existing independent audit reports, certifications and security documentation should normally be used first where reasonably sufficient.
Additional audit access may be appropriate where required by a competent Supervisory Authority, following a material Personal Data Breach, or where Customer has reasonable evidence of material non-compliance.
11. Return and Deletion of Personal Data
Upon termination or expiry of Services involving processing of Personal Data, and subject to Customer's choice where required by GDPR, HubBroker shall:
- return Personal Data to Customer; or
- securely delete Personal Data,
unless applicable law requires continued retention.
Personal Data remaining temporarily in backup systems following deletion from active systems shall remain appropriately protected and shall not be restored or otherwise processed except where required for legitimate recovery, security or legal purposes.
Such backup data shall subsequently be deleted or overwritten in accordance with HubBroker's applicable backup retention schedule.
12. Government and Regulatory Requests
Where legally permitted, HubBroker shall notify Customer if it receives a legally binding request from a public authority requiring disclosure of Customer Personal Data.
HubBroker shall assess such requests in accordance with applicable law and shall disclose only Personal Data that it is legally required to disclose.
Nothing in this provision requires HubBroker to violate applicable law or a legally binding prohibition on notification.
13. Records and Cooperation
HubBroker shall maintain records required of it under Applicable Data Protection Laws.
HubBroker shall cooperate with competent Supervisory Authorities to the extent required by applicable law in relation to processing governed by this DPA.
14. Liability
Liability arising under this DPA shall be governed by the applicable agreement between Customer and HubBroker, except to the extent such limitation or allocation of liability is prohibited by Applicable Data Protection Laws.
Nothing in this DPA limits any rights or remedies that cannot lawfully be limited.
15. Term and Termination
This DPA shall remain effective for as long as HubBroker processes Personal Data on behalf of Customer.
Provisions which by their nature must continue after termination, including confidentiality, deletion and applicable data protection obligations, shall survive termination for the period necessary to fulfil their purpose.
16. Conflict
If there is a conflict between this DPA and the main service agreement concerning processing of Personal Data, this DPA shall prevail with respect to the conflicting data protection provision.
Where applicable Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses shall prevail to the extent of that conflict.
Annex A - List of HubBroker ApS Sub-processors
On the effective date of the Data Processing Agreement, the Controller has approved the use of the following sub-processors
Sub-processor | CVR/ Company ID | ADDRESS and country | DESCRIPTION OF PROCESSING |
eEUKhost (UK) | eukhost Ltd Registration number: 5616528 | Suite 3.03, Regency House, York, North Yorkshire, YO26 6RW, England. | Hosting & Backup |
Annex B – Technical and Organizational Measures
1. Information Security Governance
HubBroker maintains appropriate information security policies, responsibilities and operational procedures covering systems and personnel involved in processing Customer Personal Data.
Security measures are periodically reviewed and adjusted where reasonably necessary to address changes in risks, technology and Services.
2. Access Control
Access to systems processing Customer Personal Data shall be limited according to business need.
Measures include, where applicable:
- individual user accounts;
- role-based access;
- least-privilege principles;
- privileged account restrictions;
- password and authentication controls;
- access provisioning and revocation processes; and
- periodic access reviews.
3. Authentication
HubBroker shall maintain appropriate authentication controls for administrative and operational systems.
Multi-factor authentication shall be used for relevant privileged or externally accessible administrative systems where technically supported and appropriate to risk.
4. Personnel and Confidentiality
Personnel with authorised access to Customer Personal Data shall:
- be subject to confidentiality obligations;
- receive appropriate information security awareness;
- receive data protection training appropriate to their responsibilities; and
- access Personal Data only where necessary for authorised business purposes.
5. Transmission Security
Personal Data transmitted across public or untrusted networks shall be protected using appropriate secure protocols where supported by the applicable integration.
Such protocols may include:
- HTTPS/TLS;
- SFTP/SSH;
- FTPS/TLS;
- AS2 using appropriate transport/message security; and
- other encrypted transport mechanisms appropriate to the Services.
6. Physical Security
Physical security of hosting infrastructure shall be provided by HubBroker's applicable data centre and infrastructure providers.
Appropriate controls may include restricted physical access, monitoring, environmental controls, fire protection, power resilience and facility security.Legacy or Customer-required protocols shall be assessed according to the applicable technical configuration and risk.
7. Network and Infrastructure Security
Appropriate infrastructure security measures shall be maintained directly by HubBroker or its hosting/infrastructure Subprocessors, depending on the applicable responsibility model.
Measures may include:
- firewalls;
- network access restrictions;
- segmentation;
- secure administrative access;
- monitoring;
- anti-malware controls;
- restriction of unnecessary services; and
- vulnerability management.
8. Vulnerability and Patch Management
HubBroker shall maintain processes appropriate to the systems under its management for:
- identifying relevant vulnerabilities;
- applying security updates;
- risk-based remediation; and
- monitoring material security weaknesses.
Infrastructure providers remain responsible for components allocated to them under applicable service agreements.
9. Logging and Monitoring
HubBroker shall maintain appropriate logging and monitoring for relevant systems.
Logs may be used for:
- security monitoring;
- incident investigation;
- troubleshooting;
- identification of unauthorised activity; and
- audit purposes.
Access to security logs shall be restricted appropriately.
10. Backup and Recovery
HubBroker and its applicable infrastructure providers shall maintain backup and recovery measures appropriate to the Services purchased.
Controls may include:
- scheduled backups;
- restricted access to backup systems;
- recovery procedures;
- infrastructure redundancy;
- business continuity arrangements; and
- disaster recovery procedures.
Actual backup frequency, retention, storage location and recovery commitments shall be governed by HubBroker's applicable service documentation and infrastructure configuration.
11. Availability and Resilience
HubBroker shall maintain measures appropriate to the Services designed to support ongoing confidentiality, integrity, availability and resilience.
Where applicable, HubBroker shall maintain procedures for restoration of services following significant technical or physical incidents.
12. Security Incident Management
HubBroker shall maintain procedures for:
- identifying security incidents;
- escalating incidents;
- containment;
- investigation;
- remediation;
- recovery; and
- documenting significant incidents.
Personal Data Breaches shall be handled in accordance with Section 5 of this DPA.
13. Customer Isolation
Where systems process data relating to multiple customers, appropriate logical or technical measures shall be used to prevent unauthorised access between customer environments.
14. Subprocessor Security
HubBroker shall assess relevant data protection and security considerations when engaging Subprocessors processing Customer Personal Data.
Applicable contractual obligations shall be imposed on Subprocessors as required under Applicable Data Protection Laws.
15. Secure Deletion
Personal Data shall be deleted in accordance with Section 11 of this DPA and HubBroker's applicable retention and backup procedures
Annex C — Data Center Location
Yorkshire are the location of our all servers (Application, database, SFTP).
Annex D -International Transfer Safeguards
1. Adequacy
Where the destination country benefits from an applicable European Commission adequacy decision, HubBroker may rely upon that decision for the relevant transfer.
2. Alternative Transfer Mechanism
Where an applicable adequacy decision ceases to apply, HubBroker shall implement an alternative lawful transfer mechanism where required.
3. SCC Fallback
Where appropriate, this may include entering into the applicable European Commission Standard Contractual Clauses for international transfers.
The applicable:
- SCC module;
- data exporter;
- data importer;
- categories of Personal Data;
- processing activities;
- Supervisory Authority;
- security measures; and
- Subprocessors
shall be identified when SCCs are actually required.
4. Supplementary Measures
Where required following an assessment of the relevant transfer, HubBroker shall implement appropriate supplementary technical, contractual or organisational measures.
5. Binding Corporate Rules
Binding Corporate Rules may be relied upon only where applicable to the relevant transfer and duly approved in accordance with Applicable Data Protection Laws.
The existence of this clause does not represent that HubBroker currently maintains approved Binding Corporate Rules.
Category: GDPR
Last date of update: 18.09.2026