Version
2.8
Datum des Inkrafttreten: 15/08/2025
In diesem Dokument:
The Customer
(hereinafter “Customer”)
and
Famly ApS, Købmagergade 19, 2tv., 1150 Copenhagen, Denmark
(hereinafter “Famly”)
(each a “Party” and collectively the “Parties”)
have concluded this Data Processing Agreement (this “DPA”) regarding the Processor’s processing of personal data on behalf of the Customer.
This DPA is effective as of the date of the Agreement.
“Agreement” means the main agreement (terms and conditions and Famly Offer) entered into between the Customer and Famly as amended from time to time in accordance with its terms;
“Application Log” means the log used for storing access to Customer Data;
“Authorised Sub-Processors” means the Sub-Processors set out in Appendix B as may be amended from time to time;
“Customer Data” means the Personal Data (as defined in the GDPR) regarding individuals made available to Famly by or on behalf of the Customer, pursuant to the Agreement for Processing to provide the Services;
“Customer Point of Contact” has the meaning given in Clause 18.3;
“Data Breach” has the meaning given in Clause 10.1;
“Data Centres” means the data centres used for hosting and storing of Customer Data on the Famly Platform;
“Data Subject Request” has the meaning given in Clause 9.1;
“DPA” means this Data Processing Agreement, including any schedules attached or referred to and including any future written amendments and additions (as applicable);
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EU;
"EEA” means the European Economic Area, and the countries which are party to the European Economic Area Treaty;
“Services” means the Famly Platform services described and provided under the Agreement and in accordance with this Data Processing Agreement;
“Sub-Processor” has the meaning given in clause 6.1;
“Transfer Mechanism” means (i)
the Standard Contractual Clauses approved by the European Commission Decision of 4 June 2021 (processor to processor) as amended from time to time, (ii)
Data Protection Clauses approved by the Swiss Federal Data Protection and Information Commissioner (“FDPIC”), (iii)
and other such legally approved mechanisms for ensuring the safety and security of data transfers from outside of the EEA/Switzerland.
The terms “Controller”, “Processor”, “Processing”, “Data Subject”, “Personal Data”, “Personal Data Breach” and “Supervisory Authority” shall have the same meaning as in the GDPR. All capitalized terms not otherwise defined herein shall have the meaning set out in the Agreement.
Any reference to writing or written includes email.
1.1. The Parties have entered into the Agreement, where the Customer has engaged Famly to provide the Services. This DPA, including all attached appendices, is incorporated into the Agreement by reference.
1.2. For the purposes of providing the Services under the Agreement, Famly will process Customer Data throughout the Term of this DPA. This DPA applies to any and all activities associated with the Agreement, in whose scope Famly’s employees or agents process the Customer Data on behalf of the Customer as set out in Appendix A.
2.1. The parties agree that under this DPA the Customer is the Controller of the Customer Data and Famly is the Processor of the Customer Data. The Customer agrees that this DPA, and not Famly’s Privacy Policy, applies to Famly’s processing of Customer Data as a Processor
2.2. The Customer is solely responsible for compliance with the GDPR, including but not limited, to the lawfulness of disclosing Customer Data to Famly and the lawfulness of having the Customer Data processed by Famly on behalf of the Customer. The Customer warrants that it is lawfully authorised to process and disclose the Customer Data to Famly. The Customer is responsible for maintaining and updating its respective privacy policy, notices and statements, including to mention Famly in it as its’ Processor.
2.3. Famly shall process Customer Data only on documented instructions from the Customer, unless required to do so by the GDPR or any other applicable law to which Famly is subject. Such instructions shall be specified in this DPA and Appendices A and C. Subsequent instructions can also be given by the Customer throughout the duration of Processing of Customer Data, but such instructions shall always be documented and kept in writing, including electronically, in connection with this DPA.
2.4. Famly shall immediately inform the Customer if instructions given by the Customer, in the opinion of Famly, contravene the GDPR. Famly is entitled to suspend performance on such instruction until the Customer confirms or modifies such instruction
2.5. Famly may access Customer Data on a limited and need-to-know basis for the purposes of providing support, troubleshooting and maintaining the Platform, provided that such access is solely for the purpose of delivering the Services in accordance with the Agreement and DPA.
3.1. The subject matter and nature of Processing of Customer Data by Famly is the performance of the Services pursuant to the Agreement and the purposes set forth in this DPA. The Customer and/or its Authorised Users upload/insert the Customer Data to the Platform, and the types of Customer Data processed depend on the Customer use of the Services. The nature, purpose of Processing, the types of Customer Data and categories of Data Subjects that may be processed under this DPA is further specified in Appendix A.
3.2. The Processing of Customer Data shall continue for the duration of the Agreement and this DPA and for 60 days after termination, unless the Customer requests earlier deletion, performs a deletion themselves, or as otherwise specified in Appendix A.
4.1. Famly is responsible for implementing technical and organisational measures to ensure the adequate protection of the Customer Data, which measures must fulfil the requirements of the GDPR and ensure ongoing security, confidentiality, integrity, availability and resilience of processing systems and Services. Such measures are described in Appendix C of this DPA.
4.2. Famly shall regularly review, assess and update, as necessary, these measures to address evolving security risks, industry standards, technological advancements, and regulatory changes. Famly reserves the right to modify the measures and safeguards implemented, provided that the level of security is not less protective than initially agreed upon. In the event of considerable changes to the measures, Famly shall notify the Customer of the changes.
4.3. Famly warrants that the company fulfils its obligations under the GDPR to implement a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
4.4. The Customer is familiar with the technical and organisational measures set out in Appendix C, and it shall be the Customer’s responsibility that such measures ensure a level of security appropriate to the risk.
5.1. Famly will keep the Customer Data confidential. This obligation persists without time limitation and will survive the termination or expiration of the Agreement and this DPA.
5.2. Famly shall only grant access to the Customer Data being processed on behalf of the Customer to persons under Famly’s authority who have committed themselves to confidentiality or are under appropriate statutory obligation of confidentiality and only on a need to know basis. The list of persons to whom access has been granted shall be kept under periodic review. On the basis of this review, such access to personal data can be withdrawn, if access is no longer necessary, and Customer Data consequently not be accessible anymore to those persons.
5.3. Famly shall at the request of the Customer demonstrate that the concerned persons under Famly’s authority are subject to the abovementioned confidentiality.
6.1. Customer generally authorises Famly to appoint Sub-Processors in accordance with this Clause 6. The Customer acknowledges that Famly uses subcontractors that act as Sub-Processors on behalf of the Customer (“Sub-Processor”).
6.2. The Customer agrees that the Sub-Processors listed in Appendix B are authorised for the purpose of the Processing of the Customer Data under this DPA, giving affirmative consent thereto.
6.3. Famly will, prior to the use of new Sub-Processor or a replacement of Sub-Processor, inform the Customer Point of Contact thereof with at least thirty (30)
days’ prior written notice. The Customer is entitled to object in writing within fourteen (14)
days after receipt of the notice from Famly, provided that such objection is based on reasonable grounds relating to data protection. Famly will evaluate the concerns and discuss possible solutions with the Customer. If these solutions are not reasonably possible in Famly’s discretion and the Customer continues to not approve the change (such approval may not be unreasonably withheld), the Customer may terminate the Agreement by giving fourteen (14)
days’ written notice after having received Famly’s aforementioned decision. If the Customer does not terminate the Agreement within this timeframe, the Customer is deemed to have accepted the respective Sub-Processor. The Customer will receive a refund of any prepaid fees for the period following the effective date of termination in respect of such terminated services. No other claims of the Customer against Famly or of Famly against the Customer may be based on such termination.
6.4. The Customer accepts that an exchange of a Sub-Processor may be required in cases where the reason for the change is outside of Famly’s reasonable control (so-called emergency replacement). Famly will notify the Customer of such change. If the Customer reasonably objects to the use of this Sub-Processor, the Customer may exercise its right to terminate the Agreement as described in the clause above.
6.5. Where Famly engages Sub-Processors, Famly is responsible for ensuring that Famly’s obligations on data protection resulting from the Agreement and this DPA are, to the extent applicable to the nature of the services provided by such Sub-Processor, valid and binding upon subcontracting. Famly will enter into written agreement and will restrict the Sub-Processor (and any new Sub-Processors) access to Customer Data only to what is necessary to provide or maintain the Services in accordance with the Agreement and this DPA.
6.6. If the Sub-Processor does not fulfil its data protection obligations, Famly will remain fully liable to the Customer as regards the fulfilment of the obligations of the Sub-Processors. Famly’s liability will be to the same extent as if Famly were directly performing those services, but within limitations of liability set out in this DPA and Agreement.
7.1. The location(s) of the Customer Data is set out in Appendix B to this DPA..
7.2. Subject to Authorised Sub-Processors in Appendix B, Famly will not transfer the Customer Data outside the EEA and/or Switzerland without following the notification and objection process set out in clause 6.3.
7.3. Customer Data may be transferred from the EEA and/or Switzerland to countries that have been recognised as providing an adequate level of data protection, either through an adequacy decision by the European Commission or by the relevant data protection authorities of Switzerland (“Adequacy Decisions”), as applicable, without any further safeguards being necessary.
7.4. If the processing of the Customer Data includes a transfer from the EEA and/or Switzerland to other countries which have not been subject to relevant Adequacy Decision (“Third Country Transfer”), the transfer shall be secured following the undertaking by Famly of a transfer risk assessment/transfer impact assessment (under EU and/or Swiss law as applicable to the Customer), through the implementation, and negotiation if applicable, of an agreement incorporating the appropriate Transfer Mechanism. If the Transfer Mechanism is insufficient to safeguard the transferred Customer Data, supplementary measures will be implemented to ensure the Customer Data is protected to the same standard as required under the GDPR, including those set out in Appendix D. The Customer acknowledges and agrees that Famly has incorporated the appropriate Transfer Mechanism into all agreements with Sub-Processors in third countries, where Adequacy Decision is not in place, ensuring that such Third Country Transfer comply with the GDPR.
8.1. Customer may delete Customer Data using the functionality provided by the Services. Where the Customer is unable to perform the deletion and/or correction of the Customer Data, Famly must perform the action if so instructed by the Customer and permitted under the GDPR. Where a deletion request relating to Customer Data, consistent with the GDPR or a corresponding restriction of Processing is impossible, Famly will, based on the Customer’s instructions, and unless agreed upon differently in the Agreement, destroy or otherwise put out of use if so instructed, in compliance with the GDPR, all Customer Data or return the same to the Customer.
8.2. Within 60 days following the termination of the Agreement, Famly shall, upon the Customer’s instructions, return all Customer Data to the Customer or delete the same, unless required otherwise by the GDPR. The Customer Data shall be irreversibly deleted and cannot be retrieved and provided to the Customer after such 60 days. In specific cases designated by the Customer, Customer Data will be stored. The associated remuneration and protective measures will be agreed upon separately, unless already agreed upon in the Agreement.
9.1. Where a Data Subject asserts claims for rectification, erasure, objection or access (“Data Subject Request”) against Famly, and where Famly is able to correlate the Data Subject to the Customer, based on the information provided by the Data Subject, Famly will without undue delay refer such Data Subject to contact the Customer directly.
9.2. Famly will, based upon the Customer’s instructions, support the Customer to the extent reasonably possible in fulfilling a Data Subject Request, where the Customer cannot do so without Famly’s assistance. Famly will not be liable in cases where the Customer fails to respond to the Data Subject’s request in total, correctly, or in a timely manner.
10.1. Famly will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of any unauthorised or unlawful Processing, alteration, loss, destruction or disclosure of, or damage or access to the Customer Data (“Data Breach”) that occurs within Famly’s scope of responsibility. This includes Data Breaches involving any Sub-Processors engaged by Famly, to the extent Famly becomes aware of such breach. Famly will implement the measures necessary for securing Customer Data and for mitigating potential negative consequences for the Data Subject. Famly will coordinate such efforts with the Customer without undue delay.
10.2. Famly will support the Customer, to the extent reasonably possible and only where the Customer cannot do so without Famly’s assistance, in communicating Data Breaches to the affected Data Subjects and notifying Data Breaches to the applicable Supervisory Authority (provided that this support does not result in any breach of Famly’s confidentiality obligations towards third parties).
11.1 To the extent that the required information is available to Famly, and the Customer does not otherwise have access to the required information, Famly will, upon written request, provide reasonable assistance to the Customer with any data protection impact assessment, and prior consultations with applicable Supervisory Authorities or the extent required under the GDPR.
12.1. Famly will on an annual basis undergo an independent external audit of information security and measures pursuant to this DPA. Famly will document Famly’s compliance with the technical and organisational measures agreed upon in this DPA by appropriate measures.
12.2. To the extent required under the GDPR and upon the Customer written request, Famly will provide the Customer with all information necessary to demonstrate compliance under this DPA and provide a copy of an independent external audit report, as may be applicable. The documentation is Famly’s confidential information and must be treated as such. ¨
12.3. The Customer agrees to exercise its audit and inspection rights by instructing Famly to share the audit report summary as described in clause 12.2 of this DPA. If the Customer reasonably concludes that an onsite audit is necessary to monitor the compliance with the technical and organisational measures in an individual case or compliance with this DPA, the Customer has the right to carry out respective onsite inspections in individual cases or to have them carried out by an auditor (that is no competitor of Famly) provided that such audits or inspections will be conducted (i)
during regular business hours, and (ii)
without disproportionately interfering with Famly’s business operations, (iii)
upon prior reasonable notice and further consultation with Famly, (iv)
all subject to (if not covered already by the Agreement) the execution of a confidentiality undertaking, in particular to protect the confidentiality of the technical and organisational measures and safeguards implemented. Onsite audit or inspection may be unannounced where the Customer has a legally binding request by a Supervisory Authority or a documented suspicion of a material breach or non-compliance with Applicable Data Protection Laws. Justification of unannounced audit or inspection must be provided at the time of arrival.
12.4. In case of an onsite audit or inspection the Customer will bear its own expenses and compensate Famly the cost for its internal resources required to conduct the onsite audit or inspection (based on time and material according to the then current price list). If the audit or inspection reveals that Famly has breached its obligations under the Agreement or this DPA, Famly will promptly remedy the breach at its own cost and refund any payments made by the Customer towards the cost of Famly’s internal resources related to the Customer onsite audit or inspection.
13.1. Famly stores Customer Data in the Application Log (the “Application Log Data”) for 60 days.
13.2. The Application Log Data is used by Famly for demonstrating compliance with regulatory and legal requirements, and for the purposes of ensuring good functioning of the Platform, only.
13.3. Access to the Application Log Data is strictly limited to the above use cases.
a) Should Customer require access to the Application Log Data for the purposes of regulatory or legal compliance, safeguarding, audit, or other similar purpose, Famly can provide access to the Customer.
13.4. Should Customer engage a Linked Service Provider, as defined in the Famly Terms & Conditions, then Famly may provide an Open API for access to certain Customer Data to enable the functioning of the Linked Services. Customer is solely responsible for ensuring that the Linked Service Provider provides sufficient protection for Personal Data, as required by the GDPR. Under no circumstances will a Linked Service Provider be considered a sub-processor to Famly of the Customer Data.
14.1. Where a Data Subject asserts any claims against the Customer as permitted by Article 82 of the GDPR, Famly will provide all reasonable assistance to the Customer in defending against such claims.
14.2. The clause above will apply, mutatis mutandis, to claims asserted by Data Subjects against Famly in accordance with the GDPR.
15.1. This DPA and Processing will continue in force until 60 days after the termination of the Agreement, except where this DPA stipulates obligations beyond the term of the Agreement.
16.1. Famly is only liable for data protection losses, costs and expenses incurred as a result of i) Famly not complying with its obligations under this DPA; ii) Famly not complying with its Processor obligations under the GDPR; or iii) Famly’s Authorised Sub-Processor not complying with its data protection obligations (whether imposed under contract to Famly or by the GDPR).
16.2. Each Party’s total aggregate liability arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in Clause 15 of the Agreement, unless otherwise agreed.
16.3. Subject to clause 16.1 and 16.2, each party (the “Indemnifying Party”) will indemnify the other Party (the “Indemnified Party”) against all claims and proceedings and all liability, loss, costs and expenses incurred by the Indemnified Party as a result of any claim made or brought by a Data Subject or other legal person in respect of any loss, damage or distress caused to them, or any fine imposed by a regulatory authority, as a result of any breach of the GDPR by the Indemnifying Party, its employees or agents, provided that the Indemnified Party gives to the Indemnifying Party prompt notice of such claim, full information about the circumstances giving rise to it, reasonable assistance in dealing with the claim and sole authority to manage, defend or settle it.
17.1. Where the Customer Data becomes subject to search and seizure, an attachment order, confiscation during bankruptcy or insolvency proceedings, or similar events or measures by third parties while in Famly’s control, Famly will notify the Customer of such action without undue delay and follow the Customer’s reasonable instructions to preserve the confidentiality of the Customer Data. Famly will, without undue delay, notify to all pertinent parties in such action, that any Customer Data affected thereby is in the Customer’s sole property and area of responsibility, that Customer Data is at the Customer’s sole disposition, and that the Customer is the responsible body in the sense of the GDPR.
17.2. Clause 21 of the Agreement regarding Famly‘s right to amend the terms of the Agreement applies to changes to this DPA as this DPA forms part of the Agreement. For the avoidance of doubt, this does not apply to notifications of new Sub-Processors under clause 6.3.
17.3. Famly has appointed a Data Protection Officer, who is responsible for matters relating to privacy and data protection. This Data Protection Officer can be reached at the following address:
Attn. Data Protection Officer
Købmagergade 19, 2. tv.
1150 Copenhagen K
Denmark
privacy@famly.co
18.1. The Parties must notify each other of a point of contact for any issues related to data protection arising out of or in connection with the Agreement and this DPA.
18.2. For any such matters, the Customer can reach out to the Famly Security & Privacy Team at privacy@famly.co.
18.3. The Customer will inform Famly of its point of contact (“Customer Point of Contact”). Such contact shall be the main point of contact when Famly is assisting with Data Subject Requests, informing of Data Breaches, and informing the Customer of new Sub-Processors or amendments to this DPA.
19.1. Except as amended by this DPA, the Agreement will remain in full force and effect. In case of any conflict, the GDPR shall take precedence over the regulations of this DPA. Where individual regulations of this DPA are invalid or unenforceable, the validity and enforceability of the other regulations of this DPA shall not be affected.
19.2. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (i)
any Transfer Mechanism, (ii)
Appendix D (Swiss Federal Data Privacy Act), Appendix E (Supplemental Clauses to the Transfer Mechanisms), (iii)
this DPA, and (iv)
the Agreement.
Clause 25 of the Agreement (Governing Law and Dispute Resolution) shall apply to this DPA.
Nature, Purpose of Processing, Type of Personal Data and Categories of Data Subjects:
The subject matter and nature of Famly’s Processing of Customer Data is the performance of the Services pursuant to the Agreement and the purposes set forth below:
Duration of Processing:
The general retention period is set out in clause 3.2 of the DPA. The table below sets out specific retention periods related to specific Authorised Sub-Processors:
As set out in clause 6.2 the Customer agrees that the following Sub-Processors are authorised for the purpose of the Processing of the Customer Data under this DPA, giving affirmative consent thereto:
†Twilio has Binding Corporate Rules (BCRs) approved by a Supervisory Authority within the EU, meaning that it is bound by GDPR across all of its operations, globally. Its approved processor BCRs require it to handle the data of third-party Controllers located in the EU compliantly with the GDPR.
Famly has in place certain technical and organisational security measures to ensure compliance with the Applicable Data Protection Laws. Those measures are set in place to prevent improper destruction, alteration, disclosure, access, and other improper form of Processing of Customer Data.
Famly reserves the right to modify the measures and safeguards implemented, provided that the level of security is not less protective than initially agreed upon. In the event of considerable changes to the measures, Famly shall notify the Customer of such changes.
Unauthorized access (in the physical sense) must be prevented.
Technical and organizational measures to control access to premises and facilities, particularly to check authorization:
Unauthorized access to IT systems must be prevented.
Technical and organisational measures for user identification and authentication:
Activities in IT systems not covered by the allocated access rights must be prevented.
Requirements-driven definition of the authorization scheme and access rights, and monitoring and logging of accesses:
a) Authorization
b) Login, Username and Passwords
c) Confidentiality
Data collected for different purposes must also be processed separately.
Measures to provide for separate processing (storage, amendment, deletion, transmission) of data for different purposes:
Aspects of the disclosure of Personal Data must be controlled: electronic transfer, data transmission, etc.
Measures to transport, transmit and communicate or store data on data media (manual or electronic) and for subsequent checking:
Full documentation of data management and maintenance must be maintained.
Measures for subsequent checking whether data have been entered, changed or removed (deleted), and by whom:
The data must be protected against accidental destruction or loss.
Measures to assure data security:
Security Breach Procedure
Order or Contract Control
Audit
For Customers resident or using the Services in Switzerland, the following Appendix shall apply and is accepted in its entirety.
1. Applicability:
a) This Appendix shall modify the DPA, inclusive of Appendix C thereto, to which it is attached solely in the case that the Customer accepting the DPA is a resident of, or is using the Services in, the territory of the Swiss Confederation.
2. Integral Part of the Data Protection Agreement:
b) Subject to Clause 1 of this Appendix D, above, this Appendix D, and all changes made by it to the text of the DPA, shall be read, construed, and understood as though they were written in that DPA originally, and form an inseparable and integral part of that DPA. Any clauses, sections, charges, stipulations, requirements or other provisions in that DPA not amended by this Annex 2 shall apply, mutatis mutandis.
3. Definitions:
a) All references to GDPR in the DPA shall be replaced with references to the nFADP. The reference to Article 82 in Clause 14.1 of the DPA shall be read as reference to Article 32 of the nFADP.
b) All references to a supervisory authority shall be understood to refer to the Federal Data Protection and Information Commissioner of the Swiss Confederation.
c) All other such similar definitional changes, wherein changing the text of the DPA to ensure compliance, and the action actually taken by Famly would factually render Famly compliant with the nFADP, shall be considered to have been made.
4. Notification of Breach:
a) Clause 10.1 of the DPA shall be replaced in its entirety with the following text:
I) Famly will notify the Customer as soon as possible upon becoming aware of any unauthorised or unlawful Processing, alteration, loss, destruction or disclosure of, or damage or access to the Customer Data within Famly’s scope of responsibility, on any Sub-Processor that may be Processing Customer Data on its behalf (“Data Breach”). Famly will implement the measures necessary for securing Customer Data and for mitigating potential negative consequences for the Data Subject. Famly will coordinate such efforts with the Customer without undue delay.
1. Personal Data will be encrypted both in transit and at rest using industry standard encryption technology.
2. Famly will resist, to the extent permitted by applicable law, any request under Section 702 of Foreign Intelligence Surveillance Act (“FISA”).
3. Famly will use reasonably available legal mechanisms to challenge any demands for data access through the national security process that it may receive in relation to Customer’s data.
4. No later than the date on which your acceptance of the DPA becomes effective, Famly will notify you of any binding legal demand for the Personal Data it has received, including national security orders and directives, which will encompass any process issued under Section 702 of FISA, unless prohibited under applicable law.
5. Famly will ensure that its data protection officer has oversight of Famly's and its Affiliates’ approach to international data transfers.