Gluu

Data Processing Agreement

For the purposes of Article 28(3) of Regulation 2016/679 (the GDPR).

This Data Processing Agreement (the “DPA”) sets out the data-processing obligations of Gluu (the “data processor”) and the Customer (the “data controller”) — each a “party” and together “the parties” — and forms part of the Agreement.

The Customer / data controller, in accordance with the Terms and Conditions, is you as the account owner using Gluu’s Service.

The parties have agreed on the following Contractual Clauses (the “Clauses”) in order to meet the requirements of the GDPR and to ensure the protection of the rights of the data subject.

1. Table of contents

  • 2. Preamble
  • 3. The rights and obligations of the data controller
  • 4. The data processor acts according to instructions
  • 5. Confidentiality
  • 6. Security of processing
  • 7. Use of sub-processors
  • 8. Transfer of data to third countries or international organisations
  • 9. Assistance to the data controller
  • 10. Notification of personal data breach
  • 11. Erasure and return of data
  • 12. Audit and inspection
  • 13. The parties’ agreement on other terms
  • 14. Commencement and termination
  • 15. Contacts / contact points
  • Appendix A — Information about the processing
  • Appendix B — Authorised sub-processors
  • Appendix C — Instructions pertaining to the use of personal data

2. Preamble

These Clauses set out the rights and obligations of the data controller and the data processor when processing personal data on behalf of the data controller.

The Clauses have been designed to ensure the parties’ compliance with Article 28(3) of Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the General Data Protection Regulation).

In the context of providing an online business process management tool, the data processor will process personal data on behalf of the data controller in accordance with the Clauses.

The Clauses take priority over any similar provisions contained in other agreements between the parties.

Three appendices are attached to the Clauses and form an integral part of them:

  • Appendix A contains details about the processing, including its purpose and nature, the type of personal data, the categories of data subject and the duration of the processing.
  • Appendix B contains the data controller’s conditions for the data processor’s use of sub-processors and a list of authorised sub-processors.
  • Appendix C contains the data controller’s instructions regarding the processing, the minimum security measures to be implemented by the data processor, and how audits are to be performed.

The Clauses and their appendices shall be retained in writing, including electronically, by both parties.

The Clauses do not exempt the data processor from obligations to which it is subject under the GDPR or other legislation.

3. The rights and obligations of the data controller

The data controller is responsible for ensuring that the processing of personal data complies with the GDPR (see Article 24 GDPR), the applicable EU or Member State data protection provisions and the Clauses.

The data controller has the right and obligation to make decisions about the purposes and means of the processing of personal data.

The data controller is responsible, among other things, for ensuring that the processing which the data processor is instructed to perform has a legal basis.

4. The data processor acts according to instructions

The data processor shall process personal data only on documented instructions from the data controller, unless required to do otherwise by EU or Member State law to which the processor is subject. Such instructions are specified in Appendices A and C. Subsequent instructions may also be given by the data controller throughout the duration of the processing, but such instructions shall always be documented and kept in writing, including electronically, in connection with the Clauses.

The data processor shall immediately inform the data controller if, in the data processor’s opinion, an instruction contravenes the GDPR or the applicable EU or Member State data protection provisions.

5. Confidentiality

The data processor shall grant access to the personal data being processed on behalf of the data controller only to persons under the data processor’s authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only on a need-to-know basis. The list of persons granted access shall be kept under periodic review, and access shall be withdrawn where it is no longer necessary.

At the data controller’s request, the data processor shall demonstrate that the persons concerned are subject to the confidentiality obligation described above.

6. Security of processing

Article 32 GDPR provides that, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the data controller and data processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Depending on their relevance, these measures may include:

  • pseudonymisation and encryption of personal data;
  • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident; and
  • a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures.

The data processor maintains an information security management system based on ISO/IEC 27001: 2022. Under Article 32 GDPR, the data processor shall — independently of the data controller — evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. To this effect, the data controller shall provide the data processor with all information necessary to identify and evaluate such risks.

The data processor shall also assist the data controller in ensuring compliance with the data controller’s obligations under Article 32 GDPR, among other things by providing information about the technical and organisational measures already implemented. If, in the data controller’s assessment, mitigation of the identified risks requires measures beyond those already implemented, the data controller shall specify the additional measures in Appendix C.

7. Use of sub-processors

The data processor shall meet the requirements of Article 28(2) and (4) GDPR in order to engage another processor (a “sub-processor”).

The data processor has the data controller’s general authorisation to engage sub-processors. The data processor shall inform the data controller in writing of any intended change concerning the addition or replacement of a sub-processor at least 20 days in advance, giving the data controller the opportunity to object before the sub-processor is engaged. The list of sub-processors already authorised by the data controller is set out in Appendix B.

Where the data processor engages a sub-processor, the same data protection obligations set out in the Clauses shall be imposed on that sub-processor by way of a contract or other legal act under EU or Member State law — in particular, providing sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the Clauses and the GDPR. The data processor remains responsible for ensuring that the sub-processor at least complies with the obligations to which the data processor is subject under the Clauses and the GDPR.

At the data controller’s request, a copy of such a sub-processor agreement — and any subsequent amendments — shall be submitted to the data controller, so that the data controller can verify that the same data protection obligations are imposed on the sub-processor. Provisions on business-related issues that do not affect the data protection content of the sub-processor agreement do not need to be submitted.

The data processor shall agree a third-party beneficiary clause with the sub-processor whereby — in the event of the data processor’s bankruptcy — the data controller becomes a third-party beneficiary and may enforce the agreement against the sub-processor, for example to instruct the sub-processor to delete or return the personal data.

If the sub-processor fails to fulfil its data protection obligations, the data processor remains fully liable to the data controller for the performance of the sub-processor’s obligations. This does not affect the rights of data subjects under the GDPR — in particular those under Articles 79 and 82 GDPR — against the data controller, the data processor and the sub-processor.

8. Transfer of data to third countries or international organisations

Customer data on the Gluu platform is hosted within the EU (Northern Europe — for example, Dublin and Amsterdam). Backup, storage and redundancy are handled within Microsoft’s Northern European data centres.

Where an optional feature relies on a sub-processor that processes data outside the EU/EEA (see Appendix B), any such transfer takes place only in compliance with Chapter V GDPR, using an appropriate transfer tool — an adequacy decision, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses. Any other transfer of personal data to a third country or international organisation shall occur only on documented instructions from the data controller.

Where a transfer to a third country or international organisation that the data controller has not instructed is required under EU or Member State law to which the data processor is subject, the data processor shall inform the data controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

Without documented instructions from the data controller, the data processor cannot, within the framework of the Clauses:

  • transfer personal data to a data controller or data processor in a third country or an international organisation;
  • transfer the processing of personal data to a sub-processor in a third country; or
  • have the personal data processed by the data processor in a third country.

The data controller’s instructions regarding the transfer of personal data to a third country, including the applicable transfer tool under Chapter V GDPR, are set out in Appendix C.6.

The Clauses shall not be confused with standard data protection clauses within the meaning of Article 46(2)(c) and (d) GDPR, and cannot be relied upon by the parties as a transfer tool under Chapter V GDPR.

9. Assistance to the data controller

Taking into account the nature of the processing, the data processor shall assist the data controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the data controller’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. This means the data processor shall, insofar as possible, assist the data controller in complying with:

  • the right to be informed when personal data is collected from the data subject;
  • the right to be informed when personal data has not been obtained from the data subject;
  • the right of access by the data subject;
  • the right to rectification;
  • the right to erasure (“the right to be forgotten”);
  • the right to restriction of processing;
  • the notification obligation regarding rectification or erasure of personal data or restriction of processing;
  • the right to data portability; and
  • the right to object.

In addition, taking into account the nature of the processing and the information available to it, the data processor shall assist the data controller in ensuring compliance with:

  • the data controller’s obligation to notify a personal data breach to the competent supervisory authority (the Danish Data Protection Agency) without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons;
  • the data controller’s obligation to communicate a personal data breach to the data subject without undue delay, where the breach is likely to result in a high risk to the rights and freedoms of natural persons;
  • the data controller’s obligation to carry out a data protection impact assessment; and
  • the data controller’s obligation to consult the competent supervisory authority before processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of mitigating measures.

The parties define in Appendix C the appropriate technical and organisational measures by which the data processor assists the data controller, as well as the scope and extent of that assistance.

10. Notification of personal data breach

In the event of a personal data breach, the data processor shall notify the data controller without undue delay after becoming aware of it, and where possible within 72 hours, so that the data controller can comply with its obligation to notify the competent supervisory authority under Article 33 GDPR.

In accordance with Clause 9, the data processor shall assist the data controller in notifying the breach to the competent supervisory authority, which means the data processor is required to help obtain the following information required under Article 33(3) GDPR:

  • the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned;
  • the likely consequences of the breach; and
  • the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.

The parties define in Appendix C all the elements to be provided by the data processor when assisting the data controller in notifying a personal data breach.

11. Erasure and return of data

On termination of the personal data processing services, the data processor shall delete all personal data processed on behalf of the data controller and certify to the data controller that it has done so, unless EU or Member State law requires storage of the personal data. See Appendix C.4 for the applicable storage period and erasure procedure.

12. Audit and inspection

The data processor shall make available to the data controller all information necessary to demonstrate compliance with Article 28 GDPR and the Clauses, and shall allow for and contribute to audits, including inspections, conducted by the data controller or another auditor mandated by the data controller. Procedures for such audits are set out in Appendix C.7.

The data processor shall provide supervisory authorities that have access under applicable legislation — or their representatives — with access to the data processor’s physical facilities on presentation of appropriate identification.

13. The parties’ agreement on other terms

The parties may agree other clauses concerning the personal data processing service — for example, specifying liability — as long as they do not directly or indirectly contradict the Clauses or prejudice the fundamental rights and freedoms of the data subject or the protection afforded by the GDPR.

14. Commencement and termination

The Clauses become effective on the date the Customer / data controller creates their account.

Either party is entitled to require the Clauses to be renegotiated if changes to the law or the inexpediency of the Clauses give rise to such renegotiation.

The Clauses apply for the duration of the personal data processing services. During that period, the Clauses cannot be terminated unless other clauses governing the provision of the services have been agreed between the parties.

If the personal data processing services are terminated, and the personal data is deleted or returned to the data controller in accordance with Clause 11 and Appendix C.4, the Clauses may be terminated by written notice from either party.

15. Contacts / contact points

On behalf of the data processor:

NameSøren Pommer
PositionCEO
Phone+45 7230 2070
E-mailspommer@gluu.biz

The parties may contact each other using the contact points above. Each party shall keep the other continuously informed of changes to its contact points.

Appendix A — Information about the processing

A.1. Purpose of the processing

The purpose of the data processor’s processing of personal data on behalf of the data controller is:

  • reporting on the data controller’s employees and their usage of the Gluu system; and
  • collection and storage of personally identifiable information in relation to hosting.

A.2. Nature of the processing

The processing mainly involves listing usage patterns associated with named users.

A.3. Types of personal data

The processing includes the following types of personal data: name, email address, telephone number, address and payment details (card).

A.4. Categories of data subject

The processing includes the following categories of data subject: the data controller’s employees, and external consultants working for the data controller.

A.5. Duration of the processing

Processing may be performed from the date the Clauses commence and continues for as long as the data controller has an account on the Gluu system. Following termination, personal data is retained and erased as set out in Appendix C.4.


Appendix B — Authorised sub-processors

B.1. Approved sub-processors

On commencement of the Clauses, the data controller authorises the engagement of the following sub-processors:

NameReg. no.AddressDescription of processing
Microsoft (data centre — South County Business Park)IE8256796UOne Microsoft Place, Carmanhall and Leopardstown, Dublin, D18 P521, IrelandHosting of the data controller’s own data and the data processor’s internal data.
Stripe Payments Europe LtdIE3208141BH1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, IrelandInvoicing system. Data processor’s internal data.
Pipedrive OÜIE3626566WHRiverside One, Sir John Rogerson’s Quay, Dublin 2, D02 X576, IrelandCRM system. Data processor’s internal data.
OpenAI Ireland Ltd737350 (CRO)1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, IrelandOptional AI assistant features for process improvement and content generation. Each AI-powered operation can be enabled or disabled individually by an account administrator. When enabled, it is clearly indicated which process data is sent to OpenAI’s API; only the content associated with the selected operation is transmitted. No personal data is sent unless it has been explicitly added by your users within work instructions or related process content. Data is handled under OpenAI’s Enterprise Privacy terms.

All other sub-processors are used for the data processor’s internal data handling. The data processor shall not — without the data controller’s explicit written authorisation — engage a sub-processor for processing different from that agreed, or have another sub-processor perform the described processing.

B.2. Prior notice for the authorisation of sub-processors

The data controller may accept or reject a new sub-processor within 20 days of receiving notice of the intended change (see Clause 7). Any rejection must state a valid, business-related reason.


Appendix C — Instructions pertaining to the use of personal data

C.1. Subject of the instruction

The data processor’s processing of personal data on behalf of the data controller consists of:

  • reporting on the data controller’s employees and their usage of the Gluu system; and
  • collection and storage of personally identifiable information in relation to hosting.

C.2. Security of processing

The data processor maintains an information security management system certified to ISO/IEC 27001, and applies the technical and organisational measures required to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR and Clause 6. These measures include access controls on a need-to-know basis, encryption of data in transit, EU-based hosting with backup and redundancy, and regular testing and review of security effectiveness.

Given the nature of the processing — routine reporting and hosting involving general (non-sensitive) personal data — the parties agree that these measures are appropriate. Should the data controller require additional measures, such as further encryption or pseudonymisation, these shall be specified here by written agreement.

C.3. Assistance to the data controller

The data processor shall, insofar as possible, assist the data controller in accordance with Clause 9.

C.4. Storage period and erasure procedure

Personal data is stored for the duration of the contract and for a further 12 months after termination, after which it is automatically erased by the data processor. On termination of the personal data processing services, the data processor shall either delete or return the personal data in accordance with Clause 11, unless the data controller has — after signing the contract — modified its original choice. Any such modification shall be documented and kept in writing, including electronically, in connection with the Clauses.

C.5. Processing location

Processing under the Clauses may not be performed at locations other than within the EU/EEA without the data controller’s prior written authorisation.

C.6. Instruction on the transfer of personal data to third countries

The data processor may transfer personal data to a third country only with the data controller’s prior written consent, or to an entity certified under the EU-U.S. Data Privacy Framework, or under another valid transfer tool permitted by Chapter V GDPR.

C.7. Audit procedures

The data controller, or its representative, may inspect the places where the data processor carries out the processing — including physical facilities and the systems used — to verify the data processor’s compliance with the GDPR, the applicable data protection provisions and the Clauses. The data processor’s ISO/IEC 27001 certification and related documentation may be provided to satisfy all or part of such an inspection.

In addition to any planned inspection, the data controller may inspect the data processor when it deems this necessary. The data controller bears its own costs relating to an inspection; the data processor shall, however, set aside the resources (mainly time) required for the inspection to take place.

References to “Member States” throughout the Clauses shall be understood as references to “EEA Member States”.

Updated 17 July 2026.