Terms and agreements

Data processing agreement

Revised7 August 2026 In force from7 August 2026

The agreement under article 28 of the GDPR, which applies when you use the portal for your own receivables management. It sets out what we may do with your data, what we must do when you ask us for something — and what happens to all of it if you stop.

§ 1

The parties

This data processing agreement is entered into between the client as controller and Rieck as processor. The client is the company that has created an account in the portal.

The processor is:

Company
Rieck Inkasso ApS
Address
Østergade 4, ground floor, 8370 Hadsten, Denmark
Company reg. no.
41645369
Phone
35 15 47 65

The agreement is entered into as the client creates an account or otherwise begins using the portal, cf. § 2 of the terms of business. It is an addendum to the terms of business and cannot be terminated separately for as long as the client uses the portal.

§ 2

When the agreement applies — and when it does not

Rieck holds two different roles in relation to the same information, and this agreement covers only one of them. The distinction determines what the client may instruct us to do:

The portal — the agreement applies
When the client uses the portal for its own receivables management — invoices, reminders, dunning letters, customer records and reports — Rieck processes personal data on the client’s behalf and on the client’s instructions. Here Rieck is a processor, and this agreement applies.
Collection services — the agreement does not apply
Once a case passes to collection, Rieck becomes an independent controller. As an authorised debt-collection firm we make our own decisions about how the case is conducted, and we are subject to the collection legislation and the supervision of Rigspolitiet (the Danish National Police). The client cannot instruct us in that processing, and no data processing agreement is required for it.

The processing of information about debtors in collection cases is described in the privacy policy for debt collection. The client must itself ensure it has a basis for disclosing personal data to Rieck when a case is created.

The same applies to the usage data Rieck collects about the use of the portal itself, cf. § 20 of the terms of business. Rieck is an independent controller for that data.

§ 3

Processing on instructions

Rieck processes personal data only on documented instructions from the client. The instructions are this agreement, the terms of business, and the use the client itself makes of the portal’s functions.

Rieck may not process the information for its own purposes beyond what the agreement permits, and does not disclose it to third parties without instructions — unless required to do so under EU or Danish law. Where that occurs, Rieck notifies the client of the requirement before processing takes place, unless notification is prohibited.

Rieck immediately notifies the client if, in Rieck’s opinion, an instruction infringes data protection law.

§ 4

Confidentiality

Rieck ensures that only those employees with a work-related need have access to the personal data processed on the client’s behalf. Access is removed once the need ceases.

Employees are bound by confidentiality, either by a confidentiality undertaking or by an equivalent statutory duty of secrecy. Confidentiality continues after the employment ends.

§ 5

Security of processing

Rieck implements appropriate technical and organisational measures under article 32 of the GDPR, so that the level of security matches the risk to the rights of data subjects.

The measures are described in § 16 and on the security page. Rieck may change them as technology or the threat picture changes, but never so that the level of protection is reduced.

The client is itself responsible for the measures within its own control: that user accounts are granted the correct permissions, that access is closed when an employee leaves, and that account credentials are not shared.

§ 6

Use of sub-processors

The client grants Rieck a general authorisation to use sub-processors — typically for hosting, operations, email and letter dispatch, payment processing and support.

The current sub-processors appear on the public list, which forms part of this agreement. Rieck gives at least 30 days’ notice of additions and replacements on that list before the new sub-processor is put to use.

The client may object to a new sub-processor before the notice period expires. If the parties cannot find a solution, the client may terminate the use of the affected parts of the portal at no cost. An objection is not a right to halt Rieck’s operations for other customers.

Rieck enters into a written agreement with each sub-processor imposing the same obligations as this agreement, and is liable to the client for the sub-processor’s processing as for its own.

§ 7

Transfers to third countries

Personal data is processed within the EU/EEA as a general rule.

Where information is transferred to a country outside the EU/EEA, it takes place only on a valid transfer basis: an adequacy decision from the European Commission, the Commission’s standard contractual clauses (SCC) or another basis under chapter V of the Regulation, supplemented by any measures that an assessment of the recipient country may require.

The transfer basis for each sub-processor appears on the list. The client may at any time request a copy of the basis.

§ 8

Assistance with data subject rights

If a data subject approaches Rieck directly about information processed on the client’s behalf, Rieck forwards the request to the client without undue delay and does not respond to it itself.

Rieck assists the client with appropriate technical and organisational measures so that the client can meet its obligation to respond to requests for access, rectification, erasure, restriction, data portability and objection.

The assistance is provided at no separate charge to the extent the portal’s own functions suffice. Where a request requires extraordinary manual work, Rieck may invoice the direct costs subject to the client’s prior acceptance.

§ 9

Assistance with the client’s other obligations

Rieck assists the client in complying with articles 32 to 36 of the Regulation, to the extent relevant to processing in the portal, taking into account the nature of the processing and the information available to Rieck. This covers:

  1. Security of processing under article 32 — see § 5 and § 16.
  2. Notification of a personal data breach to Datatilsynet (the Danish Data Protection Agency) under article 33 — see § 10.
  3. Communication of a breach to the data subjects under article 34.
  4. Data protection impact assessments and prior consultation under articles 35 and 36 — Rieck makes available the information about the portal that the assessment requires.

§ 10

Personal data breaches

If Rieck becomes aware of a personal data breach affecting information processed on the client’s behalf, Rieck notifies the client without undue delay.

The notification contains, to the extent the information is available, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, the measures Rieck has taken or proposes, and a point of contact at Rieck.

Where not all information is immediately available, it is provided in phases as it emerges. Rieck does not notify Datatilsynet on the client’s behalf unless separately agreed.

§ 11

Documentation and audit

Rieck makes available the information necessary to demonstrate compliance with the obligations in this agreement and in article 28.

The client may once a year request documentation of Rieck’s security measures. Rieck meets the request by providing existing statements, audit reports or a completed security questionnaire.

If the documentation is not sufficient, the client may require an inspection. It is notified at least 30 days in advance, carried out during normal working hours, must not disrupt operations or give access to other customers’ data, and is performed by the client itself or by an independent auditor bound by confidentiality. The client bears its own and Rieck’s costs of the inspection, unless it uncovers material non-compliance.

Datatilsynet has access at all times under the rules laid down in legislation.

§ 12

Erasure and return on termination

On termination of the client’s use of the portal, Rieck, at the client’s election, erases or returns the personal data processed on the client’s behalf, and deletes existing copies.

The client may export its data under the data portability provisions in § 21 of the terms of business. The request must be made before erasure is carried out.

If the client has had no cases with Rieck for more than 3 months, Rieck may close the account and delete the information, cf. § 15 of the terms of business. The client is itself responsible for securing a copy.

§ 13

Liability and entry into force

The parties are liable under article 82 of the GDPR for damage caused by processing that infringes the Regulation. As between the parties, the limitations of liability in § 13 of the terms of business apply.

The agreement enters into force when the client creates an account and applies for as long as the client uses the portal. The provisions on confidentiality, erasure and documentation also apply after termination.

In the event of a conflict between this agreement and the terms of business regarding the processing of personal data in the portal, this agreement prevails. The agreement is governed by Danish law, and disputes are settled as set out in § 22 of the terms of business.

§ 14

Annex A — Nature and purpose of the processing

Purpose

To make the portal available for the client’s own receivables management: issuing and sending invoices, reminders and dunning letters, recording payments, customer records, reconciliation and reporting.

Nature of the processing

Collection, recording, storage, use, alteration, collation, disclosure on instructions and erasure — performed automatically in the portal and manually where the client enters data itself or support assists.

Categories of data subjects

  • The client’s own customers (debtors) — both businesses and private individuals.
  • Contact persons at the client’s customers.
  • The client’s own users of the portal.

Categories of personal data

Ordinary data
Name, address, email, telephone number, company and job title.
Financial data
Invoices, amounts, due dates, payment history, balances, dunning history and bank details.
Civil registration number
Only where the client records it itself, or where it is necessary to identify a private debtor.
User data
Login, role, permissions and activity log for the client’s own users.

The client must not record special categories of personal data under article 9 in the portal’s free-text fields. If the client nevertheless does so, it falls outside the instructions and is at the client’s own risk.

Duration

The processing continues for as long as the client holds an account, and ceases in accordance with § 12.

§ 15

Annex B — Sub-processors

The approved sub-processors appear on the public list, which is updated on an ongoing basis and constitutes annex B to this agreement. For each supplier, the list states what it is used for, where the processing takes place, and on what basis information is transferred outside the EU/EEA, if applicable.

Changes are notified in accordance with § 6.

§ 16

Annex C — Technical and organisational measures

Rieck has as a minimum implemented the following measures. They are set out in more detail on the security page.

Access control
Role- and need-based access, personal accounts, mandatory two-factor authentication on administrative access, and logging of access to customer data.
Encryption
Traffic is encrypted in transit (TLS). Data is encrypted at rest, including backups.
Separation
Clients’ data is logically separated so that one client can never access another client’s information. Development and test environments do not use production data.
Backup
Regular backups with tested restoration and a documented contingency plan for outages.
Logging and monitoring
Operational and security logging with monitoring for anomalous behaviour and an established procedure for handling security incidents.
Supplier management
Data processing agreements with all sub-processors and ongoing review of their level of security.
Employees
Duty of confidentiality, training in data protection, and immediate closure of access on departure.
Physical security
Operations run in data centres with access control, surveillance and redundant power and network supply.
Questions about the terms

Shall we take you through them
before you sign?

Call us, and an advisor will go through them with you — including the ones that are not in your favour. Better that you know now than in the first case.

Talk to an advisor

Call on any business day or write — we reply within 2 hours on any business day.

35 15 47 65 rieck@rieckflow.com

See the pricing

Subscriptions, payment fees and success fee are itemised in the price matrix — the same figures as in § 3 to § 8 of the terms of business.

Pricing

Complain about collection conduct

Rieck is an authorised debt-collection firm. Rigspolitiet (the Danish National Police) supervises our compliance with god inkassoskik (proper debt-collection practice).

politi.dk
  • 30 days free
  • No payment card
  • One day's notice