---
title: "Data Processing Agreement | Movea"
description: "The data processing agreement between Movea and moving companies that use the system: instructions, security, sub-processors, breaches, deletion and audit under Article 28 of the GDPR."
url: "https://movea.dk/en/data-processing-agreement"
lang: "en"
---

Legal

# Data Processing Agreement

Last updated 4 October 2026

The agreement on how Movea processes personal data on your behalf when you use the system. It is based on Article 28 of the General Data Protection Regulation (GDPR) and on the Danish Data Protection Agency’s standard contractual clauses, and it is part of your agreement on Movea.

01

## Parties and background

This data processing agreement is entered into between the company that has set up a subscription to Movea (the Customer, the controller) and B2X ApS, CVR 46399250, Sofienhøjvej 10, 3. th., 2300 København S (the Processor). Each is referred to as a party and together as the parties.

The Processor provides Movea to the Customer under the terms for Movea (the Main Agreement). When the Customer uses Movea, the Processor processes personal data about the Customer’s own customers, employees and partners on behalf of the Customer. This agreement sets out the rights and obligations of the parties in relation to that processing.

The agreement is designed to comply with Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, the GDPR) and follows the structure of the Danish Data Protection Agency’s standard contractual clauses. Terms defined in Article 4 of the GDPR have the same meaning here.

The agreement is accepted together with the terms for Movea when the Customer sets up a subscription, and is an integral part of the Main Agreement. It has four annexes: Annex A on the processing, Annex B on sub-processors, Annex C on instructions and security, and Annex D on the parties’ other terms.

The agreement only applies to the processing the Processor carries out on behalf of the Customer. Processing for which B2X ApS is itself the controller, for example of the Customer’s contact persons, invoicing and demo requests, is described in the privacy policy.

02

## The rights and obligations of the controller

The Customer is responsible for ensuring that the processing of personal data takes place in compliance with the GDPR, the Danish Data Protection Act and other relevant legislation, cf. Article 24 of the GDPR.

The Customer has the right and the obligation to decide for which purposes and by which means personal data may be processed in Movea.

The Customer is responsible for ensuring that there is a legal basis for the processing the Processor is instructed to carry out, and for fulfilling the duty to inform the data subjects. This applies, among other things, when the Customer sends SMS and email to its own customers and employees through Movea.

03

## The Processor acts on instructions

The Processor may only process personal data on documented instructions from the Customer, unless the processing is required by EU law or Danish law to which the Processor is subject. In that case, the Processor informs the Customer of the legal requirement before the processing, unless that law prohibits such information on important grounds of public interest.

The instructions are set out in this agreement with its annexes and in the Main Agreement. The Customer’s use of the functions in Movea, including setup, integrations and the sending of messages, is a documented instruction. The Customer may give further instructions in writing to info@b2x.dk. Instructions that require development or work beyond the ordinary service are agreed separately.

The Processor immediately informs the Customer if, in the Processor’s opinion, an instruction infringes the GDPR or data protection provisions of other EU law or Danish law. The Processor may await the Customer’s decision before the instruction is carried out.

04

## Confidentiality

The Processor only grants access to personal data processed on behalf of the Customer to persons who are under the Processor’s authority, who have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and only to the extent necessary for their work.

The list of persons with access is reviewed on an ongoing basis. Access is closed when it is no longer necessary.

At the request of the Customer, the Processor can demonstrate that the persons concerned are subject to confidentiality. The duty of confidentiality also applies after the agreement has ended.

05

## Security of processing

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks of the processing, cf. Article 32 of the GDPR. The assessment takes into account the state of the art, the costs, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of natural persons.

The Customer assesses the risks of its own processing itself. The Processor makes an independent assessment of the risks of the processing that takes place in Movea and implements, as a minimum, the measures set out in Annex C.

The Processor assists the Customer in complying with the Customer’s obligations under Article 32 of the GDPR by making available the information necessary for the Customer’s own risk assessment. If the Customer’s assessment requires measures beyond those in Annex C, they and the payment for them are agreed separately.

06

## Sub-processors

The Processor meets the conditions in Article 28(2) and (4) of the GDPR for engaging another processor (a sub-processor).

By this agreement the Customer gives the Processor a general written authorisation to use sub-processors. The sub-processors authorised when the agreement is entered into are listed in Annex B.

The Processor informs the Customer in writing at least 30 days before a sub-processor is added or replaced, by email to the Customer’s account owner or by notice in Movea. Within that time limit the Customer may object, if the objection is objectively justified on data protection grounds. If the parties cannot find a solution, the Customer may terminate the Main Agreement with effect from the time the change takes effect and have prepaid fees for the remaining period refunded.

The Processor imposes on each sub-processor the same data protection obligations as those set out in this agreement, by way of a contract or other legal act under EU law or Danish law, including a requirement for sufficient guarantees of appropriate technical and organisational measures.

If a sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Customer for the sub-processor’s obligations. This does not affect the rights of the data subjects under Articles 79 and 82 of the GDPR.

Services that the Customer itself chooses to connect to Movea, for example an accounting system, are not sub-processors of the Processor. The Customer has its own contractual relationship with that provider, and the transfer to it takes place on the Customer’s instructions.

07

## Transfers to third countries

Any transfer of personal data to third countries or international organisations may only take place on documented instructions from the Customer and always in compliance with Chapter V of the GDPR.

Personal data processed on behalf of the Customer is stored and processed within the EU/EEA at the locations set out in Annex B and Annex C. Without instructions from the Customer, the Processor may not transfer data to a controller or processor in a third country, entrust the processing to a sub-processor in a third country, or have the data processed by the Processor itself in a third country.

If a transfer is required by EU law or Danish law to which the Processor is subject, the Processor informs the Customer of the requirement before the processing, unless that law prohibits it.

Where a sub-processor in Annex B is part of a group with a parent company outside the EU/EEA, the transfer basis is stated there. This agreement is not in itself a transfer basis under Chapter V of the GDPR.

08

## Assistance to the controller

Taking into account the nature of the processing, the Processor assists the Customer, as far as possible, by appropriate technical and organisational measures in responding to requests from data subjects to exercise their rights under Chapter III of the GDPR: the duty to inform, access, rectification, erasure, restriction, notification, data portability, objection and automated decision-making.

Movea is built so that the Customer can itself find, correct, export and delete data about its clients: a client's data can be downloaded as one file, and a client can be deleted, after which the data is erased for good after 30 days, or at once if the Customer so chooses. Data about employees the Customer can itself find, correct and remove; the Processor delivers a complete export of an employee's data on request. If the Processor receives a request directly from a data subject, the Processor forwards it to the Customer without undue delay and does not respond to it itself.

The Processor also assists the Customer in complying with Articles 33 to 36 of the GDPR: notification of breaches to the competent supervisory authority, in Denmark Datatilsynet (the Danish Data Protection Agency), communication to data subjects, data protection impact assessments and prior consultation of the supervisory authority, taking into account the nature of the processing and the information available to the Processor.

For assistance that goes beyond the functions in Movea and ordinary support, the Processor may charge a reasonable fee based on time spent, unless the need is due to the Processor’s own breach of contract.

09

## Notification of personal data breaches

The Processor notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach concerning data processed on behalf of the Customer, so that the Customer can meet its 72-hour time limit under Article 33 of the GDPR.

The notification is sent to the Customer’s account owner and contains, to the extent the information is available, what is set out below. If not everything can be provided at once, the information is provided in phases without undue further delay.

The Processor documents all breaches, including the facts, the effects and the remedial measures, and immediately takes reasonable measures to limit the damage.

- The nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned.
- The likely consequences of the breach.
- The measures the Processor has taken or proposes to take to address the breach and to limit its adverse effects.
- A contact point at the Processor where the Customer can obtain more information.

10

## Deletion and return of data

When the main agreement ends, for whatever reason, the Processor continues to store the Customer's data, so that the Customer can see and export it in a structured, commonly used and machine-readable format, until the Customer requests deletion. The Customer itself chooses whether the data is to be exported or simply deleted.

The Customer can at any time, also while the agreement is running, request that all personal data processed on the Customer's behalf be deleted. The request is made by the Customer's account owner in Movea and confirmed with the account owner's password. The Processor deletes the data from the active systems once 60 days have passed from the request; until then the Customer can withdraw the request. Backups are overwritten according to the fixed rotation and no later than 90 days after that, and are not restored for anything other than deletion in that period.

The deletion also covers user accounts that are not attached to another customer of the Processor. Data in systems the Customer itself has connected, for example an accounting system, is not affected.

The Processor confirms the deletion in writing. Deletion does not take place to the extent that EU law or Danish law requires the Processor to store the data. In that case it is processed only for the purpose and for the period the law requires.

If the Customer deletes a client, a job, a vehicle or equipment while the agreement is running, it can be restored for 30 days. After that the personal data is erased for good from the active systems, including names, contact details, addresses, notes, messages and photos, and from backups according to the same rotation. The Customer can choose to erase a client's data at once. Invoices the Customer has issued, and quotes that have been accepted, are kept unchanged for as long as the Customer must keep them under bookkeeping law.

Without the Customer doing anything, the Processor deletes absence records five years after the absence ended, enquiries from the Customer's website 12 months after the last activity, and comments in reviews after three years. Quotes that have not been accepted lose their link and the details the recipient gave when answering, 12 months after they expired.

11

## Audit and supervision

The Processor makes available all information necessary to demonstrate compliance with Article 28 of the GDPR and this agreement, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

Once a year the Processor prepares a written statement on the technical and organisational measures and on the supervision of sub-processors, and sends it to the Customer on request. The Customer may also put written questions, which the Processor answers within a reasonable time.

If the statement and the answers do not give the Customer sufficient assurance, the Customer may, with at least 30 days’ written notice and no more than once a year, carry out an audit at the Processor, during ordinary working hours and subject to confidentiality. That limitation does not apply in the event of a specific breach or an order from a supervisory authority. The Customer bears its own costs and those of its auditor. The Processor’s time spent beyond one working day per audit may be invoiced based on time spent.

An audit may not give access to information about the Processor’s other customers. The Processor gives supervisory authorities that have access to the Customer’s or the Processor’s facilities under the legislation access upon presentation of proper identification.

The Processor supervises its sub-processors, as described in Annex C, and shares the result with the Customer on request.

12

## Liability and precedence

The parties’ liability to each other for breach of this agreement follows the liability rules and the limitations of liability in the Main Agreement. The limitations do not apply in the event of intent or gross negligence, and they do not limit the data subjects’ right to compensation under Article 82 of the GDPR or a party’s liability for fines or other penalties that a supervisory authority or a court has imposed on that party itself.

In the event of a conflict between this agreement and the Main Agreement or other agreements between the parties, this agreement takes precedence in all matters concerning the processing of personal data. In the event of a conflict between this agreement and the GDPR, the GDPR takes precedence.

The agreement is governed by Danish law, and disputes are settled at the same venue as under the Main Agreement.

13

## Commencement, changes and termination

The agreement takes effect when the Customer sets up a subscription and accepts the terms for Movea, and applies for as long as the Processor processes personal data on behalf of the Customer. It cannot be terminated separately while the Main Agreement is running, and it applies after the Main Agreement has ended until the data has been deleted or returned as described above.

Either party may require the agreement to be renegotiated if changes in the law, practice from a competent supervisory authority or the Court of Justice of the European Union, or inexpediencies in the agreement give rise to it.

The Processor may change the agreement with at least 30 days’ written notice where the change is due to legal requirements, the practice of authorities or changes to the service, and the change does not reduce the protection of the data subjects. Changes to Annex B follow the rules on sub-processors. The version in force is always at movea.dk/en/data-processing-agreement with a date.

The Customer can obtain a signed copy of the agreement by writing to info@b2x.dk.

14

## Annex A: Information about the processing

Purpose. The Processor processes personal data on behalf of the Customer in order to make Movea available: quotes and invoicing, scheduling and calendar, crews and time tracking, routes, vehicles and equipment, damage reports, customer archive, SMS and email sent by the Customer, reports, support and secure operation.

Nature of the processing. Collection, recording, organisation, storage, adaptation, retrieval, use, disclosure by transmission to the recipients the Customer has chosen, combination, restriction, erasure and backup.

Duration. The processing lasts for as long as the Main Agreement is running, and thereafter until deletion has taken place in accordance with the section Deletion and return of data.

Categories of data subjects and types of data are set out below. As a rule, the processing only covers ordinary personal data under Article 6 of the GDPR. The Customer may not enter special categories of data under Article 9, data relating to criminal convictions and offences, or national identification numbers in free-text fields, images or notes, unless this has been agreed in writing with the Processor.

- The Customer’s customers and their contact persons: name, address, email, phone number, move-from and move-to addresses with access conditions, job history, quotes and invoices, messages, internal notes and consent to marketing.
- The Customer’s employees and users: name, email, phone number, role, licence categories, assigned jobs, time entries, activity log, login details and two-factor setup.
- Other persons who appear in jobs, damage reports or images, for example contact persons at an address: the data the Customer chooses to record.
- Recipients of SMS and email sent through Movea: phone number or email, the content of the message and delivery status.

15

## Annex B: Sub-processors

When the agreement takes effect, the Customer has authorised the use of the sub-processors below for the processing described. The Processor may not use a sub-processor for processing other than that described, or have another sub-processor carry it out, without following the rules in the section Sub-processors.

Sub-processors with a parent company in the USA process the data at the EU locations stated. To the extent a transfer to the USA should nevertheless take place, it takes place on the basis of the European Commission’s decision on the EU-U.S. Data Privacy Framework, under which the provider is certified, and otherwise on the European Commission’s standard contractual clauses.

Address search and maps in Movea are provided by Google Maps Platform. When a user types an address, the typed text and the user's IP address are sent to Google, and when a job is planned, the coordinates of the addresses can be sent to Google to calculate drive time. Google is an independent data controller for that processing under Google's own terms (Google Maps Controller-Controller Data Protection Terms) and is therefore not a sub-processor. By this agreement the Customer instructs the Processor to disclose the data to Google for that purpose.

- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: hosting of application and database. Location: Germany.
- DigitalOcean, LLC, USA: storage of uploaded files, including images of damage and vehicles. Location: Frankfurt, Germany.
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg: sending of email (Amazon SES). Location: EU region.
- inMobile ApS, Denmark: sending of SMS. Processes phone number, the content of the message and delivery status. Location: Denmark/EU.
- Cloudflare, Inc., USA: network, protection against attacks and spam check in front of app.movea.dk and api.movea.dk. Processes IP addresses and traffic data in transit. Location: Cloudflare’s global network, where traffic from the EU is as a rule served from European data centres. Transfer mechanism: EU-U.S. Data Privacy Framework.
- motorapi.dk, Denmark: lookup of vehicle information from the registration number. Processes only the registration number. Location: Denmark.
- Laravel Holdings Inc., USA: monitoring of errors and response times in the application (Laravel Nightwatch). Processes technical data about requests, errors and background jobs, which can include the user's id, name, email and IP address. Location: EU.
- 650 Industries, Inc. (Expo), USA: delivery of push notifications to the Movea app on the phone. Processes the device's push token and the content of the notification, which is not kept longer than needed to hand the notification to Apple or Google. Location: USA. Transfer basis: the European Commission's standard contractual clauses.

16

## Annex C: Instructions and security

Subject matter of the processing. The Processor processes personal data by operating Movea for the Customer as described in Annex A and in the Main Agreement.

Level of security. The processing covers ordinary personal data about a large number of private individuals, including addresses and contact details, and a high level of security must therefore be established. The Processor may and must itself decide which measures are necessary, but implements, as a minimum, those set out below.

Storage period and deletion routines. The data is stored until the Customer deletes it or until the agreement ends, after which it is deleted in accordance with the section Deletion and return of data. The Customer itself determines the storage periods for its data in Movea.

Location. The processing takes place at the Processor in Denmark and at the locations set out in Annex B. Employees may work remotely within the EU/EEA through secured connections.

Instructions on third countries. The Customer has not given instructions on transfers to third countries beyond what is stated in Annex B. Without such instructions the Processor may not make transfers.

Supervision of sub-processors. The Processor assesses each sub-processor before it is taken into use, and thereafter reviews, at least once a year, the sub-processor’s audit reports, certifications or equivalent documentation, for example ISO 27001 or SOC 2, and follows up on material deviations.

- Encryption in transit: all traffic to and from Movea is encrypted with TLS.
- Encryption in the database: sensitive fields, including contact details, access keys for integrations and two-factor secrets, are encrypted at field level. Passwords are stored only as hashes.
- Separation of customers: every query is automatically scoped to the Customer’s own company on the server, and access without a valid company returns nothing.
- Access control: role-based access, where every action is authorised on the server against the user’s role. Two-factor login is available to all users. Passwords must be at least 12 characters and are checked against known leaks.
- Administrative access: only those employees of the Processor who have a work-related need have access to production data, with personal accounts and two-factor login.
- Logging: actions on jobs, customers and vehicles are recorded in an activity log. The system is built so that sensitive personal data is not written to technical log files.
- Protection against misuse: limits on the number of attempts at login and on public forms, spam check and protection against denial-of-service attacks.
- Protection against wrongly sent messages: duplicate check and a cap on the number of SMS per recipient and per company, and test environments cannot send to real recipients.
- Backup: the database is backed up regularly, the copies are stored encrypted within the EU, and restoration is tested.
- Development and operations: changes go through automated tests and code review, dependencies are kept up to date, and production data is not used in development and test environments.
- Organisational: employees are subject to confidentiality and are instructed in the processing of personal data, and there is a fixed procedure for handling personal data breaches.

17

## Annex D: The parties’ other terms

Contact point at the Processor for all enquiries under this agreement, including about personal data breaches: info@b2x.dk.

The contact point at the Customer is the user registered as account owner in Movea. The Customer is responsible for keeping the account owner’s email up to date, as notifications under this agreement are sent there.

The Processor has not designated a data protection officer, as the Processor is not obliged to do so under Article 37 of the GDPR.

See also [Terms](https://movea.dk/en/terms).
