Legal
STANDARD DATA PROCESSING AGREEMENT
for the Omniday platform — data processing agreement pursuant to Article 28 of the General Data Protection Regulation
Version 1.0 · Effective from 5 August 2026
Data processor: Clouda ApS (Omniday) · CVR no. 41509775
ABOUT THIS DOCUMENT
This agreement applies to customers who accept it electronically when signing up on the Omniday platform or in their account. It replaces previous online versions for customers who expressly accept this version.
If the Customer wishes to have a separately signed data processing agreement, the data processor offers this as well.
The current version and all previous versions are available at omniday.ai/legal/dpa. The data processor is Clouda ApS (CVR 41509775), which operates the platform under the name Omniday.
1 Parties and scope
This data processing agreement (the “DPA”) is entered into between Clouda ApS, CVR no. 41509775, Industrivej 21, 4000 Roskilde, Denmark, which operates the Omniday platform (“Omniday”), as data processor, and the legal entity identified as the customer in an order form, subscription agreement, account or other agreement concerning the Omniday platform (the “Customer”), as data controller.
The DPA forms part of the agreement governing the Customer’s use of the Omniday platform (the “Master Agreement”). In the event of conflict concerning the processing of personal data, the DPA prevails. The DPA applies only to the extent Omniday processes personal data on behalf of the Customer.
2 Definitions
Customer Data: information submitted to or generated through the platform by the Customer or by persons acting on the Customer’s behalf.
Customer Personal Data: personal data within Customer Data that Omniday processes on behalf of the Customer.
Order Form: the order, agreement or electronic configuration identifying the Customer and the selected services.
Sub-processor Register: the current, version-controlled overview at omniday.ai/legal/subprocessors.
Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the same meaning as in the General Data Protection Regulation.
3 Instructions and purpose limitation
Omniday processes Customer Personal Data only on the Customer’s documented instructions. The instructions consist of the DPA, the Master Agreement, the Order Form, the Customer’s lawful configuration and use of the platform, and subsequent written instructions accepted by the parties.
Omniday does not process Customer Personal Data for its own purposes, does not sell it, and does not use it to train or fine-tune general AI models, whether at Omniday or at a sub-processor, unless the Customer has separately and expressly instructed this. Omniday may use genuinely anonymised and aggregated information, which is no longer personal data, for statistics, security and product improvement.
If Omniday considers that an instruction infringes applicable data protection law, the Customer is informed without undue delay. Omniday may suspend the affected processing until the instruction has been clarified.
4 AI processing and human control
Omniday may use AI for categorisation, search, summarisation and the drafting of replies. Omniday applies automated screening and replaces supported direct identifiers with placeholders before text is sent to the AI language model.
The platform must not be used for decisions based solely on automated processing which produce legal effects or similarly significant effects for a data subject, unless this has been separately agreed and is lawful. An outbound reply requires, as a general rule, approval by an authorised user of the Customer. Any other workflow must be expressly set out in the Order Form or in a subsequent documented instruction.
5 Confidentiality and access
Omniday ensures that persons with access to Customer Personal Data are bound by confidentiality, are granted access only on the basis of a work-related need, and are instructed in relevant data protection and information security. Access is granted on the principle of least privilege and is removed when the need ceases.
6 Security of processing
Omniday implements and maintains appropriate technical and organisational measures pursuant to Article 32, taking into account the nature, scope, context and purposes of the processing and the risks involved. The minimum measures are set out in Annex 2. Omniday may change a measure provided that the overall level of security is not materially reduced.
7 Sub-processors
The Customer grants Omniday a general written authorisation to use the sub-processors listed in Annex 3 and in the Sub-processor Register at the time the Customer accepts the DPA. The recorded version of the DPA and of the Register constitutes the Customer’s authorisation.
Omniday notifies the Customer’s account administrator at least 30 days before a planned addition or replacement. The Customer may raise a reasoned objection within 14 days. The parties will first seek a reasonable solution; if this is not possible, the Customer may deactivate the affected feature or terminate the affected service before the change takes effect.
A sub-processor is bound by data protection obligations corresponding, to the relevant extent, to this DPA. Omniday remains liable to the Customer for the sub-processor’s performance of these obligations.
8 Third-country transfers
Omniday may transfer Customer Personal Data outside the EU/EEA only on the Customer’s documented instructions and in accordance with Chapter V of the General Data Protection Regulation. The Customer instructs Omniday regarding the specific transfer scenarios set out in Annex 3 and in the approved version of the Sub-processor Register.
A transfer must be based on a relevant adequacy decision or appropriate safeguards, including the European Commission’s standard contractual clauses, together with supplementary measures where necessary. Upon request, Omniday makes documentation of the transfer basis available, subject to necessary redaction of confidential information.
9 Assistance to the Customer
Taking into account the nature of the processing, Omniday assists the Customer with suitable features and reasonable information in connection with requests concerning access, rectification, erasure, restriction, data portability and objection, and in the assessment of automated decisions. Omniday does not respond directly to the data subject unless instructed to do so by the Customer.
Omniday further provides reasonable assistance with the Customer’s obligations under Articles 32–36, including security, notification and communication of breaches, data protection impact assessments and prior consultation. Standard assistance is included. Extensive bespoke work may be invoiced subject to prior agreement, unless the need arises from Omniday’s non-compliance.
10 Personal data breaches
Omniday notifies the Customer without undue delay after becoming aware of a personal data breach concerning Customer Personal Data, and aims to provide an initial notification within 24 hours. To the extent the information is available, the notification includes the nature of the breach, the data subjects and data concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases.
Omniday’s notification does not constitute an acknowledgement of liability. The Customer is responsible for any notification to the supervisory authority and communication to data subjects.
11 Deletion, return and retention
The Customer determines the retention period through the Order Form or the platform’s settings. Unless otherwise agreed, conversation and e-mail content is deleted 180 days after the most recent activity. Limited copies for quality and error monitoring, together with operational and security logs, are as a general rule retained for no more than 90 days. Encrypted backups as a general rule expire within 35 days.
Upon termination of the Master Agreement, the Customer may within 30 days choose to have Customer Personal Data returned in a commonly used format or instruct that it be deleted. If the Customer makes no choice, Omniday deletes the data after the export period and no later than 30 days thereafter, except for copies existing solely in inaccessible backups, which are deleted upon normal expiry. Data may be retained longer where EU or Danish law so requires, and is in that case processed solely for that purpose.
12 Documentation, audit and supervision
Omniday makes available reasonable information necessary to demonstrate compliance with Article 28 and this DPA. The Customer may, as a general rule once per year and with at least 30 days’ notice, carry out a document-based audit, either itself or through an independent auditor, under appropriate confidentiality. Existing audit reports, certifications and security questionnaires are used first where they are sufficient.
In the event of a specific security breach, substantiated suspicion of non-compliance, or a requirement from a supervisory authority, the limitations on frequency and notice do not apply. An audit must not compromise other customers’ data or the security of the systems. Each party bears its own costs, but Omniday covers reasonable audit costs if the audit demonstrates material non-compliance on Omniday’s part.
13 Liability, duration and termination
The DPA applies for as long as Omniday processes Customer Personal Data. Limitations of liability, governing law and venue follow the Master Agreement, without limiting the inalienable rights of data subjects or supervisory authorities. If Omniday materially breaches the DPA and fails to remedy the breach within a reasonable period, the Customer may suspend the affected processing or terminate the affected service.
14 Changes and versioning
Omniday may update the DPA to reflect changes in law, new features or improved security measures. Material changes are notified at least 30 days before they take effect. A change which materially reduces the Customer’s data protection or expands the purpose of the processing requires the Customer’s renewed express acceptance or a separate agreement.
The version accepted by the Customer remains available to the Customer. Non-material editorial changes, and changes which solely improve protection, may take effect upon notice in accordance with the Master Agreement.
15 Acceptance of the agreement
The DPA is entered into either electronically or by way of a separately signed data processing agreement. It is entered into electronically when a person with authority to bind the Customer actively ticks an acceptance box or selects an equivalent “Accept” action where the DPA is clearly available. Acceptance by way of a signed Order Form referring to this DPA has the same effect. If the parties instead enter into a separately signed data processing agreement, that agreement prevails over this DPA for the customer concerned.
As documentation, Omniday records at least the Customer, the accepted version, the date and time, the accepting account or user, and the relevant order or account. The Customer may retrieve or request a copy. The person accepting declares that they hold the necessary authority.
16 Contact
Data protection enquiries, instructions and breach notifications concerning Omniday are sent to hello@omniday.ai. The Customer’s point of contact is the account administrator or contact person stated in the Order Form or in the Customer’s account. If the Customer has designated a data protection officer or a specific data protection contact in its account, notifications under Section 10 are sent to that person.
Annex 1 Information about the processing
| Field | Description |
|---|---|
| Subject matter and purpose | Delivery, operation, support and securing of the Omniday platform, which receives, organises, stores, categorises and supports the answering of enquiries via the channels the Customer has activated. |
| Nature of the processing | Collection, recording, structuring, storage, retrieval, analysis, pseudonymisation, generation of draft replies, display, transmission on the Customer’s instructions, and deletion. |
| Duration | For as long as the Master Agreement is in force, plus the limited period necessary for export, deletion and expiry of backups after termination. |
| Data subjects | Persons who contact the Customer; persons mentioned in enquiries; the Customer’s employees, administrators and other authorised users. |
| Ordinary personal data | Name, address, e-mail, telephone number, enquiry and correspondence content, attachments, appointment and booking information, user and role data, technical metadata, IP address, and time and audit information, to the extent processed in the chosen configuration. |
| Sensitive data | Special categories under Article 9, data relating to criminal offences under Article 10, and national identification numbers may occur in free text or attachments. Systematic processing of such data may only take place where expressly agreed in the Master Agreement or in a separate instruction and supported by appropriate security measures. |
| Channels and features | The channels, integrations, retention periods and any special workflows the Customer has activated in its account or which are set out in the Order Form. |
Annex 2 Technical and organisational measures
- Encryption. Customer Personal Data is encrypted in transit using TLS 1.2 or newer and at rest using AES-256, including in backups.
- Access control. Role-based access, least privilege, and multi-factor authentication for privileged access to the production environment.
- Logical separation. Customer Data is logically separated between customers, and access controls are enforced at the application and data layers.
- Pseudonymisation before AI. Supported direct identifiers are detected and replaced with placeholders before disclosure to the AI language model. The mapping to the original values is protected separately.
- Data minimisation. Only data necessary for the selected feature is disclosed to a sub-processor. Customer Personal Data is not used for general model training.
- Logging and monitoring. Administrative actions and relevant security events are logged and monitored. Log content is restricted so that message content and direct identifiers are not included unless necessary and separately protected.
- Backup and recovery. Encrypted backups, documented recovery procedures, and periodic testing of the ability to restore relevant services.
- Vulnerabilities and changes. Risk-based patching, vulnerability management, code review, and controlled change management for production systems.
- Incident management. Documented process for recording, assessing, containing, remediating and communicating security incidents.
- Personnel and equipment. Confidentiality obligations, appropriate security instruction, secured workstations, screen lock, and full disk encryption for equipment with production access.
- Vendor management. Risk-based assessment of sub-processors and annual review of available attestations, certifications or other relevant documentation.
- Evaluation. Regular assessment and improvement of the effectiveness of the measures, taking into account changes in risks, technology and the platform’s processing.
Annex 3 Sub-processors and processing locations
The list below reflects the standard configuration at the time this version takes effect. Only providers and features actually used for the Customer process the Customer’s data. The approved, version-controlled overview is available in the Sub-processor Register at omniday.ai/legal/subprocessors.
| Provider | Purpose | Location / transfer |
|---|---|---|
| Microsoft Ireland Operations Limited | Hosting, database, file storage, key management and identity; AI language model and vectorisation; operational and security logging as well as quality and error monitoring. | EU: Azure regions in the Netherlands and Sweden; the language model runs within the EU Data Zone. |
| Twilio Inc. (SendGrid) | Sending of transactional e-mails, where the feature is activated. | EU data residency is used for Customer Data. |
INTEGRATIONS WITH THE CUSTOMER’S OWN SYSTEMS
Where the Customer connects the platform to a system the Customer itself has an agreement with — for example its own booking or case-management system — and access takes place using credentials issued within the Customer’s own customer relationship, the provider of that system is not a sub-processor under this DPA. In that case, Omniday merely transmits data to and from the system on the Customer’s instructions, and the Customer’s own agreement with the provider governs the processing there.
Where Omniday itself engages a provider as part of the service, the provider is added to the Sub-processor Register in accordance with Section 7 before processing begins.
Omniday’s own administrative support and operations access takes place from Denmark or other approved locations within the EU/EEA. No permanent local copies of Customer Data are stored on employee equipment.