Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") governs Casan's processing of personal data on behalf of customers using Casan for property management. This DPA supplements the Terms of Service and Privacy Policy.
The Creative Company ApS — CVR 44404974 · 14 July 2026
1. Background and parties
This agreement is entered into between the Customer (data controller) and The Creative Company ApS, CVR 44404974, Denmark ("Processor", "Casan").
The Customer needs to process personal data in connection with rental and property management. Casan provides a platform where the Customer can register and manage such information.
By accepting the Terms of Service or signing this DPA, the parties agree to the terms herein.
2. Definitions
Terms such as "personal data", "processing", "data controller", "data processor", and "data subject" have the same meaning as in the GDPR.
"Customer Data" means personal data that the Customer or its users enter, upload, or generate in Casan, including information about tenants, applicants, contacts, contractors, and other data subjects.
3. Nature, purpose, and duration of processing
Casan processes Customer Data solely to provide, operate, secure, and support the platform, including storage, backup, communication features, reports, integrations, and technical troubleshooting.
Processing typically includes: receipt, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, and destruction.
Processing continues for as long as the Terms of Service are in effect, and thereafter in accordance with the section on deletion and return.
4. Customer instructions
Casan processes Customer Data only on documented instructions from the Customer, including as described in the Terms of Service, the product's functionality, and this DPA.
If Casan believes an instruction conflicts with the GDPR or other data protection law, we will notify the Customer without undue delay.
5. Confidentiality
Casan ensures that persons authorised to process Customer Data are subject to appropriate confidentiality obligations.
Access is limited to what is necessary to deliver the service, support the Customer, or comply with legal requirements.
6. Security measures
Casan implements appropriate technical and organisational measures in accordance with Art. 32 GDPR, including access control, encryption in transit, logging, backup, role-based access, and incident response procedures.
The Customer is responsible for configuring access rights correctly within its organisation and for secure use of its own user accounts.
7. Sub-processors
The Customer grants Casan general written authorisation to engage sub-processors, provided Casan enters into a data processing agreement with each sub-processor imposing equivalent data protection obligations.
Key sub-processors include Supabase (hosting/database), Microsoft Azure (hosting, email, AI), Plaid (bank integration), Visma e-conomic (accounting), Mapbox (maps), Mailgun (email), and Stripe (payments).
Casan will inform the Customer of planned changes to sub-processors with reasonable notice so the Customer may object where relevant.
8. Transfers to third countries
Customer Data is primarily stored within the EU/EEA. Transfers to third countries occur only where a valid transfer basis exists, such as Standard Contractual Clauses approved by the EU Commission.
9. Assistance to data subjects
Casan assists the Customer, to the extent possible, in responding to requests from data subjects to exercise their rights under the GDPR, including access, rectification, erasure, and data portability.
Requests from data subjects relating to Customer Data will be forwarded to the Customer unless the Customer has given other instructions.
10. Assistance to the Customer
Casan assists the Customer in fulfilling obligations relating to security, data breaches, impact assessments, and prior consultation, to the extent reasonable and consistent with the nature of the service.
The Customer shall notify Casan without undue delay if the Customer assesses that a personal data breach may affect Customer Data in Casan.
11. Deletion and return
Upon termination of the agreement, Casan will delete or return Customer Data at the Customer's choice and in accordance with the Terms of Service, unless retention is required by law.
Backup copies may be retained for a limited period as part of ordinary backup routines, after which they are automatically deleted.
12. Audit and documentation
Casan makes relevant documentation available demonstrating compliance with this DPA, including security measures and a sub-processor list.
The Customer may request information or, where required by law, conduct an audit with reasonable notice and due regard for Casan's and other customers' confidentiality.
13. Liability
Each party is responsible for GDPR compliance within its area of responsibility. Casan's liability as processor is limited in accordance with the limitation of liability provisions in the Terms of Service, unless mandatory law provides otherwise.
14. Term
This DPA applies for as long as Casan processes Customer Data on behalf of the Customer, and terminates automatically when all Customer Data has been deleted or returned, unless legal requirements require continued retention.
The Customer may request a signed copy or company-specific customisation by contacting fpa@casan.co.