Data Processing Agreement

Last updated: 9 September 2026

This Data Processing Agreement ("DPA") governs Onpoint's processing of personal data on behalf of its customers under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). It forms part of the Terms of Service and applies for as long as Onpoint processes data on the customer's behalf.

No signature is required. This DPA takes effect automatically when a customer creates an Onpoint account, installs Onpoint from an accounting-system marketplace, or connects an accounting system to Onpoint. It covers paid subscriptions, free trials, pilots and evaluations alike. If you need a countersigned copy for your own records, email privacy@onpoint.finance and we will return one.

1. Parties and Roles

Data Controller: the customer - the legal entity that creates an Onpoint account, installs Onpoint from a marketplace, or authorises a connection between Onpoint and its accounting system.

Data Processor: Onpoint Finance ApS, CVR 46425170, Copenhagen, Denmark. Contact: privacy@onpoint.finance.

Onpoint processes personal data only on documented instructions from the customer. The Terms of Service, this DPA, the customer's configuration of the platform, and the customer's use of its features together constitute those instructions. Onpoint will inform the customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

2. Subject Matter, Nature and Purpose of Processing

Onpoint processes invoice and accounting data supplied by the customer, or retrieved from systems the customer has connected, in order to provide the platform. This includes:

  • Extraction of structured line items from invoice documents
  • Categorisation of items, suppliers and spend
  • Budget versus actuals reporting and variance analysis
  • Comparison of prices for the same item across suppliers and over time
  • Storage, display and export of the resulting data to authorised users

3. Duration

This DPA applies for as long as the customer has an active Onpoint account or an active integration connection, and continues to apply until Onpoint has deleted or returned the customer's data in accordance with section 11. It is not limited to a pilot, evaluation or trial period.

4. Categories of Data Subjects

  • The customer's employees and other individuals who use Onpoint
  • Individuals identified in the customer's invoices and accounting records, such as supplier contacts, named recipients, approvers, and employees named on an invoice line

5. Types of Personal Data

  • Account data - name, work email address, company name, job title
  • Invoice data - invoice headers and line items, including any personal data they contain
  • Supplier data - supplier names and any contact details appearing on invoices
  • Accounting data - vouchers, entries, departments and dimensions, and supplier records retrieved from a connected accounting system
  • Usage data - IP address, browser type, timestamps, and actions taken in the product

Onpoint does not require, and asks customers not to supply, special categories of personal data as defined in Article 9 GDPR.

6. Scope and Restrictions

  • Customer data is processed solely to deliver the service.
  • Customer data is not used to train AI or machine-learning models, by Onpoint or by any subprocessor.
  • AI is used only for inference - reading documents and producing structured data from them.
  • Customer data is not sold, and is not shared or pooled across customers.
  • Personnel with access to customer data are bound by confidentiality obligations.

7. Data Location and International Transfers

Customer data is stored and processed in EU regions of Google Cloud. Onpoint does not transfer customer data outside the EU/EEA.

If this ever changes, Onpoint will notify affected customers in advance, and any transfer will be made under an adequacy decision or the European Commission's Standard Contractual Clauses together with any supplementary measures required.

8. Subprocessors

The customer authorises Onpoint to engage the following subprocessors:

SubprocessorPurposeLocation
Google CloudHosting, storage, database and authenticationEU regions
Google Vertex AIAI inference for extracting structured data from invoice documentsEU regions

This page is the current subprocessor list. Onpoint imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to the customer for a subprocessor's performance.

Onpoint will give at least 30 days' notice before adding or replacing a subprocessor. To receive that notice by email, write to privacy@onpoint.finance. A customer may object on reasonable data protection grounds within those 30 days; if the objection cannot be resolved, the customer may terminate the affected service without penalty.

Connected accounting systems are not subprocessors

An accounting system that the customer connects to Onpoint - for example e-conomic - is the customer's own system and its provider is not an Onpoint subprocessor. Onpoint reads data from it on the customer's instruction, given when the customer authorises the connection, and the customer's own agreement with that provider continues to apply.

9. Security Measures

Taking into account the state of the art and the risks presented by the processing, Onpoint implements the following technical and organisational measures under Article 32 GDPR:

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256)
  • Role-based access control, with access granted on a least-privilege basis
  • Access to production data restricted to authorised personnel
  • Logical data isolation between customers
  • Logging of access and system activity
  • Confidentiality obligations for all personnel with access to customer data

10. Personal Data Breach

Onpoint will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.

Onpoint will assist the customer in meeting its own obligations under Articles 33 and 34 GDPR.

11. Assistance to the Controller

Taking into account the nature of the processing, Onpoint will assist the customer with:

  • Data subject requests - access, rectification, erasure, restriction, portability and objection. The platform's own export and delete functions are the primary means; where they are not sufficient, Onpoint will assist by other reasonable means. If a data subject contacts Onpoint directly, Onpoint will refer them to the customer and will not respond on the customer's behalf without instruction.
  • Data protection impact assessments and prior consultation under Articles 35 and 36, using the information available to Onpoint.

12. Audit

Onpoint will make available to the customer the information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the customer or an auditor it mandates.

In practice: high-level documentation of Onpoint's security measures is available on request. On-site or in-depth audits may be requested no more than once per year, with at least 30 days' written notice, at the customer's reasonable cost, and subject to confidentiality. These limits do not apply where an audit follows a personal data breach or is required by a supervisory authority.

13. Return and Deletion of Data

The customer may export its data from the platform at any time during the term. On termination, or at any time on written request, Onpoint will delete the customer's data within 30 days. Residual copies held in encrypted backups are removed on the normal backup rotation cycle.

Onpoint retains its own accounting records relating to the customer relationship, such as Onpoint's invoices to the customer, where Danish bookkeeping law requires it. This does not include the customer's invoice or accounting data.

14. Confidentiality

All customer data is treated as confidential. It is not disclosed to third parties other than the subprocessors named in section 8, except where required by law - in which case, unless legally prohibited, Onpoint will inform the customer first.

15. Precedence, Changes and Governing Law

Where this DPA conflicts with the Terms of Service or any other agreement between the parties, this DPA prevails in respect of the processing of personal data.

Onpoint may update this DPA to reflect changes in the service or in applicable law. Material changes will be notified at least 30 days in advance by email or in-app notice.

This DPA is governed by Danish law, with the courts of Copenhagen as the venue for disputes, consistent with the Terms of Service.

16. Contact

Onpoint Finance ApS, CVR 46425170
Copenhagen, Denmark
privacy@onpoint.finance