Last updated: 9 September 2026
This Data Processing Agreement ("DPA") governs Onpoint's processing of personal data on behalf of its customers under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). It forms part of the Terms of Service and applies for as long as Onpoint processes data on the customer's behalf.
No signature is required. This DPA takes effect automatically when a customer creates an Onpoint account, installs Onpoint from an accounting-system marketplace, or connects an accounting system to Onpoint. It covers paid subscriptions, free trials, pilots and evaluations alike. If you need a countersigned copy for your own records, email privacy@onpoint.finance and we will return one.
Data Controller: the customer - the legal entity that creates an Onpoint account, installs Onpoint from a marketplace, or authorises a connection between Onpoint and its accounting system.
Data Processor: Onpoint Finance ApS, CVR 46425170, Copenhagen, Denmark. Contact: privacy@onpoint.finance.
Onpoint processes personal data only on documented instructions from the customer. The Terms of Service, this DPA, the customer's configuration of the platform, and the customer's use of its features together constitute those instructions. Onpoint will inform the customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
Onpoint processes invoice and accounting data supplied by the customer, or retrieved from systems the customer has connected, in order to provide the platform. This includes:
This DPA applies for as long as the customer has an active Onpoint account or an active integration connection, and continues to apply until Onpoint has deleted or returned the customer's data in accordance with section 11. It is not limited to a pilot, evaluation or trial period.
Onpoint does not require, and asks customers not to supply, special categories of personal data as defined in Article 9 GDPR.
Customer data is stored and processed in EU regions of Google Cloud. Onpoint does not transfer customer data outside the EU/EEA.
If this ever changes, Onpoint will notify affected customers in advance, and any transfer will be made under an adequacy decision or the European Commission's Standard Contractual Clauses together with any supplementary measures required.
The customer authorises Onpoint to engage the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud | Hosting, storage, database and authentication | EU regions |
| Google Vertex AI | AI inference for extracting structured data from invoice documents | EU regions |
This page is the current subprocessor list. Onpoint imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to the customer for a subprocessor's performance.
Onpoint will give at least 30 days' notice before adding or replacing a subprocessor. To receive that notice by email, write to privacy@onpoint.finance. A customer may object on reasonable data protection grounds within those 30 days; if the objection cannot be resolved, the customer may terminate the affected service without penalty.
An accounting system that the customer connects to Onpoint - for example e-conomic - is the customer's own system and its provider is not an Onpoint subprocessor. Onpoint reads data from it on the customer's instruction, given when the customer authorises the connection, and the customer's own agreement with that provider continues to apply.
Taking into account the state of the art and the risks presented by the processing, Onpoint implements the following technical and organisational measures under Article 32 GDPR:
Onpoint will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.
Onpoint will assist the customer in meeting its own obligations under Articles 33 and 34 GDPR.
Taking into account the nature of the processing, Onpoint will assist the customer with:
Onpoint will make available to the customer the information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the customer or an auditor it mandates.
In practice: high-level documentation of Onpoint's security measures is available on request. On-site or in-depth audits may be requested no more than once per year, with at least 30 days' written notice, at the customer's reasonable cost, and subject to confidentiality. These limits do not apply where an audit follows a personal data breach or is required by a supervisory authority.
The customer may export its data from the platform at any time during the term. On termination, or at any time on written request, Onpoint will delete the customer's data within 30 days. Residual copies held in encrypted backups are removed on the normal backup rotation cycle.
Onpoint retains its own accounting records relating to the customer relationship, such as Onpoint's invoices to the customer, where Danish bookkeeping law requires it. This does not include the customer's invoice or accounting data.
All customer data is treated as confidential. It is not disclosed to third parties other than the subprocessors named in section 8, except where required by law - in which case, unless legally prohibited, Onpoint will inform the customer first.
Where this DPA conflicts with the Terms of Service or any other agreement between the parties, this DPA prevails in respect of the processing of personal data.
Onpoint may update this DPA to reflect changes in the service or in applicable law. Material changes will be notified at least 30 days in advance by email or in-app notice.
This DPA is governed by Danish law, with the courts of Copenhagen as the venue for disputes, consistent with the Terms of Service.
Onpoint Finance ApS, CVR 46425170
Copenhagen, Denmark
privacy@onpoint.finance