Data Processing Agreement
Last updated: September 29, 2026
Version 2026-09-29. This agreement governs personal data processed by Limita on a customer’s behalf and forms part of the Terms of Service.
It is adapted for Limita from Datatilsynet’s Article 28 template, March 2024, version 1.2. The terms below use that structure and include Limita’s service details and electronic contracting arrangements.
For a processing instruction, a copy of the applicable agreement or a privacy request, contact privacy@limita.org.
1. Parties and application
Customer: the organisation or individual accepting the Terms for the identified Limita subscription and workspaces. The Customer is the controller, or an authorised processor acting on the controller’s instructions.
Limita: Dannie Hansen Consulting ApS, CVR DK45631044, Grenaa, Denmark, acting as processor for the Customer. Contact: privacy@limita.org.
This agreement applies when accepted as part of the Terms by a person authorised to act for the Customer, or through a separate written or electronic agreement identifying the parties and this version. The Customer’s identity, covered subscription/workspaces and contact are those identified in that agreement or the customer relationship. An employee using a board does not thereby become the contracting controller.
This agreement prevails over conflicting data-processing provisions in the Terms. It does not restrict mandatory law or data subjects’ rights. Appendices A to D form part of it, and the parties may retain it electronically. Limita’s own controller processing is described in the Privacy Policy.
2. Customer responsibilities
The relevant controller determines the purposes and essential means of processing and is responsible for its lawful basis and information to individuals. A Customer acting as processor passes on that controller’s authorised instructions. The Customer is responsible for ensuring its instructions and supplied data are lawful and authorised. This includes appropriate information to staff about time tracking and who can see their records.
The Customer supplies information reasonably needed to assess risks and provide assistance. Where it acts for another controller, it must have authority to appoint Limita and give the relevant instructions.
3. Documented instructions
Limita processes customer personal data only on documented instructions: this agreement, authorised service settings and lawful written instructions sent to the contact above. Appendices A and C describe the authorised processing.
If EU or Member State law requires other processing, Limita informs the Customer beforehand unless the law prohibits that notice on important public-interest grounds. Limita immediately informs the Customer if it considers an instruction contrary to applicable data-protection law and suspends that instruction while the parties resolve it.
Limita does not use customer personal data for unrelated advertising, sale or independent purposes under this agreement.
4. Confidentiality
Access is limited to authorised persons who need the data for their work and are bound by contractual or statutory confidentiality. Limita reviews access and withdraws it when no longer needed. Information demonstrating these arrangements is provided on the Customer’s reasonable request.
5. Security of processing
Taking account of the state of the art, implementation costs, the nature and scope of processing, and risks to individuals, each party implements appropriate technical and organisational measures under Article 32 GDPR.
Limita evaluates its processing risks, maintains the measures in Appendix C and assists the Customer with relevant security information. Measures address confidentiality, integrity, availability, recovery and assessment of effectiveness. Necessary additional measures are documented between the parties.
6. Subprocessors
The Customer gives general written authorisation for the customer-data subprocessors in Appendix B for their stated purposes. Limita imposes contractual data-protection obligations providing the protection required by this agreement and Article 28 GDPR. Limita remains responsible to the Customer for the fulfilment of those obligations.
Limita gives at least 30 days’ advance written notice before adding or replacing a customer-data subprocessor, including its identity, processing, locations and transfer arrangements. Notice is sent to the designated customer contact or another agreed written channel. Updating a website alone is not notice.
The Customer may object on reasonable data-protection grounds before the change takes effect. The parties seek an alternative or additional safeguards. If they cannot resolve the objection, the Customer may end the affected service before that provider receives its data, without a termination penalty for that service.
On request, Limita provides relevant subprocessor terms and compliance information. Unrelated commercial provisions and other customers’ confidential information may be redacted. Statutory customer and data-subject rights remain unaffected.
7. International transfers
Transfers outside the EEA occur only on documented Customer instructions and with a valid Chapter V GDPR mechanism. Appendix C identifies the permitted arrangements. Limita assesses and implements any necessary supplementary safeguards before relying on that mechanism.
A provider’s broad permission to process worldwide does not expand the Customer’s instructions. Further destinations or processing require the applicable written notice and authorisation. The prior-notice rule in section 3 applies to transfers required by EU or Member State law.
This Article 28 agreement is not itself an international-transfer safeguard under Article 46 GDPR.
8. Assistance and individual rights
Taking account of the processing and information available, Limita assists the Customer with Chapter III GDPR rights, security obligations, breach assessment and notification, data protection impact assessments and required consultation with a supervisory authority.
Limita promptly informs the Customer of a request concerning data processed on its behalf, unless legally prohibited. It does not respond substantively on the Customer’s behalf without instructions, except where law requires it. Requests concerning Limita’s own controller processing are handled separately.
Assistance includes locating records by Trello member and workspace identifiers, providing available exports and applying verified correction, restriction or deletion instructions. Verification must be proportionate. An unmatched email address does not itself establish that no records exist.
Assistance is provided without undue delay so the Customer can meet its obligations. The usual one-month deadline for responding to an individual’s rights request is distinct from breach-notification deadlines.
9. Personal data breaches
Limita notifies the Customer without undue delay after becoming aware of a personal data breach affecting data processed under this agreement. Initial information may be provided in stages as facts become available.
Notification includes the nature of the breach, affected categories and approximate numbers of people and records where known, likely consequences, measures taken or proposed, and a contact for further information. Limita preserves relevant evidence, investigates, mitigates effects and provides material updates.
The Customer decides whether to notify an authority or affected individuals, with Limita’s assistance. The GDPR’s 72-hour authority-notification period, where applicable, concerns the controller; it is not a waiting period for Limita to notify the Customer.
10. Return and deletion
The Customer instructs Limita to provide the limited post-subscription export and recovery period in Appendix C. Workspace data is deleted from the live service within 120 days after subscription or trial access ends, unless the subscription resumes beforehand. For a board associated with the organisation after that access end, the period starts at the later association, as described in Appendix C. The Customer may instruct earlier return or deletion.
At the end of the processing services, Limita, at the Customer’s choice, returns or deletes customer personal data and deletes existing copies unless EU or Member State law requires storage. The Customer may request return before deletion or change its instruction in writing. Unless it requests return, the default instruction is deletion without undue delay after any necessary, limited completion of the service.
Deletion under Appendix C covers identifiable supporting records as well as ordinary product records. Limita confirms completion and identifies any retained data, its reason and the relevant period.
Legally required retention is restricted to its purpose and period. Backup copies remain isolated from ordinary use until expiry; completed deletion instructions are reapplied before restored data is made available.
11. Information, audits and inspections
Limita makes available information necessary to demonstrate compliance with Article 28 and this agreement, and allows and contributes to audits and inspections by the Customer or its mandated independent auditor. Appendix C describes the arrangements.
Confidentiality, reasonable notice and protection of other customers’ data may shape the procedure but do not remove statutory audit rights. Limita cooperates with competent authorities and permits legally required access to relevant facilities, systems and records.
12. Duration, changes and contacts
This agreement continues while Limita holds or processes customer personal data on the Customer’s behalf. Subscription termination does not end these protections. It may end once return, deletion and legally required retention are completed, or be replaced by an equally protective lawful agreement.
The parties document material changes, including those needed because of law or processing risks. Changes do not retrospectively remove obligations or lower legally required protection. The accepted version remains identifiable.
Limita’s contact is privacy@limita.org; contractual enquiries may also go to legal@limita.org. The Customer’s contact is its designated representative. Both parties keep contact details current.
Appendix A. Processing details
A.1. Subject and purpose
Providing Limita’s Trello service: timers, manual entries, estimates, billable records, client assignments, custom fields, team reports, synchronisation, configured activity automation, and related support and service security.
A.2. Nature of processing
Authorised collection from Trello and users; storage, organisation, calculation, display, retrieval, synchronisation, export, correction, restriction, backup and deletion. Access is provided to the Customer’s authorised users under the service’s permission model.
A.3. Personal data
Member, organisation, board, card and list identifiers; names and usernames used for display; card/checklist text and custom fields; time-entry dates, start/end times, durations, estimates, billable status and notes; client names, emails and contacts where entered; preferences; relevant audit, access and diagnostic identifiers, including IP/session information; integration credentials; and personal data in customer support correspondence.
A.4. People concerned
Customer staff, contractors, authorised users, client contacts and other individuals whose ordinary personal information the Customer lawfully enters. Special-category and criminal-offence data must not be included without a separate written agreement and appropriate safeguards.
A.5. Duration
The service period and limited return, deletion or legally required retention described in section 10 and Appendix C. Cancellation is not an instruction to retain data indefinitely.
Appendix B. Authorised subprocessors
The following providers are authorised for the stated customer-data processing when this version is accepted. The provider register contains the same information. Changes follow section 6; the accepted list and written notices form the applicable record.
Hetzner Online GmbH
Platform hosting, database and encrypted backups
- Legal contact address
- Industriestr. 25, 91710 Gunzenhausen, Germany.
- Data
- Customer service data, including board and member identifiers, time records, estimates, custom fields, clients and integration credentials.
- Locations
- Platform in Nuremberg, Germany; backups in Falkenstein, Germany. Provider support is within the EU.
- Processing and transfers
- EU processing for the specified hosting and backup services under Hetzner’s data-processing agreement.
Sentry (Functional Software, Inc.)
Error reporting and diagnostics
- Legal contact address
- 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States.
- Data
- Exceptions, diagnostic breadcrumbs and technical context, which may include workspace, member and session identifiers. Session replay is disabled.
- Locations
- EU region in Frankfurt for service events. Account, integration and organisation metadata and support can involve the United States. Sentry Software Canada Inc. provides parts of the service and technical support from Canada.
- Processing and transfers
- Sentry’s published DPA provides for covered EU-US Data Privacy Framework transfers and Standard Contractual Clauses as fallback. EU storage does not exclude international processing or access.
Proton AG
Email support and privacy requests
- Legal contact address
- Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland. Registration CHE-354.686.492.
- Data
- Contact details, message content, attachments and email metadata. Acts as a customer-data subprocessor where support correspondence contains customer personal data.
- Locations
- Switzerland, Germany and Norway.
- Processing and transfers
- EEA processing and the European Commission adequacy decision for Switzerland.
Cloudflare’s public-website services, Stripe’s billing services, PagerDuty’s operational alerts and Dinero’s accounting services are listed separately in the provider register because they primarily support Limita’s own controller activities. The Customer’s separate Trello service is not appointed as a Limita subprocessor by this agreement.
Appendix C. Instructions and measures
C.1. Service instructions
The Customer instructs Limita to perform Appendix A processing for its selected workspaces and settings, including necessary support, security and recovery. Further instructions must identify the Customer, scope and action. Limita may verify the sender’s authority.
C.2. Technical and organisational measures
- Authenticated access, workspace isolation and server-side permissions. Integration credentials are restricted to authorised service functions.
- HTTPS for public application connections, encrypted database and monitoring storage, and encrypted off-site backups.
- Need-to-know operational access, confidentiality obligations and access removal when no longer required.
- Security logging, error monitoring, dependency checks and tests of access boundaries. Diagnostic data is limited to its purpose; session replay is disabled.
- Backup and recovery procedures, review of failures and recovery testing. Production customer data is not copied to staging.
- Proportionate protection of authorised personnel’s devices and remote access, and use of hosting providers’ physical-security controls.
- Review of measures when services, providers or relevant risks change.
C.3. Assistance
Requests go to privacy@limita.org. Limita locates records, supplies available exports and relevant supplementary information, applies verified instructions, identifies retained exceptions, and provides security/incident information within its control. The parties coordinate scope and deadlines.
C.4. Storage and erasure procedure
You can request the return or deletion of your workspace data by contacting privacy@limita.org.
We retain customer data while the subscription or trial is active. After subscription or trial access ends, workspace data is deleted from the live service within 120 days, unless the subscription resumes before deletion. Export any records you need before your subscription or trial access ends.
For a board connected or transferred into an organisation after its subscription has already ended, the period starts at that later connection or transfer. Recently transferred data is not treated as if it had already been inactive in its new organisation.
You can request earlier return or deletion. This ordinary retention window does not extend the deadline for handling a valid individual rights request.
Customer data that EU or Member State law requires us to keep is retained only for that purpose and period. Separately, we may retain narrowly necessary records for our own bookkeeping or legal claims where we act as controller and have a lawful basis. That does not authorise retaining the customer’s other records against a deletion instruction. Limited copies in backups remain protected until the relevant backup cycle expires. Completed deletions must be reapplied before restored data is returned to normal use.
Limita verifies identity and authority, identifies affected live and supporting records, performs the authorised action and keeps minimal evidence of the outcome. This includes audit data, cached responses and integration/access state where identifiable. Erasure must not reactivate a revoked credential.
Primary backup pruning is configured for 30 days, with separate storage snapshots. This does not mean every copy disappears exactly 30 days after a request. Limita identifies the remaining backup lifetime, protects retained copies and explains their treatment in its response. Recovery copies are not reused for ordinary processing.
C.5. Processing locations
Limita operates from Denmark. Platform and backup locations are in Germany. Appendix B identifies authorised provider service locations and relevant international processing. Further locations require applicable written notice and authorisation; provider headquarters alone do not describe where processing occurs.
C.6. Transfer instructions and safeguards
The Customer authorises the EEA processing in Appendix B, Proton Mail storage in Switzerland under the European Commission adequacy decision, and Sentry’s described United States metadata and support processing and Canadian service and technical-support processing, subject to an effective Chapter V mechanism.
Sentry’s published transfer terms provide for covered transfers under the EU-US Data Privacy Framework and Standard Contractual Clauses as fallback. Canadian processing must be covered by an applicable adequacy decision or the relevant Standard Contractual Clauses, including onward-transfer safeguards. Limita must establish coverage for the actual transfer and assess any necessary supplementary safeguards. Other third-country processing requires further documented instructions, not merely a general reference to provider terms.
These instructions do not authorise optional AI analysis or model training using customer data. Such processing requires a separate assessment and documented authorisation before it is enabled.
C.7. Audits of Limita
The Customer may first request relevant processing and security information. If this is insufficient, the parties arrange a proportionate audit or inspection by a qualified, confidential auditor. Notice and timing are reasonable; urgent incidents or authority requirements can justify shorter notice. Scope protects other customers’ data and unrelated secrets without preventing verification. No certification or independent audit report is promised unless separately identified as available.
C.8. Oversight of subprocessors
Limita reviews relevant provider terms, security information and available audit evidence, seeks further assurance when needed, and provides relevant information to the Customer. Necessary inspections are coordinated under subprocessor arrangements. Limita’s responsibility and the Customer’s statutory audit rights remain.
Appendix D. Other terms
The Terms govern commercial matters to the extent they do not conflict with this agreement or mandatory law. They cannot restrict data subjects’ statutory rights, authority powers or liability that cannot lawfully be limited.
Supplementary arrangements may be documented electronically. A website revision alone does not establish acceptance of a changed agreement. Each party should retain its applicable version and acceptance or other written agreement.