Skip to content

Data Processing Agreement

Last updated: September 29, 2026

Version 2026-09-29. This agreement governs personal data processed by Limita on a customer’s behalf and forms part of the Terms of Service.

It is adapted for Limita from Datatilsynet’s Article 28 template, March 2024, version 1.2. The terms below use that structure and include Limita’s service details and electronic contracting arrangements.

For a processing instruction, a copy of the applicable agreement or a privacy request, contact privacy@limita.org.

1. Parties and application

Customer: the organisation or individual accepting the Terms for the identified Limita subscription and workspaces. The Customer is the controller, or an authorised processor acting on the controller’s instructions.

Limita: Dannie Hansen Consulting ApS, CVR DK45631044, Grenaa, Denmark, acting as processor for the Customer. Contact: privacy@limita.org.

This agreement applies when accepted as part of the Terms by a person authorised to act for the Customer, or through a separate written or electronic agreement identifying the parties and this version. The Customer’s identity, covered subscription/workspaces and contact are those identified in that agreement or the customer relationship. An employee using a board does not thereby become the contracting controller.

This agreement prevails over conflicting data-processing provisions in the Terms. It does not restrict mandatory law or data subjects’ rights. Appendices A to D form part of it, and the parties may retain it electronically. Limita’s own controller processing is described in the Privacy Policy.

2. Customer responsibilities

The relevant controller determines the purposes and essential means of processing and is responsible for its lawful basis and information to individuals. A Customer acting as processor passes on that controller’s authorised instructions. The Customer is responsible for ensuring its instructions and supplied data are lawful and authorised. This includes appropriate information to staff about time tracking and who can see their records.

The Customer supplies information reasonably needed to assess risks and provide assistance. Where it acts for another controller, it must have authority to appoint Limita and give the relevant instructions.

3. Documented instructions

Limita processes customer personal data only on documented instructions: this agreement, authorised service settings and lawful written instructions sent to the contact above. Appendices A and C describe the authorised processing.

If EU or Member State law requires other processing, Limita informs the Customer beforehand unless the law prohibits that notice on important public-interest grounds. Limita immediately informs the Customer if it considers an instruction contrary to applicable data-protection law and suspends that instruction while the parties resolve it.

Limita does not use customer personal data for unrelated advertising, sale or independent purposes under this agreement.

4. Confidentiality

Access is limited to authorised persons who need the data for their work and are bound by contractual or statutory confidentiality. Limita reviews access and withdraws it when no longer needed. Information demonstrating these arrangements is provided on the Customer’s reasonable request.

5. Security of processing

Taking account of the state of the art, implementation costs, the nature and scope of processing, and risks to individuals, each party implements appropriate technical and organisational measures under Article 32 GDPR.

Limita evaluates its processing risks, maintains the measures in Appendix C and assists the Customer with relevant security information. Measures address confidentiality, integrity, availability, recovery and assessment of effectiveness. Necessary additional measures are documented between the parties.

6. Subprocessors

The Customer gives general written authorisation for the customer-data subprocessors in Appendix B for their stated purposes. Limita imposes contractual data-protection obligations providing the protection required by this agreement and Article 28 GDPR. Limita remains responsible to the Customer for the fulfilment of those obligations.

Limita gives at least 30 days’ advance written notice before adding or replacing a customer-data subprocessor, including its identity, processing, locations and transfer arrangements. Notice is sent to the designated customer contact or another agreed written channel. Updating a website alone is not notice.

The Customer may object on reasonable data-protection grounds before the change takes effect. The parties seek an alternative or additional safeguards. If they cannot resolve the objection, the Customer may end the affected service before that provider receives its data, without a termination penalty for that service.

On request, Limita provides relevant subprocessor terms and compliance information. Unrelated commercial provisions and other customers’ confidential information may be redacted. Statutory customer and data-subject rights remain unaffected.

7. International transfers

Transfers outside the EEA occur only on documented Customer instructions and with a valid Chapter V GDPR mechanism. Appendix C identifies the permitted arrangements. Limita assesses and implements any necessary supplementary safeguards before relying on that mechanism.

A provider’s broad permission to process worldwide does not expand the Customer’s instructions. Further destinations or processing require the applicable written notice and authorisation. The prior-notice rule in section 3 applies to transfers required by EU or Member State law.

This Article 28 agreement is not itself an international-transfer safeguard under Article 46 GDPR.

8. Assistance and individual rights

Taking account of the processing and information available, Limita assists the Customer with Chapter III GDPR rights, security obligations, breach assessment and notification, data protection impact assessments and required consultation with a supervisory authority.

Limita promptly informs the Customer of a request concerning data processed on its behalf, unless legally prohibited. It does not respond substantively on the Customer’s behalf without instructions, except where law requires it. Requests concerning Limita’s own controller processing are handled separately.

Assistance includes locating records by Trello member and workspace identifiers, providing available exports and applying verified correction, restriction or deletion instructions. Verification must be proportionate. An unmatched email address does not itself establish that no records exist.

Assistance is provided without undue delay so the Customer can meet its obligations. The usual one-month deadline for responding to an individual’s rights request is distinct from breach-notification deadlines.

9. Personal data breaches

Limita notifies the Customer without undue delay after becoming aware of a personal data breach affecting data processed under this agreement. Initial information may be provided in stages as facts become available.

Notification includes the nature of the breach, affected categories and approximate numbers of people and records where known, likely consequences, measures taken or proposed, and a contact for further information. Limita preserves relevant evidence, investigates, mitigates effects and provides material updates.

The Customer decides whether to notify an authority or affected individuals, with Limita’s assistance. The GDPR’s 72-hour authority-notification period, where applicable, concerns the controller; it is not a waiting period for Limita to notify the Customer.

10. Return and deletion

The Customer instructs Limita to provide the limited post-subscription export and recovery period in Appendix C. Workspace data is deleted from the live service within 120 days after subscription or trial access ends, unless the subscription resumes beforehand. For a board associated with the organisation after that access end, the period starts at the later association, as described in Appendix C. The Customer may instruct earlier return or deletion.

At the end of the processing services, Limita, at the Customer’s choice, returns or deletes customer personal data and deletes existing copies unless EU or Member State law requires storage. The Customer may request return before deletion or change its instruction in writing. Unless it requests return, the default instruction is deletion without undue delay after any necessary, limited completion of the service.

Deletion under Appendix C covers identifiable supporting records as well as ordinary product records. Limita confirms completion and identifies any retained data, its reason and the relevant period.

Legally required retention is restricted to its purpose and period. Backup copies remain isolated from ordinary use until expiry; completed deletion instructions are reapplied before restored data is made available.

11. Information, audits and inspections

Limita makes available information necessary to demonstrate compliance with Article 28 and this agreement, and allows and contributes to audits and inspections by the Customer or its mandated independent auditor. Appendix C describes the arrangements.

Confidentiality, reasonable notice and protection of other customers’ data may shape the procedure but do not remove statutory audit rights. Limita cooperates with competent authorities and permits legally required access to relevant facilities, systems and records.

12. Duration, changes and contacts

This agreement continues while Limita holds or processes customer personal data on the Customer’s behalf. Subscription termination does not end these protections. It may end once return, deletion and legally required retention are completed, or be replaced by an equally protective lawful agreement.

The parties document material changes, including those needed because of law or processing risks. Changes do not retrospectively remove obligations or lower legally required protection. The accepted version remains identifiable.

Limita’s contact is privacy@limita.org; contractual enquiries may also go to legal@limita.org. The Customer’s contact is its designated representative. Both parties keep contact details current.

Appendix A. Processing details

A.1. Subject and purpose

Providing Limita’s Trello service: timers, manual entries, estimates, billable records, client assignments, custom fields, team reports, synchronisation, configured activity automation, and related support and service security.

A.2. Nature of processing

Authorised collection from Trello and users; storage, organisation, calculation, display, retrieval, synchronisation, export, correction, restriction, backup and deletion. Access is provided to the Customer’s authorised users under the service’s permission model.

A.3. Personal data

Member, organisation, board, card and list identifiers; names and usernames used for display; card/checklist text and custom fields; time-entry dates, start/end times, durations, estimates, billable status and notes; client names, emails and contacts where entered; preferences; relevant audit, access and diagnostic identifiers, including IP/session information; integration credentials; and personal data in customer support correspondence.

A.4. People concerned

Customer staff, contractors, authorised users, client contacts and other individuals whose ordinary personal information the Customer lawfully enters. Special-category and criminal-offence data must not be included without a separate written agreement and appropriate safeguards.

A.5. Duration

The service period and limited return, deletion or legally required retention described in section 10 and Appendix C. Cancellation is not an instruction to retain data indefinitely.

Appendix B. Authorised subprocessors

The following providers are authorised for the stated customer-data processing when this version is accepted. The provider register contains the same information. Changes follow section 6; the accepted list and written notices form the applicable record.

Hetzner Online GmbH

Platform hosting, database and encrypted backups

Legal contact address
Industriestr. 25, 91710 Gunzenhausen, Germany.
Data
Customer service data, including board and member identifiers, time records, estimates, custom fields, clients and integration credentials.
Locations
Platform in Nuremberg, Germany; backups in Falkenstein, Germany. Provider support is within the EU.
Processing and transfers
EU processing for the specified hosting and backup services under Hetzner’s data-processing agreement.

Provider privacy and processing information

Sentry (Functional Software, Inc.)

Error reporting and diagnostics

Legal contact address
45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States.
Data
Exceptions, diagnostic breadcrumbs and technical context, which may include workspace, member and session identifiers. Session replay is disabled.
Locations
EU region in Frankfurt for service events. Account, integration and organisation metadata and support can involve the United States. Sentry Software Canada Inc. provides parts of the service and technical support from Canada.
Processing and transfers
Sentry’s published DPA provides for covered EU-US Data Privacy Framework transfers and Standard Contractual Clauses as fallback. EU storage does not exclude international processing or access.

Provider privacy and processing information

Proton AG

Email support and privacy requests

Legal contact address
Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland. Registration CHE-354.686.492.
Data
Contact details, message content, attachments and email metadata. Acts as a customer-data subprocessor where support correspondence contains customer personal data.
Locations
Switzerland, Germany and Norway.
Processing and transfers
EEA processing and the European Commission adequacy decision for Switzerland.

Provider privacy and processing information

Cloudflare’s public-website services, Stripe’s billing services, PagerDuty’s operational alerts and Dinero’s accounting services are listed separately in the provider register because they primarily support Limita’s own controller activities. The Customer’s separate Trello service is not appointed as a Limita subprocessor by this agreement.

Appendix C. Instructions and measures

C.1. Service instructions

The Customer instructs Limita to perform Appendix A processing for its selected workspaces and settings, including necessary support, security and recovery. Further instructions must identify the Customer, scope and action. Limita may verify the sender’s authority.

C.2. Technical and organisational measures

  • Authenticated access, workspace isolation and server-side permissions. Integration credentials are restricted to authorised service functions.
  • HTTPS for public application connections, encrypted database and monitoring storage, and encrypted off-site backups.
  • Need-to-know operational access, confidentiality obligations and access removal when no longer required.
  • Security logging, error monitoring, dependency checks and tests of access boundaries. Diagnostic data is limited to its purpose; session replay is disabled.
  • Backup and recovery procedures, review of failures and recovery testing. Production customer data is not copied to staging.
  • Proportionate protection of authorised personnel’s devices and remote access, and use of hosting providers’ physical-security controls.
  • Review of measures when services, providers or relevant risks change.

C.3. Assistance

Requests go to privacy@limita.org. Limita locates records, supplies available exports and relevant supplementary information, applies verified instructions, identifies retained exceptions, and provides security/incident information within its control. The parties coordinate scope and deadlines.

C.4. Storage and erasure procedure

You can request the return or deletion of your workspace data by contacting privacy@limita.org.

We retain customer data while the subscription or trial is active. After subscription or trial access ends, workspace data is deleted from the live service within 120 days, unless the subscription resumes before deletion. Export any records you need before your subscription or trial access ends.

For a board connected or transferred into an organisation after its subscription has already ended, the period starts at that later connection or transfer. Recently transferred data is not treated as if it had already been inactive in its new organisation.

You can request earlier return or deletion. This ordinary retention window does not extend the deadline for handling a valid individual rights request.

Customer data that EU or Member State law requires us to keep is retained only for that purpose and period. Separately, we may retain narrowly necessary records for our own bookkeeping or legal claims where we act as controller and have a lawful basis. That does not authorise retaining the customer’s other records against a deletion instruction. Limited copies in backups remain protected until the relevant backup cycle expires. Completed deletions must be reapplied before restored data is returned to normal use.

Limita verifies identity and authority, identifies affected live and supporting records, performs the authorised action and keeps minimal evidence of the outcome. This includes audit data, cached responses and integration/access state where identifiable. Erasure must not reactivate a revoked credential.

Primary backup pruning is configured for 30 days, with separate storage snapshots. This does not mean every copy disappears exactly 30 days after a request. Limita identifies the remaining backup lifetime, protects retained copies and explains their treatment in its response. Recovery copies are not reused for ordinary processing.

C.5. Processing locations

Limita operates from Denmark. Platform and backup locations are in Germany. Appendix B identifies authorised provider service locations and relevant international processing. Further locations require applicable written notice and authorisation; provider headquarters alone do not describe where processing occurs.

C.6. Transfer instructions and safeguards

The Customer authorises the EEA processing in Appendix B, Proton Mail storage in Switzerland under the European Commission adequacy decision, and Sentry’s described United States metadata and support processing and Canadian service and technical-support processing, subject to an effective Chapter V mechanism.

Sentry’s published transfer terms provide for covered transfers under the EU-US Data Privacy Framework and Standard Contractual Clauses as fallback. Canadian processing must be covered by an applicable adequacy decision or the relevant Standard Contractual Clauses, including onward-transfer safeguards. Limita must establish coverage for the actual transfer and assess any necessary supplementary safeguards. Other third-country processing requires further documented instructions, not merely a general reference to provider terms.

These instructions do not authorise optional AI analysis or model training using customer data. Such processing requires a separate assessment and documented authorisation before it is enabled.

C.7. Audits of Limita

The Customer may first request relevant processing and security information. If this is insufficient, the parties arrange a proportionate audit or inspection by a qualified, confidential auditor. Notice and timing are reasonable; urgent incidents or authority requirements can justify shorter notice. Scope protects other customers’ data and unrelated secrets without preventing verification. No certification or independent audit report is promised unless separately identified as available.

C.8. Oversight of subprocessors

Limita reviews relevant provider terms, security information and available audit evidence, seeks further assurance when needed, and provides relevant information to the Customer. Necessary inspections are coordinated under subprocessor arrangements. Limita’s responsibility and the Customer’s statutory audit rights remain.

Appendix D. Other terms

The Terms govern commercial matters to the extent they do not conflict with this agreement or mandatory law. They cannot restrict data subjects’ statutory rights, authority powers or liability that cannot lawfully be limited.

Supplementary arrangements may be documented electronically. A website revision alone does not establish acceptance of a changed agreement. Each party should retain its applicable version and acceptance or other written agreement.