Finance Department AMJ Denmark

Data Processing Agreement

This Data Processing Agreement describes the data-processing controls that apply when the private Finance application processes personal data in connection with authorized finance operations.

Subject and purpose

Processing is limited to operating, securing and supporting the Finance application, preparing and validating finance workflows, and retrieving accounting information from connected services for authorized reporting.

Categories of data

Depending on the finance workflow, processed data may include names, contact details, customer or supplier identifiers, transaction references, accounting entries, user account information, access logs and other information contained in authorized finance records.

Data subjects

Data may relate to authorized users, members or customers, suppliers, payees and other persons represented in legitimate finance records.

Processing instructions

Personal data must be processed only for authorized finance and administrative purposes and in accordance with documented organizational procedures and applicable law.

Confidentiality and security

Access is restricted by role. Finance users use multi-factor authentication. Integration credentials are encrypted at application level. Reasonable technical and organizational measures must be maintained to protect confidentiality, integrity and availability.

Third-party services and subprocessors

Only services required to host, secure or operate the application and its approved integrations may process data. The organization operating this site is responsible for maintaining any additional processor or subprocessor agreements required by applicable law.

Retention and deletion

Personal data must not be retained longer than required for its authorized purpose, applicable accounting obligations, security requirements or legal obligations. Temporary e-conomic report caches are limited to less than one hour.

Security incidents

Suspected unauthorized access, loss or disclosure of personal data must be escalated promptly through the organization’s security and incident-handling procedures.

Assistance and review

The organization will maintain reasonable records and controls necessary to respond to data-protection requests, security inquiries and compliance reviews relating to the application.

Contact

Questions concerning data processing can be sent to dpo@alislam.dk.