Data processing agreement

Version 1.0 — effective 1 August 2026

This is a courtesy translation provided for convenience. In case of any discrepancy or dispute, the Danish version prevails.

1. Parties and background

This data processing agreement is part of the agreement between you (the customer, the "controller") and Stilnote ApS, CVR 45863166 (the "processor"), and applies automatically when you use Stilnote. It fulfils the requirements of Article 28 of the GDPR.

When you create projects in Stilnote, you may enter personal data about your clients — such as a name and address on a project. For that data you are the controller, and Stilnote processes it solely on your behalf.

2. Scope of processing

  • Purpose: providing Stilnote — project management, client pages and PDF material plans
  • Categories of data: ordinary personal data — name, address and any information you enter in notes and descriptions
  • Data subjects: your clients and other persons you enter information about
  • Duration: for as long as you have an account; the data is deleted when your account is deleted

3. Instructions

Stilnote processes the data only on your documented instructions — constituted by your use of the Service (e.g. when you create, share or delete a project) — and never for its own purposes. If we are legally required to process the data otherwise, we will notify you unless the law prohibits it.

Note:When you publish a client page, you decide yourself (via "Customise client page") whether the client's name and address are shown on the shared page. Sharing therefore happens on your instruction.

4. Confidentiality and security

Everyone processing the data at Stilnote is bound by confidentiality. We implement appropriate technical and organisational measures (GDPR Art. 32), including:

  • Data is stored in the EU (Frankfurt, Germany) and encrypted in transit and at rest
  • Row-level access control in the database (Row Level Security) — only your account can access your data
  • Shared client pages sit behind long, random links and are excluded from search engine indexing
  • Ongoing security reviews and need-based access restriction

5. Sub-processors

You give a general authorisation for Stilnote to use sub-processors. The current list is below. If the list changes, we update this page and notify you by email at least 30 days in advance so you can object. All sub-processors are bound by data processing agreements with at least the same level of protection as this one.

Sub-processorFunctionData location
SupabaseDatabase, login and file storageEU (Frankfurt)
VercelHosting of the web applicationEU/US
AnthropicAI features (product import, image analysis)US
SentryError loggingUS

For transfers to countries outside the EU/EEA, the European Commission's Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework are used as the transfer mechanism.

6. Assistance to you

Stilnote assists you — to the extent possible via the Service's features or on request — in responding to requests from data subjects (access, rectification, erasure, etc.) and with your obligations regarding security, breaches and any impact assessments. You can rectify and delete data directly in the Service yourself.

7. Personal data breaches

If Stilnote becomes aware of a breach affecting your data, we notify you without undue delay and no later than within 48 hours, with the information you need to meet your own 72-hour notification deadline to the supervisory authority.

8. Deletion on termination

When you delete your account, all data — including your clients' — is permanently deleted from our systems. If you want to keep a copy, export your materials (e.g. PDF plans) before deleting the account.

9. Documentation and audits

On request, Stilnote makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits. Contact info@stilnote.com.