Legal, Effective Date: 8. aug. 2026
Vilkår, betingelser og databehandleraftale
Part 1: Terms and Conditions
These Terms and Conditions ("Terms") govern the use of Hubverk ("the Service"), provided by Enia, CVR: Pending ("the Provider", "we", "us"). By registering for and using the Service, you ("the Tenant", "User") agree to be bound by these Terms.
1. Nature of the Service and Legal Capacity
- B2B and B2C Data: The Service is a multi-tenant Field Service Management tool designed primarily for business entities, freelancers, and solopreneurs. While the Tenant uses the Service to manage their own business operations and store end-consumer (B2C) data, the contractual relationship is strictly between the Provider and the Tenant.
- Tenant Responsibility for End-Users: The Tenant represents and warrants that they have all necessary legal rights, consents, and permissions to collect, store, and process data belonging to their end-consumers (B2C clients) within the Service.
2. Subscription, Billing, and Grace Periods
- Billing Cycle: The Service is billed on a recurring monthly basis. Payment is due upfront at the start of each billing cycle.
- Failed Payments & 30-Day Grace Period: If a recurring payment fails, the Provider will notify the Tenant via email or in-app notification. The Tenant is granted a 30-day grace period from the initial failure date to update their payment details and settle the balance.
- Suspension: If the balance is not settled within the 30-day grace period, the Provider reserves the right to suspend access to the infrastructure immediately without further notice.
- Price Adjustments: The Provider reserves the right to modify subscription fees. Notice of price changes will be communicated to the Tenant with the minimum notice required by applicable law before taking effect.
3. Invoicing and Third-Party Payment Integrations
- Tenant Payment Gateways: The Service allows Tenants to connect third-party payment gateways (e.g., Stripe) to facilitate payments from their own clients. The Tenant must sign up for, maintain, and abide by the terms of these third-party services independently. The Provider is not a party to these transactions and bears zero liability for gateway failures, chargebacks, or transaction disputes.
- Compliance: The Service provides tools to generate invoices. While the Provider strives to keep the software features aligned with standard accounting practices, the Tenant is ultimately responsible for ensuring their generated invoices comply with Danish tax laws (Skattelovgivningen).
4. Data Ownership, Backups, and Total Liability Exclusion for Data Loss
- Data Ownership: The Tenant retains full and exclusive ownership of all data, leads, quotes, schedules, and client information uploaded to the platform. The Provider retains exclusive ownership of the application, infrastructure, code, design, and intellectual property.
- Tenant Responsibility for Backups: While the Provider implements standard automated infrastructure backups, the Tenant acknowledges and agrees that the Provider is not an archival or data vault service. The Tenant bears sole responsibility for maintaining independent, local backups of all critical business records, customer details, invoices, and schedules exported from the Service.
- Absolute Exclusion of Liability for Data Loss: To the maximum extent permitted by Danish law, the Provider shall under no circumstances be liable for any loss, corruption, alteration, destruction, or unauthorized access to Tenant data, nor for any direct, indirect, incidental, consequential, special, or financial losses resulting directly or indirectly from such data loss. This absolute exclusion includes, but is not limited to:
- Loss of business profits, revenue, opportunities, or contracts resulting from unrecoverable schedule or client data.
- Costs associated with manual data reconstruction, customer notification, or business downtime.
- Data loss caused by hardware failure, cloud provider outages, software bugs, malicious attacks, or accidental Tenant deletion.
- Aggregate Financial Cap on Liability: In the event that liability cannot be completely excluded under mandatory Danish law, the Provider’s total aggregate financial liability arising out of or related to the Service, whether in contract, tort (including negligence), or otherwise, shall be strictly limited to the total subscription fees actually paid by the Tenant to the Provider in the three (3) months preceding the incident giving rise to the claim.
- Indemnification by Tenant: The Tenant agrees to defend, indemnify, and hold harmless the Provider against any third-party claims, liabilities, damages, losses, or legal fees arising from data loss, GDPR breaches concerning end-consumer data, or unlawful use of the Service by the Tenant.
- Data Deletion & 5-Year Retention: The Service includes safety measures requiring explicit Tenant confirmation before data deletion. However, to ensure mutual compliance with the Danish Bookkeeping Act (Bogføringsloven), financial data and relevant logs will be retained securely by the Provider for 5 years following the end of the financial year to which the data relates, even if the account is terminated.
5. Acceptable Use and Immediate Suspension
- Illegal Activity: The Tenant agrees not to use the Service for any unlawful, fraudulent, or abusive activities (including, but not limited to, sending spam SMS reminders, phishing, or violating GDPR/Databeskyttelsesloven).
- Right to Terminate: The Provider reserves the right to immediately suspend or terminate any Tenant account, without prior notice or refund, if the Provider reasonably suspects or identifies illegal activity, system abuse, or actions that threaten the stability of the multi-tenant infrastructure.
6. Governing Law and Venue
- These Terms shall be governed by and construed in accordance with the laws of Denmark.
- Any legal disputes arising out of or in connection with these Terms that cannot be settled amicably shall be brought exclusively before the District Court of Nykøbing Falster (or the relevant city court nearest to the Provider's registered address).
Part 2: Data Processing Agreement (DPA)
Between:
- The Tenant using the SaaS platform (hereinafter the "Data Controller")
- Enia, CVR: Pending (hereinafter the "Data Processor")
1. Scope and Purpose
1.1. This Agreement applies to the Data Processor’s processing of personal data on behalf of the Data Controller through the Field Service Management software ("the Service").
1.2. The categories of personal data processed include: B2C customer contact details (names, addresses, email addresses, phone numbers), service appointment schedules, notes, and invoicing metadata uploaded by the Data Controller.
1.3. The purpose of the processing is strictly limited to delivering the core functionality of the Service (scheduling, invoicing, lead tracking, and system administration).
2. Obligations of the Data Processor
2.1. Instructions: The Data Processor shall process personal data exclusively on documented instructions from the Data Controller, including with regard to transfers of personal data to a third country or an international organization.
2.2. Confidentiality: The Data Processor shall ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
2.3. Security Measures (Art. 32 GDPR): The Data Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Logical data separation between distinct tenant accounts in the database architecture (multi-tenancy isolation).
- Encrypted connections (TLS/HTTPS) for data in transit and encrypted automated backups.
- Restricted access control limited strictly to system maintainers and required operational tasks.
3. Sub-Processors
3.1. The Data Controller hereby grants general authorization to the Data Processor to engage third-party sub-processors.
3.2. The Data Processor shall ensure that any sub-processor is bound by data protection obligations at least equivalent to those outlined in this Agreement.
3.3. Primary sub-processors include:
- Cloud Hosting & Infrastructure: [e.g., Hetzner / DigitalOcean / AWS] (Server locations within EU/EEA).
- Transactional Email / SMS: [e.g., Mailgun / Brevo / Twilio] (Used for automated notifications).
4. Rights of Data Subjects and Assistance
4.1. Taking into account the nature of the processing, the Data Processor shall assist the Data Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Data Controller's obligation to respond to requests for exercising data subject rights under GDPR.
4.2. In the event a data subject (end-consumer) contacts the Data Processor directly, the Data Processor shall redirect the request to the Data Controller without delay.
5. Personal Data Breaches
5.1. The Data Processor shall notify the Data Controller without undue delay (and no later than 48 hours) after becoming aware of a personal data breach impacting the Data Controller's data.
5.2. The notification shall contain reasonable details regarding the nature of the breach, affected data categories, and immediate mitigation steps taken.
6. Audit Rights and Compliance
6.1. The Data Processor shall make available to the Data Controller information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.
6.2. Reasonable audits may be satisfied by the Data Processor providing technical documentation, security architecture overviews, or third-party server compliance certifications.
7. Data Retention, Return, and Deletion
7.1. Upon termination of the subscription, the Data Controller is responsible for exporting their data using the tools provided within the Service.
7.2. In accordance with the Danish Bookkeeping Act (Bogføringsloven), financial records, invoice metadata, and relevant transactional logs will be retained securely in an archived state by the Data Processor for 5 years from the end of the current financial year, after which they will be permanently purged or anonymized.
7.3. Non-financial, non-required operational data will be purged within 90 days of subscription termination.
8. Governing Law and Jurisdiction
8.1. This Agreement shall be governed by Danish law (Dansk ret), and any dispute shall be submitted to the jurisdiction specified in the main Terms and Conditions.