Data Processing Agreement (DPA)
Public Article 28 GDPR processor agreement for Bidmio customers.
1. Subject
This is an Article 28 GDPR processor agreement between the Bidmio customer (controller) and Sikmo Digital, CVR 32014283 (processor). It applies when these terms are accepted or confirmed in writing before production personal data is loaded.
2. Processing details
Purpose: providing the Bidmio cloud ERP. Categories and data types are set by the customer. Special-category data only if the customer enters it. Duration: the contract term plus deletion periods.
3. Processor obligations
We process only on documented instructions, keep data confidential, assist with data-subject requests, notify incidents without undue delay, and delete or return data after the contract ends except where law requires retention.
4. Subprocessors
The customer authorises the subprocessors listed on the Technology page and here: Hetzner, Neon, Replit, OpenAI, Zoho, Resend and Google. We will give prior notice of a new subprocessor; the customer may object on reasonable grounds.
5. Security
We use HTTPS/TLS, hashed passwords, role-based access, organisation isolation, regular backups and access logging. We do not hold an ISO 27001 or SOC 2 certificate. Independent test results will be shared in writing when available.
6. Deletion and audit
Production data is deleted 30 days after access ends; backups within 90 days. The customer may request reasonable written information about compliance once per year.
Signature and questions
privacy@bidmio.com
Sikmo Digital
CVR: 32014283
Præstbrovej 22, 8464 Galten, Denmark
Responsible person: Daniel Gadus
Confirm the DPA by email before loading production data.
