Data Privacy Policy

Your privacy is very important to us. This policy explains the information we collect from
you, how we use it, and our information security measures.
This Data Privacy Policy regulates the processing of personal data on behalf of the customer
(the “Data Controller”) by Oracle Erp Solutions, trading as Digital Solutions (the “Data
Processor”). It is incorporated into the Oracle Erp Solutions subscription agreement (the
“Main Agreement”), which outlines the terms for the delivery of services to the Data
Controller (the “Main Services”).

Legislation
This Privacy Policy ensures that the Data Processor complies with applicable data protection
and privacy legislation (the “Applicable Law”), including:
 Directive 95/46/EC on the protection of individuals regarding personal data
processing and free movement of such data, implemented into Danish law under the
Act on Processing of Personal Data (Act No. 429 of 31 May 2000).
 Regulation (EU) 2016/679 (GDPR), effective from 25 May 2018.
Processing of Personal Data
In delivering the Main Services, Oracle Erp Solutions processes specific categories and types
of personal data on behalf of the Data Controller. “Personal data” includes any information
about an identifiable natural person, as defined in GDPR Article 4(1). The categories of
personal data are outlined in Sub-Appendix A and are only processed as necessary for
delivering the Main Services. Oracle Erp Solutions will maintain a processing activities
register as required by GDPR Article 32(2).
Personal data processed for sales, marketing, and product development where Oracle Erp
Solutions is the Data Controller are governed by our standalone privacy policy, available on
our website.

Instruction
(Digital Solutions) Oracle Erp Solutions may only process personal data in accordance with the documented
instruction from the Data Controller, which is to provide the Main Services as outlined in the
Main Agreement. Oracle Erp Solutions will notify the Data Controller without undue delay if
any instruction is deemed to conflict with the Applicable Law.

The Data Processor’s Obligations

Confidentiality

All personal data will be treated with strict confidentiality. Access is restricted to employees
who require it to fulfill the Main Services. All such employees are bound by confidentiality
obligations.

Security
Oracle Erp Solutions will implement technical and organizational measures aligned with
GDPR Article 32 to protect personal data and ensure secure access controls. Documentation
of these measures will be provided upon written request.
Assistance & Rights of Data Subjects
Where necessary, Oracle Erp Solutions will assist the Data Controller in data protection
impact assessments (GDPR Article 35), consultations (Article 36), and handling data subject
requests.

Personal Data Breaches
Any breach will be reported immediately, with a register maintained containing the nature,
consequences, and remedial actions of the breach. Copies of this register will be provided
upon request.

Compliance Documentation
Documentation verifying compliance with this policy and GDPR will be provided upon
written request within reasonable timeframes.

Data Transfer
Personal data may be transferred outside the EEA only in compliance with Applicable Law
and only for service delivery purposes.
The Data Controller’s Obligations
The Data Controller agrees to comply with their obligations under the Data Protection Laws,
including obtaining any necessary consents for processing personal data and issuing lawful
instructions.

Sub-Processors
Oracle Erp Solutions may engage third-party Sub-Processors. All Sub-Processors are
contractually required to meet equivalent data protection obligations as set out in this
agreement.

Remuneration and Costs
Oracle Erp Solutions may charge for time and materials required to adapt processing in
response to changes in instructions or applicable laws.
Breach and Liability

In the event of a security breach, Oracle Erp Solutions will promptly notify the Data
Controller and assist with necessary reporting. Liability is limited except in cases of gross
negligence or willful misconduct.

Duration
This agreement remains valid until termination of the Main Agreement.
Personal Data Processed
Includes contact information of relevant employees, names, phone numbers, emails,
addresses, IPs, and data provided by users.
Categories of Data Subjects
 Customers
 End-users

Legal Disclaimer
We may disclose personal data if required by law or to protect our rights in a legal
proceeding.

Security Statement
We use SSL and industry-standard measures to protect data, though no method is 100%
secure.

Termination
Upon termination, Oracle Erp Solutions will cease processing and return all personal data to
the Data Controller, unless retention is required by law.
Changes to This Policy

We may update this policy from time to time. Any significant changes will be communicated
through appropriate channels. For inquiries, please contact us via our website.