Scope
This Data Processing Agreement ("DPA") forms part of the ChartKit Terms of Service (the "Agreement") between ChartKit ApS, CVR 46291883, Ane Katrines Vej 14, 3. 3., 2000 Frederiksberg, Denmark ("ChartKit") and the customer that accepts the Agreement ("Customer"). It is deemed executed when Customer accepts the Agreement or signs an Order Form that references it. If this DPA conflicts with the Agreement, this DPA prevails for the processing of Personal Data.
1. Definitions
“Data Protection Law” means the EU General Data Protection Regulation 2016/679 (“GDPR”), the Danish Data Protection Act, and any other data protection law that applies to the processing under this DPA.
“Customer Data” means the data Customer's users create or upload through the Service: chart tables, chart specifications, icons, and prompts sent to AI features.
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR.
“Sub-processor” means a third party engaged by ChartKit to process Personal Data on Customer's behalf.
“Service” means the ChartKit extension, add-in, web application and API described in the Agreement.
2. Roles
2.1 For Customer Data, Customer is the Controller and ChartKit is the Processor.
2.2 For account data (name, email, Google account identifier), billing data and usage events, ChartKit is an independent Controller and processes that data under its Privacy Policy. This DPA does not apply to that processing.
2.3 Customer warrants that it has a lawful basis for the Personal Data it places in Customer Data and that its instructions to ChartKit comply with Data Protection Law.
3. Details of processing
The subject matter, duration, nature, purpose, categories of Data Subjects and categories of Personal Data are set out in Annex I.
4. ChartKit's obligations
4.1 Instructions. ChartKit processes Customer Data only on Customer's documented instructions. The Agreement, this DPA, and Customer's use of the Service are the complete instructions. ChartKit informs Customer if it believes an instruction infringes Data Protection Law, unless the law prohibits it.
4.2 Purpose limitation. ChartKit does not use Customer Data for any purpose other than providing the Service. ChartKit does not use Customer Data, prompts or outputs to train or improve machine-learning models, and requires the same of its AI Sub-processors.
4.3 Confidentiality. Persons authorised to process Customer Data are bound by confidentiality obligations.
4.4 Security. ChartKit implements the technical and organisational measures in Annex II and maintains them at a level appropriate to the risk. ChartKit may update Annex II provided the overall level of protection does not decrease.
4.5 Data Subject requests. ChartKit forwards to Customer without undue delay any request it receives from a Data Subject relating to Customer Data, and assists Customer with reasonable technical measures to respond.
4.6 Assistance. ChartKit assists Customer, at Customer's reasonable request, with data protection impact assessments and consultations with a Supervisory Authority, taking into account the nature of the processing and the information available to ChartKit.
4.7 Personal Data Breach. ChartKit notifies Customer of a Personal Data Breach affecting Customer Data without undue delay and no later than 48 hours after becoming aware of it. The notice describes the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. ChartKit may provide the information in phases as it becomes available.
4.8 Deletion and return. Customer may export Customer Data through the Service during the term. Within 30 days after the Agreement ends, ChartKit deletes all Customer Data, or returns it first if Customer requests the return in writing before the end of that period. ChartKit confirms deletion in writing on request. Copies in backups are deleted within 90 days. ChartKit may retain data that Union or Danish law requires it to keep, and only for as long as that law requires.
4.9 Audit. ChartKit makes available the information reasonably necessary to demonstrate compliance with this DPA. Customer may audit that compliance once in any 12-month period, on 30 days' written notice, first through a written questionnaire and the audit reports of ChartKit's Sub-processors. An on-site audit is available only after a confirmed Personal Data Breach affecting Customer Data. Customer bears its own audit costs and ChartKit's reasonable costs of participation.
5. Sub-processors
5.1 Customer authorises ChartKit to engage the Sub-processors listed in Annex III.
5.2 ChartKit gives at least 30 days' written notice, by email to the Customer's team administrator and to the address subscribed at getchartkit.app/legal/subprocessors, before adding or replacing a Sub-processor.
5.3 Customer may object in writing within the notice period on reasonable grounds relating to data protection. The parties then discuss the objection in good faith. If ChartKit cannot resolve it, Customer may terminate the affected part of the Service and receive a pro-rated refund of prepaid fees for the remaining term.
5.4 ChartKit imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable to Customer for the Sub-processor's performance.
6. International transfers
6.1 ChartKit stores Customer Data in the European Union (Annex III). Where a Sub-processor processes Personal Data outside the EU or EEA, the transfer relies on an adequacy decision of the European Commission, including the EU-US Data Privacy Framework, or on the Standard Contractual Clauses adopted under Article 46(2)(c) GDPR as entered into between ChartKit and that Sub-processor.
6.2 If Customer is established outside the EU or EEA and Data Protection Law requires a transfer mechanism for ChartKit's processing, the Standard Contractual Clauses, Module Two (controller to processor), are incorporated into this DPA with Customer as data exporter and ChartKit as data importer, with the Annexes to this DPA serving as the Annexes to those clauses, Danish law and the Danish courts for Clauses 17 and 18, and the Danish Data Protection Agency as the competent Supervisory Authority.
7. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits a party's liability to a Data Subject or a Supervisory Authority where Data Protection Law does not permit that limitation.
8. Term, changes and governing law
8.1 This DPA applies for as long as ChartKit processes Customer Data.
8.2 ChartKit may update this DPA to reflect changes in Data Protection Law or the Service by publishing a new version at getchartkit.app/legal/dpa and notifying Customer's team administrator at least 30 days before it takes effect, provided the change does not reduce the protection of Personal Data.
8.3 This DPA is governed by Danish law and the courts named in the Agreement.
Annex I: Description of processing
| Subject matter | Charts, icons and AI prompts that Customer's users create in Google Slides, Docs, Sheets and Microsoft PowerPoint through the Service |
| Duration | The term of the Agreement plus the deletion period in clause 4.8 |
| Nature and purpose | Storing chart models so that they can be re-opened and edited; rendering chart images for insertion into the host document; generating chart suggestions from prompts when a user invokes AI features |
| Categories of Data Subjects | Customer's employees and contractors who use the Service. Any person whose data a user places in a chart, for example employees, customers or survey respondents named in a table |
| Categories of Personal Data | Any Personal Data a user types into a chart table or a prompt. The Service does not require Personal Data and does not scan for it. Google Drive and Slides access is limited to files the Service itself created |
| Special categories | None intended. Customer is responsible for not placing special-category data in charts unless it has a lawful basis |
| Frequency | Continuous during use |
| Retention | Chart models: until deleted by the user or under clause 4.8. Rendered images: expire within 10 minutes. AI prompts: not stored by ChartKit after the response is returned |
Annex II: Technical and organisational measures
- Authentication. Users sign in with Google OAuth. ChartKit stores no passwords. Team administrators control membership.
- Least privilege on Google data. The Service requests the
drive.filescope only, so it can read and write the files it created and nothing else in the user's Drive. - Encryption. TLS 1.2 or higher on every connection. Encryption at rest in the database and the chart store, provided by the hosting Sub-processors.
- Data location. The database is hosted in the EU (Ireland). Chart models are stored in Cloudflare's key-value store and rendered images expire from Cloudflare's edge within 10 minutes.
- Access control. Production access is limited to named ChartKit personnel, with multi-factor authentication on every vendor account and no shared credentials.
- Analytics separation. Usage events carry event names and account identifiers only, never chart or document content, and can be disabled per user in the extension settings.
- Backups. Daily database backups by the hosting Sub-processor, encrypted at rest, retained for 7 days.
- Sub-processor assurance. Hosting, database, identity and payment Sub-processors hold SOC 2 Type II or ISO 27001 certification. ChartKit itself does not currently hold a certification and provides a security questionnaire on request.
- Incident handling. Security incidents are logged, assessed and, where they meet the threshold in clause 4.7, notified to Customer within 48 hours.
- Secure development. Type-checked code, dependency updates, and review of every change before release.
Annex III: Sub-processors
| Sub-processor | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, chart model storage, rendered image cache, edge delivery | Global edge network, US entity | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Supabase, Inc. | Database and authentication | EU (Ireland, eu-west-1) | Standard Contractual Clauses; data remains in the EU |
| Google LLC | Sign-in, Google Drive and Slides API, Gemini API for AI features, Google Analytics for usage events | US | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Stripe, Inc. | Subscription billing | US | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend, Inc. | Transactional email | US | Standard Contractual Clauses |
| GitHub, Inc. | Feedback tracking, only for feedback a user submits | US | EU-US Data Privacy Framework |
Last updated 14 September 2026. Subscribe to change notices at getchartkit.app/legal/subprocessors.