GDPR at Available

Clients trust us with personal data — in the services we build and run, and in their own systems where our consultants work. This page answers the standard GDPR due-diligence questions once, publicly, so your vendor assessment can start here instead of with a blank questionnaire. The data processing agreement (DPA) signed with each client governs the specific engagement.

Our roles

  • Processor — for personal data we handle on a client's behalf: in the services we operate for you, and in your own systems (most often your Zendesk instance) during consulting engagements. You are the controller; we act on your documented instructions under a written DPA.
  • Controller — for Available's own business data: employees, applicants, and business contacts.

Available ApS (CVR 42398683) is established in Denmark; our supervisory authority is Datatilsynet.

What our DPA commits us to

The Article 28 processor obligations, in plain terms:

  • Processing only on your documented instructions, for the purposes of the engagement.
  • Confidentiality — everyone with access is bound contractually, surviving employment.
  • Security (Article 32) — encryption in transit and at rest, MFA and least-privilege access reviewed quarterly, hourly backups with regular restore tests, and security training for everyone. The full picture is in the Security overview.
  • Subprocessors only under written agreements with equivalent obligations, published on our subprocessor list, with 30 days' written notice of changes and a right to object.
  • Assistance with data subject requests and with your own security, breach-notification, and impact-assessment obligations (Articles 32–36).
  • Breach notification without undue delay after we become aware that a breach affects your data — with the facts you need for your own 72-hour notification to the supervisory authority.
  • Return or deletion of personal data at the end of the engagement, at your choice.
  • Audit and information rights — start with this site; much of the documentation is already public here.

Copy of our standard DPA: security@available.dk.

Where personal data is processed

Within the EU/EEA, unless stated otherwise on the subprocessor list — where a subprocessor involves a third-country transfer, the safeguards (EU Standard Contractual Clauses, EU-US Data Privacy Framework where applicable) are listed per subprocessor. Clients can choose the Danish-only AI option: all AI processing of their data happens exclusively with our Danish provider, and no client data is transferred outside the EU/EEA.

Accountability

  • GDPR runs inside the same management system as security: an ISMS aligned with ISO/IEC 27001:2022 (certification in progress), whose risk assessments, internal audits, and management reviews cover privacy alongside security.
  • We maintain records of processing activities (Article 30) for both roles.
  • Data minimisation and retention — we work with the minimum personal data the task needs and delete per defined retention periods.

Your rights

Where we process your personal data as a processor, the controller is the client whose service you use — contact them, and we assist them in answering you. Where Available is the controller (e.g. applicants and business contacts), write to security@available.dk to exercise your rights of access, rectification, erasure, restriction, portability, or objection. You can always lodge a complaint with Datatilsynet.

Version 0.1 · Last reviewed 2026-08-26