CleanTracker logo CleanTracker
Home Blog Help Center Pricing
Log in Dansk
CleanTracker logo CleanTracker
Home Blog Help Center Pricing Log in Dansk

CleanTracker

Data Processing Agreement

Data-processing terms under which Idealrent ApS processes customer operational personal data through CleanTracker.

Effective date
August 29, 2026
Last updated
August 29, 2026
Version
1.0

Provider: Idealrent ApS, CVR 38302388, Monica Zetterlunds Vej 27, 4., 2450 København SV, Denmark · [email protected]

1. Parties and status

This Data Processing Agreement (the DPA) forms part of the agreement under which Idealrent ApS provides CleanTracker to the customer (the Main Agreement). The customer is the Controller, and Idealrent ApS is the Processor, for Customer Personal Data processed through the service. If the customer acts as a processor for another controller, this DPA also applies with the necessary role adjustments, and Idealrent ApS acts as a subprocessor.

The DPA applies automatically when a customer uses CleanTracker to process personal data on behalf of its organization. Terms defined in the GDPR have the same meaning here. If this DPA conflicts with the Main Agreement on protection of Customer Personal Data, this DPA prevails; mandatory data-protection law and applicable transfer clauses prevail over both.

2. Subject matter and duration

Idealrent ApS processes Customer Personal Data to host, operate, maintain, support, secure, and provide CleanTracker and customer-enabled features. Processing continues for the duration of the Main Agreement and the post-termination period described in section 16.

The customer retains control of its data and determines the purposes and essential means of the processing. The processing operations include collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission to instructed integrations and subprocessors, restriction, export, and deletion.

3. Nature and purpose of processing

CleanTracker supports customer and service-address administration, staff and account administration, jobs, visits, scheduling, notes and instructions, check-in/check-out and time registration, optional point-in-time location registration, invoicing workflows, accounting integrations, customer payments, communications, reporting, and CSV import.

If the customer chooses AI-assisted CSV import, relevant content from that selected import may be sent to OpenAI solely to interpret, normalize, and structure the import. This instruction is feature-specific and does not authorize sending all Customer Personal Data to OpenAI.

4. Data subjects

Depending on the customer’s use, data subjects may include:

  • the customer’s customers and their contact persons;
  • the customer’s employees, workers, contractors, and other field personnel;
  • the customer’s users, organization members, and account administrators; and
  • other individuals whose information the customer lawfully enters into CleanTracker.

5. Categories of personal data

Customer Personal Data may include names, addresses, email addresses, telephone numbers, customer/company contact information, employee and account identifiers, roles and access information, schedules, jobs, visits and service-address information, free-text notes and instructions, check-in/check-out timestamps, actual work-duration information, optional GPS coordinates recorded at check-in/out, invoice and accounting-related operational data, communication information, and imported CSV data.

CleanTracker does not require special-category data or personal data relating to criminal convictions and offences. The customer must not intentionally use CleanTracker for such data unless the parties have separately agreed in writing on the processing and the customer has established a lawful basis and appropriate safeguards.

6. Customer instructions and responsibilities

The Main Agreement, this DPA, the customer’s use and configuration of the service, and written instructions accepted by Idealrent ApS constitute the customer’s documented instructions. Idealrent ApS will process Customer Personal Data only on those instructions, including for international transfers, unless EU or Member State law requires otherwise. Where legally permitted, Idealrent ApS will inform the customer before required processing.

Idealrent ApS will promptly inform the customer if, in its opinion, an instruction infringes applicable data-protection law and may suspend the affected processing until the parties resolve the issue.

The customer is responsible for the lawfulness, accuracy, and transparency of its processing, including providing required notices, establishing a legal basis, responding to data subjects, minimizing entered data, managing access, and lawfully configuring optional time and location features and integrations. These responsibilities do not reduce Idealrent ApS’s processor or security obligations.

7. Processor obligations

Idealrent ApS will:

  • process Customer Personal Data only as described in section 6;
  • ensure that authorized personnel process it only as necessary and are bound by confidentiality;
  • implement and maintain appropriate technical and organizational measures under Article 32 GDPR;
  • assist the customer as described in sections 12–14;
  • maintain required processing records and make information necessary to demonstrate compliance available under section 15; and
  • notify the customer if it can no longer meet its material obligations under this DPA.

8. Confidentiality

Idealrent ApS restricts production and support access to authorized persons who need access for service operation, support, security, or legal compliance. Those persons are subject to contractual or statutory confidentiality obligations. Customer Personal Data remains confidential information under the Main Agreement.

9. Security measures

Idealrent ApS will maintain measures appropriate to the risk, taking account of the nature, scope, context, and purposes of the processing. The current measures are summarized in Annex 2. Measures may evolve as technology and the service change, provided the overall protection is not materially reduced.

10. Subprocessors and general authorization

The customer gives Idealrent ApS general written authorization to engage subprocessors needed to provide CleanTracker. The current list is maintained on the public Subprocessors page, which is incorporated into this DPA by reference.

Idealrent ApS will provide reasonable advance notice before a relevant addition or replacement. The notice will identify the proposed subprocessor, its purpose, and a reasonable deadline for objections before the change takes effect. The customer may object within that period on reasonable grounds relating to protection of Customer Personal Data.

The parties will work in good faith to address a valid objection, including through a commercially reasonable alternative where available. If no reasonable resolution is possible, the customer may stop using the affected feature or terminate the affected service where it cannot be provided without that subprocessor. An objection does not authorize the customer to withhold fees already due for unaffected or already-delivered services.

Idealrent ApS will impose data-protection obligations on each subprocessor that are appropriate and substantially equivalent for the delegated processing. Idealrent ApS remains responsible to the customer for its subprocessors’ performance to the extent required by applicable law.

Payment, app-store, authentication, and customer-selected accounting providers may act as independent or separate controllers for some activities. They are listed separately from subprocessors where appropriate.

11. International transfers

The customer’s primary CleanTracker application and database are hosted in Frankfurt, Germany. This does not mean that every provider processes exclusively within the EU/EEA.

Idealrent ApS will not transfer Customer Personal Data to a third country except on the customer’s documented instructions, as required by law, or through an authorized subprocessor under a valid Chapter V GDPR mechanism. Depending on the provider, safeguards may include an adequacy decision, the EU-U.S. Data Privacy Framework for an eligible recipient, or the European Commission’s Standard Contractual Clauses together with supplementary measures where required. Current provider information appears on the Subprocessors page.

12. Data-subject rights

Taking account of the nature of processing, Idealrent ApS will provide reasonable technical and organizational assistance for the customer to respond to requests under GDPR Chapter III. If Idealrent ApS receives a request relating to Customer Personal Data, it will direct the requester to the customer and will not respond substantively unless instructed or legally required.

13. Security, DPIAs, and regulatory assistance

Taking account of the nature of processing and information available, Idealrent ApS will reasonably assist the customer with security obligations, personal-data-breach assessments and notifications, data-protection impact assessments, and prior consultation under Articles 32–36 GDPR.

14. Personal data breaches

Idealrent ApS will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will provide available information reasonably needed for the customer to meet its obligations, including the nature of the incident, affected data and data subjects, likely consequences, and measures taken or proposed. Information may be supplied in phases as the investigation proceeds.

Idealrent ApS will take reasonable steps to contain, investigate, mitigate, and remediate the incident. Notification does not constitute an admission of fault or liability.

15. Information and audit rights

Idealrent ApS will make information reasonably necessary to demonstrate compliance with Article 28 and this DPA available on request. The customer should first use current security documentation, subprocessor information, and relevant independent reports made available by Idealrent ApS or its infrastructure providers.

If that information is insufficient, the customer may request an audit no more than once in a 12-month period, unless a breach, regulator, or well-founded compliance concern reasonably requires more. Audits must be arranged with reasonable notice, during normal business hours, minimize disruption, protect other customers and confidential information, and be performed by the customer or an independent auditor bound by confidentiality. The customer bears its audit costs unless the audit establishes a material breach by Idealrent ApS.

16. Return and deletion after termination

During the relationship, the customer may use available service functionality to access and export Customer Personal Data. On termination, Idealrent ApS will retain operational Customer Personal Data for up to 30 days to allow orderly closure and restoration of the relationship where applicable. No later than the end of that period, it will delete the data from active systems unless EU or Member State law requires retention.

Residual backup copies expire through the normal backup cycle after active-system deletion and remain protected and unavailable for ordinary use in the meantime. The current primary database backup retention is approximately three days; operational backup cycles may change without amending this DPA, provided copies are retained only for continuity/recovery and expire in accordance with the documented cycle.

This section does not require deletion of separate records for which Idealrent ApS is controller and has a lawful retention purpose, such as accounting, security/fraud, contractual documentation, statutory obligations, or legal claims. Such records are not used to continue the customer’s terminated operational processing.

17. Liability and Main Agreement

Liability under this DPA is subject to the allocation and limitations in the Main Agreement to the extent permitted by applicable law. Nothing in this DPA limits rights or liability that cannot legally be limited, including data subjects’ mandatory rights.

18. Governing framework and changes

This DPA is governed by Danish law and the jurisdiction provision in the Main Agreement, without displacing the GDPR, applicable Member State data-protection law, or mandatory rights of supervisory authorities and data subjects.

Idealrent ApS may update this DPA to reflect legal requirements or service changes. Material changes will receive appropriate advance notice. Changes will not materially reduce the protection of Customer Personal Data during a current paid term without a lawful basis or the customer’s agreement.

Annex 1 — Processing details

Subject matter and purpose: Provision, support, security, and customer-directed use of CleanTracker as described in sections 2–5.

Duration: The Main Agreement, up to 30 days of post-termination active-system retention, and normal backup expiry afterward.

Data subjects and data: The categories in sections 4 and 5.

Frequency: Continuous during ordinary service use; optional integrations and AI-assisted import are used only when selected or configured by the customer.

Controller rights and obligations: The customer determines purpose and essential means, gives lawful instructions, manages users/configuration, and fulfils controller obligations. It may access, correct, export, restrict, and request deletion of data through available service features or support.

Annex 2 — Technical and organizational measures

  • Hosting and transmission: Primary application and PostgreSQL database hosted on Render in Frankfurt. TLS is used for data in transit between clients and the service.
  • Authentication and access: Authenticated accounts, organization-scoped authorization, role/permission checks, and server-side validation protect non-public functions.
  • Production access: Production access is limited to authorized personnel with an operational need. Secrets and service credentials are managed outside source code through deployment configuration.
  • Application safeguards: Input validation, organization-level data separation, permission enforcement, dependency maintenance, and review/testing practices support confidentiality and integrity.
  • Logging and detection: Application/server logs and diagnostic information are used to operate, troubleshoot, and investigate security events. Logs are access-restricted and should avoid unnecessary personal data.
  • Availability and backups: Infrastructure health checks and Render database backups support recovery. Current primary-database backup retention is approximately three days.
  • Incident handling: Suspected security incidents are assessed, contained, investigated, documented as appropriate, and communicated under section 14.
  • Development practices: Development and production configuration are separated; production credentials are not intended for development use.
  • Provider governance: Providers are selected for defined purposes, subject to appropriate contractual terms, and reviewed through the public provider inventory and change process.

No certification, 24/7 monitoring commitment, or encryption-at-rest guarantee by Idealrent ApS is stated beyond measures verified for the relevant infrastructure provider.

© 2026 CLEANTRACKER

CleanTracker is a product of Idealrent ApS

CVR: 38302388

Legal

  • Privacy
  • Data Processing Agreement
  • Subprocessors
  • Terms