Legal
Data processing agreement
When your business sells gift cards and tickets or takes table bookings through Kuvert, Kuvert processes information about your customers and guests on your behalf. This agreement regulates that processing and is entered into between the business («the data controller») and MICCI («the data processor»).
Last updated 15 September 2026
1. Subject matter and duration
Processing is carried out solely for the purpose of providing the service: to issue, deliver, view and redeem gift cards and tickets, to take and keep track of table bookings and the business's guest book, and to make available the associated reports to the business.
The agreement runs as long as the business has an account with Kuvert, and ends at the same time as the account.
2. Categories of data subjects and information
Data subjects are buyers and recipients of gift cards and tickets, guests who book a table, and the business's own users. Ordinary personal data is processed:
- Name, email address and telephone number.
- The personal greeting the buyer writes to the recipient.
- Order, card and redemption history, including amounts and times.
- For table booking: time and number of guests, notes and answers to the business's questions, the business's own notes about the guest, visit, cancellation and no-show history, ratings after the visit, and the card's brand and last four digits for a deposit or fee.
- Allergies and special needs that a guest gives when booking a table can be health data and thus a special category of personal data. They are processed solely so that the business can take them into account, are shown only to the users whose role gives access to the guest book, and are deleted together with the guest. Beyond this, no special categories of personal data are processed.
3. Instructions
The data processor processes personal data only according to documented instructions from the data controller. Use of the service according to its documented purpose constitutes such an instruction.
The data processor notifies the data controller if an instruction, in the data processor's assessment, conflicts with data protection rules.
4. Confidentiality and security
Access to personal data is limited to those who have a need for it, and these are bound by confidentiality.
Appropriate technical and organisational measures have been taken, including encryption of data in transit, role-based access control, hashed passwords, signed webhooks and separation of each business's data.
5. Sub-processors
The data controller gives general approval for the use of the following sub-processors:
- Stripe — payment processing and identity verification.
- PostStack — sending of email to buyers, recipients and guests.
- HostStack — hosting and operation of application and database.
6. Transfers to third countries
Processing is generally carried out within the EU/EEA. If transfer to a third country occurs through a sub-processor, it takes place on a valid transfer basis, including the European Commission's standard contractual clauses.
7. Assistance to the data controller
The data processor assists to a reasonable extent the data controller in responding to requests from data subjects for access, correction, deletion and restriction, as well as with security, breach notification and impact assessments.
If the data processor becomes aware of a personal data security breach, it notifies the data controller without undue delay.
8. Deletion upon termination
Upon termination of the agreement, the data processor deletes personal data unless the law requires continued storage — including the Danish Bookkeeping Act's (bogføringsloven) requirement for five years' storage of accounting material.
The data controller may request that its data be supplied in a commonly used format before termination. The business's gift card data can additionally be downloaded as CSV directly in the dashboard without asking.
9. Audit
The data processor makes available the information necessary to demonstrate compliance with this agreement and permits audit subject to prior written agreement.
Have questions about this page? Write to hej@kuvert.dk.