Data Processing Agreement (DPA)

Last updated: 28-07-2026

Purpose

This data processing agreement forms an integral part of the agreement between Credimigo and its business customers.

Roles

The customer is the controller.

Credimigo acts as processor.

Processed data

Depending on usage, Credimigo processes, among other things:

  • company details;
  • personal data of contact persons;
  • invoice information;
  • payment information;
  • communication;
  • audit data;
  • log files.

Purposes

Processing takes place solely for:

  • debt collection management;
  • payment processing;
  • workflow automation;
  • AI analysis;
  • communication;
  • customer support.

Sub-processors

Credimigo may engage carefully selected sub-processors, including for example:

  • cloud hosting;
  • AI providers;
  • email providers;
  • payment providers;
  • monitoring services.

An up-to-date list is made available upon request.

Security

Credimigo takes appropriate measures including:

  • encryption;
  • access control;
  • logging;
  • monitoring;
  • backups;
  • MFA for administrators.

Data breaches

Credimigo reports a data breach without undue delay after it has been identified.

Deletion

Upon termination of the agreement, personal data is deleted or returned, unless statutory retention obligations require otherwise.