GDPR & Data Protection
At Teamful, data protection is a foundational part of how we build and operate our platform. As a company headquartered in Copenhagen, Denmark, we operate under the European Union’s General Data Protection Regulation (GDPR) as a default standard, not as an optional add-on.
Our services are used by agencies, brands, creators, and collaborators to manage complex campaign workflows involving personal data. We recognise that our customers rely on Teamful not only for functionality, but also for trust, confidentiality, and regulatory compliance. This page explains how we approach GDPR and data protection in practice.
⸻
Our Role Under GDPR
When customers use Teamful, they remain the data controllers for the personal data processed within the platform. This means customers decide what data is collected, how it is used, who has access to it, and how long it is retained.
Teamful acts as a data processor. We process personal data solely on the documented instructions of our customers and only to the extent necessary to provide and operate the service. We do not determine the purposes for which customer data is processed, and we do not use customer data for advertising, resale, or independent profiling.
The processor–controller relationship is formally governed by our Data Processing Addendum (DPA), which forms part of our contractual framework and aligns with GDPR Article 28 requirements.
⸻
Lawful Processing and Purpose Limitation
All personal data processed within Teamful is handled for specific, legitimate, and limited purposes related to the delivery of the service. These purposes include enabling campaign planning, collaboration, approvals, reporting, integrations with third-party platforms at customer instruction, platform security, and customer support.
Personal data is not processed beyond what is necessary for these purposes. Customers retain control over the data they input into the platform, the users they invite, and the scope of access granted to each participant. Teamful does not expand or repurpose customer data beyond the agreed service context.
⸻
Data Protection by Design and by Default
Teamful applies the GDPR principles of data protection by design and by default across product development, infrastructure, and internal operations.
From a technical perspective, the platform is designed so that access is restricted by default rather than open. Projects, campaigns, and workspaces are structured to minimise unnecessary data exposure, and permissions must be explicitly granted. From an operational perspective, privacy considerations are incorporated into feature planning, system architecture, and internal procedures.
New features are reviewed with data protection in mind to ensure they support confidentiality, integrity, and lawful processing from the outset.
⸻
Access Control, Segmentation, and Confidentiality
A core GDPR requirement is ensuring that personal data is accessible only to individuals who need it for legitimate purposes. Teamful is built specifically to support this requirement in real-world campaign workflows.
Within the platform, access is controlled through role-based permissions. Users can only see the projects, deliverables, and data they are assigned to. External collaborators such as creators or clients are isolated from internal workspaces unless explicitly invited. Parallel projects within the same campaign remain separated, ensuring that stakeholders do not gain visibility into unrelated scopes, budgets, or performance data.
This approach helps customers maintain confidentiality, reduce the risk of accidental disclosure, and meet GDPR obligations around access control and data minimisation.
⸻
Security of Processing
Teamful implements technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures are proportionate to the nature of the data processed and the risks involved.
Security controls include access restrictions, authentication mechanisms, encryption of data in transit and, where appropriate, at rest, monitoring and logging of system activity, and defined incident response procedures. Access to customer data is limited to authorised personnel with a legitimate business need and subject to confidentiality obligations.
Further details about our security practices are available on our Security & Compliance page and in the Annex to our Data Processing Addendum.
⸻
Sub-processors and International Transfers
To deliver the Teamful service, we rely on carefully selected sub-processors, such as cloud infrastructure providers, payment processors, and support tooling. All sub-processors are subject to contractual obligations that require them to implement appropriate data protection and security measures.
Where personal data is transferred outside the European Economic Area, including to the United States, Teamful ensures that appropriate safeguards are in place. These safeguards may include Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms recognised under GDPR.
Teamful remains responsible for the protection of personal data processed by its sub-processors in accordance with the DPA.
⸻
Data Subject Rights
GDPR grants individuals a set of rights over their personal data, including the right to access, rectify, erase, restrict processing, and receive a copy of their data.
As data controller, the customer is responsible for handling data subject requests. Teamful supports customers in fulfilling these obligations by providing access to relevant data, enabling deletion or modification where applicable, and offering reasonable assistance in line with the nature of the processing.
Teamful does not respond directly to data subject requests unless legally required to do so or instructed by the customer.
⸻
Data Retention and Deletion
Personal data is retained only for as long as necessary to provide the service and to meet contractual and legal obligations. Customers control the lifecycle of their data within the platform, including the deletion of content and user access.
Upon termination of a customer account, personal data is deleted or returned in accordance with the Data Processing Addendum, subject to reasonable backup retention periods and applicable legal requirements.
⸻
Transparency and Accountability
We believe GDPR compliance is not only about meeting legal requirements, but also about transparency and accountability. Our data protection framework is supported by clearly defined policies, contractual safeguards, and documented processes.
Customers can review our Privacy Policy, Data Processing Addendum, Cookie Policy, and Security & Compliance documentation to understand how data is handled across the platform. We are also available to respond to reasonable compliance and security inquiries from customers and procurement teams.
⸻
Contact and Further Information
If you have questions about GDPR, data protection, or how Teamful supports compliance, you can contact us at:
Teamful ApS
Copenhagen, Denmark
Email: privacy@teamful.io
