Dual ApS

Denmark · owned by Independent (Denmark) · wearedual.dk · 8 vendors

Dual ApS is a Copenhagen-based web development company that designs and builds custom web systems and websites for small teams and businesses. Founded by Jim Pannell and Michael Rasmussen, the company has been active since the early 2000s, offering services including bespoke web systems, SEO/performance/UX audits, business process clarity, and modernisation of legacy systems. They emphasise long-term client relationships, with some customers having stayed with them for over 15 years.

Resilience scores

Disruption prediction

Dual ApS has an estimated 17% probability of disruption in the next 6 months.

5 of Dual ApS's 8 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-13 · revision 14

8 direct vendors, 123 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Dual ApS demonstrates high migration readiness, largely due to its core business expertise. A significant strength is the company's offering of 'Legacy System Modernisation' services, which means they possess strong internal expertise and a proven methodology for migrating complex systems, directly benefiting their own potential migration efforts. Their internal tech stack already incorporates 'European cloud hosting' and 'Self-hosted AI/LLM infrastructure,' indicating existing cloud adoption and modern infrastructure components. The company also has a clear understanding of GDPR and Danish Data Protection Act requirements, including data residency rules and international data transfer mechanisms (e.g., SCCs for Fathom Analytics to Canada), which is crucial for planning a compliant migration. The reliance on 'Total Services: 10' suggests a moderate number of external dependencies, which, if managed well, could indicate lower vendor lock-in compared to relying on a very small number of critical vendors. However, weaknesses include the lack of financial stability data (revenue concentration, growth history), making it difficult to assess their capacity to fund a significant migration project. The 'Partially Compliant' status for GDPR and the Danish Data Protection Act, with 'Medium risk,' means that regulatory compliance aspects would need careful management during any migration to ensure continued adherence and avoid increased risk. Data residency requirements, while understood, impose constraints on where data can be hosted and processed, adding a layer of complexity to migration planning. The 'Unknown' vendor lock-in risk means potential dependencies or contractual complexities with existing service providers are not fully clear.

Compliance

6 in-scope frameworks identified; showing 3.

Danish E-Commerce Act — Compliant

The Danish E-Commerce Act requires information society service providers to display certain mandatory information (company name, address, CVR number, contact details). Dual ApS's website clearly displays: company name (Dual ApS), address (Sjællandsgade 51, 2200 Copenhagen), CVR number (32309542), email (hello@dual.dk), and phone number (+45 93 96 99 84). All mandatory disclosure requirements appear to be met. Risk is Low as the company appears compliant with these basic transparency requirements.

Evidence: https://dual.dk

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognised information security management standard. It is not legally mandated in Denmark for web development companies, but it is increasingly expected by enterprise clients and public sector procurement. Dual ApS mentions security measures in its privacy policy (SSL encryption, rate limiting, spam filtering, secure transmission, access controls), indicating awareness of information security principles. However, there is no evidence of formal ISO 27001 certification or a documented ISMS. For a 2-person micro-enterprise, ISO 27001 certification is costly and operationally complex, making it unlikely at this stage. Risk is Low because the company's small size and SME client base reduce the likelihood of mandatory ISO 27001 requirements, and the consequences of non-certification are primarily commercial (lost contracts) rather than regulatory.

Evidence: https://dual.dk/privatlivspolitik

GDPR (source) — Partially Compliant

GDPR is unambiguously applicable: Dual ApS is incorporated and headquartered in Denmark (EU member state), processes personal data of EU/EEA residents (website visitors, clients, suppliers, employees), and explicitly references GDPR in its published privacy policy. The company demonstrates meaningful compliance effort — a published privacy policy referencing GDPR, identified legal bases (legitimate interest, legal obligation), documented data retention periods (12 months), data subject rights disclosures, and reference to the Danish supervisory authority (Datatilsynet). However, several gaps elevate risk to Medium: (1) No Data Protection Officer (DPO) appointment is publicly disclosed — while likely not mandatory for a micro-enterprise of this size, it should be assessed; (2) No Records of Processing Activities (RoPA) are publicly evidenced; (3) Use of Fathom Analytics (a Canadian processor) relies on Standard Contractual Clauses (SCCs) for the international transfer, which is appropriate but requires an active Transfer Impact Assessment (TIA) — no evidence this has been formally documented; (4) No cookie consent banner or consent management platform is mentioned, though the company claims to use only a session cookie and no tracking cookies — this claim should be verified against actual site behaviour; (5) No evidence of a formal Data Processing Agreement (DPA) register with sub-processors beyond Fathom. Enforcement risk is moderate: Denmark's Datatilsynet is an active supervisory authority that has issued fines and reprimands to small businesses. For a micro-enterprise with limited data processing, the likelihood of a major fine is low, but the absence of documented internal controls is a genuine gap.

Evidence: https://dual.dk/privatlivspolitik, https://dual.dk/en/privacy-policy, https://dual.dk

Financials

Three-year financials

Financial Resilience Score: 5/10

Dual ApS is a micro-scale, founder-owned Copenhagen web development boutique whose financial resilience rests on unusually long client tenure (some clients retained since 2003, 15+ years) and a low-overhead, two-partner operating structure. This provides recurring maintenance/support revenue and high flexibility atypical for a project-based development shop. The firm's niche specialization in legacy modernization (Drupal 7, old PHP migrations) addresses a growing market as end-of-life and security deadlines force clients to migrate. However, resilience is materially constrained by extreme key-person dependency on the two founders (Jim Pannell and Michael Rasmussen) with no visible bench, very small scale with limited cash reserves typical of micro-firms, and apparent client concentration among a handful of long-tenured customers. The Danish web development market is crowded with agencies and freelancers, and differentiation rests on quality and relationships rather than scale or IP. Financial transparency is limited as small ApS filings typically disclose only gross profit (bruttofortjeneste) rather than full revenue. Specific quantitative figures could not be retrieved in this session and would require pulling årsrapporter directly from datacvr.virk.dk.

Key strengths: Extremely long client tenure (clients since 2003, 15+ years retention), Low overhead, founder-run two-partner structure, Niche specialization in legacy system modernization (Drupal 7, old PHP), Diversified service mix reduces reliance on one-off project revenue, International client base despite Danish HQ

Risk factors: Key-person dependency on two founders with no visible bench, Micro-firm scale with likely limited cash reserves, Client concentration risk among a handful of anchor customers, Competitive pressure in crowded Danish web dev market, Limited financial transparency due to small ApS reporting requirements

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report