Dual ApS
Denmark · owned by Independent (Denmark) · wearedual.dk · 8 vendors
Dual ApS is a Copenhagen-based web development company that designs and builds custom web systems and websites for small teams and businesses. Founded by Jim Pannell and Michael Rasmussen, the company has been active since the early 2000s, offering services including bespoke web systems, SEO/performance/UX audits, business process clarity, and modernisation of legacy systems. They emphasise long-term client relationships, with some customers having stayed with them for over 15 years.
Resilience scores
- Digital Sovereignty: 25
- Digital Resilience: 4
- Financial Resilience: 5
Disruption prediction
Dual ApS has an estimated 17% probability of disruption in the next 6 months.
5 of Dual ApS's 8 vendors monitored for disruptions.
Technology vendors
- Google LLC — Technology — United States
- Stripe, Inc. — Financial Services — United States
- Twilio — Telecommunications — United States
- and 5 more
Insights
Last updated 2026-09-13 · revision 14
8 direct vendors, 123 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Denmark: 1
- Germany: 1
Subvendors by controlling owner country (sample)
- United States: 94
- Norway: 1
- United Kingdom: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Dual ApS demonstrates high migration readiness, largely due to its core business expertise. A significant strength is the company's offering of 'Legacy System Modernisation' services, which means they possess strong internal expertise and a proven methodology for migrating complex systems, directly benefiting their own potential migration efforts. Their internal tech stack already incorporates 'European cloud hosting' and 'Self-hosted AI/LLM infrastructure,' indicating existing cloud adoption and modern infrastructure components. The company also has a clear understanding of GDPR and Danish Data Protection Act requirements, including data residency rules and international data transfer mechanisms (e.g., SCCs for Fathom Analytics to Canada), which is crucial for planning a compliant migration. The reliance on 'Total Services: 10' suggests a moderate number of external dependencies, which, if managed well, could indicate lower vendor lock-in compared to relying on a very small number of critical vendors. However, weaknesses include the lack of financial stability data (revenue concentration, growth history), making it difficult to assess their capacity to fund a significant migration project. The 'Partially Compliant' status for GDPR and the Danish Data Protection Act, with 'Medium risk,' means that regulatory compliance aspects would need careful management during any migration to ensure continued adherence and avoid increased risk. Data residency requirements, while understood, impose constraints on where data can be hosted and processed, adding a layer of complexity to migration planning. The 'Unknown' vendor lock-in risk means potential dependencies or contractual complexities with existing service providers are not fully clear.
Compliance
6 in-scope frameworks identified; showing 3.
Danish E-Commerce Act — Compliant
The Danish E-Commerce Act requires information society service providers to display certain mandatory information (company name, address, CVR number, contact details). Dual ApS's website clearly displays: company name (Dual ApS), address (Sjællandsgade 51, 2200 Copenhagen), CVR number (32309542), email (hello@dual.dk), and phone number (+45 93 96 99 84). All mandatory disclosure requirements appear to be met. Risk is Low as the company appears compliant with these basic transparency requirements.
Evidence: https://dual.dk
ISO 27001 (source) — Assessment Required
ISO 27001 is an internationally recognised information security management standard. It is not legally mandated in Denmark for web development companies, but it is increasingly expected by enterprise clients and public sector procurement. Dual ApS mentions security measures in its privacy policy (SSL encryption, rate limiting, spam filtering, secure transmission, access controls), indicating awareness of information security principles. However, there is no evidence of formal ISO 27001 certification or a documented ISMS. For a 2-person micro-enterprise, ISO 27001 certification is costly and operationally complex, making it unlikely at this stage. Risk is Low because the company's small size and SME client base reduce the likelihood of mandatory ISO 27001 requirements, and the consequences of non-certification are primarily commercial (lost contracts) rather than regulatory.
Evidence: https://dual.dk/privatlivspolitik
GDPR (source) — Partially Compliant
GDPR is unambiguously applicable: Dual ApS is incorporated and headquartered in Denmark (EU member state), processes personal data of EU/EEA residents (website visitors, clients, suppliers, employees), and explicitly references GDPR in its published privacy policy. The company demonstrates meaningful compliance effort — a published privacy policy referencing GDPR, identified legal bases (legitimate interest, legal obligation), documented data retention periods (12 months), data subject rights disclosures, and reference to the Danish supervisory authority (Datatilsynet). However, several gaps elevate risk to Medium: (1) No Data Protection Officer (DPO) appointment is publicly disclosed — while likely not mandatory for a micro-enterprise of this size, it should be assessed; (2) No Records of Processing Activities (RoPA) are publicly evidenced; (3) Use of Fathom Analytics (a Canadian processor) relies on Standard Contractual Clauses (SCCs) for the international transfer, which is appropriate but requires an active Transfer Impact Assessment (TIA) — no evidence this has been formally documented; (4) No cookie consent banner or consent management platform is mentioned, though the company claims to use only a session cookie and no tracking cookies — this claim should be verified against actual site behaviour; (5) No evidence of a formal Data Processing Agreement (DPA) register with sub-processors beyond Fathom. Enforcement risk is moderate: Denmark's Datatilsynet is an active supervisory authority that has issued fines and reprimands to small businesses. For a micro-enterprise with limited data processing, the likelihood of a major fine is low, but the absence of documented internal controls is a genuine gap.
Evidence: https://dual.dk/privatlivspolitik, https://dual.dk/en/privacy-policy, https://dual.dk
Financials
Three-year financials
- 2025: gross profit DKK 817K, EBIT DKK -223K, equity DKK 94.9K
- 2024: gross profit DKK 1.18M, EBIT DKK 77.5K, equity DKK 118K
- 2023: gross profit DKK 963K, EBIT DKK -185K, equity DKK 79.9K
Financial Resilience Score: 5/10
Dual ApS is a micro-scale, founder-owned Copenhagen web development boutique whose financial resilience rests on unusually long client tenure (some clients retained since 2003, 15+ years) and a low-overhead, two-partner operating structure. This provides recurring maintenance/support revenue and high flexibility atypical for a project-based development shop. The firm's niche specialization in legacy modernization (Drupal 7, old PHP migrations) addresses a growing market as end-of-life and security deadlines force clients to migrate. However, resilience is materially constrained by extreme key-person dependency on the two founders (Jim Pannell and Michael Rasmussen) with no visible bench, very small scale with limited cash reserves typical of micro-firms, and apparent client concentration among a handful of long-tenured customers. The Danish web development market is crowded with agencies and freelancers, and differentiation rests on quality and relationships rather than scale or IP. Financial transparency is limited as small ApS filings typically disclose only gross profit (bruttofortjeneste) rather than full revenue. Specific quantitative figures could not be retrieved in this session and would require pulling årsrapporter directly from datacvr.virk.dk.
Key strengths: Extremely long client tenure (clients since 2003, 15+ years retention), Low overhead, founder-run two-partner structure, Niche specialization in legacy system modernization (Drupal 7, old PHP), Diversified service mix reduces reliance on one-off project revenue, International client base despite Danish HQ
Risk factors: Key-person dependency on two founders with no visible bench, Micro-firm scale with likely limited cash reserves, Client concentration risk among a handful of anchor customers, Competitive pressure in crowded Danish web dev market, Limited financial transparency due to small ApS reporting requirements
Workforce by country
- Denmark: 2
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.