Data Processing AgreementAvtalor

Data Processing Agreement

Effective 29 September 2026 · version 1.1

This data processing agreement (the "Agreement") forms part of the terms between Avtalor AS, reg. no. 916 048 092, Oslo ("Avtalor", the "Processor") and the business using the service, whether as a company with a portal or as a supplier (the "Customer", the "Controller"). The Agreement governs Avtalor's processing of personal data on behalf of the Customer, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Norwegian Personal Data Act. In case of conflict, this Agreement prevails over the terms in matters concerning the processing of personal data.

1. Roles and responsibility

The Customer is the controller for the personal data entered into or collected through the Customer's use of the service. This applies both to companies that create a portal for their employees and to suppliers that manage agreements and receive requests.

Avtalor is the processor and processes the personal data only on documented instructions from the Customer. This Agreement, the terms and the Customer's use of the features of the service constitute the documented instructions. If Avtalor considers an instruction to infringe the GDPR or other data protection law, we notify the Customer without undue delay.

2. Nature, purpose and duration of the processing

The purpose of the processing is to deliver the service: a portal where employees find the company's agreements, where the company and the suppliers maintain agreement content, and where notifications and mailings go to those who have consented.

The processing comprises collection, storage, structuring, disclosure by transmission (email and notifications), combination and erasure. The processing lasts as long as the Customer has an active customer relationship and ends upon export or deletion under section 9.

3. Categories of data subjects and data

Data subjects: the Customer's employees and administrators, suppliers' contact persons, and people the Customer invites to the service.

Data types: name, email address, phone number, job title, office affiliation, sign-in and consent history, push tokens for mobile devices, and usage data related to agreements (views and clicks, aggregated where possible). The service is not intended for special categories of personal data, and the Customer must not enter such data.

4. The Customer's ownership and Avtalor's right of use

The Customer owns all data entered into the service, both personal data and agreement content. Avtalor claims no ownership.

Avtalor has a limited right to use the data to operate, secure, troubleshoot and improve the service. Improvement is done on an aggregated or anonymised basis where possible. Avtalor never sells personal data and does not use it for third-party marketing.

5. Confidentiality and security

Persons authorised to process the personal data at Avtalor are bound by confidentiality through agreement or statutory duty.

Avtalor implements technical and organisational measures under GDPR Article 32, including: encryption of data in transit and at rest, row-level security separating customers' data, role-based access control, irrevocable logging of support access, and continuous security testing of the access rules in the codebase.

6. Sub-processors

The Customer gives a general prior authorisation for Avtalor to use sub-processors. For planned changes, Avtalor notifies the Customer at least 30 days in advance so the Customer can object.

Current sub-processors: Supabase (database, authentication and file storage; data stored in the EU/EEA), Vercel (hosting of the web application; EU region for function execution), Resend (sending email on behalf of the Customer) and Anthropic (machine reading of agreement documents the Customer uploads to AI import; the content is not used to train models). Planned sub-processor: Expo (650 Industries, Inc., USA; sending push notifications to the mobile app, with the device's push token and the notification's title, text and link). Expo will be engaged when push notifications in the app launch, no earlier than 30 days after the Customer has been notified.

If personal data is transferred to countries outside the EU/EEA, this happens only with a valid transfer mechanism under GDPR Chapter V, such as the EU Commission's Standard Contractual Clauses (SCC) or an adequacy decision, with supplementary measures where needed.

7. Assistance to the controller

Avtalor assists the Customer, insofar as possible and taking into account the nature of the processing, in responding to requests from data subjects under GDPR Chapter III (access, rectification, erasure, data portability and more). Much of this the Customer's employees can do themselves in the service: view their data, download it and delete their account.

Avtalor also assists the Customer in meeting the obligations under GDPR Articles 32 to 36, including data protection impact assessments and prior consultations with the Norwegian Data Protection Authority, when the Customer so requests.

8. Personal data breaches

In the event of a personal data breach, Avtalor notifies the Customer without undue delay after becoming aware of the breach. The notice describes the nature of the breach, the data subjects and data affected, the likely consequences and the measures taken or proposed. The Customer is responsible for any notification to the Data Protection Authority and to the data subjects.

9. Deletion and return

Upon termination of the customer relationship, the Customer chooses whether the personal data is to be returned in a structured, commonly used and machine-readable format, or deleted. Without an active choice, the data is deleted no later than 90 days after termination. Copies in backups are deleted in line with their rotation, no later than a further 35 days.

Avtalor may retain data where storage is required by law, for example accounting records, but only for as long and to the extent the law requires.

10. Audits and documentation

Avtalor makes available the information necessary to demonstrate compliance with the obligations in GDPR Article 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are announced in writing at least 14 days in advance and are conducted so as not to unduly disturb operations or give access to other customers' data.

11. Duration, governing law and venue

The Agreement applies for as long as Avtalor processes personal data on behalf of the Customer. The Agreement is governed by Norwegian law, and Oslo District Court is the agreed venue, in accordance with the terms.

Data processing agreement | Avtalor