Data Processing Agreement
Last updated 2026-08-01
This is the reference copy, with party details left blank. The signable copy carrying your own company details is available under Legal inside the app.
This agreement sets out how EMIL EDB EMIL RANDEN processes personal data on behalf of [Legal entity name] when providing the MaaS marketing platform, as required by Article 28 of the GDPR.
1. Parties and roles
This Data Processing Agreement (the “DPA”) is entered into between [Legal entity name], organisation number [Organisation number], of [Registered address] (the “Controller”), and EMIL EDB EMIL RANDEN, organisation number 917 235 716, of Thygesons vei 15, 0667 Oslo (the “Processor”). It takes effect on 1 August 2026.
The DPA forms part of, and is subject to, the main services agreement between the parties. It governs the Processor's processing of personal data on the Controller's behalf under Article 28 of Regulation (EU) 2016/679 (the “GDPR”) as implemented in Norway by the Personal Data Act.
Where the Controller is itself acting as a processor for a third party, the Controller warrants that it has the authority to appoint the Processor and to give the instructions set out in this DPA.
2. Subject matter, duration, nature and purpose
The Processor processes personal data solely to provide the marketing services described in the main agreement: campaign creation, launch and optimisation; website generation and publishing; conversion measurement and attribution; audience management; email and SMS messaging; CRM synchronisation; and AI-assisted creative generation.
Processing operations are limited to those necessary to deliver those services, namely collection, storage, structuring, retrieval, hashing and pseudonymisation, transmission to the sub-processors listed in the register, and erasure.
This DPA applies for the term of the main agreement and for as long as the Processor processes personal data on the Controller's behalf.
3. Categories of personal data and data subjects
The Processor processes the following categories of personal data:
- contact details submitted through forms and landing pages — name, email address, telephone number, company and free-text message content;
- marketing contact records, including subscription status and the source and time of consent;
- pseudonymous online identifiers — visitor and session identifiers, hashed IP address, user agent, approximate country, and advertising click identifiers;
- hashed matching identifiers — SHA-256 email and telephone hashes transmitted to advertising platforms for conversion measurement;
- conversion and order events, including value and currency;
- content submitted for creative generation, including photographs, video and voice recordings, which may contain the image or voice of identifiable individuals; and
- account data for the Controller's own personnel who use the service — name, email address, authentication credentials and audit logs.
The data subjects are the Controller's customers, prospective customers, website and application visitors, and the Controller's own personnel.
The Processor does not process special categories of personal data under Article 9, or personal data relating to criminal convictions under Article 10, and the Controller shall not submit such data to the service.
4. Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which the Processor is subject. In that case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
This DPA, the main agreement, and the Controller's use of the service's configuration options together constitute the Controller's complete documented instructions. Any additional instruction must be agreed in writing.
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
The Controller is responsible for establishing a lawful basis for the processing, for providing the information required by Articles 13 and 14, and for obtaining and recording any consent required before personal data is submitted to the service.
5. Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to deliver the services.
6. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, the Processor implements appropriate technical and organisational measures under Article 32, including:
- hosting and application compute within the European Union, and storage of persisted personal data in an EU region;
- encryption of all data in transit using TLS;
- encryption at rest of contact details and access credentials using AES-256-GCM with versioned keys supporting rotation;
- deterministic hashing of matching identifiers so that records can be located without decrypting the underlying data;
- logical tenant isolation enforced at a single authorisation choke point, so that one customer cannot reach another's data;
- authentication controls including password hashing, rate limiting, optional two-factor authentication and session revocation;
- an append-only audit log of privileged and personal-data access, retained independently of the records it describes;
- automated retention enforcement that erases personal data once its retention period expires; and
- regular application of security updates to dependencies and infrastructure.
The Processor may update these measures over time provided the level of security is not reduced. The current measures are published alongside the sub-processor register at https://maa-s.vercel.app/subprocessors.
7. Sub-processors
The Controller gives the Processor general written authorisation to engage sub-processors. The current sub-processors, the purpose for which each is engaged, the categories of data each receives, and the transfer mechanism relied on, are listed in the register published at https://maa-s.vercel.app/subprocessors. That register is the authoritative list.
The Processor imposes on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of that sub-processor's obligations.
8. Changes to sub-processors
The Processor shall give the Controller at least thirty (30) days' notice before adding or replacing a sub-processor. Notice is given by updating the register at https://maa-s.vercel.app/subprocessors, by an in-application announcement, and by email to the data protection contact the Controller has registered.
The Controller may object on reasonable data protection grounds within that period. If the parties cannot agree a resolution, the Controller may terminate the affected services without penalty, with a pro-rata refund of prepaid fees.
Where a change is required urgently to protect the security or availability of the service, the Processor may make it immediately and shall notify the Controller without undue delay.
9. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise the rights in Chapter III of the GDPR — access, rectification, erasure, restriction, portability and objection.
The service provides self-service export and erasure of a data subject's records across all stores in which the Processor holds them. Where a data subject contacts the Processor directly, the Processor shall not respond on the merits but shall refer the request to the Controller without undue delay.
An erasure request is honoured across the Processor's systems and, where the relevant integration supports it, propagated to the sub-processors that received the data. The Processor also records a suppression entry so that the erased identifier is not re-ingested from a connected source.
10. Personal data breaches
The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting personal data processed on the Controller's behalf, so that the Controller can meet its own seventy-two (72) hour obligation under Article 33.
The notification shall describe, to the extent known at the time:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address it and to mitigate its adverse effects; and
- a contact point for further information.
Where the full picture is not available at the time of notification, the Processor shall provide information in phases without further undue delay. The Processor shall not make any public statement identifying the Controller in connection with a breach without the Controller's prior written consent, unless legally required to do so.
11. Assistance with Articles 32 to 36
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations in Articles 32 to 36 — security of processing, breach notification, data protection impact assessments and prior consultation with the supervisory authority.
12. Deletion or return of personal data
On termination of the services, the Processor shall, at the Controller's choice, delete or return all personal data processed on the Controller's behalf, and delete existing copies, unless Union or Member State law requires continued storage.
The Controller may export its data at any time during the term. Unless the Controller requests otherwise, personal data is deleted within ninety (90) days of termination. Routine backups are overwritten on their normal cycle, and personal data remaining in them is not accessed or restored other than for disaster recovery.
During the term, the Processor applies the retention periods published in its records of processing activities and erases personal data automatically once they expire.
13. Information and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.
Audits shall be conducted on at least thirty (30) days' written notice, no more than once in any twelve-month period except following a personal data breach or at the request of a supervisory authority, during business hours, subject to confidentiality undertakings, and in a manner that does not disrupt the Processor's operations or compromise the confidentiality of other customers' data.
14. International transfers
Personal data is stored and primarily processed within the European Economic Area. Some sub-processors are established outside the EEA; each such transfer, and the mechanism relied on for it, is identified in the register at https://maa-s.vercel.app/subprocessors.
Where a transfer is not covered by an adequacy decision, it is made under the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional technical and organisational measures following a transfer impact assessment. The Controller authorises the Processor to enter into those clauses with sub-processors on the Controller's behalf.
15. Liability
Each party is liable for damage caused by processing that infringes the GDPR in accordance with Article 82. The limitations and exclusions of liability in the main agreement apply to claims under this DPA to the extent permitted by law, save that nothing limits either party's liability for administrative fines imposed on it directly, for death or personal injury caused by negligence, or for fraud.
Where one party has paid compensation for damage to which both contributed, it may claim back from the other the part corresponding to that party's responsibility, in accordance with Article 82(5).
16. Governing law and disputes
This DPA is governed by Norwegian law. Disputes shall be resolved by the ordinary Norwegian courts, with Oslo District Court as the agreed legal venue, unless mandatory law provides otherwise.
If any provision of this DPA conflicts with the main agreement, this DPA prevails in respect of the processing of personal data.
Version 2026-08-01 · document fingerprint b9bf50084504. The fingerprint is a SHA-256 hash of this exact text; it is recorded with every acceptance so both parties can prove what was agreed.