Data Processing Agreement
GDPR Article 28 processor terms. Version 2026-08-23. This DPA applies to every PrivyLedger workspace from first use — no counter-signature required. Downloadable for your records.
Download DPA (.txt)DATA PROCESSING AGREEMENT
PrivyLedger — Processor Services under GDPR Article 28
Between:
The customer ("Controller"), identified by their PrivyLedger workspace, and
Vassbrekke AS, org.nr 835 834 212, Norway ("Processor").
Effective: upon first use of PrivyLedger by the Controller's account.
Version: 2026-08-23. The current version is always published at https://privyledger.com/dpa.
1. ROLES AND SCOPE
1.1 The Controller determines the purposes and means of processing personal data it enters into PrivyLedger (vendor records, contact persons, DSAR cases, notes).
1.2 The Processor processes such personal data solely to provide the PrivyLedger service (hosting, storage, backup, display, export) and on the Controller's documented instructions. Additional instructions may be given through workspace settings or written notice.
1.3 Each party complies with its obligations under Regulation (EU) 2016/679 (GDPR) as incorporated into the EEA Agreement, and applicable Norwegian data protection law.
2. NATURE AND PURPOSE OF PROCESSING
Subject matter: vendor/processor register records and related account data entered by the Controller.
Duration: for the life of the workspace, until deletion by the Controller, or until the account ends.
Categories of data subjects: the Controller's personnel and contact persons of the Controller's vendors.
Categories of data: names, business email addresses, roles, free-text notes the Controller chooses to enter, account credentials (hashed).
3. PROCESSOR PERSONNEL
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. SUB-PROCESSORS
4.1 The Controller grants general written authorisation for the sub-processors listed at https://privyledger.com/subprocessors as of the Effective Date.
4.2 The Processor will notify the Controller of intended changes to sub-processors via the published page (updated with a change log and advance notice date) in sufficient time to object.
4.3 The Controller may object to a new sub-processor on reasonable data-protection grounds within 30 days of publication. If no resolution is reached, the Controller may terminate the affected service with pro-rata refund.
4.4 The Processor imposes the same data protection obligations as this DPA on each sub-processor by contract, and remains liable for their performance.
5. TRANSFERS OUTSIDE THE EEA
5.1 Core service processing (application, database, backups) takes place on infrastructure operated by the Processor in Norway/EEA. Register data is not transferred outside the EEA by the Processor.
5.2 Where a listed sub-processor processes outside the EEA (currently: payment card data handling by Stripe), the transfer relies on the EU-US Data Privacy Framework adequacy decision where certified, or Standard Contractual Clauses (Commission Decision 2021/914), supplemented by appropriate technical measures. The current list states each sub-processor's status.
5.3 If an adequacy decision relied upon under 5.2 is invalidated, the Processor will promptly assess alternatives, implement supplementary measures where possible, and notify affected Controllers.
6. DATA SUBJECT RIGHTS
The Processor assists the Controller, taking into account the nature of the processing, by using the workspace tools (export, deletion, editing) so the Controller can respond to data subject requests without undue delay. The Processor forwards any direct data subject request to the Controller and does not respond except to confirm routing.
7. SECURITY MEASURES
The Processor maintains the technical and organisational measures described at https://privyledger.com/security, including: encryption in transit (TLS), scrypt-hashed credentials, hashed session tokens, role-based access control, rate limiting, least-privilege host configuration, and regular dependency updates. The measures are reviewed continuously and updated as the service evolves; material changes are reflected on the security page.
8. ASSISTANCE AND ACCOUNTABILITY
The Processor provides the information reasonably necessary to demonstrate compliance with Article 28 (this DPA, the published sub-processor list, and the security page constitute that information). Where the Controller's regulatory context requires further assistance beyond these published materials, the Processor will provide it at reasonable commercial rates. The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28(3)(h) and allows for and contributes to audits, including inspections, in accordance with Article 28(3)(h) GDPR: as first-line audit evidence, the Processor maintains a dated internal record of processing activities (ROPA) available on request, publishes its security review, and provides the workspace activity log (who did what, when) through the product. On-site or third-party audits beyond these materials are accommodated where required by the Controller's regulators, at the Controller's cost and no more than once per year, with 30 days' notice.
9. BREACH NOTIFICATION
Upon becoming aware of a personal data breach affecting Controller data, the Processor notifies the Controller without undue delay and within 72 hours, describing the nature of the breach, categories concerned, likely consequences, and measures taken. Notification goes to the workspace admin email(s).
10. DELETION OR RETURN
Upon termination of the Controller's account, the Processor deletes workspace data within 30 days, per the retention schedule published in the Privacy Policy, unless EEA/Norwegian law requires storage (e.g. accounting records under bokføringsloven). The Controller may export all register data at any time before termination using built-in exports.
11. AUDITS
The published documentation (sections 7–8 references) serves as the primary audit evidence. Anything beyond it is provided under section 8.
12. LIABILITY AND ORDER OF PRECEDENCE
This DPA forms part of the PrivyLedger Terms of Service. In case of conflict regarding processing of personal data, this DPA prevails. Liability follows the Terms of Service.
CONTACT
Vassbrekke AS — privacy contact published at https://privyledger.com/privacy and https://privyledger.com/.well-known/security.txt