1. Purpose and Scope
1.1. This Data Processing Addendum ("DPA") governs the Processing of Personal Data by the Data Processor on behalf of the Data Controller in connection with the delivery of cloud-based AI and automation services (including
AidEun,
SalesQuote, and associated platforms).
1.2. This DPA shall ensure that Personal Data is processed in compliance with the European General Data Protection Regulation (GDPR Art. 28) and applicable Norwegian data protection legislation.
2. Nature, Purpose, and Duration of Processing
2.1.
Purpose: Processing shall strictly occur to deliver, operate, automate, and support the Services pursuant to the
Customer Agreement.
2.2. Categories of Data Subjects: Customer’s employees, recipients of customer end-user documents, email correspondents, and primary contact persons.
2.3. Types of Personal Data: Names, email addresses, contact details, free text/promptsin emails and quotations, system audit logs, and access credentials.
2.4. Duration: This DPA remains effective for as long as the Customer Agreement is active and terminates once all Personal Data has been deleted or returned.
3. Obligations of the Data Processor (GDPR Art. 28)
The Data Processor covenants and agrees to:
- a. Instructions: Process Personal Data solely on documented written instructions from the Data Controller, including with regard to transfers of personal data to a third country.
- b. Confidentiality: Ensure that persons authorized to process the Personal Data have committed them selves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- c. Technical Security (Art. 32): Implement appropriate technical and organizational security measures in alignment with ISO 27001 standards (including encryption of data in transit and at rest, Role-Based Access Control, Multi-Factor Authentication, and continuous logging).
- d. Assistance with Data Subject Rights: Assist the Data Controller by appropriate technical and organizational measures in fulfilling its obligations to respond to requests for exercising data subjects' rights (access, erasure, rectification).
- e. Incident Notification (Art. 33/34): Notify the Data Controller without undue delay after becoming aware of a personal data breach or security incident affecting Customer Personal Data.
- f. Deletion or Return: At the choice of the Data Controller, delete or return all Personal Data upon termination of services within 30 days, unless applicable law requires retention.
- g. Audits and Compliance: Make available to the Data Controller all information necessary to demonstrate compliance with GDPR Art. 28 obligations (e.g., by providing ISO 27001 certificates or SOC 2 summaries).
4. Special Terms for AI Processing and Model Training
4.1. No Base Model Training: The Data Processor guarantees that Personal Data, prompts, email content, or documents processed via external AI model endpoints (e.g., OpenAI API) are not utilized by AI model providers to train, fine-tune, or improve their base models.
4.2. EphemeralProcessing: AI prompts and inference payloads are processed ephemerally. Operational security logs retained by underlying model providers are automatically purged within 30 days.
5. Sub-processors and Disclosure
5.1. The Data Controller grants general written authorization for the Data Processor to engage sub-processors to deliver and support the Services.
5.2. An up-to-date, comprehensive list of all authorized sub-processors, including their locations, processing purposes, and transfer mechanisms, is maintained and publicly disclosed at:
👉
https://www.aisolutions.no/suppliers5.3. Notification of Changes: The Data Processor shall notify the Data Controller (via email or website announcement) at least 15 days prior to adding or replacing any sub-processor. The Data Controller retains the right to object to such changes on reasonable, documented data protection grounds.
6. International Data Transfers
Transfers or remote access to data from jurisdictions outside the EU/EEA (such as technical support access from India) shall strictly occur on the basis of valid Chapter V transfer mechanisms, including standard EU Standard Contractual Clauses (SCCs Module 3) supplemented by robust technical measures (encryption in transit and zero local persistent storage).
7. Governing Law and Jurisdiction
This DPA is governed by the laws of Norway, with Oslo District Court (Oslo tingrett) as the agreed venue.
8. Changes to Terms
We reserve the right to modify these Terms at any time. We will provide notice of material changes, for example, by email or by posting a notice on our Service. Your continued use of the Service after such changes constitutes your acceptance of the new Terms.
9. Contact Information
If you have any questions about these Terms, please
contact us at: