Skip to content
HolmestrandIT Call 995 60 122 Call

Data processing agreement for the website and Google Business Profile

Version of 6 October 2026.

This is an English translation. If the two versions differ, the Norwegian version applies: Databehandleravtale for nettside og Google-profil.

What this agreement covers

This agreement accompanies the website agreement, and applies for as long as that agreement lasts. It is required under Article 28 of the General Data Protection Regulation (GDPR), because we process personal data on your behalf when we build and run the site, and when we keep your Google Business Profile accurate, if you have that add-on.

You receive it by e-mail together with the website agreement, filled in with the details of your business, and you accept both with a single reply.

If we also do other work for you, such as remote support, IT operations or fixing faults, the general data processing agreement applies to that work.

The parties

Controller (the customer)NAME, org. no. NUMBER
ProcessorHOLMESTRANDIT AS, org. no. 938 342 121
DatedDATE
Contact point on your sideNAME, otherwise the person who replies to the agreement
Contact point on our side[email protected], phone 995 60 122

1 · What we process, and why

The purpose is to build and run your website, to keep the information about your business accurate, and, if you have the add-on, to keep your Google Business Profile accurate and visible. We do not process the data for anything else.

We come into contact with the following data:

  • What you send us for the site: text and images, and the names, phone numbers and e-mail addresses of you and the people at your business who are to appear on the site.
  • E-mails that you and the people at your business send us about the site, and our replies.
  • The IP address of people who visit the site. The server logs it to stop attacks, and deletes it after 24 hours. Visits are counted without the IP address. If a visitor triggers an attack alert, the address is also sent to CrowdSec (section 5).
  • With the add-on: the reviews on your Google Business Profile, with the name of the person who wrote them, when we draft replies for you to approve.

The data subjects are you, your employees and others who are named or pictured in what you send us, the people who visit the site, and the people who write reviews of your business.

The site has no forms, no login and no tracking. The fonts are stored on the same server as the site, so no one else finds out who visits it.

The Google Business Profile is your own, held with Google under the terms you yourself have with Google. We work in it with a role you give us, and only for as long as you have the add-on.

We ask you not to send us special categories of personal data, such as health data, and we do not put them on the site.

2 · Instructions

We process personal data only on your instructions, and this agreement constitutes those instructions. If we believe that something you ask for infringes data protection rules, we tell you straight away. We never use the data for our own purposes, nor to market ourselves or anyone else.

3 · Confidentiality

Everyone on our side who is given access has a duty of confidentiality, and it also applies after the agreement has ended. At present, that is one person.

4 · Security

These are the measures, and they are the real ones, not a list of good intentions:

  • The site is hosted on our own server, and the connection to it is encrypted, with a certificate from Let's Encrypt.
  • Our e-mail correspondence with you is kept in our mailbox and in our case management tool, which runs on our own server.
  • We work in the Google Business Profile with our own login and two-step verification. You own the profile, and you can remove us whenever you like.
  • Access only to what we need, and only for as long as we need it.
  • Our equipment has disk encryption and screen lock.

5 · Sub-processors

We use these, and no others, for this service:

WhoWhatWhere
DomeneshopOur mailbox, where e-mail exchanged with you ends up. Your domain, when it is held in our account.Norway
ResendSending e-mail from us to you.EU and USA
AnthropicReads e-mail you send us about the site, and the description the site is built from, and suggests changes and replies. We review the suggestion before anything is done.USA
CloudflareThe page where you approve a change we have suggested.Worldwide
CrowdSecProtection against attacks. When a visitor triggers an alert, the IP address, the time and the type of attack are sent to CrowdSec.France, EU and USA

Resend and Cloudflare, Inc. are certified under the EU-US Data Privacy Framework, and that is the basis when data is transferred to them in the USA. For Anthropic, the basis is the EU standard contractual clauses (modules 2 and 3), which form part of Anthropic's data processing agreement. The list of certified companies was checked on 6 October 2026. CrowdSec also uses the addresses for a shared list of attackers, and under its own terms is a joint controller of that list together with those who use the service. CrowdSec stores data with AWS and Google, among others, and the basis when data is transferred out of the EU is the EU standard contractual clauses. CrowdSec's terms were read on 4 October 2026.

If we want to replace or add a sub-processor, we notify you at least 30 days in advance. You can object, and we will then find another solution or end that part of the engagement. We are liable to you for what they do.

6 · Assistance to you

We assist you in responding to requests from data subjects for access, rectification or erasure, including requests concerning someone who is named or pictured on the site. If you ask us to remove an image or a piece of text from the site, we do so. We also assist you in ensuring the security of the processing.

7 · Personal data breaches

If we discover a personal data breach, we notify you without undue delay, and no later than 24 hours after becoming aware of it. The notification states what has happened, which data is affected, what the likely consequences are, and what we are doing about it.

You are the one who notifies the Norwegian Data Protection Authority (Datatilsynet), because you are the controller. We give you what you need to do so within the 72-hour deadline.

8 · When the agreement ends

We take down the site as the website agreement says, and remove our role in your Google Business Profile if you have the add-on. We keep the content the site is built from, text and images, for six months after the site has been taken down, so that you can take it with you, as the website agreement says. After that, we delete the personal data we hold on your behalf within 30 days. If you would rather have it handed over before then, let us know, and you will get it.

We keep nothing beyond what the law requires of us, such as accounting records for five years under the Bookkeeping Act (bokføringsloven).

9 · Audits

You can ask for documentation showing that we comply with this agreement, and we will respond within a reasonable time. If you require an audit, we will facilitate it.

10 · Governing law

Norwegian law applies. We do not agree on a particular court, so any dispute is brought where the law otherwise provides.