Data processing agreement
Template, version of 6 October 2026. DRAFT, read through before use
This is an English translation. If the two versions differ, the Norwegian version applies: Databehandleravtale.
When this agreement is needed
When we process personal data on behalf of a customer, the task and the responsibility must be set out in a data processing agreement. The agreement is adapted to the service, the data and the suppliers actually involved.
Whether we are a processor depends on what the service actually is. The fact that we see personal data while solving an IT task is not enough on its own to decide that.
Private individuals do not need this agreement. For them, the privacy policy is enough.
If it concerns a website and Google Business Profile, use the agreement for that service instead.
The parties
| Controller (the customer) | NAME, org. no. NUMBER |
|---|---|
| Processor | HOLMESTRANDIT AS, org. no. 938 342 121 |
| Agreement effective from | DATE |
| Contact point on the customer's side | NAME AND E-MAIL |
| Contact point on our side | [email protected], phone 995 60 122 |
The customer decides what the data is to be used for. HolmestrandIT processes it only on the customer's instructions.
All enquiries about access, rectification, erasure and personal data breaches go to the contact points above.
1 · What we process, and why
| Purpose | To provide IT support: fixing faults, set-up, operations and advice |
|---|---|
| Duration | For as long as the engagement lasts |
| Types of personal data | ADAPT, e.g. name, e-mail, phone, files on machines we work on |
| Categories of data subjects | ADAPT, e.g. the customer's employees and their customers |
⚠️ If we are to process special categories of personal data, such as health data, this must be agreed separately and written in here.
2 · Instructions
We process personal data only on documented instructions from the customer, including this agreement. If we believe an instruction infringes data protection legislation, we say so immediately.
We never use the data for our own purposes.
3 · Confidentiality
Everyone on our side who is given access to the data has a duty of confidentiality. The duty of confidentiality also applies after the agreement has ended.
4 · Security
We implement appropriate technical and organisational measures, including:
- Access only for those who need it, and only for as long as it is needed.
- Encrypted connection for remote support, in a session that the customer starts themselves and can end.
- Remote support runs through our own server, not through a third-party service.
- No recording of remote support sessions.
- Equipment with disk encryption and screen lock.
- ADD what is actually done
5 · Sub-processors
The list must be checked against the suppliers actually used in the engagement.
We use these sub-processors:
| Who | What | Where |
|---|---|---|
| Resend | Sending e-mail | EU and USA |
| Cloudflare | Website delivery and protection | Worldwide |
| CrowdSec SAS | Protection against attacks: the IP address of a visitor who triggers an alert | France, EU and USA |
If we want to replace or add a sub-processor, we notify the customer at least 30 days in advance. The customer can object, and we will then find another solution or end that part of the engagement.
We are liable to the customer for what the sub-processors do.
6 · Assistance to the customer
We assist the customer with:
- Responding to requests from data subjects for access, rectification or erasure.
- Ensuring the security of the processing.
- Data protection impact assessments where needed.
7 · Personal data breaches
If we discover a personal data breach, we notify the customer without undue delay, and no later than 24 hours after becoming aware of it.
The notification describes what has happened, which data is affected, the likely consequences and what we are doing about it. It is the customer who notifies the Norwegian Data Protection Authority (Datatilsynet), since the customer is the controller.
8 · When the agreement ends
When the agreement ends, we delete all personal data we hold on the customer's behalf, or return it if the customer so wishes. The customer chooses which of the two within 30 days.
We keep nothing beyond what the law may require of us, such as accounting records.
9 · Audits
The customer can ask for documentation showing that we comply with the agreement. We respond within a reasonable time and facilitate an audit if the customer requires one.
10 · Governing law
Norwegian law applies. We do not agree on a particular court, so any dispute is brought where the law otherwise provides.
Signature
| For the customer | For HolmestrandIT |
|---|---|
| Place and date: | Place and date: |
| Name: | Name: |
| Signature: | Signature: |