Skip to content
HolmestrandIT Call 995 60 122 Call

Data processing agreement

Template, version of 6 October 2026. DRAFT, read through before use

This is an English translation. If the two versions differ, the Norwegian version applies: Databehandleravtale.

When this agreement is needed

When we process personal data on behalf of a customer, the task and the responsibility must be set out in a data processing agreement. The agreement is adapted to the service, the data and the suppliers actually involved.

Whether we are a processor depends on what the service actually is. The fact that we see personal data while solving an IT task is not enough on its own to decide that.

Private individuals do not need this agreement. For them, the privacy policy is enough.

If it concerns a website and Google Business Profile, use the agreement for that service instead.

The parties

Controller (the customer)NAME, org. no. NUMBER
ProcessorHOLMESTRANDIT AS, org. no. 938 342 121
Agreement effective fromDATE
Contact point on the customer's sideNAME AND E-MAIL
Contact point on our side[email protected], phone 995 60 122

The customer decides what the data is to be used for. HolmestrandIT processes it only on the customer's instructions.

All enquiries about access, rectification, erasure and personal data breaches go to the contact points above.

1 · What we process, and why

PurposeTo provide IT support: fixing faults, set-up, operations and advice
DurationFor as long as the engagement lasts
Types of personal dataADAPT, e.g. name, e-mail, phone, files on machines we work on
Categories of data subjectsADAPT, e.g. the customer's employees and their customers

⚠️ If we are to process special categories of personal data, such as health data, this must be agreed separately and written in here.

2 · Instructions

We process personal data only on documented instructions from the customer, including this agreement. If we believe an instruction infringes data protection legislation, we say so immediately.

We never use the data for our own purposes.

3 · Confidentiality

Everyone on our side who is given access to the data has a duty of confidentiality. The duty of confidentiality also applies after the agreement has ended.

4 · Security

We implement appropriate technical and organisational measures, including:

  • Access only for those who need it, and only for as long as it is needed.
  • Encrypted connection for remote support, in a session that the customer starts themselves and can end.
  • Remote support runs through our own server, not through a third-party service.
  • No recording of remote support sessions.
  • Equipment with disk encryption and screen lock.
  • ADD what is actually done

5 · Sub-processors

The list must be checked against the suppliers actually used in the engagement.

We use these sub-processors:

WhoWhatWhere
ResendSending e-mailEU and USA
CloudflareWebsite delivery and protectionWorldwide
CrowdSec SASProtection against attacks: the IP address of a visitor who triggers an alertFrance, EU and USA

If we want to replace or add a sub-processor, we notify the customer at least 30 days in advance. The customer can object, and we will then find another solution or end that part of the engagement.

We are liable to the customer for what the sub-processors do.

6 · Assistance to the customer

We assist the customer with:

  • Responding to requests from data subjects for access, rectification or erasure.
  • Ensuring the security of the processing.
  • Data protection impact assessments where needed.

7 · Personal data breaches

If we discover a personal data breach, we notify the customer without undue delay, and no later than 24 hours after becoming aware of it.

The notification describes what has happened, which data is affected, the likely consequences and what we are doing about it. It is the customer who notifies the Norwegian Data Protection Authority (Datatilsynet), since the customer is the controller.

8 · When the agreement ends

When the agreement ends, we delete all personal data we hold on the customer's behalf, or return it if the customer so wishes. The customer chooses which of the two within 30 days.

We keep nothing beyond what the law may require of us, such as accounting records.

9 · Audits

The customer can ask for documentation showing that we comply with the agreement. We respond within a reasonable time and facilitate an audit if the customer requires one.

10 · Governing law

Norwegian law applies. We do not agree on a particular court, so any dispute is brought where the law otherwise provides.

Signature

For the customerFor HolmestrandIT
Place and date:      Place and date:      
Name:      Name:      
Signature:Signature: