Data controllers rights and duties
- This agreement is intended to regulate rights and obligations regarding processing of personal data under the terms of the GDPR Art. 28. The agreement shall ensure that personal data on the registered parties is never used improperly or by any unauthorized part.
- The agreement governs the data processor's use of personal data on behalf of the data controller - including collection, registration, assembly, storage, extradition or combinations of such uses.
- Notices under this agreement should be sent in writing to firstname.lastname@example.org.
- Data controller: The legal part who determines the purpose of processing personal data and the assistive to be used.
- Data processor: The legal part that is processing personal data on behalf of the data controller.
- Personal data: Information and assessments that can be linked to an individual.
- Processing personal data: Any use of personal information, such as collection, registration, assembly, storage and extradition or a combination of such uses.
- Data being processed
- The data processor provides and operates services like web hosting, domain name, CloudVPS (virtual server), co-location (server hosting), server rental and consultant and advisory services. The provider will be the data processor on behalf of the data controller for the services that is agreed to be provided.
- Full name
- Sosial security number
- (Company name and organization number)
- Relevant logs
The customer as a data controller has the following responsibilities:
Data processor rights and duties
- Specify which category of personal data, as well as what information can be processed and set the purpose of processing the given information.
- Ensure that personal data is processed in accordance with applicable law.
- When transferring data to the service, allow the data processor to process this data.
- Perform security actions and backup of the stored information.
The provider as data processor has the following responsibilities:
Security, recommendations and revision
- Data processor can only process data according to instructions given by the data controller.
- Data processor is responsible for documenting where information is stored.
- All employees must be familiar with the agreement and have signed a non-disclosure agreement.
- Data processor shall tale any necessary technical and organizational security actions to ensure adequate security of any data, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.
- The data controller should be given access to information stored at any time.
- Data processor will be at any assistance tp delete/rotate information that no longer needs to be stored. Limited to our service logs and backups. The data controller is responsible for files/databases on their own storage area.
- In case of security breaches, affected parties must be notified by the data processor within 24 hours. A _deviation_ should be made to the event, which is closed only by documenting necessary actions taken.
- If the data processor processes personal data for other purposes, or by methods other than agreed, the data processor is considered to be the data controller with the duties and responsibilities it entails, cf. GDPR art. 82.83, and 84.
- Upon request, the data processor may assist in audits and/or inspections to comply with the requirements of this agreement and GDPR.
- The provider processes all data, including personal information, in accordance with internal security practices and processes. This includes, among other things:
For customers who use shared hosting services, it is recommended not to store sensitive personal data. There is also a responsibility on the customer to ensure the security of files and data uploaded, as well as the selection of good passwords, multi factor authentication where possible and updates to the web page.
Encrypted protocols for all communications for the services are available, and these should be used as far as possible.
Duration and termination of the agreement
- Physical access control for equipment located in data centers
- Regular backup to dedicated backup servers
- Regular security updates
- Encryption of communication and data
- This agreement has the same duration, notice period and termination as the service provided. When the agreement expires, the service will be deleted from the system and information will be rotated out of backup no later than 3 months after end of the agreement.
- If either party fails to fulfill its obligations under this Agreement, the agreement may be terminated with immediate effect.
- This agreement is governed by Norwegian law, and Oslo District Court is appointed as a court of law. This also applies after the expiration of the agreement.
- Data Processors use sub-processors to carry out parts of the delivery of the services. This list contains the sub-processors that the data processor has entered into data processing agreements with.
||Domain names & SSL certificates
|AS Domain Registry
|Kappa Regnskap AS
|INBS.Software Konrad Keck
|Google Ireland Limited
||Review & analysis
||Marketing & analysis
22.07.2020, Nordhost, NordkappNett AS