# Data Processing Addendum (DPA)

**Between:**
**Noblewolf AS**, org.no. 911 977 547, Wessels gate 4, 0165 Oslo, Norway ("**Processor**")
**and**
**[CLIENT NAME]**, org.no. [###], [ADDRESS] ("**Controller**")

Effective from: **[DATE]**

---

## 1. Background and purpose

The Controller uses the Processor's service **NW-Stage** (the "Service") to deliver live events, register attendees and communicate with them. The Service is provided as SaaS by Noblewolf AS.

This Addendum governs how the Processor processes personal data on behalf of the Controller, in compliance with the GDPR (EU 2016/679) art. 28 and applicable Norwegian/EEA data protection law.

## 2. Definitions

Terms have the same meaning as in the GDPR, with these specifications:
- "**Personal Data**" means data processed in the Service on behalf of the Controller.
- "**Data Subjects**" means natural persons whose personal data is processed (typically event attendees, contacts, client admin users).
- "**Sub-processors**" means third parties used by the Processor to deliver the Service (see Annex B).

## 3. Nature and purpose of processing

| Item | Description |
|---|---|
| **Purpose** | Run live events, register attendees, send email communications, deliver analytics. |
| **Nature of processing** | Collection, storage, sharing with Controller, deletion on instruction. |
| **Categories of personal data** | Email address, name, phone (optional), registration form answers, attendance status, IP for analytics (anonymized by default), device/browser data. |
| **Categories of Data Subjects** | Event attendees, administrators at the Controller. |
| **Duration** | Until termination of the agreement or deletion instructed by the Controller. |

The Processor does **not** process special categories of personal data by default. If the Controller chooses to collect such data via custom registration fields, this shall be documented separately.

## 4. Controller obligations

The Controller:
- Is responsible for the lawful basis for processing personal data in the Service.
- Determines the purposes and means of processing.
- Shall obtain necessary consents from Data Subjects and provide information notices.
- Configures the Service (registration forms, email templates, cookie modes) in line with its own privacy framework.

## 5. Processor obligations

The Processor shall:

1. **Process personal data only on documented instructions** from the Controller, including for transfers to third countries.
2. **Ensure confidentiality**: Persons processing the data are bound by confidentiality.
3. **Implement technical and organizational security measures** as described in Annex A.
4. **Assist the Controller** in fulfilling Data Subject rights (access, rectification, erasure, portability, objection).
5. **Notify the Controller without undue delay** of any personal data breach, within 24 hours at the latest.
6. **Delete or return** all personal data on termination, at the Controller's choice.
7. **Make available all information** necessary to demonstrate compliance with art. 28.
8. **Allow and contribute to audits**, including inspections, conducted by the Controller or an auditor mandated by the Controller (with reasonable notice and under confidentiality).

## 6. Sub-processors

The Controller grants general prior authorization for the Processor to use the sub-processors listed in **Annex B**, and as updated at `https://stage.noblewolf.no/underleverandorer`.

The Processor shall:
- Give the Controller at least **30 days** notice before changes to the list.
- Ensure sub-processors are bound by data protection obligations equivalent to this Addendum.
- Remain liable to the Controller for sub-processor performance.

The Controller may object to a change within 30 days on documented data protection grounds. If no agreement is reached, the Controller may terminate the affected part of the Service.

## 7. International transfers

Personal data is stored primarily in the EU. Transfers to third countries (typically the USA via Resend/OpenAI for email and AI features) occur only:
- To recipients covered by the **EU-US Data Privacy Framework (DPF)**, or
- Under **EU-approved Standard Contractual Clauses (SCCs)** as transfer mechanism.

Per-sub-processor details are in Annex B.

## 8. Security measures

See **Annex A**.

## 9. Personal data breach

In the event of a security breach the Processor shall:
- Notify the Controller within **24 hours** of becoming aware of the breach.
- Provide available information about the nature of the breach, categories and approximate number of affected Data Subjects, consequences, and mitigations applied.
- Assist the Controller with any reporting obligation to the supervisory authority (within 72 hours of the Controller's awareness).

## 10. Term and termination

This Addendum is in force as long as the Processor processes personal data on behalf of the Controller.

On termination the Processor shall, within 30 days:
- **Delete** all data, or
- **Export** data to the Controller in a structured machine-readable format (JSON/CSV),

at the Controller's choice. Backups are deleted according to rotation schedule (max 90 days).

## 11. Liability

Each party is liable for damages resulting from its own breach of this Addendum and the GDPR. Liability caps and insurance follow the master agreement between the parties.

## 12. Governing law and jurisdiction

This Addendum is governed by Norwegian law. Oslo District Court has jurisdiction.

---

## Annex A — Technical and organizational security measures

**Cryptography:**
- All traffic over HTTPS/TLS 1.2+
- Passwords hashed with PBKDF2 (Web Crypto)
- Certificates managed automatically per (sub)domain

**Access control:**
- Multi-tenant architecture — each client's data is logically isolated
- Admin access requires login sessions with expiry
- Audit log for all changes

**Data location:**
- Primary database and file storage in the EU (Cloudflare EEUR/WEUR regions)
- Email processing via Resend (USA, EU-US DPF + SCCs)
- AI processing via OpenAI (USA/EU instance, EU-US DPF + SCCs, model training opt-out)

**Backup:**
- Cloudflare D1 has automatic backup with 30-day retention
- R2 storage redundant within region

**Personnel:**
- Only authorized Noblewolf personnel have system access
- All employees and contractors sign confidentiality agreements

**Logging:**
- Audit log for all admin actions
- Access logs retained 90 days

---

## Annex B — List of sub-processors

| Name | Country | Purpose | Transfer mechanism |
|---|---|---|---|
| **Cloudflare, Inc.** | USA (data processing in EU EEUR/WEUR) | Hosting (DB, storage, edge delivery, cert management) | EU SCCs |
| **Plus Five Five, Inc.** (Resend) | USA | Transactional email | EU-US DPF + SCCs |
| **OpenAI, L.L.C.** | USA (EU instance for EU customers) | Optional AI-assisted text generation | EU-US DPF + SCCs |

Updated list published at: **https://stage.noblewolf.no/underleverandorer**

---

## Signatures

**For the Controller:** ___________________________
Name: _______________ Title: _______________ Date: ______

**For the Processor (Noblewolf AS):** ___________________________
Name: Daniel Aadne — Managing Director Date: ______
