Data Processing Agreement

Summary · GDPR Art. 28
Roles

Your company is the controller. Norse AI AB (Stockholm, org. no. 559XXX-XXXX) is the processor. The DPA is signed during onboarding, before any personal data is processed.

Subprocessors

The following subprocessors process personal data to deliver Round Table: Supabase (EU, AWS Stockholm eu-north-1) — authentication and database; Vercel — application hosting and cookieless analytics; Anthropic — hosted model inference for the EU cloud tier; Resend — transactional email; Microsoft — calendar holds for booking. Sessions delivered on the sovereign-cloud tier (Sweden) run on NorseAI's private cloud at Evroc AB, where Evroc AB acts as infrastructure subprocessor for that tier. On-premises and air-gapped deployments (client premises) do not send session content to the hosted model provider. Any change of subprocessor requires 30 days' prior written notice and gives you a right to object.

Instructions & scope

We process personal data only on your documented instructions, only for delivering the Round Table engagement, and only the categories listed in the privacy notice.

Security measures

TLS 1.3 in transit, AES-256 at rest, role-based access on a need-to-know basis, logged and auditable access, annual penetration testing. Full TOMs annex available on request.

Breach & audit

Personal-data breaches are notified to you without undue delay, within 48 hours of discovery. You may audit compliance once per year, or after any incident, on 14 days' notice.

End of engagement

At termination you choose: return of all personal data in a structured format, or certified deletion — completed within 2 weeks.

Questions? Write to privacy@norse-ai.com. This summary does not replace the signed agreement for your engagement.

← Back to norse-ai.com