Data processing agreement

    Data Processing Agreement (DPA)

    Version 1.0 — April 27, 2026

    Sign the DPA in the app

    You sign the data processing agreement electronically while signed in. The exact wording you sign, the version, the timestamp and who signed are stored as evidence, and you receive the signature record as a PDF.

    Sign the DPA

    Annex B — named sub-processors

    Annex B is not published publicly. The button places your request in an internal queue for manual handling. Nothing is disclosed automatically.

    This document exists in Norwegian and English. The Norwegian version prevails if the two versions differ.

    1. Background and parties

    This Data Processing Agreement ("DPA") governs Brødrene Gåsdal AS's processing of personal data on behalf of the customer ("Controller") in connection with use of the Justera service. The DPA is an addendum to the Terms of Service and prevails in case of conflict on data protection matters.

    2. Nature and purpose of processing

    • Type of processing: storage, analysis and structuring of legal documents and questions.
    • Categories of data subjects: customer's employees, counterparties referenced in contracts.
    • Categories of personal data: names, contact details, employment details, and any special categories if the customer uploads such content.
    • Duration: for the term of the service, then deleted within 30 days.

    3. Justera's obligations

    • Processes personal data only on documented instructions from the customer.
    • Ensures personnel with access are bound by confidentiality.
    • Implements technical and organisational measures (TLS, RLS, audit log, MFA).
    • Assists the customer in fulfilling obligations toward data subjects (access, rectification, deletion).
    • In the event of a personal data breach we notify the customer without undue delay so the customer can meet its own obligation to notify the Norwegian Data Protection Authority. We state no response deadline of our own.

    4. Sub-processors

    Justera uses sub-processors within the following categories:

    • Cloud provider for database and file storage (EEA)
    • Error reporting provider (EEA)
    • Providers of AI model inference
    • Transactional email provider
    • Web analytics provider
    • Payment provider
    • Norwegian public registries

    We do not name sub-processors publicly. The named list is Annex B to the data processing agreement and is provided to customers on request. Changes are notified by email at least 30 days in advance, and the customer may object and terminate without cost.

    5. Transfers outside the EEA

    Customer data is stored in the EU/EEA. Some sub-processors may process data outside the EEA, and such transfers take place under the EU Commission's Standard Contractual Clauses (SCC 2021/914) with supplementary measures.

    6. Audit and control

    The customer may request Justera's own security documentation and mapping against the NSM Basic Principles. Justera is not ISO 27001 or SOC 2 certified. On-site audits can be arranged with 30 days' notice at the customer's expense.

    7. Deletion and return

    On termination, Justera deletes all customer data within 30 days unless law requires longer retention. The customer may request export (JSON/PDF) before deletion.

    8. Governing law

    The DPA is governed by Norwegian law, including the Personal Data Act and GDPR. The agreement is governed by Norwegian law. The venue is Sunnmøre District Court.