Data processing agreement
Data Processing Agreement (DPA)
Version 1.0 — April 27, 2026
Sign the DPA in the app
You sign the data processing agreement electronically while signed in. The exact wording you sign, the version, the timestamp and who signed are stored as evidence, and you receive the signature record as a PDF.
Annex B — named sub-processors
Annex B is not published publicly. The button places your request in an internal queue for manual handling. Nothing is disclosed automatically.
This document exists in Norwegian and English. The Norwegian version prevails if the two versions differ.
1. Background and parties
This Data Processing Agreement ("DPA") governs Brødrene Gåsdal AS's processing of personal data on behalf of the customer ("Controller") in connection with use of the Justera service. The DPA is an addendum to the Terms of Service and prevails in case of conflict on data protection matters.
2. Nature and purpose of processing
- Type of processing: storage, analysis and structuring of legal documents and questions.
- Categories of data subjects: customer's employees, counterparties referenced in contracts.
- Categories of personal data: names, contact details, employment details, and any special categories if the customer uploads such content.
- Duration: for the term of the service, then deleted within 30 days.
3. Justera's obligations
- Processes personal data only on documented instructions from the customer.
- Ensures personnel with access are bound by confidentiality.
- Implements technical and organisational measures (TLS, RLS, audit log, MFA).
- Assists the customer in fulfilling obligations toward data subjects (access, rectification, deletion).
- In the event of a personal data breach we notify the customer without undue delay so the customer can meet its own obligation to notify the Norwegian Data Protection Authority. We state no response deadline of our own.
4. Sub-processors
Justera uses sub-processors within the following categories:
- Cloud provider for database and file storage (EEA)
- Error reporting provider (EEA)
- Providers of AI model inference
- Transactional email provider
- Web analytics provider
- Payment provider
- Norwegian public registries
We do not name sub-processors publicly. The named list is Annex B to the data processing agreement and is provided to customers on request. Changes are notified by email at least 30 days in advance, and the customer may object and terminate without cost.
5. Transfers outside the EEA
Customer data is stored in the EU/EEA. Some sub-processors may process data outside the EEA, and such transfers take place under the EU Commission's Standard Contractual Clauses (SCC 2021/914) with supplementary measures.
6. Audit and control
The customer may request Justera's own security documentation and mapping against the NSM Basic Principles. Justera is not ISO 27001 or SOC 2 certified. On-site audits can be arranged with 30 days' notice at the customer's expense.
7. Deletion and return
On termination, Justera deletes all customer data within 30 days unless law requires longer retention. The customer may request export (JSON/PDF) before deletion.
8. Governing law
The DPA is governed by Norwegian law, including the Personal Data Act and GDPR. The agreement is governed by Norwegian law. The venue is Sunnmøre District Court.