Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Illeris Web AS ("Processor") and the customer using Kustmr ("Controller") where the Processor processes personal data on the Controller's behalf.

Last updated: July 15, 2026

Illeris Web AS (org. no. 926 563 890)
Brynsveien 3, 0667 Oslo, Norway
support@kustmr.com

1. Roles and scope

The Controller determines the purposes and means of processing personal data entered into a Kustmr workspace, including customer, contact, employee and other business records.

The Processor processes that data only to provide, secure, maintain and support the service, in accordance with the Controller's documented instructions as expressed through use of the product, these terms and applicable law.

2. Subject matter and duration

Processing concerns personal data stored in the Controller's workspace while the subscription or trial remains active and for a limited period thereafter as needed for backup, legal compliance, dispute resolution and secure deletion.

3. Nature and purpose of processing

Processing may include:

  • Storage and organisation of workspace records
  • Display to authorised workspace users
  • Export, deletion and backup operations
  • Authentication, access control and audit-related operations
  • Support, troubleshooting and service improvement limited to what is necessary

4. Categories of data and data subjects

The categories of personal data and data subjects depend on how the Controller uses the service. They may include business contacts, customers, employees, contractors and other individuals whose information the Controller chooses to store in the workspace.

5. Processor obligations

The Processor will:

  • Process personal data only on documented instructions, unless required by law
  • Ensure that persons authorised to process data are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Use subprocessors only in accordance with this DPA
  • Assist the Controller with data-subject requests where reasonably possible
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting workspace data, where legally required
  • Delete or return personal data after the end of the service, subject to legal retention requirements

6. Subprocessors

The Controller authorises the Processor to engage subprocessors listed on our Subprocessors page. We will keep that list current and impose data-protection obligations on subprocessors through contract or equivalent measures.

7. Security measures

The Processor maintains security measures described on our public Security page, including mandatory two-factor login verification, workspace-scoped access, role-based controls and data export/deletion functionality.

8. International transfers

Where subprocessors process personal data outside the EEA, appropriate safeguards such as standard contractual clauses or equivalent mechanisms will be used where required by applicable law.

9. Audits and information

On reasonable request, the Processor will provide information necessary to demonstrate compliance with this DPA. Formal audits may be conducted no more than once per year on reasonable notice, during business hours, and in a manner that does not unreasonably disrupt operations or expose unrelated customer data.

10. Signed copies

This page summarises the DPA incorporated into use of Kustmr. If you require a countersigned copy for procurement or vendor review, contact support@kustmr.com.