Legal

Data Processing Agreement

Appendix 1 to the License Agreement for the use of AIMZ

Appendix 1 to the License Agreement for the use of AIMZ

Data Processing Agreement

Version: March 2026

This is an English translation provided for convenience. The Norwegian version is the legally binding text.

Processor
Aimz ASOrg. no. 933 876 179
Controller
The CustomerAs defined in the Contract

1Parties and purpose of the agreement

1.1

Aimz AS is referred to herein as the “Processor” and the Customer (as defined in the Contract) is referred to as the “Controller”.

1.2

The purpose of this Data Processing Agreement (the “Agreement”) is to regulate the parties’ rights and obligations under applicable data protection legislation, including the Norwegian Personal Data Act of 2018, which incorporates the EU General Data Protection Regulation 2016/679 (GDPR) (hereinafter jointly referred to as the “data protection legislation”).

2General

2.1

The purpose of this Agreement is to regulate the Processor’s use of personal data on behalf of the Controller to which the Processor gains access in connection with the delivery of services under the License Agreement for the use of AIMZ (the “Contract”), in accordance with GDPR Article 28.

2.2

Annexes A and B to this Data Processing Agreement form an integral part of the agreement and contain, respectively, further details on the processing of personal data and the list of approved sub-processors.

2.3

The Agreement takes precedence over any corresponding data protection provisions in other agreements between the parties, including the Contract.

2.4

This Agreement does not release the Processor from obligations imposed on the Processor by the data protection legislation or other legislation. This Agreement only regulates the Processor’s processing on behalf of the Controller in connection with the Solution. For personal data that the Processor processes as an independent controller (e.g. CRM, invoicing, supplier and support channels outside the Solution), the Processor’s own privacy documents apply and not this Agreement.

3The Controller’s rights and obligations

3.1

The Controller is responsible for ensuring that the processing of personal data takes place in accordance with the data protection legislation.

3.2

The Controller has the right and the obligation to determine the purpose of the processing of personal data and the means to be used. The Controller is further responsible for ensuring that there is a legal basis for the processing of personal data that the Processor is instructed to carry out.

4The Processor’s obligations

4.1

Instructions: The Processor shall only process personal data on documented instructions from the Controller, unless otherwise required by national or European law. The Processor shall immediately notify the Controller if the Processor is of the opinion that an instruction infringes the data protection legislation.

4.2

Confidentiality: The Processor may only grant access to personal data processed on behalf of the Controller to persons who are subject to the Processor’s authority of instruction and who have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality, and only to the extent necessary.

At the request of the Controller, the Processor shall be able to demonstrate that the persons concerned who are subject to the Processor’s authority of instruction are bound by the above obligation of confidentiality.

4.3

Security: The Processor shall implement appropriate technical and organisational measures to achieve a level of security appropriate to the risk, cf. GDPR Article 32. The Processor shall also assist the Controller in complying with the Controller’s obligations under GDPR Article 32, including by making the necessary information available to the Controller.

The Controller shall likewise make available to the Processor the information necessary to enable the Processor to identify and assess risks in accordance with GDPR Article 32.

5Sub-processors

5.1

The Processor shall meet the requirements of GDPR Article 28(2) and (4) where the Processor engages another processor (a “sub-processor”).

5.2

The Controller gives a general authorisation for the Processor to engage sub-processors. The Processor shall maintain an up-to-date list of current sub-processors on its website. Changes to the list (addition or replacement of sub-processors) will be published on the Processor’s website. The Processor may additionally notify the Controller by e-mail, but this is not a requirement for the change to be valid. The Controller may, within thirty (30) days of a published change, raise objectively justified objections to a new sub-processor. If the parties fail to reach agreement, the Controller may terminate the Contract with effect from the date on which the new sub-processor was to be taken into use. Continued use of the Service after the expiry of the objection period is deemed acceptance of the new sub-processor. The list of sub-processors already approved by the Controller is set out in Annex B.

5.3

When engaging sub-processors, the sub-processor shall as a minimum be subject to the same data protection obligations as set out in this Agreement. A copy of the sub-processor agreement and any subsequent amendments shall – at the Controller’s request – be sent to the Controller, who thereby has the opportunity to ensure that the sub-processor is subject to the same data protection obligations as set out in this Agreement. Commercial terms that do not affect the data protection content of the sub-processor agreement are not subject to the requirement of a copy to the Controller.

5.4

The Processor shall remain fully liable for any failure by the sub-processor to fulfil its data protection obligations.

6Transfers to third countries or international organisations

6.1

The Processor may only transfer personal data to third countries or international organisations on documented instructions from the Controller, unless the transfer is required by national or European law. In that case the Controller shall be informed of that legal requirement unless public interest prevents this. For the avoidance of doubt, a transfer to a third country in connection with the use of approved sub-processors pursuant to clause 5 above shall always be regarded as a transfer on documented instruction from the Controller. Any transfer shall always take place in accordance with GDPR Chapter V, including being subject to a lawful transfer mechanism.

Transfer mechanism for third countries: For transfers of personal data to third countries (including the USA), the Processor shall ensure that the transfer takes place in accordance with GDPR Chapter V, including by using the EU Standard Contractual Clauses (EU SCC 2021/914) and carrying out a Transfer Impact Assessment (TIA) with the necessary supplementary measures. At the Controller’s request, the Processor shall make available high-level documentation confirming a valid transfer mechanism.

6.2

This Agreement shall not be confused with standard data protection clauses as referred to in GDPR Article 46(2)(c) and (d), and this Agreement cannot constitute a basis for the transfer of personal data under GDPR Chapter V.

7Assistance to the Controller

7.1

To the extent possible, the Processor shall assist the Controller in responding to requests from data subjects for the exercise of their rights, assist with information and notification in the event of qualifying personal data breaches, assist with data protection impact assessments and assist in connection with prior consultations with the Norwegian Data Protection Authority (Datatilsynet).

7.2

In the event of a personal data breach, the Processor shall notify the Controller of the breach without undue delay after becoming aware of it, so that the Controller can comply with its obligation to notify the breach to the competent supervisory authority (in Norway: Datatilsynet), cf. GDPR Article 33.

8Liability

8.1

Each party is liable for any financial loss it causes the other party through breach of this Agreement. The limitations of liability in the Contract also apply here.

8.2

Each party is liable to a data subject who has suffered material or non-material damage where the damage is caused by the party having acted outside or contrary to this Agreement or the data protection legislation, cf. GDPR Article 82(1).

9Deletion and return of personal data

9.1

Upon termination of the data processing services, the Processor shall, at the Controller’s choice, delete all personal data processed on behalf of the Controller or return all personal data and delete existing copies, unless national or European law prevents this or otherwise agreed in the Contract. The Processor undertakes to process the personal data exclusively for the purpose(s), for the duration and under the conditions laid down in these rules.

9.2

Deletion at sub-processors: Upon termination, the Processor shall instruct relevant sub-processors to delete or return personal data processed on behalf of the Controller. The Processor shall confirm completed deletion/return within a reasonable time (normally within 30–90 days) after termination, unless another deadline follows from law.

10Audits, including inspections

10.1

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under the data protection legislation and this Agreement. Furthermore, the Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

11Entry into force and termination

11.1

The Agreement enters into force on the same date as the Contract.

11.2

The Agreement applies for as long as the data processing services last and cannot be terminated during that period, unless the parties agree other terms governing the delivery of the data processing services in accordance with applicable data protection legislation.

11.3

If the Contract or the delivery of the data processing services ends, and the personal data has been deleted or returned to the Controller in accordance with clause 9.1 above, this Agreement terminates.

Annex A

Description of the processing

1. Purpose of the Processor’s processing of personal data on behalf of the Controller

The purpose of the Processor’s processing of personal data on behalf of the Controller is to deliver Aimz’s digital service for financial and project management in building and construction projects, including functionality for invoice import, forecast follow-up and reporting.

The processing takes place solely to enable the Controller’s use of the Solution and to support its operation.

2. Nature of the processing

The processing will include collection of and access to relevant data from the Controller’s systems, recording, organisation, structuring, compilation and alignment of data, analysis, calculation of KPIs, preparation and provision of reports and dashboards, storage, retrieval, use and advice, as well as restriction and deletion upon termination. The Processor also performs technical support, troubleshooting and handling of necessary operational and access logs related to the service.

AI processing: The processing may include the use of AI functionality for analysis, prediction and generation of suggestions related to financial and project management (e.g. indicators/health score, insights and follow-up suggestions). AI functions shall not be trained on the Controller’s data unless specifically agreed in writing. The Processor shall ensure that AI providers only process data in accordance with this Agreement, and within the agreed region where relevant.

Storage and operation: The Solution is hosted in Microsoft Azure in the EU/EEA. The Processor shall ensure that all data processed for the Controller is stored in the EU/EEA, unless otherwise agreed in accordance with clause 6.

3. Types of personal data

The Controller will normally process, including have access to, the following personal data:

  • Contact and identity data: name, position/role, department, e-mail, telephone.
  • Employment/organisational data: organisational affiliation, cost centre/project, user attributes (access role/ID in relevant systems).
  • Transaction and financial data that can be linked to individuals: travel expenses/outlays (not attachments containing special categories), order/invoice references with contact fields, timesheets linked to project/resource (where this forms part of the financial data).
  • System/operational logs related to the delivery: support/incident logs, access logs (minimised to what is necessary, typically 90 days retention).
  • Support and communication requests: name, e-mail, content of requests (including attachments if sent), technical metadata (time, browser/IP) to the extent necessary to provide support for the Solution.

As a general rule, the Controller will not process special categories of (sensitive) personal data, cf. GDPR Article 9(1), under this Agreement.

4. Categories of data subjects

The processing covers employees of the Controller, including managers and other persons with roles relevant to financial and project follow-up, as well as contact persons at the Controller’s customers and suppliers appearing in financial and invoice data. The processing may also cover hired consultants and contractors where personal data about them forms part of project or financial data.

5. Duration of the processing

The Processor will process personal data for as long as the Contract is in force.

Annex B

Sub-processors

Approved sub-processors

Upon entry into force of the Agreement, the Controller has approved the use of the sub-processors listed below for the processing activity described for each sub-processor. The Processor may not – without the Controller’s approval – use a sub-processor for a processing activity other than the one agreed for that sub-processor, or use another sub-processor for the described processing activity.

ProviderService/roleLocationDescription of the processing
FrontedIT consultancyEEAProvides full-time software developers assisting AIMZ in software development.
MicrosoftHosting (Azure) and admin (365)EEAStorage and processing of application data, e-mail, video conferencing, databases, backup, operations and monitoring.
HubSpotCRMEEAManagement of the customer’s users/contacts and activity patterns for follow-up, onboarding and health indicators.
IntercomCustomer support/chatUSAName, e-mail, content of requests and technical metadata for user support related to the Solution. Transfer mechanism: EU SCC (2021/914) + TIA; deletion upon termination in accordance with clause 9.
PostHogProduct analyticsEEAEvents/user behaviour, pseudonymous IDs and technical metadata for analysis and product improvement.
OpenAIProduct enrichmentUSAAnalysis and suggestions. Transfer mechanism: EU SCC (2021/914) + TIA; deletion upon termination in accordance with clause 9.
Aimz AS · Org.nr 933 876 179 · aimz.noData Processing Agreement · March 2026