Legal

Data Processing Agreement

For clients where Nordic Riser AB processes personal data on your behalf as a processor, not a controller. Available on request — contact us to have this executed alongside your engagement.

This document is not yet available in Polski. The English text below is authoritative while a professional legal translation is prepared. Contact us with questions.
Last Updated: 19 August 2026

This Data Processing Agreement (“DPA”) applies whenever Nordic Riser AB (“Processor”) processes personal data on behalf of a client (“Controller”) in connection with NR-BOS, the Member Portal, or another Nordic Riser software product, under Article 28 of the GDPR. It supplements — and does not replace — the underlying service agreement or Terms of Service between the parties.

This published version is a template. Contact us to have it executed as a signed agreement referencing your specific engagement.

1 Subject Matter & Duration

The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller in the course of providing the Services described in the parties' underlying agreement (for example, an NR-BOS license or Member Portal engagement).

This DPA takes effect on the date the underlying service agreement takes effect and remains in force for as long as the Processor processes personal data on the Controller's behalf, including during any post-termination period described in Section 11.

2 Nature & Purpose of Processing

The Processor processes personal data to provide, maintain, and support the Services — including hosting, storage, field-report processing, project and task tracking, secure messaging, document exchange, and, where enabled, AI-assisted analysis as described in the Privacy Policy.

The Processor processes personal data only on the Controller's documented instructions, including as set out in the underlying agreement, this DPA, and the Controller's own configuration of the Service (for example, which features are enabled) — unless required to do otherwise by EU or Member State law, in which case the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits such notice.

3 Categories of Data & Data Subjects

Categories of personal data processed depend on which Service the Controller uses, and may include: account identifiers and contact details; employment and role information; worksite photographs and associated location/timestamp metadata; project, task, and cost records; logged working hours; uploaded documents; and message content.

Categories of data subjects may include: the Controller's employees, contractors, and subcontractors; the Controller's own clients or customers, where their data is entered into the Service by the Controller; and other individuals whose data the Controller submits in the course of using the Service.

4 Controller's Instructions

The Controller instructs the Processor to process personal data to provide the Services, in accordance with the underlying agreement, this DPA, and the Controller's use of the Service's own configuration options.

The Controller warrants that it has a valid legal basis for the personal data it submits to the Service and, where applicable, has provided any notices to or obtained any consents from its own data subjects that its use of the Service requires.

5 Processor Obligations

The Processor:

  • Processes personal data only on the Controller's documented instructions, as described in Section 2
  • Ensures persons authorised to process personal data have committed to confidentiality
  • Implements the technical and organisational security measures described in Section 7
  • Assists the Controller as described in Sections 8 and 9
  • Does not engage a new sub-processor without providing notice as described in Section 6
  • Makes available the information necessary to demonstrate compliance with this Article 28 and allows for audits as described in Section 10

6 Sub-processors

The Controller gives the Processor general written authorisation to engage the sub-processors listed on the Processor's published Sub-processor list, available on the Nordic Riser AB website.

The Processor will give the Controller notice of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data-protection grounds before the change takes effect. Every sub-processor is bound by data-protection obligations no less protective than those in this DPA.

7 Security Measures

The Processor implements the technical and organisational measures described in the Privacy Policy's Data Security section, including, as applicable to the specific Service:

  • Encrypted communication channels for the transmission of sensitive information
  • Authentication and access controls restricting each user to their own data
  • Private, non-public storage for uploaded files, accessed only via short-lived signed links rather than a public path
  • Regular review of security practices and staff awareness of data protection obligations

8 Assistance & Data Subject Requests

Where a data subject exercises a GDPR right (access, rectification, erasure, restriction, portability, or objection) directly against the Processor concerning data the Processor holds as a processor for the Controller, the Processor will promptly forward that request to the Controller and will not itself respond substantively to the data subject, since the Controller is the appropriate party to respond.

The Processor will provide the Controller with reasonable assistance, taking into account the nature of the processing, to help the Controller fulfil its own obligations to respond to data subject requests and to fulfil its obligations under Articles 32–36 of the GDPR.

9 Personal Data Breach Notification

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably available to it to help the Controller meet its own breach-notification obligations under Articles 33 and 34 of the GDPR.

10 Audit Rights

On reasonable prior written notice, and no more than once per calendar year unless a personal data breach or a regulatory investigation gives cause for more frequent review, the Controller may request information demonstrating the Processor's compliance with this DPA, and may conduct or mandate an audit of the Processor's relevant processing activities, subject to reasonable confidentiality and scheduling arrangements to avoid disrupting the Processor's operations or other clients' data.

11 Deletion & Return on Termination

On termination of the underlying agreement, the Processor will, at the Controller's choice, delete or return all personal data processed on the Controller's behalf, and delete existing copies, within a reasonable period — except to the extent the Processor is required by EU or Member State law to retain some or all of that data, in which case it will continue to protect that data and process it only for the purposes that law requires.

12 Article 28(3) Compliance Statement

This DPA is intended to give effect to the requirements of Article 28(3) of the GDPR for the processing described in this document. Where a specific engagement requires additional or different terms — for example, a Controller's own standard DPA, or terms specific to a regulated sector — the parties may agree a supplementary or substitute document in writing; that document will govern to the extent it conflicts with this one.

13 Liability & Governing Law

Liability under this DPA is subject to the limitations set out in the Terms of Service between the parties, except where such limitation is not permitted by applicable data protection law.

This DPA is governed by the laws of Sweden, with the Stockholm District Court (Stockholms tingsrätt) as the court of first instance for any dispute arising from it, consistent with the Terms of Service.