Data Processing Agreement
Last Updated: July 31, 2026
1. What this is, and when it applies
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and Alvesta Systems AS(Org. nr. 936 927 548), Norway ("Vashana", "we"). It applies automatically, with no signature required, whenever we process personal data on your behalf. You do not need to ask us for one.
It is the agreement required by Article 28(3) of the GDPR (Regulation (EU) 2016/679, as incorporated into Norwegian law by personopplysningsloven).
Two different relationships, and this document covers one of them. For your own account — your name, your email, your billing — we are the controller, and our Privacy Policy governs. For the people who use the sites you build — your visitors, your customers, your renters — you are the controller and we are the processor. That is what this DPA is about.
2. What we process, and why
Subject matter and duration. Providing the Service to you, for as long as your account is active, plus the retention periods in Section 9.
Nature and purpose. Hosting and serving your published site; storing the content and files you upload; and — where you enable them — operating bookings, payments against your own payment provider, transactional email to your customers, and an AI assistant.
Categories of data subject. Visitors to your published sites; your customers, renters or attendees who make a booking; people who submit a contact form; and any individual whose personal data you choose to put into your site content.
Types of personal data. Depending on which features you use:
- Contact details supplied when booking — name, email address, telephone number
- Booking records — what was booked, when, for how much, and its status
- Payment references and status held on your own provider's account (we never hold card data)
- Identity assertions supplied by a payment provider where the rail offers them — for Vipps, a verified name, phone number and email address
- Evidence attached to a handover — the agreement your customer accepted, and photographs they upload at pickup and return, which may incidentally show faces, vehicles or premises
- Anything else you place in your site content or files
We do not knowingly process special category data (Article 9) on your behalf, and the Service is not designed for it. If your use requires it, tell us first — it needs a different conversation, not a different setting.
3. Our obligations
We will:
- Process only on your documented instructions. Your use of the Service, and its configuration, are those instructions. We will tell you if we believe an instruction breaches data protection law, and we will not process for our own purposes.
- Keep it confidential. Everyone we authorise to process your data is bound by confidentiality.
- Secure it in line with Article 32 — see Section 8.
- Help you meet your own obligations — data subject requests (Section 6), breach notification (Section 7), and any impact assessment or prior consultation you have to carry out.
- Delete or return it when we stop providing the Service (Section 9).
- Show our work. Make available the information you need to demonstrate compliance with Article 28, and allow for audits (Section 10).
4. Your obligations
You are the controller, which means the decisions that matter are yours. You are responsible for having a lawful basis for the data you put into the Service, for telling your own customers what you do with it, and for the accuracy and legality of the instructions you give us through your use of the Service.
One consequence worth naming: the booking agreement your renters accept, and any terms you write into it, are yours. We supply a template as a starting point. We are not in a position to write enforceable terms for your business in a jurisdiction we do not know, and we do not claim to.
5. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at vashana.com/legal/sub-processors, with what each one does and where it processes.
We will give you at least 30 days' notice before a new sub-processor begins processing, by updating that page and emailing your account address. If you object on reasonable data-protection grounds within those 30 days, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the Service without penalty for the remainder of your term.
We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain fully liable to you for their performance.
Your payment provider is not our sub-processor. Money from bookings goes to your own Vipps MobilePay or Stripe account under your own agreement with them. We call their API on your instruction using the credentials you connected; their handling of that data is between you and them.
6. Data subject rights
Requests come to you, not to us — you are the controller. If one reaches us directly we will not answer it on your behalf; we will pass it to you without undue delay.
Most requests you can satisfy yourself from the dashboard, which is deliberate: access, correction and deletion of a booking and its evidence are all things you can do without asking us. Where the Service does not let you do it, we will help by appropriate technical and organisational measures, taking into account the nature of the processing.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any event in time for you to meet your own 72-hour obligation under Article 33.
The notification will describe what happened, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and what we are doing about it — and will be updated as we learn more rather than withheld until complete.
8. Security
The measures we maintain, described concretely rather than as adjectives:
- Encryption in transit — TLS on every connection between you, your visitors, our services and our sub-processors.
- Encryption at rest for secrets — payment credentials and lock PIN codes are stored encrypted with AES-256-GCM, and are never returned by any API. Where a provider key is shown back to you it is truncated.
- Access control — every request is authenticated, and ownership of a site is checked on every operation against it. Booking evidence is served only through the API, never as a public storage URL.
- Isolation— each site's data is scoped to that site, and a request for one site cannot read another's.
- Data minimisation— we collect what a feature needs and stop there. We do not ask your payment provider for a customer's date of birth, and we do not store card data at any point.
- Retention limits — evidence is deleted on a schedule rather than kept indefinitely (Section 9).
- Logging and monitoring — application logs are retained 14 days, and errors are monitored so incidents are detected rather than reported to us.
9. Retention and deletion
We do not keep personal data indefinitely. The schedule, which the Service enforces automatically:
- Booking photographs— deleted 90 days after the booking ends. Photos are held longer only while a deposit remains open, because they are the evidence a damage claim rests on and deleting them under a live claim would destroy one party's argument.
- Accepted agreement documents — deleted 3 years after the booking ends, matching the general Norwegian limitation period. The record that an agreement was accepted, and which version, is kept with the booking; the document itself is not.
- Application logs — 14 days.
- Everything else — for as long as your account is active. On termination we delete your data within 90 days, unless you ask us to return it first or we are required by law to keep it.
10. Audits
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits conducted by you or an auditor you mandate.
In practice we will answer a written security questionnaire, and provide such third-party reports as we hold. An on-site audit is available where a supervisory authority requires one or following a personal data breach affecting your data; otherwise we ask for 30 days' notice, no more than once a year, at your cost, subject to confidentiality and without disrupting the Service or exposing another customer's data.
11. International transfers
We process within the EEA wherever we can, and our hosting, database and object storage are EU-based.
Some sub-processors are outside the EEA, marked as such on the sub-processor page. Those transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), or on an adequacy decision where one exists, together with any supplementary measures the transfer requires.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
13. Contact
Alvesta Systems AS (Org. nr. 936 927 548), Norway.
Data protection enquiries: [email protected]
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local supervisory authority.