FYND CORE PRIVACY POLICY
TABLE OF CONTENTS
loading...
Updated version April 2025
1. PURPOSE OF THIS DATA PROCESSING AGREEMENT
This Agreement (the “Data Processing Agreement”) sets out the Parties’ rights and obligations when the Data Processor processes personal data on behalf of the Data Controller, as part the services delivered under the Main Agreement. The purpose of the Data Processing Agreement is to ensure that the Parties comply with the Applicable Privacy Policy.
2. DEFINITIONS
Applicable Privacy Policy: The applicable versions of the EU’s General Data Protection Regulation (2016/679) (“GDPR”) and the Norwegian Act on the Processing of Personal Data of 15.06.2018 (the Personal Data Act) with related regulations etc., and any other relevant legislation concerning the processing and protection of personal data.
Service Agreement Front Page: One or more agreements between the Data Controller and the Data Processor concerning the provision of services which entail the processing of personal data. The Data Processing Agreement may apply to several underlying agreements.
Data Controller: Customer and owner of the data being processed under this agreement.
Data Processor: Fynd Reality, the party processing the data as governed under this agreement.
Subprocessor: A company or person used by the Data Processor as a subcontractor for the processing of personal data under the Main Agreement.
Article 4 of GDPR will apply to privacy policy terms not defined in this agreement.
3. RIGHTS AND OBLIGATIONS OF THE DATA CONTROLLER
The Data Controller is responsible for the processing of personal data in accordance with the Applicable Privacy Policy. The Data Controller must specifically ensure that:
-
the processing of personal data is for a specified and explicit purpose and is based on valid legal grounds
-
the data subjects have received the necessary information concerning the processing of the personal data
-
the Data Controller has carried out adequate risk assessments; and
-
the Data Processor always has adequate instructions and information to fulfil its obligations under the Data Processing Agreement and the Applicable Privacy Policy.
4. INSTRUCTIONS FROM THE DATA CONTROLLER TO THE DATA PROCESSOR
The Data Processor shall process the personal data in accordance with the Applicable Privacy Policy and the Data Controller’s documented instructions, cf. section 4.2. If other processing is necessary to fulfil obligations to which the Data Processor is subject under applicable law, the Data Processor must notify the Data Controller to the extent this is permitted by law, cf. Article 28 (3) (a) of GDPR.
The Data Controller's instructions are stated in the Service Agreement and the Data Processing Agreement with Appendices. The Data Processor must notify the Data Controller immediately if the Data Processor believes the instructions conflict with the Applicable Privacy Policy, cf. Article 28 (3) (h) of GDPR.
5. ASSISTANCE TO THE DATA CONTROLLER
When requested, the Data Processor shall assist the Data Controller with the fulfilment of the rights of the data subjects under Chapter III of the GDPR through appropriate technical or organisational measures. The obligation to assist the Data Controller solely applies insofar as this is possible and appropriate, taking into consideration the nature and extent of the processing of personal data under the Service Agreement.
Without undue delay, the Data Processor shall forward all enquiries that the Data Processor may receive from the data subject concerning the rights of said data subject under the Applicable Privacy Policy to the Data Controller. Such enquiries may only be answered by the Data Processor when this has been approved in writing by the Data Controller.
The Data Processor must assist the Data Controller in ensuring compliance with the obligations pursuant to Articles 32-36 of GDPR, including aiding with personal data impact assessments and prior consultations with the Norwegian Data Protection Authority, in view of the nature and extent of the processing of personal data under the Main Agreement.
If the Data Processor, at the request of the Data Controller, provides assistance as described in sections 6.1 or 6.3, and the assistance goes beyond what is necessary for the Data Processor to fulfil its own obligations under the Applicable Privacy Policy, the Data Processor may claim all documented costs related to the assistance be reimbursed. The assistance will be reimbursed in accordance with the price provisions of the Main Agreement.
6. SECURITY OF PROCESSING
The Data Processor shall implement the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, considering the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
The Data Processor shall carry out risk assessments to ensure that an appropriate security level is always maintained. The Data Processor must ensure regular testing, analysis and assessment of the security measures, ensuring sustained confidentiality, integrity, availability and robustness in processing systems and services, and the ability to quickly restore the availability of personal data in the event of an incident.
7. NOTIFICATION OF BREACH OF PERSONAL DATA SECURITY
In case of a personal data breach, the Data Processor shall without undue delay, notify the Data Controller in writing of the breach, and in addition provide the assistance and information necessary for the Data Controller to be able to report the breach to the supervisory authorities in line with the Applicable Privacy Policy.
Notification in accordance with section 8.1 must be given to the Data Controller’s point of contact, and must:
- describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned, and the categories of and approximate number of personal data records concerned
- state the name and contact details of the data protection officer or other contact point from where more information can be obtained
- describe the likely consequences of the personal data breach; and
- describe the measures taken or proposed by the Data Controller to address the breach, including where appropriate, measures to mitigate possible adverse effects.
If necessary, information may be given in phases without any further undue delay. The Data Processor shall implement all necessary measures that may reasonably be required to rectify and avoid similar personal data breaches. As far as possible, the Data Processor must consult the Data Controller concerning the measures to be taken, including assessment of any measures proposed by the Data Controller.
The Data Controller is responsible for notifying the Data Protection Authority and the data subjects affected by the personal data breach. The Data Processor may not inform third parties of any breach of personal data security unless otherwise required under applicable law or in accordance with the express written instructions of the Data Controller.
8. USE OF SUBPROCESSOR
If a Data Processor engages a Subprocessor for carrying out specific processing activities on behalf of the Data Controller, the same data protection obligations as set out in this Data Processing Agreement shall be imposed on the Subprocessor by way of written agreement. See section 9.5 concerning the use of standard third-party services.
The Data Processor may only engage Subprocessors who provide appropriate technical and organisational measures to ensure that the processing fulfils the requirements in accordance with the Applicable Privacy Policy. The Data Processor must assess and verify that satisfactory measures have been taken by the Subprocessors. Upon request, the Data Processor must be able to submit reports from such assessments to the Data Controller.
If the Subprocessor fails to fulfil its data protection obligations, the Data Processor shall remain liable to the Data Controller for the performance of the Subprocessor’s obligations in the same way as if the Data Processor themselves was responsible for the processing.
The Data Processor is obligated, on request, to disclose agreements with Subprocessors to the Data Controller. This solely applies to the parts of the agreement that are relevant to the processing of personal data, and subject to any statutory or regulatory limitations. Commercial terms and conditions are not required to be submitted.
If the Data processor uses a subcontractor that provides standardised third-party services, the Parties may agree that the subcontractor’s standard data processing agreement will be used and applied directly to the Data Controller as in a direct data processing relationship (i.e., not as a Subprocessor) under the following terms:
- The Data Controller must expressly accept under the Service Agreement that the standardised third-party services are provided on the subcontractor’s standard terms
- The Data processor must follow up on the standard terms on behalf of the Data Controller
- The standard terms must fulfil the requirements in the Applicable Privacy Policy.
The Data Processor must follow up the data processing agreement with the subcontractor on behalf of the Data Controller, unless otherwise agreed in each individual case.
9. TRANSFER OF PERSONAL DATA TO COUNTRIES OUTSIDE THE EFA
Personal data may only be transferred to a country outside the EEA ('Third country') or to an international organisation if the Data Controller has approved such transfer in writing and the terms in section 10.3 are fulfilled. Transfer includes, but is not limited to:
- processing of personal data in data centres, etc. located in a Third Country, or by personnel located in a Third Country (by remote access)
- assigning the processing of personal data to a Subprocessor in a Third State; or
- disclosing the personal data to a Data Controller in a Third Country, or in an international organisation.
The Data Processor may nonetheless transfer personal data if this is required by applicable law in the EEA area. In such cases, the Data Processor must notify the Data Controller, to the extent permitted by law.
Transfer to Third Countries or international organisations may only take place if there are the necessary guarantees of an adequate level of data protection in accordance with the Applicable Privacy Policy. Unless otherwise agreed between the Parties, such transfer may only take place on the following grounds:
-
a decision of the European Commission concerning an adequate level of protection in accordance with Article 45 of GDPR; or
-
a Data Processing Agreement which incorporates standard personal data protection provisions as specified in Article 46 (2) (c) or (d) of the GDPR (EU model clauses); or
-
binding corporate rules in accordance with Article 47 of GDPR.
10. AUDIT
Upon request, the Data Processor shall make available to the Data controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this Data Processing Agreement.
The Data Processor shall allow and contribute to inspections and audits carried out by or on behalf of the Data Controller. The Data Processor shall also allow and contribute to inspections conducted by relevant supervisory authorities. The Data Controller's review of any Subprocessor shall be conducted by the Data Processor, unless otherwise specifically agreed.
If an audit reveals a breach in the obligations in the Applicable Privacy Policy or the Data Processing Agreement, the Data Processor must rectify the breach as soon as possible. The Data Controller may require the Data Processor to temporarily stop all or part of the processing activities until the breach has been rectified and approved by the Data Controller.
Each Party shall pay its own costs associated with an annual audit. If an audit reveals significant breaches of the obligations under the Applicable Privacy Policy or the Data Processing Agreement, the Data Processor shall pay for the Data Controller’s reasonable costs accrued from the audit.
11. DELETE AND RETURN OF INFORMATION
The Data Controller may at any point request a return and delete of all personal data processed on behalf of the Data Controller under the Data Processing Agreement by sending an inquiry to privacy@fyndreality.com
The Data Controller will determine how any return of personal data is to take place. The Data Controller may require return to take place in a structured and commonly used machine-readable format. The Data Controller will pay the Data Processor’s documented costs associated with the return unless this is included in the remuneration under the Main Agreement.
If a shared infrastructure or back-up is used and direct erasure is not technically possible, the Data Processor must ensure that the personal data is made inaccessible until it has been overwritten.
The Data Processor must confirm in writing to the Data Controller that the data has been deleted or made inaccessible, and shall, upon request document how this has taken place.
All personal data processed under this Data Processing Agreement must be deleted without undue delay and no later than within 90 calendar days of the expiry of the Main Agreement. The same applies to any other relevant information managed on behalf of the Data Controller.
12. BREACH AND SUSPENSION ORDER
In the event of breach of the Data Processing Agreement and/or Applicable Privacy Policy, the Data Controller and relevant supervisory authorities may order the Data Processor to cease all or part of the processing of the data effective immediately.
If the Data Processor fails to comply with its obligations pursuant to this Data Processing Agreement and/or Applicable Privacy Policy, this shall be deemed a breach of the Main Agreement, and the obligations, deadlines, sanctions and limitations of liability in the Main Agreement's regulation of the Supplier’s breach will be applied.
13. GOVERNING LAW AND LEGAL VENUE
The Data Processing Agreement is governed by Norwegian law. Disputes will be resolved in accordance with the provisions of the Main Agreement, including any provisions concerning legal venue.
14. DATA COLLECTED
The Data Processor does not have the right to use the personal data other than to the extent necessary to fulfil its obligations under the Data Processing Agreement and may not process this data for the Data Processor’s own purposes.
The Data Processor’s processing of personal data on behalf of the Data Controller concerns (nature of the processing):
-
For registered users: registration of names and email addresses for the delivery of the Service(s). Logging of sign-ins and interactions with the servers, like creating new sessions.
-
For all users: registration of activity upon joining network sessions, for monitoring usage.
-
When submitting a bug report, users agree to the Service(s) attaching limited device logs as underlying material for the report.
