Data Processing Agreement

Last updated: 2 May 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Stack Seven AS, Terrasseveien 31 E, 1363 Høvik, Norway, company registration number 938 211 795 ("Stack Seven", "Processor") and the customer ("Customer", "Controller") and applies whenever the Customer uses Policy Confirm to process personal data.

This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and other applicable data protection laws.

In the event of conflict between this DPA and the Terms of Service in matters relating to processing of personal data, this DPA prevails.

1. Roles

The Customer is the data controller and Stack Seven is the data processor with respect to personal data processed through Policy Confirm.

2. Subject matter and duration

Subject matter. Provision of Policy Confirm: a software-as-a-service platform enabling the Customer to distribute internal policies, collect explicit acknowledgements, and generate audit-ready proof documentation.

Duration. This DPA applies for the duration of the Customer's subscription and any subsequent period during which Stack Seven processes personal data on behalf of the Customer.

Nature and purpose of processing. Hosting, storage, transmission, and processing of personal data necessary to deliver Policy Confirm, including distribution of policy acknowledgement requests, recording of confirmations, and generation of proof documentation.

Categories of data subjects. The Customer's employees, contractors, board members, administrators, and other individuals invited to acknowledge policies through Policy Confirm.

Categories of personal data. Identity data (name), contact data (email address), organizational affiliation, acknowledgement records, activity timestamps, and limited technical metadata (IP address and browser information) collected at the moment of confirmation.

3. Processor obligations

Stack Seven shall:

  • Process personal data only on documented instructions from the Customer, as set out in the Terms of Service, this DPA, and the Customer's configuration of Policy Confirm. Such instructions include the operation, security, abuse prevention, troubleshooting, and maintenance of Policy Confirm
  • Ensure that persons authorized to process personal data are bound by confidentiality obligations that continue beyond the termination of their engagement
  • Implement the technical and organizational measures set out in Section 7
  • Engage sub-processors only in accordance with Section 4
  • Assist the Customer, taking into account the nature of processing, in fulfilling the Customer's obligation to respond to data subject requests under Chapter III of the GDPR
  • Assist the Customer in ensuring compliance with Articles 32 to 36 of the GDPR
  • Make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR
  • Inform the Customer if, in Stack Seven's opinion, an instruction infringes the GDPR or other applicable data protection law

4. Sub-processors

The Customer authorizes Stack Seven to engage sub-processors to deliver Policy Confirm, subject to the conditions in this Section.

The current list of sub-processors, including processing locations and applicable transfer mechanisms, is published at policyconfirm.com/legal/subprocessors and forms part of this DPA.

Stack Seven shall:

  • Ensure that each sub-processor is subject to data protection obligations that meet the requirements of Article 28(4) of the GDPR
  • Remain responsible to the Customer for the performance of the sub-processor's obligations
  • Provide reasonable advance notice of any addition or replacement of sub-processors

If the Customer objects to a new sub-processor on reasonable data protection grounds and the parties cannot agree on a resolution, the Customer may terminate the affected service in accordance with the Terms of Service.

5. International transfers

Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom to a country that does not benefit from an adequacy decision, Stack Seven shall ensure that an appropriate transfer mechanism is in place. Such mechanisms include the EU Standard Contractual Clauses, the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, or other lawful transfer mechanisms recognized under applicable data protection law.

The transfer mechanisms applicable to each sub-processor are identified at policyconfirm.com/legal/subprocessors.

6. Personal data breaches

Stack Seven shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA.

The notification shall include, to the extent the information is available:

  • The nature of the breach, including the categories and approximate number of data subjects and records concerned
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach
  • Contact details for further information

Stack Seven shall cooperate with the Customer and provide reasonable assistance to enable the Customer to comply with its notification obligations under Articles 33 and 34 of the GDPR.

7. Technical and organizational measures

Stack Seven implements technical and organizational measures to protect personal data in accordance with Article 32 of the GDPR.

Access to personal data is restricted through role-based access control and multi-factor authentication for administrators. Recipients authenticate through magic-link mechanisms. All personnel with access to personal data are subject to confidentiality obligations.

Personal data is encrypted in transit and at rest using industry-standard mechanisms. Confirmation records are stored as immutable entries, and administrative actions are logged in audit trails. Regular backups are maintained.

Stack Seven follows secure development practices, including code review and dependency monitoring, and maintains a documented incident response process. Sub-processors are subject to data protection obligations consistent with this DPA.

These measures may be updated from time to time, provided the level of protection is not materially diminished.

8. Audit rights

Stack Seven shall make available to the Customer the information necessary to demonstrate compliance with this DPA.

On reasonable prior written notice, the Customer (or an independent auditor mandated by the Customer and reasonably acceptable to Stack Seven) may conduct an audit of Stack Seven's processing activities under this DPA, no more than once per calendar year, except where required by applicable law or triggered by a confirmed personal data breach.

Stack Seven may satisfy its obligations under this Section by providing current third-party audit reports, certifications, or comparable documentation, where reasonably available.

9. Data subject rights

Taking into account the nature of the processing, Stack Seven shall assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests for the exercise of data subject rights under Chapter III of the GDPR.

Where Stack Seven receives a request directly from a data subject in relation to personal data processed on behalf of the Customer, Stack Seven shall promptly forward the request to the Customer and shall not respond to the request directly unless authorized by the Customer.

10. Return or deletion of personal data

Prior to termination or expiry of the Customer's subscription, the Customer may export confirmation records and proof documentation from Policy Confirm using the available CSV and PDF export functionality.

Following termination, the Customer may instruct Stack Seven to either return or delete all personal data processed on behalf of the Customer. In the absence of such instruction within thirty (30) days of termination, Stack Seven shall delete the personal data within ninety (90) days thereafter.

Retention beyond this period is permitted only where required by applicable law or based on documented instructions from the Customer, including where necessary to support audit, compliance, or contractual obligations. Personal data may persist in backup systems for a limited period in accordance with backup retention practices, after which it is deleted.

11. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except to the extent such limitations or exclusions are prohibited by applicable data protection law.

12. Term and termination

This DPA takes effect when the Customer accepts the Terms of Service and remains in force for the duration of the Customer's subscription and any subsequent period during which Stack Seven processes personal data on behalf of the Customer.

Termination of the Terms of Service automatically terminates this DPA, subject to the obligations that by their nature survive termination, including Sections 7, 10, and 11.

13. Governing law

This DPA is governed by Norwegian law. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Norway, with Oslo District Court as agreed venue, unless mandatory law of the Customer's jurisdiction provides otherwise.

14. Contact

For matters relating to this DPA, please contact:

Stack Seven AS
Terrasseveien 31 E
1363 Høvik
Norway

Email: contact@policyconfirm.com