Legal
Data Processing Agreement
Links and resources
- Terms of Service
- Privacy Policy
- Data Processing Agreement
- Contact
Content overview⌄
- About this agreement
- Definitions
- Processing instructions and use of data
- The Controller's obligations
- Assistance and customer-specific instructions
- Confidentiality and access
- Information security
- Personal data breaches
- Sub-processors
- Place of processing and transfers
- Documentation and audit
- Deletion and return
- Further development and changes to the agreement
- Suspension and termination
- Liability, governing law and dispute resolution
- Appendix 1: The processing of personal data
- Appendix 2: Technical and organisational security measures
- Appendix 3: Sub-processors
Version 1.0. Last updated: 16 September 2026
This Data Processing Agreement governs the processing of personal data that Journalia carries out on behalf of the organisation using the Service. It forms part of the Main Agreement and applies for as long as Journalia or a sub-processor processes customer data. The agreement consists of the agreement text and three appendices: Appendix 1 on the processing, Appendix 2 on technical and organisational security measures, and Appendix 3 on sub-processors. It is written in Norwegian; this is a translation. In the event of conflict between language versions, the Norwegian version prevails.
About this agreement
1.1 This data processing agreement, including its appendices (the “Data Processing Agreement”), governs the processing of personal data that Journalia AS, company registration number 933 860 078 (the “Processor”), carries out on behalf of the organisation that has entered into an agreement for use of the Service (the “Controller”). Together they are referred to as the “Parties”. 1.2 The Data Processing Agreement forms part of the Main Agreement between the Processor and the Controller and is accepted as part of it. It applies for as long as the Processor or a Sub-processor processes Customer Data on behalf of the Controller. In the event of conflict, the Data Processing Agreement and its appendices prevail over the Main Agreement on questions concerning the processing of personal data, unless a specific exception from the Data Processing Agreement has been agreed in writing between the Processor and the Controller. 1.3 This Data Processing Agreement consists of the agreement text, Appendix 1 on the processing, Appendix 2 on security measures and Appendix 3 on Sub-processors. Other product and service obligations, including those relating to medical devices and artificial intelligence, are governed by the Main Agreement or by separate agreement.
Definitions
2.1 Main Agreement: the agreement between the Processor and the Controller on access to and use of the Service, including service terms, order and any addenda. 2.2 the Service: Journalia's services and functionality covered by the Main Agreement. 2.3 Customer Data: personal data that the Processor processes on behalf of the Controller through the Service, including data entered into or generated through its use. 2.4 Sub-processor: another processor engaged by the Processor to process Customer Data on behalf of the Controller. 2.5 Applicable data protection law: Regulation (EU) 2016/679 (the “GDPR”), the Norwegian Personal Data Act and other binding data protection legislation applicable to the processing. Other data protection terms are to be understood in accordance with the GDPR.
Processing instructions and use of data
3.1 The Processor shall process Customer Data in accordance with applicable data protection law and the Controller's documented instructions. The Main Agreement, the Data Processing Agreement and the Controller's use and configuration of the Service within the agreed framework constitute such instructions. 3.2 Customer Data may be processed in order to deliver, administer, secure, quality-assure and improve the Service and to provide support, to the extent necessary for the delivery to the Controller. The processing is described in Appendix 1. The Processor may choose and further develop the technical implementation within the framework of this agreement. 3.3 As part of the delivery, the Processor may produce anonymous and aggregated statistics about the Service and use these for analysis, quality measurement, product development and reporting, including after termination. The statistics shall not render individuals identifiable by means that may reasonably be expected to be used. Such use shall respect the duty of confidentiality and agreed confidentiality obligations, and does not provide a basis for extending the retention of Customer Data. 3.4 Customer Data shall not be sold, used for marketing purposes, or used to train or fine-tune AI models. This applies equally to masked and pseudonymised Customer Data, and correspondingly at Sub-processors. Quality assurance, testing and evaluation that is necessary in order to deliver, secure and improve the Service, cf. clause 3.2, forms part of the delivery and does not constitute training within the meaning of this clause. 3.5 Journalia may process personal data as an independent controller where Journalia determines its own purposes and essential means, including in the administration of the customer relationship. Such processing is governed by Journalia's privacy policy and does not in itself give any right to use content made available by the Controller in the Service for Journalia's own purposes. 3.6 Where EU/EEA law or Norwegian law requires other processing, the Processor shall inform the Controller before the processing takes place, unless the law prohibits this. The Processor shall notify the Controller immediately if, in the Processor's assessment, an instruction infringes applicable data protection law, and may suspend implementation until the matter has been clarified.
The Controller's obligations
4.1 The Controller determines the purposes of the processing and is responsible for a valid legal basis, for providing the necessary information to data subjects and for safeguarding their rights. 4.2 The Controller shall carry out the necessary risk assessments and data protection impact assessments and ensure that its use remains within the agreed framework. 4.3 The Controller shall ensure that users are authorised, that access is properly managed and that the necessary instructions are in place. 4.4 The Controller shall keep its registered contact points up to date. Notices are sent to the registered administrator or to a separately agreed contact point. Enquiries to the Processor under this agreement are sent to hei@journalia.no or to another contact point notified in writing.
Assistance and customer-specific instructions
5.1 The Processor shall, taking into account the nature of the processing and insofar as this is possible, assist the Controller in responding to requests from data subjects under Chapter III of the GDPR. Requests received directly are forwarded without undue delay and are answered only on instruction, unless legislation requires otherwise. 5.2 The Processor shall assist in meeting the obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available. Assistance is normally provided through the functionality of the Service and available documentation, supplemented as required. 5.3 Assistance, participation in audits, specific documentation, return of data and customer-specific instructions that are not covered by the agreed fee may be invoiced on a time-spent basis at agreed rates or at the Processor's applicable hourly rates. Expected costs are notified in advance and shall be reasonable and proportionate. Work arising from the Processor's own breach is not charged to the Controller. A dispute about payment does not limit obligations imposed by law. 5.4 The Service is delivered on a standardised basis. Adaptations beyond what the Processor is obliged to deliver under this agreement or under legislation require a separate agreement on scope, price and implementation. This also applies to customer-specific requirements as to functionality and technical implementation.
Confidentiality and access
6.1 The Processor shall ensure that persons processing Customer Data are subject to a statutory or contractual duty of confidentiality and have access only to the extent necessary. The duty of confidentiality survives the end of the employment relationship and of this agreement. The same applies at Sub-processors. 6.2 Access to Customer Data in connection with support, quality assurance, error correction or security handling is limited to the necessary purpose, personnel and period, takes place within documented instructions, and is logged.
Information security
7.1 The Processor shall implement appropriate technical and organisational measures under Article 32 of the GDPR, adapted to the risk of the processing, and shall as a minimum maintain the level of security set out in Appendix 2. The Processor may change the technology and the implementation of the measures provided that the agreed level of security is maintained. The measures shall be reviewed and tested at regular intervals. 7.2 The Processor supports the Controller's compliance with the Norwegian Code of Conduct for information security and privacy in the healthcare and care services sector (“Normen”) through the measures in Appendix 2 and through available documentation.
Personal data breaches
8.1 The Processor shall notify the Controller in writing without undue delay after becoming aware of a personal data breach affecting Customer Data. 8.2 The notification shall, to the extent the information is available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or planned, and a contact point for follow-up. The information may be provided in phases without further undue delay. 8.3 The Processor shall investigate and handle the breach and assist the Controller with the information necessary for notification to the supervisory authority and to data subjects. A notification does not in itself constitute an admission of liability.
Sub-processors
9.1 The Controller gives general written authorisation for the use of Sub-processors. The list in Appendix 3 sets out the approved suppliers. 9.2 Before engaging a Sub-processor, the Processor shall assess that the Sub-processor provides sufficient guarantees and shall enter into a written agreement imposing equivalent data protection obligations. The Processor remains fully liable to the Controller for the Sub-processor's performance. 9.3 The Processor informs the Controller of intended additions to, or replacements of, Sub-processors by updating the list in Appendix 3 and by notifying the registered administrator. The Controller may raise a written objection on reasonable grounds within 30 days of the notification. Absent an objection within that period, the change is deemed approved. Where an objection is raised, the Parties shall discuss a solution in good faith. If the Processor cannot reasonably continue the delivery without the change, either Party may terminate the affected part of the Service on 30 days' notice. Changes involving a transfer outside the EEA are governed by clause 10.
Place of processing and transfers
10.1 Customer Data shall be stored and processed within the EU/EEA. Transfer to, or access from, countries outside the EEA requires the Controller's documented instruction and a valid basis under Chapter V of the GDPR. Such an instruction may be given in the Main Agreement or by electronic acceptance of a specifically described processing operation. 10.2 For instructed transfers, the Processor may rely on a relevant adequacy decision or on another valid basis, including the European Commission's standard contractual clauses. Where these are used, they shall be entered into between the relevant parties using the correct module, with completed annexes and with the necessary transfer impact assessments and supplementary measures. 10.3 The Processor makes the places of processing and the transfer bases available. If a basis ceases to apply or no longer affords sufficient protection, the Processor shall inform the Controller and suspend the transfer unless another valid basis has been established.
Documentation and audit
11.1 The Processor shall make available the information necessary to demonstrate compliance with Article 28 of the GDPR and with this agreement. Verification shall, so far as possible, be based on available security documentation, certifications and independent audit reports. 11.2 The Controller may carry out an audit itself or through an independent auditor bound by a duty of confidentiality. An audit is normally notified at least 30 days in advance and is carried out no more than once in any twelve-month period. 11.3 These limitations do not apply in the event of a security breach, a material unresolved deficiency, a requirement from a supervisory authority, or where a further audit is reasonably necessary in order for the Controller to meet its statutory control obligations. 11.4 An audit is limited to the relevant processing and is carried out without undue disruption to operations. It shall have regard to security, confidentiality and other customers' data. The Processor shall cooperate with audits and inspections and shall remedy identified deficiencies without undue delay or in accordance with a sound remediation plan. Cost recovery follows clause 5.3.
Deletion and return
12.1 Customer Data is retained and deleted in accordance with Appendix 1 and documented instructions. The Controller may use available functionality or contact the Processor for deletion and return of data. 12.2 On termination, remaining Customer Data shall, at the Controller's option, be deleted or returned. The Controller may give such an instruction until 30 days after termination (the retrieval period). If no instruction is given within that period, the data is deleted without undue delay. Previously agreed or instructed deletion periods, including for Session Data, are not extended by the retrieval period. 12.3 Return takes place in a commonly used, machine-readable format to the extent the data still exists, and is followed by deletion of remaining copies. During the retrieval period, processing is limited to storage, security, return and deletion. The data is protected in accordance with this agreement until deletion. 12.4 Backups are handled in accordance with Appendix 2. Data may continue to be retained to the extent required by EU/EEA law or Norwegian law, and shall in that case be processed only for that purpose. The Processor confirms that deletion has been carried out on request.
Further development and changes to the agreement
13.1 The Processor may update the Data Processing Agreement and its appendices. The current version is published on Journalia's website with version and date, and the registered administrator is notified of changes that are not purely editorial. Changes that weaken agreed data protection obligations or the Controller's rights take effect no earlier than 30 days after notification. 13.2 Extension beyond the agreed purposes or data categories, extension of agreed retention periods, or other changes that weaken the Controller's rights, require written agreement. This may be documented electronically, including through an authorised representative's selection or acceptance in the Service after the change has been described. Configuration within options already agreed does not require a separate amendment to the agreement. 13.3 Changes that are necessary in order to comply with binding legal requirements or orders from a competent authority may be implemented to the extent necessary on shorter notice. The Processor gives notice as early as possible and explains the basis. This does not permit other changes without the necessary agreement or instruction. 13.4 The agreement is identified by version and date. The Processor retains previous versions and documentation making it possible to establish which terms apply to the Controller. In the event of discrepancy between language versions, the Norwegian text prevails, unless the Parties have expressly agreed otherwise.
Suspension and termination
14.1 The Controller may require the affected processing to be suspended if the Processor no longer provides sufficient guarantees of compliance with applicable data protection law. If the matter cannot be, or is not, remedied within a reasonable time, the Controller may terminate the affected part of the Main Agreement. 14.2 Termination is otherwise governed by the Main Agreement. Provisions on confidentiality, deletion, documentation, audit and liability survive termination to the extent necessary for the Parties to meet their obligations under law and under this agreement.
Liability, governing law and dispute resolution
15.1 The limitations of liability in the Main Agreement also apply to claims between the Parties arising out of the Data Processing Agreement, so far as permitted under applicable data protection law. Data subjects' rights under Article 82 of the GDPR are not limited. Administrative fines are borne by the Party on which the fine is imposed. 15.2 The agreement follows the governing law and dispute resolution provisions of the Main Agreement. Where these are not regulated, Norwegian law applies, with Oslo District Court as the agreed venue.
Appendix 1: The processing of personal data
1. Purpose and processing activities The purpose is to assist the Controller with documentation, processing and compilation of information, and with the preparation and follow-up of professional and administrative work processes, including case handling, through the functionality used under the Main Agreement. The processing may include collection, receipt, transmission, storage, transcription, translation, search, analysis, structuring, generation, editing, display, sharing, export and deletion. It also includes the necessary administration, support, quality assurance, error correction, security and statistics. The actual scope follows from the Controller's use, configuration and instructions. 2. Categories of data subjects Users of the Service and persons who take part in, or are referred to in, the material being processed, including patients, service recipients, citizens, children, guardians, next of kin, employees and other affected third parties. 3. Categories of personal data The data may include identity and contact details, voice and communications, relationship, event and case data, professional assessments, and user, access and operational data relating to the processing. This covers both material supplied and data generated through the Service. The processing may include health data, data on ethnicity, religion, political affiliation, trade union membership, sex life and other special categories under Article 9 of the GDPR appearing in the material, as well as data on criminal offences under Article 10 and confidential social and welfare matters. Which data is actually processed follows from the Controller's purposes and use within this agreement. 4. Scope, duration and retention The processing takes place for as long as the Processor delivers the Service and until remaining Customer Data has been returned or deleted in accordance with clause 12 of the Data Processing Agreement. The scope is determined by the Controller's actual use. Session Data is processed in accordance with the principle of data minimisation and is deleted automatically when the agreed retention period for the function in question expires. Retention periods and the options available are set out in the service documentation, which forms part of the processing instruction. The Controller's documented configuration or a separate agreement prevails over the default settings. Changes follow clause 13 of the Data Processing Agreement. Other Customer Data is retained for as long as is necessary in order to deliver, administer and secure the functionality the Controller uses, in accordance with documented instructions. The Controller may instruct deletion during the term of the agreement. Audio is processed on an ongoing basis in order to deliver the function in question and is not stored beyond what is necessary for the processing. Backups are handled in accordance with Appendix 2. 5. Place of processing Customer Data is processed within the EU/EEA. Further details of the places of processing and of any specifically agreed transfers are set out in Appendix 3 and in instructions under clause 10.1 of the Data Processing Agreement.
Appendix 2: Technical and organisational security measures
The measures set out the agreed minimum level. The technical implementation may be changed in accordance with clause 7.1 of the Data Processing Agreement provided that this level is maintained. 1. Governance and personnel Documented procedures and allocation of responsibility for information security and privacy, with regular risk assessments and verification of compliance. Relevant personnel shall be subject to a duty of confidentiality and receive the necessary training. Suppliers are followed up on a risk basis. 2. Access management Personal user accounts, access on a need-to-know basis, and multi-factor authentication for privileged and administrative access. Access rights are reviewed regularly and removed when no longer needed. Support and administration access is limited and logged. 3. Encryption and separation Encryption in transit and at rest using recognised methods, together with access-restricted key management. Sensitive Customer Data is protected by additional encryption at application or field level. Customers' data is kept logically separated, and the production environment is separated from development and test environments. Physical security is provided by the relevant hosting and data centre suppliers. 4. Logging and monitoring Logging of relevant access, security events and system activity, with protection against unauthorised access, alteration and deletion. Logs are limited to the necessary data and retained on the basis of documented security and control needs. Monitoring and alerting shall help to detect and handle misuse and operational deviations. 5. Secure development and incident handling Procedures for change control, testing, updating and risk-based handling of vulnerabilities. Security measures are tested and assessed at regular intervals. Customer Data that is not session data may be used in development or test environments to the extent necessary for the activities covered by clause 3.2 of the Data Processing Agreement, or where this follows from a separate documented instruction. Such use is limited to the necessary data, personnel and period, is given protection equivalent to that in production, and is logged. 6. Availability, backup and deletion Measures for capacity, continuity and recovery are adapted to the risk of the processing and to the agreed service level. Recovery capability is tested at regular intervals. Backups are stored encrypted within the EU/EEA with restricted access and are used only for necessary recovery or for testing recovery capability. Backups of Session Data follow the applicable retention period for such data. Other backups are deleted through a rolling overwrite cycle of up to 365 days. Data deleted from active systems is not returned to ordinary use upon recovery. Necessary deletions are carried out again before ordinary processing resumes. Deletion procedures shall cover relevant systems and Sub-processors.
Appendix 3: Sub-processors
Journalia's list of Sub-processors is made available at any time on request by contacting hei@journalia.no.