MARKVISS
Features Solutions Guide Pricing
  • English
  • Norsk
  • Dansk
  • Svenska
Log in Start free

DATA PROCESSING AGREEMENT

Markviss AS
Organization number: 917 324 689

Effective Date: 08.09.2026
Last Updated: 08.09.2026


This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the Markviss Terms of Service (the “Agreement”) between Markviss AS (“Markviss,” “we,” “us”) and the customer that has entered into the Agreement (the “Customer”). It applies whenever Markviss processes personal data on the Customer’s behalf in the course of providing the SaaS Services.

No separate signature is required: by accepting the Agreement, the Customer accepts this DPA. A Customer that requires a signed counterpart on its own paper may request one at info@markviss.com.

This DPA governs personal data that Markviss processes as a processor, on the Customer’s instructions. Personal data that Markviss processes as a controller in its own right — visitors to markviss.com, prospects, billing contacts, and its own marketing — is described in the Privacy Policy instead.

1. Definitions

Terms defined in the Agreement have the same meaning here. In addition:

  1. “GDPR” means Regulation (EU) 2016/679, as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven).
  2. “Customer Personal Data” means personal data contained in Customer Data that Markviss processes on the Customer’s behalf under the Agreement.
  3. “Sub-Processor” means a third party engaged by Markviss to process Customer Personal Data.
  4. “Controller,” “Processor,” “Data Subject,” “Processing,” “Personal Data Breach” and “Supervisory Authority” have the meanings given in Article 4 of the GDPR.

2. Roles and Scope

The Customer is the Controller of Customer Personal Data and Markviss is the Processor. Where the Customer is itself a processor acting for a third-party controller, Markviss is a sub-processor and the Customer warrants that it has the authority to enter into this DPA on that controller’s behalf.

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1, as required by GDPR Article 28(3).

Each party shall comply with its own obligations under applicable data protection law. The Customer is responsible for the lawfulness of the Customer Personal Data it makes available to Markviss, including having a valid legal basis and providing any required information to data subjects.

3. Processing on Documented Instructions

Markviss shall process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which Markviss is subject. Where such a legal requirement applies, Markviss shall inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest.

The Agreement, this DPA, and the Customer’s use of the features and configuration options of the Services constitute the Customer’s complete documented instructions. Additional instructions outside that scope require written agreement and may be subject to a fee.

Markviss shall inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

Markviss shall not sell Customer Personal Data, and shall not use it to train, fine-tune or improve any machine-learning model.

4. Confidentiality

Markviss shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those personnel who need it in order to perform the Agreement. Confidentiality obligations survive the end of a person’s engagement with Markviss.

5. Security

Markviss shall implement and maintain the technical and organisational measures set out in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by GDPR Article 32.

Markviss may update these measures from time to time provided that the level of protection is not reduced. The measures in force at any time are those published in Annex 2 of this page.

6. Sub-Processors

The Customer grants Markviss general written authorisation to engage Sub-Processors, subject to this Section.

  1. The current list of Sub-Processors is published at markviss.com/sub-processors and forms Annex 3 to this DPA.
  2. Markviss shall notify the Customer of any intended addition or replacement of a Sub-Processor before that Sub-Processor begins processing Customer Personal Data. Customers may ask to be added to the notification list at info@markviss.com.
  3. The Customer may object to a new Sub-Processor on reasonable data protection grounds within fourteen (14) days of notification. The parties shall discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the Agreement in respect of the affected Services without penalty, as provided in Section 10.5 of the Terms of Service.
  4. Markviss shall impose on each Sub-Processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each Sub-Processor’s obligations.

7. Assistance with Data Subject Rights

The Services allow the Customer to access, correct, export and delete Customer Personal Data directly. To the extent the Customer cannot do so through the Services, Markviss shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests under Chapter III of the GDPR.

If Markviss receives a request directly from a data subject relating to Customer Personal Data, it shall not respond to the substance of the request, and shall forward it to the Customer without undue delay.

8. Personal Data Breach

Markviss shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, to the extent that information is available at the time.

Markviss shall assist the Customer in meeting its own obligations under GDPR Articles 33 and 34. Notification of a breach is not an acknowledgement of fault or liability.

9. Data Protection Impact Assessments

Taking into account the nature of the processing and the information available to it, Markviss shall provide reasonable assistance to the Customer with data protection impact assessments and with prior consultation of a Supervisory Authority under GDPR Articles 35 and 36.

10. Deletion and Return

On termination or expiry of the Agreement, Markviss shall, at the Customer’s choice, delete or return Customer Personal Data.

  1. Customer Personal Data remains available for export through the Services for thirty (30) days after termination.
  2. Markviss shall delete Customer Personal Data from its production systems no later than twelve (12) months after termination, in line with the retention schedule in the Privacy Policy. The Customer may request earlier deletion in writing.
  3. Residual copies in routine backups are deleted on the ordinary backup rotation described in Annex 2, and remain protected by this DPA until they are.
  4. Markviss may retain Customer Personal Data to the extent required by Union or Member State law, for the period required by that law, and shall continue to protect it in accordance with this DPA.

11. Information and Audit

Markviss shall make available to the Customer all information necessary to demonstrate compliance with GDPR Article 28, and shall allow for and contribute to audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer.

  1. In the first instance, Markviss shall respond to reasonable written questions and security questionnaires, and provide any then-current third-party certifications or reports held by Markviss or its Sub-Processors.
  2. Where that is not sufficient to demonstrate compliance, the Customer may conduct an on-site audit no more than once in any twelve (12) month period, on thirty (30) days’ written notice, during business hours, subject to confidentiality undertakings, and in a manner that does not disrupt the Services or affect the data of other customers. A Supervisory Authority may audit at any time as required by law.
  3. The Customer bears its own costs and Markviss’s reasonable costs of an on-site audit, except where the audit reveals a material breach of this DPA by Markviss.

12. International Transfers

Customer Personal Data is stored and processed within the European Economic Area. Markviss shall not transfer Customer Personal Data outside the EEA except where an appropriate safeguard under Chapter V of the GDPR is in place, such as an adequacy decision or the EU Standard Contractual Clauses, together with any supplementary measures required following a transfer impact assessment.

The location of processing for each Sub-Processor is stated at markviss.com/sub-processors. Where a Sub-Processor is established outside the EEA, the transfer mechanism relied upon is stated there.

13. Liability and Term

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law, including a data subject’s rights under GDPR Article 82.

This DPA takes effect when the Customer accepts the Agreement and continues for as long as Markviss processes Customer Personal Data. Sections 4, 10, 12 and 13 survive termination.

In the event of a conflict between this DPA and the Agreement in respect of the processing of personal data, this DPA prevails.

14. Changes to This DPA

Markviss may update this DPA to reflect changes in law, in the Services, or in its Sub-Processors. Material changes will be communicated to the Customer at least thirty (30) days in advance, in accordance with Section 12.5 of the Terms of Service. Changes to the Sub-Processor list follow the notice and objection process in Section 6 instead.

15. Governing Law

This DPA is governed by the laws of Norway, and disputes are subject to the jurisdiction of the courts of Oslo, Norway, in accordance with Sections 12.1 and 12.2 of the Terms of Service.

16. Contact

For any matter arising under this DPA, including data subject requests, security questions and audit requests:

Markviss AS
Tanumveien 272, 1339 Vøyenenga, Norway
Email: info@markviss.com
Phone: +47 45207543

Markviss has not appointed a Data Protection Officer, as it is not required to do so under GDPR Article 37. Enquiries are handled at the address above.

17. Governing Language

This DPA is published in English, Norwegian, Swedish and Danish. The English version is the authoritative text. In the event of any discrepancy, ambiguity or conflict between the English version and any translation, the English version prevails.


Annex 1 — Details of the Processing

Subject matter

Provision of the Markviss goal, metric and planning platform as described in the Agreement.

Duration

The term of the Agreement, plus the deletion period set out in Section 10.

Nature and purpose of the processing

  1. Hosting and storage of Customer Data.
  2. Creating and administering user accounts, authentication and access control.
  3. Calculating metrics, KPIs, formulas and scenarios from data the Customer enters, uploads or imports.
  4. Importing data from source systems the Customer chooses to connect, on the Customer’s instruction.
  5. Generating responses in the AI assistant in reply to a user’s prompt, and proposing column mappings for uploaded files.
  6. Sending service and account notifications, and providing customer support.
  7. Maintaining security, availability, backups and audit logs.

Categories of data subjects

  1. The Customer’s authorised users — employees, officers, contractors and other individuals to whom the Customer grants access.
  2. Individuals whose personal data appears in data the Customer enters, uploads or imports — which may include the Customer’s own employees, customers, suppliers and business contacts.

Categories of personal data

  1. Identification and contact data: name, email address, telephone number, employer or company name, job role.
  2. Account data: user identifier, profile settings, language, permissions and role assignments, subscription and seat information.
  3. Authentication data: hashed passwords, session tokens, API keys, and access tokens for source systems the Customer connects.
  4. Usage and technical data: IP address, browser and device type, access times, pages viewed, and actions taken in the application.
  5. Content submitted by users: metric and category names, comments, notes, goal descriptions, AI assistant prompts and conversation history, uploaded spreadsheets, and records imported from connected source systems — any of which may contain personal data chosen by the Customer.

Special categories of personal data

None. The Services are not designed for special categories of personal data within the meaning of GDPR Article 9, or for personal data relating to criminal convictions and offences under Article 10, and the Customer shall not submit such data to the Services.

Frequency of the processing

Continuous, for the duration of the Agreement.

Annex 2 — Technical and Organisational Measures

The following measures are in place as at the Last Updated date above. They are described at a level of detail that is meaningful without itself creating a security risk; further detail is available under a confidentiality undertaking as part of the process in Section 11.

Encryption

  1. Traffic between users and the Services, and between Markviss components and Sub-Processors, is encrypted in transit using TLS.
  2. Databases and the connection and task stores are encrypted at rest using keys managed by AWS Key Management Service.
  3. Passwords are stored as salted hashes, never in plain text.

Access control and tenant separation

  1. Each customer account’s business data is held in a separate database, addressed through a per-account connection; application requests are scoped to the account of the authenticated user.
  2. Application access is authenticated with signed, expiring tokens and authorised by role, with a default-deny model for privileged operations.
  3. Programmatic access uses scoped API keys that can be revoked individually.
  4. Administrative access to production infrastructure is restricted to named personnel, requires individual credentials, and is limited by network-level allow-listing.

Secrets and credential handling

  1. Application secrets, and the access tokens for source systems the Customer connects, are held in AWS Secrets Manager rather than in application code or configuration files.
  2. Connector credentials are entered by the Customer and are never displayed back in full.

Hosting and physical security

  1. The Services are hosted on Amazon Web Services in the Stockholm region (eu-north-1), within the EEA. Physical and environmental security of the data centres is provided by AWS under its own certifications.
  2. Network access to database instances is restricted by security group rules that permit only known application components and explicitly allow-listed administrative addresses.

Resilience and backup

  1. Automated daily database backups retained for 30 days, with point-in-time recovery to any moment within that window.
  2. Infrastructure is defined as code, so environments can be rebuilt deterministically.

Logging and monitoring

  1. Application and infrastructure logs are collected centrally, with alerting on error conditions and on anomalous cost or usage.
  2. Administrative and authentication events are logged.

Organisational measures

  1. Personnel are bound by written confidentiality obligations and receive data protection and security guidance.
  2. Access rights are granted on a need-to-know basis and removed when an engagement ends.
  3. Changes to production code are reviewed before release and deployed through an automated pipeline.
  4. Sub-Processors are assessed before engagement and bound by written data protection terms.

Annex 3 — Sub-Processors

The current list of Sub-Processors, with the purpose of each engagement, the categories of personal data involved and the location of processing, is published at markviss.com/sub-processors and forms part of this DPA.


Last updated: 08.09.2026

MARKVISS
Contact Partner with us Implication Intelligence Privacy Terms DPA Cookie settings

© 2016–2026 Markviss · A Norwegian company · Your data stays in the EU · No cookies without your consent.