Legal Document
Data Processing Agreement
How Catenda processes personal data as your processor under GDPR Article 28, including security measures, sub-processors, and breach procedures.
Version 1.1 — September 2026
Parties
This Data Processing Agreement ("DPA") is entered into between:
- The customer identified in the applicable Order Form (the "Controller"), and
- Catenda AS, organisation number 994 023 977, Drammensveien 288, 0283 Oslo, Norway (the "Processor" or "Catenda").
The Controller and Catenda are individually a "Party" and collectively the "Parties". An Order Form may name a different Catenda group entity as the contracting party, in which case the substitutions in that Order Form apply.
1. Purpose and scope
This DPA supplements and is incorporated into the Master Subscription Agreement (the "MSA") between the Parties. It governs the processing of Personal Data by Catenda on behalf of the Controller in connection with the Subscription Service.
This DPA satisfies the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection (FADP), and the Japanese Act on the Protection of Personal Information (the "APPI") where applicable.
Where this DPA conflicts with the MSA in respect of the processing of Personal Data, this DPA prevails.
This DPA does not apply to anonymized data. Where Catenda anonymizes Personal Data under MSA §7.2 — including content uploaded to or created in the Subscription Service, and data about how the Subscription Service is used — to develop and improve the Subscription Service, produce statistical analyses and benchmark studies, or train and improve artificial intelligence and machine-learning models, the resulting data is no longer Personal Data under the GDPR, the UK GDPR, the FADP, or the APPI, and falls outside the scope of this DPA.
2. Definitions
Personal Data, Data Subject, Processing, and Personal Data Breach have the meanings given in GDPR Articles 4 and 33. In addition:
- Sub-processor means a third party engaged by Catenda to process Personal Data on its behalf.
- Standard Contractual Clauses or SCCs means the EU Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914.
3. Subject matter and details of processing
| Aspect | Description |
|---|---|
| Nature and purpose | Providing the Subscription Service per the MSA — hosting, storage, retrieval, support, and incidental analytics for service operation and security. Excludes any processing of anonymized data under MSA §7.2, which falls outside this DPA per §1. |
| Categories of Data Subjects | Controller's employees, contractors, consultants, Registered Users, project participants, and any other individuals whose Personal Data the Controller uploads. |
| Categories of Personal Data | Identification (name, email, user ID, job title, phone, company); authentication and access data; user-generated content and activity logs; project metadata; any Personal Data in files uploaded by the Controller's users. |
| Special categories | Not solicited. The Controller is responsible for any lawful basis if it uploads data covered by GDPR Articles 9 or 10. |
| Duration | MSA term plus a 90-day data export window after termination (per MSA §6.6 and §8.4). |
4. Catenda's obligations as Processor
Catenda will:
- (a) Process on documented instructions. Process Personal Data only on the Controller's documented instructions, unless required to do otherwise by EU, Member State, or other applicable law. Catenda will inform the Controller of any such legal requirement before processing, unless prohibited by law.
- (b) Confidentiality. Ensure that persons authorised to process Personal Data are bound by confidentiality.
- (c) Security. Implement appropriate technical and organisational measures consistent with GDPR Article 32 and the measures in Annex A.
- (d) Sub-processors. Engage Sub-processors only in accordance with §7.
- (e) Data Subject rights. Assist the Controller in responding to Data Subject requests under GDPR Chapter III, using appropriate technical and organisational measures.
- (f) Assistance with Controller obligations. Assist the Controller with its obligations under GDPR Articles 32 to 36, including the breach notification process in §6.
- (g) Return or deletion. Return or delete Personal Data on termination as set out in §8.
- (h) Records of processing. Maintain a record of processing activities, as required by GDPR Article 30(2).
- (i) Audits. Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and allow for audits per §10.
- (j) Notify of conflicting instructions. Notify the Controller if Catenda considers that an instruction infringes the GDPR or other applicable data-protection law.
5. Controller's obligations
The Controller:
- Confirms it is the data controller of the Personal Data processed under this DPA and has a lawful basis for the processing.
- Is responsible for the accuracy, quality, and legality of Personal Data uploaded to the Subscription Service.
- Is responsible for ensuring it has obtained any necessary consents or other lawful bases from Data Subjects before processing.
- Is responsible for responding to Data Subject requests and for notifying supervisory authorities of Personal Data Breaches where required.
6. Personal Data Breaches
Catenda will notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a confirmed Personal Data Breach affecting Personal Data processed on the Controller's behalf.
The notification will include, to the extent then known:
- The nature of the breach, the categories and approximate number of Data Subjects affected, and the categories and approximate number of Personal Data records concerned
- The likely consequences of the breach
- The measures Catenda has taken or proposes to take to address the breach, including measures to mitigate its possible adverse effects
- The contact point at Catenda for further information
Catenda will provide updates as additional information becomes available and will cooperate with the Controller's efforts to investigate, mitigate, and notify (where required) the breach to supervisory authorities and Data Subjects under GDPR Articles 33 and 34.
Notification of a Personal Data Breach is not an acknowledgement of fault or liability.
7. Sub-processors
7.1 General authorisation. The Controller grants Catenda general written authorisation to engage Sub-processors to process Personal Data. The current list of Sub-processors is set out in Annex B to this DPA.
7.2 New Sub-processors. Before engaging a new Sub-processor, Catenda will give the Controller at least 30 days' prior written notice by email to the contact specified in the Order Form, and will publish an updated version of this DPA reflecting the change (including an updated Annex B) at catenda.com/legal/dpa. The Controller may object on documented data-protection grounds within 14 days of notice. If the Parties cannot resolve the objection in good faith within a further 30 days, the Controller may terminate the affected Subscription Service component.
7.3 Sub-processor obligations. Catenda will require each Sub-processor in writing to provide protections substantially equivalent to those in this DPA. Catenda remains fully liable to the Controller for the performance of each Sub-processor.
8. Return or deletion on termination
On termination or expiry of the MSA, the Controller may export Personal Data using the self-service export functions of the Subscription Service for 90 days, per MSA §6.6.
At the Controller's written request made during that 90-day window, Catenda will either (a) return all Personal Data in a structured, commonly used, machine-readable format, or (b) certify its deletion. Absent a request, Catenda may delete the Personal Data after the 90-day window.
Where applicable law requires retention, Catenda will retain only what is required and only for as long as required; the DPA's obligations continue to apply to that retained data.
9. International data transfers
Personal Data is stored on Amazon Web Services infrastructure within the European Economic Area (default: AWS eu-west-1, Ireland). Catenda may deploy customer data in another EU region on request. Where Catenda Japan KK processes Japan-originating Personal Data, transfers to Catenda AS (Norway) rely on APPI Article 28 and Catenda's internal binding rules.
Where Catenda or a Sub-processor processes Personal Data outside the EEA, the UK, or Switzerland to a jurisdiction not covered by an adequacy decision, the Parties rely on:
- The EU Standard Contractual Clauses, Module 2 (Controller to Processor) or Module 3 (Processor to Sub-processor) as applicable
- The UK International Data Transfer Addendum, where UK personal data is transferred
- The Swiss FDPIC-approved clauses, where Swiss personal data is transferred
The SCCs are incorporated by reference and, on the Controller's written request, Catenda will provide an executed copy. Catenda undertakes a transfer impact assessment before any new onward transfer and applies appropriate supplementary measures where required.
10. Audit rights
The Controller may, on at least 30 days' prior written notice, audit Catenda's compliance with this DPA — no more than once per 12 months, during normal business hours, under written confidentiality terms, and at the Controller's cost. Catenda may satisfy an audit request by providing a current ISO 27001 certificate or equivalent third-party attestation, where the report covers the scope of the audit request.
Audits in response to a Personal Data Breach affecting the Controller's data are not subject to the once-per-12-months limit.
11. Liability
The liability provisions of MSA §10 apply to claims under this DPA. Nothing in this DPA increases or decreases the liability cap in the MSA, except as required by applicable law.
12. Governing law
This DPA is governed by the laws of Norway, and disputes are subject to the exclusive jurisdiction of Oslo tingrett (Oslo District Court). The applicable Order Form may specify a different governing law and venue where the contracting Catenda entity so requires, consistent with the MSA.
13. Term
This DPA takes effect on the effective date of the MSA and continues for as long as Catenda processes Personal Data on behalf of the Controller. Provisions intended to survive termination — including confidentiality, security incidents pre-dating termination, audits, and return/deletion — continue in force after termination.
Annex A — Technical and organisational measures
Catenda applies the following security measures to Personal Data processed under this DPA, and reviews and updates them at least annually.
A.1 Encryption
- Data in transit: TLS 1.2 or higher
- Data at rest: AES-256 encryption
A.2 Access control
- Role-based access controls (RBAC) limiting access to authorised personnel
- Multi-factor authentication for administrative and privileged access
- Access reviewed quarterly; revoked promptly on role change or termination
A.3 Logging and monitoring
- All access to Personal Data is logged
- Logs retained for at least 12 months
- Automated alerts on anomalous access patterns
A.4 Security testing
- Periodic penetration testing by independent security firms
- Remediation of critical vulnerabilities within 30 days
A.5 Data backup and recovery
- Daily backups to geographically redundant locations within the EEA, encrypted to the same standard as production data
- Recovery procedures tested at least twice per year; documented RTO and RPO targets
A.6 Personnel
- Annual mandatory data-protection and information-security training
- Confidentiality agreements with all personnel
- Background checks for personnel with privileged access
A.7 Physical and infrastructure security
Data centres are provided by Amazon Web Services in the EEA, with restricted physical access, surveillance, environmental controls, firewalls, intrusion detection, DDoS mitigation, and network segmentation.
A.8 Incident response
- Documented incident response plan, tested at least annually
- Internal incident escalation per documented procedure
- Post-incident reviews for material incidents
A.9 Certifications
Catenda holds ISO 27001 certification. Current certificates and audit summaries are available to customers on request and under NDA.
A.10 Sub-processor security
Sub-processors are required by contract to maintain security measures substantially equivalent to those in this Annex A.
Annex B — Sub-processors
This Annex B is Catenda's current list of Sub-processors, updated as set out in §7.2 — any change is reflected here and republished as a new version of this DPA at catenda.com/legal/dpa. As of the effective date of this version of the DPA, Catenda's primary Sub-processors are:
| Sub-processor | Service and purpose | Data location |
|---|---|---|
| Amazon Web Services EMEA SARL | Cloud hosting of the Subscription Service | EU (default: eu-west-1, Ireland) |
| Google LLC | Product analytics (Google Analytics, BigQuery) | EU |
| HubSpot Inc. | CRM and sales | US (SCCs apply) |
| Intercom Inc. | Support and in-app messaging | US (SCCs apply) |
| LinkedIn Corp. | Marketing | US (SCCs apply) |
| Amplitude | Product analytics | EU |
Annex C — Contacts
Catenda data-protection and security incident contact: compliance@catenda.com. Catenda legal: post@catenda.com. Norwegian supervisory authority: Datatilsynet — datatilsynet.no.