1. Parties, formation and roles
This DPA is between the Customer named in an Order and Preferium AS, Norwegian org. no. 999 323 286. It becomes binding through a signed Order, separate signature or Dashboard acceptance by an authorised representative with version evidence. A website visitor does not enter it merely by browsing.
Customer may be (a) Controller, with Preferium as Processor, or (b) Processor for an End Controller, with Preferium as Subprocessor. In (b), Customer warrants prior written authority for Preferium and further subprocessors and lawful flow-down instructions. Preferium is independent Controller for account, billing, security, compliance and its own business purposes under the Privacy Notice.
2. Scope and instructions
Preferium processes Personal Data only to provide, secure, troubleshoot, support and terminate the Services under the Order, Terms, configuration and other documented instructions. No Customer Personal Data is used for our own advertising or general-model training for other customers.
Consulting and IT support apply only where a separate IT-support engagement has been agreed. Access must be necessary for the documented support case, time-limited where practicable and logged under the applicable security procedures.
Preferium immediately informs Customer if an instruction appears to violate data-protection law and may suspend only that processing pending resolution. Legally required processing outside instructions is notified beforehand where permitted.
3. Processing description
| Field | AI Edge / Dashboard |
|---|---|
| Subject | Server-side analysis, generation, publishing, delivery, measurement, security and administration of websites/workspaces |
| Duration | Agreement, any expressly applicable Frozen Delivery, transition/export and deletion |
| Operations | Collection, organisation, storage, retrieval, analysis, generation, alteration, transmission, display, restriction, export, deletion |
| Purpose | Configured SEO/AI features, integrations, support, security, accountability |
| Data subjects | Customer users/representatives; site visitors; people in public Customer content; agency End Customers |
| Data | Account/role; IP/user agent/URL/referrer/logs; public HTML/content; configuration/change history; keyword/citation/measurement; encrypted OAuth tokens/selected Google data; support content |
| Frequency | Continuous during active Edge delivery and upon user actions, scheduled jobs and integrations |
| Sensitive data | Not expected/permitted without prior written agreement, assessment and safeguards |
| Locations | Public Subprocessor Register; may be global/outside EEA |
Customer determines purpose, lawful basis, data subjects, allowed content, controls, retention and lawful instructions.
4. Confidentiality and personnel
Preferium limits access by need, binds authorised persons to confidentiality and provides relevant privacy/security instruction. Access is removed or changed when no longer needed.
5. Technical and organisational measures
Risk-based measures include TLS in transit and provider-supported encryption at rest; encrypted third-party token/secret handling; role/tenant access, least privilege and supported MFA; environment separation, secure development and patching; minimised security/error/audit logging; backup/recovery under documented architecture; incident response/provider review; supported continuity/fail-safe controls; and retention/deletion jobs with operational verification.
Preferium does not promise ISO 27001, SOC 2, annual external penetration tests, three independent backup systems or any control not expressly verified. Measures may evolve without materially reducing overall security; material reduction is notified.
6. Further subprocessors
Customer generally authorises the public Subprocessor Register, incorporated here. Preferium imposes equivalent obligations and remains responsible as Article 28(4) requires. New/replacement providers receive 30 days’ notice and a 14-day reasoned objection window. We seek an alternative; if none exists, Customer may terminate the affected Service before change and receive unused prepaid fees. Emergency security/continuity/legal changes are notified without undue delay.
7. Restricted transfers
No restricted transfer occurs without a valid mechanism. Where adequacy/current verified DPF does not apply, the parties use the applicable completed EU SCC module and annexes plus transfer assessment; UK transfers use the UK Addendum or IDTA and necessary UK assessment. Customer authorises Module 2 when Controller and Module 3 when Processor. Applicable non-sensitive safeguards are available on request. This clause does not replace execution of the instrument.
8. Assistance
Considering processing nature and available information, Preferium reasonably assists with rights requests, security, DPIAs, prior consultation and regulators. Requests are normally routed through Customer. Customer identifies the workspace, End Customer and Controller. Extraordinary work may be charged if not caused by Preferium breach, but mandatory minimum assistance is not withheld for non-payment.
9. Personal Data Breach
Preferium notifies Customer without undue delay after awareness and aims for a preliminary notice within 24 hours where possible. Information is provided in stages and includes known event, affected data/people, likely consequences, measures and contact. We document/cooperate; Customer makes its own notifications unless law/role requires otherwise. Notice is not admission.
10. Audit and evidence
Preferium provides necessary information and contributes to Article 28 audits. Routine audit defaults: once annually, 30 days’ notice, remote-first, no access to other customers, source code or exploitable details. Suitable independent reports may satisfy covered controls/periods.
Limits do not apply to a competent authority/legal requirement, relevant breach or credible material noncompliance. Audits remain proportionate, confidential and minimally disruptive. Customer pays ordinary cost; Preferium pays reasonable cost if material noncompliance is confirmed.
11. Exit, Frozen Delivery, export and deletion
Customer selects return/export and deletion under the Terms. Active optimisation, Frozen Delivery, account access and stored Personal Data are distinct. Cancellation of the subscription alone does not end this DPA while Preferium continues to process Personal Data for expressly agreed Frozen Delivery, transition or deletion. Frozen Delivery remains a limited Service/processor relationship only if expressly selected or earned and includes only data needed to serve the last approved configuration, security and uptime. Customer may expressly request technical disconnection, export and deletion at any time.
Export remains available during transition and at least 30 days after. Production data is deleted/anonymised under the agreed process. A fixed 30-day deletion commitment is confirmed only when the operational mechanism is verified; if an agreed deadline cannot be met, data is restricted, Customer notified and correction prioritised. Backups expire by rotation; legal/claim evidence is isolated. Written deletion confirmation is available.
12. California addendum
When Preferium is a CCPA/CPRA service provider/contractor, it processes only for limited defined business purposes; does not sell/share; does not use outside the direct business relationship or for incompatible commercial purposes; does not combine except where permitted; and flows equivalent duties. We notify inability to comply. Customer may monitor and require unlawful processing to stop/remediate. Terms follow Cal. Civ. Code §§ 1798.100 and 1798.140 where applicable.
13. Liability and law
The Core Terms’ liability allocation applies between the parties without restricting regulators, data-subject rights, non-limitable liability or external Article 82 allocation. The DPA follows the Core Terms’ law/venue and prevails for Personal Data conflict. Norwegian/English versions have the same substantive version; accepted contract language is recorded.
14. Contact and acceptance record
Preferium AS · org. no. 999 323 286 · Sponheimveien 19, 1613 Fredrikstad, Norway · post@preferium.no.
The Order/signature/acceptance record must identify Customer legal name/number/address/contact, role (Controller/Processor), relevant End Controllers, version, actor, authority confirmation and timestamp.