Template — customer fills in name, address, effective date, and counter-signs. Email dpo@preferium.com for the DocuSign-ready PDF.

Data Processing Agreement

Last updated: 2026-05-10 Effective version: 1.0

This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement between Preferium AS (Org. nr. xxx xxx xxx, Norway — the “Processor”) and the customer (“Controller”) for the provision of Preferium AI Edge (the “Service”). It implements Article 28 of Regulation (EU) 2016/679 (GDPR) and Schedule 1 of the UK Data Protection Act 2018.

1. Definitions

Terms defined in the GDPR have the same meaning when used in this DPA. “Personal Data” means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Service.

2. Subject matter and duration

ItemDetails
Subject matterServer-side optimization of the Controller’s website HTML for AI search engines, including caching of optimized content at edge nodes.
DurationThe term of the active subscription plus 30 days for the deletion process described in §10.
Nature of processingStorage, retrieval, transformation (AI rewriting), and serving of HTML on behalf of the Controller.
PurposeTo provide the Service as described in the Master Services Agreement.
Categories of data subjectsVisitors to the Controller’s website, including identified individuals where the Controller’s HTML contains them.
Categories of Personal DataIP addresses, user agents, request paths, referrers (limited retention — 14 days). HTML content as published by the Controller, which may contain personal data the Controller has chosen to publish.

3. Roles

The Controller determines the purposes and means of processing. The Processor processes Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries.

4. Processor obligations

The Processor shall:

  1. Process Personal Data only on documented instructions from the Controller, including transfers to third countries — unless required to do so by Union or Member State law.
  2. Ensure that persons authorized to process the Personal Data are bound by confidentiality obligations.
  3. Take all measures required pursuant to Article 32 GDPR (security of processing — see §6).
  4. Respect the conditions for engaging Sub-Processors (§5).
  5. Assist the Controller in fulfilling its obligations to respond to data subject requests.
  6. Assist the Controller in ensuring compliance with Articles 32–36 GDPR.
  7. At the Controller’s choice, delete or return all Personal Data after the end of the provision of services and delete existing copies (see §10).
  8. Make available all information necessary to demonstrate compliance with Article 28 GDPR.

5. Sub-Processors

The Controller authorizes the Processor to engage the following Sub-Processors:

Sub-ProcessorServiceLocationTransfer mechanism
Cloudflare, Inc.Edge worker hosting + KV cacheGlobal edge networkEU SCCs + UK addendum
Supabase, Inc.Postgres databaseEU (Frankfurt / Stockholm)EU SCCs + DPA
Anthropic PBCLLM inference (Claude)USEU SCCs + DPA
OpenAI L.L.C.LLM inference (GPT)USEU SCCs + DPA
Google LLCLLM inference (Gemini) + GSC/GA4 accessUS/EUEU SCCs
DataForSEO LLCSERP + backlink dataUS/EUEU SCCs
Resend, Inc.Transactional emailEU (Ireland)DPA
Stripe, Inc.Payment processingUS (with EU branch)EU SCCs + DPA
Better StackLogging + uptimeEU (Germany)DPA
Sentry (Functional Software, Inc.)Error monitoringUS (EU data residency available)EU SCCs + DPA

The Processor will inform the Controller of any intended changes to this list at least 30 days before the change takes effect, allowing the Controller to object. If the Controller objects in writing within 14 days of that notice, the Processor will work with the Controller to find a mutually acceptable resolution; failing that, the Controller may terminate the Service with pro-rata refund.

6. Security measures

The Processor maintains the following technical and organizational measures (Article 32 GDPR):

7. Personal Data breach

The Processor will notify the Controller without undue delay (target: within 24 hours) after becoming aware of a Personal Data breach affecting the Controller’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

8. Data subject requests

The Processor will assist the Controller, by appropriate technical and organizational measures, in responding to requests for exercising data subject rights under Articles 15–22 GDPR. Tooling:

9. International transfers

For transfers of Personal Data outside the EEA, UK, or Switzerland, the Processor uses the European Commission’s Standard Contractual Clauses (SCCs) (2021/914/EU) as updated. Where Sub-Processors are located in jurisdictions without an adequacy decision, supplementary measures apply (encryption-in-transit-and-at-rest by default, plus contractual obligations on the Sub-Processor).

10. Return or deletion

Upon termination of the Service, the Processor will:

  1. Stop accepting new requests within 24 hours of termination notice.
  2. Make all Personal Data available for export for 30 days following termination.
  3. Delete all Personal Data from production systems within 30 days of the export window closing.
  4. Delete from backups within the natural backup-rotation window (90 days for R2, 30 days for Supabase) — the Processor cannot selectively erase from backup snapshots without invalidating the entire snapshot.
  5. Issue a written certification of deletion within 7 days of completion.

11. Audits

The Controller may, no more than once per calendar year and at its own cost, audit the Processor’s compliance with this DPA. The Processor may satisfy this obligation by providing a current SOC 2 Type II report or equivalent third-party assessment. Audits requiring on-premises access require 30 days’ written notice and may be subject to confidentiality undertakings.

12. Liability and termination

This DPA is governed by Norwegian law. Disputes will be resolved by Oslo District Court. Liability under this DPA is subject to the limitations set out in the Master Services Agreement; nothing in this DPA limits the Controller’s right to bring claims directly against the Processor under the GDPR.

13. Changes

The Processor will notify the Controller of material changes to this DPA at least 30 days before they take effect. The Controller may terminate the Service if it does not accept the changes.


Signed for and on behalf of the Processor:

Robert Andre Johansen, CEO Preferium AS post@preferium.no

Signed for and on behalf of the Controller:

[Customer fills in]