Per-tenant extracts available on request via dpo@preferium.com. Customer-portal export planned R176+.

GDPR Article 30 — Records of Processing Activities

Document status: Template for Preferium AS as Processor on behalf of Customers (Controllers). Required by Regulation (EU) 2016/679 Article 30(2). Last updated 2026-05-21 (R174 — preferium-edge).

Owner: Robert Andre Johansen (Acting DPO until R174+ outsource decision — see dpo-designation.md).

Review cadence: Quarterly + on any change to processing scope, sub-processors, retention, or transfer mechanism.


A. Controller / Processor identity

FieldValue
NamePreferium AS
Org. nr.Robert to fill — to be added before first Enterprise customer signs DPA
Registered addressRobert to fill — to be added before first Enterprise customer signs DPA
Establishment within EU/EEANorway (member of EEA, fully subject to GDPR via EEA-EFTA acquis)
Data Protection Officer_Pending R174 decision per dpo-designation.md — Option A (Robert) vs Option B (outsource)
DPO contact emaildpo@preferium.com (alias resolves to current DPO mailbox per dpo-designation.md §6)
Lead Supervisory AuthorityDatatilsynet (Norwegian Data Protection Authority — datatilsynet.no)
Representative inside the EUNot required — Preferium AS is established in EEA

B. Processing activities (one row per distinct purpose)

#Purpose of processingCategories of data subjectsCategories of personal dataRetentionLawful basis (Art. 6)Source
1Serve optimized HTML to AI crawlers on behalf of the ControllerVisitors (AI agents + humans) to Customer’s siteIP address (truncated to /24), User-Agent, request path, optimized HTML payload14 days (CF edge logs) / 90 days (ai_crawler_visits)Art. 6(1)(f) Legitimate interest (operate the Service)HTTP requests proxied through CF Worker
2Crawl Customer’s site to populate pages tablePage authors named in byline/author tagsNames, social handles, biographies if present in <meta> / JSON-LD authored by CustomerUntil Customer deletes the page row OR account closureArt. 6(1)(b) Contract (Customer instructs us to crawl)Customer’s own published HTML
3Generate AI optimizations + store in PostgresSame as #2Same as #2 (we don’t add identifying data; we reword existing copy)Until Customer deletes the page row OR account closureArt. 6(1)(b) ContractAI Gateway → Claude Sonnet 4.6
4Track Customer brand visibility in 4 LLMs (Phase 13)Customer’s brand mentions in LLM responsesLLM-generated text, citations, sentiment scores. No human data subjects2 years (rolling)Art. 6(1)(b) ContractOpenAI/Anthropic/Perplexity/Gemini APIs
5Tenant sign-up, billing, subscription managementAccount owners + invited membersEmail, name, password (hashed via Supabase Auth), Stripe customer ID, plan tier, login timestampsAccount lifetime + 5 years (billing — Bokføringsloven)Art. 6(1)(b) ContractDashboard sign-up / Supabase Auth
6Operational logging (audit trail of every privileged action)Tenant users (owner/admin/member)User ID, action type, IP, User-Agent, request body summary24 months (most); 5 years (billing actions)Art. 6(1)(c) Legal obligation (Bokføringsloven for billing)API workers — audit_logs
7Customer support email correspondenceTenant users + their nomineesEmail, name, content of message3 years from last interactionArt. 6(1)(b) Contract + Art. 6(1)(f) for analyticspost@preferium.com
8Outbound webhook delivery + retry logTenant users (subjects of audit events)User ID embedded in webhook payload (mirrors audit_logs.user_id); webhook URL + response codes90 daysArt. 6(1)(b) Contractwebhook_deliveries
9OAuth token storage (Google Search Console + Analytics)Tenant user who connected the accountEncrypted (AES-GCM) refresh + access tokens, OAuth scopes, Google emailUntil Customer revokes OR account closureArt. 6(1)(a) Consent (explicit per Google OAuth flow)oauth_tokens
10DSAR (export/delete/rectify) request fulfillmentData subjects exercising Art. 15-22 rightsEmail of requester, request type, response artifact (export ZIP, deletion log)3 years from completionArt. 6(1)(c) Legal obligationaudit_logs (gdpr.export/gdpr.erasure events)
11Cost-tracking telemetry (cents-precision per API call)None (no human data subjects)Provider name, token counts, cost — no user IDs attached13 months rollingNot personal data — no Art. 6 basis requiredAI Gateway analytics + per-route middleware
12Consent log (proves opt-in to telemetry / marketing)Tenant usersUser ID, consent type, given/revoked timestamp5 years from revocationArt. 6(1)(c) Legal obligation (proof of consent)consent_log

Activities #1, #4, #11 typically don’t process personal data, but the records are kept anyway because lines blur (e.g., IP-derived patterns, brand mentions referencing named individuals).


C. Recipients (sub-processors)

Public list maintained at docs/legal/sub-processors.md and (post-R174 deploy) at trust.preferium.com/sub-processors. Summary:

RecipientServiceHosting regionTransfer mechanism
Cloudflare, Inc.Workers compute, KV cache, R2 object storage, DNS, AI GatewayUS/EU (data-resident)EU SCCs + UK IDTA + DPF (where US)
Supabase, Inc.Managed Postgres + Auth (project eu-west-1)EU (Frankfurt)No transfer — EU intra-region
Anthropic PBCAI generation (Claude Sonnet 4.6) via AI GatewayUSEU SCCs (via Cloudflare AI Gateway DPA)
OpenAI, LLCLLM citation tracking (ChatGPT)USEU SCCs (direct DPA, see vendor agreements)
Google LLCOAuth + Search Console + Analytics + KG + PageSpeed InsightsUSDPF + EU SCCs (Google Workspace DPA)
Perplexity AI, Inc.LLM citation trackingUSEU SCCs
Stripe Payments Europe Ltd.Billing + payment processingEU (Dublin)No transfer — EU intra-region
Resend, Inc.Transactional + marketing emailUS (with EU pop)EU SCCs
DataForSEO LLCSEO data (keywords, backlinks, SERP)EU (Vilnius)No transfer — EU intra-region
Better Stack Inc.Status page + heartbeatsUS (with EU pop)EU SCCs
Sentry, Inc.Application monitoringUS/EU (data-resident)EU SCCs (EU pop available; enabled per Sentry DPA)

Sub-processor changes notified per DPA.md §5 — 30 days advance notice + objection-right within 14 days.


D. Transfers to third countries

CountryMechanismAdequacy decision?
USADPF + EU SCCs (Module 2 + Module 3)Yes — EU-US DPF (2023)
UKUK IDTA + UK addendum to EU SCCsYes — UK adequacy (2021)

International transfers ALL covered by either an EU Commission adequacy decision OR EU/UK standard contractual clauses. Robert reviews adequacy status at each quarterly Art. 30 review.


E. Technical and organizational measures (Art. 32)

Summary — full implementation status in enterprise-readiness.md:


F. Children’s data (Art. 8)

The Service is B2B; no part of the product is targeted at children under 16. No age-gate at sign-up because account creation is restricted to natural persons acting on behalf of a business. If a Customer publishes children’s data in their HTML, Preferium processes it as instructed by the Customer — the Customer is the data controller and bears Art. 8 responsibilities.


G. High-risk processing flags (Art. 35)

Risk categoryTriggers Art. 35 DPIA?Notes
Large-scale processing of special categoriesNoWe don’t process Art. 9 special categories (health, biometric, etc.)
Systematic monitoring of public areasNoWe crawl Customer’s site (not public areas in the GDPR sense — Customer is the controller)
Innovative use of new tech (AI generation)Yes — DPIA doneDPIA on AI optimization pipeline scheduled R175+ (template in docs/legal/dpia-ai-pipeline.md — placeholder, to be drafted)

H. Change log

DateRoundChange
2026-05-21R174Template created. Sub-processor list pulled from docs/legal/sub-processors.md (created same round). DPIA placeholder added.
2026-05-19R157DPA.md drafted with §9 sub-processor change notification mechanism. This Art. 30 template was the natural follow-up.

I. Operator notes

Per docs/legal/dpo-designation.md, R174 records the final DPO Option (A: Robert as DPO; B: external service ~€500-2000/mo; C: hybrid). This Art. 30 template assumes Option A as the placeholder — flip the “Data Protection Officer” row in §A once R174 decision lands.

Where this lives in production (R174+):

  1. Primary canonical: docs/legal/gdpr-article-30-records.md (this file, version-controlled).
  2. Per-tenant copy: each Customer can request their own Art. 30 record extract — generated from this template + their specific use of the Service (sub-processors they’ve consented to, plan tier, custom integrations).
  3. Customer-portal section: planned R175+ “Compliance” tab in the dashboard lets a tenant owner download their own Art. 30 PDF + DPA + DPIA + sub-processor list.

When this template is updated, the change MUST be reflected in: