Per-tenant extracts available on request via post@preferium.no. There is no self-service export in the dashboard.

GDPR Article 30 — Records of Processing Activities

Document status: Template for Preferium AS as Processor on behalf of Customers (Controllers). Required by Regulation (EU) 2016/679 Article 30(2). Last updated 2026-09-20.

Owner: Robert Andre Johansen (operational Privacy Contact; no appointed DPO — see dpo-designation.md).

Review cadence: Quarterly + on any change to processing scope, sub-processors, retention, or transfer mechanism.


A. Controller / Processor identity

Field Value
Name Preferium AS
Org. nr. 999 323 286
Registered address Sponheimveien 19, 1613 Fredrikstad, Norway
Office address Produksjonsveien 18, 2nd floor, 1618 Fredrikstad, Norway
Public registers Enhetsregisteret (entered 5 January 2013), Foretaksregisteret, Merverdiavgiftsregisteret
Establishment within EU/EEA Norway (member of EEA, fully subject to GDPR via EEA-EFTA acquis)
Data Protection Officer Not appointed; current assessment is recorded in dpo-designation.md
Privacy contact email post@preferium.no
Lead Supervisory Authority Datatilsynet (Norwegian Data Protection Authority — datatilsynet.no)
Representative inside the EU Not required — Preferium AS is established in EEA

B. Processing activities (one row per distinct purpose)

# Purpose of processing Categories of data subjects Categories of personal data Retention Lawful basis (Art. 6) Source
1 Serve optimized HTML to AI crawlers on behalf of the Controller Visitors (AI agents + humans) to Customer’s site IP address (truncated to /24), User-Agent, request path, optimized HTML payload 7 days (CF edge logs) / 30 days (ai_crawler_visits) Art. 6(1)(f) Legitimate interest (operate the Service) HTTP requests proxied through CF Worker
2 Crawl Customer’s site to populate pages table Page authors named in byline/author tags Names, social handles, biographies if present in <meta> / JSON-LD authored by Customer Until Customer deletes the page row OR account closure Art. 6(1)(b) Contract (Customer instructs us to crawl) Customer’s own published HTML
3 Generate AI optimizations + store in Postgres Same as #2 Same as #2 (we don’t add identifying data; we reword existing copy) Until Customer deletes the page row OR account closure Art. 6(1)(b) Contract Cloudflare Workers AI via AI Gateway (default @cf/meta/llama-4-scout-17b-16e-instruct)
4 Track Customer brand visibility in 4 LLMs (Phase 13) Customer’s brand mentions in LLM responses LLM-generated text, citations, sentiment scores. No human data subjects 2 years (rolling) Art. 6(1)(b) Contract OpenAI/Anthropic/Perplexity/Gemini APIs
5 Tenant sign-up, billing, subscription management Account owners + invited members Email, name, password (hashed via Supabase Auth), Stripe customer ID, plan tier, login timestamps Account lifetime + 5 years (billing — Bokføringsloven) Art. 6(1)(b) Contract Dashboard sign-up / Supabase Auth
6 Operational logging (audit trail of every privileged action) Tenant users (owner/admin/member) User ID, action type, IP, User-Agent, request body summary 24 months (most); 5 years for billing. / sso. / gdpr. actions — see §E “Right to erasure” Art. 6(1)(c) Legal obligation (Bokføringsloven §13 for billing) API workers — audit_logs
7 Customer support email correspondence Tenant users + their nominees Email, name, content of message 3 years from last interaction Art. 6(1)(b) Contract + Art. 6(1)(f) for support administration post@preferium.no
8 Outbound webhook delivery + retry log Tenant users (subjects of audit events) User ID embedded in webhook payload (mirrors audit_logs.user_id); webhook URL + response codes 90 days Art. 6(1)(b) Contract webhook_deliveries
9 OAuth token storage (Google Search Console + Analytics) Tenant user who connected the account Encrypted (AES-GCM) refresh + access tokens, OAuth scopes, Google email Until Customer revokes OR account closure Art. 6(1)(a) Consent (explicit per Google OAuth flow) oauth_tokens
10 DSAR (export/delete/rectify) request fulfillment Data subjects exercising Art. 15-22 rights Email of requester, request type, response artifact (export ZIP, deletion log) 3 years from completion Art. 6(1)(c) Legal obligation audit_logs (gdpr.export/gdpr.erasure events)
11 Cost-tracking telemetry (cents-precision per API call) None (no human data subjects) Provider name, token counts, cost — no user IDs attached 13 months rolling Not personal data — no Art. 6 basis required AI Gateway analytics + per-route middleware
12 Consent log (proves opt-in to telemetry / marketing) Tenant users User ID, consent type, given/revoked timestamp 5 years from revocation Art. 6(1)(c) Legal obligation (proof of consent) consent_log

Activities #1, #4, #11 typically don’t process personal data, but the records are kept anyway because lines blur (e.g., IP-derived patterns, brand mentions referencing named individuals).


C. Recipients (sub-processors)

Public register published at https://preferium.com/subprocessors (its only canonical copy, maintained in the preferium.com repository). Summary:

Recipient Service Hosting region Transfer mechanism
Cloudflare, Inc. Workers compute, KV cache, R2 object storage, DNS, AI Gateway, Browser Rendering US/EU (data-resident) EU SCCs + UK IDTA + DPF (where US)
Cloudflare, Inc. (Workers AI) Standard generative AI (SEO meta, headings, JSON-LD, alt-text, translations and citation-prompt suggestions) via AI Gateway US/EU (data-resident) EU SCCs + UK IDTA + DPF (where US)
Supabase, Inc. Managed Postgres + Auth (project region eu-north-1) EU (Stockholm) No transfer — EU intra-region
Anthropic PBC Claude responses for brand-visibility measurement US EU SCCs (via Cloudflare AI Gateway DPA)
OpenAI, LLC LLM citation tracking (ChatGPT) US EU SCCs (direct DPA, see vendor agreements)
Google LLC OAuth + Search Console + Analytics + KG + PageSpeed Insights + Gemini visibility measurement US DPF + EU SCCs (Google Workspace DPA)
Perplexity AI, Inc. LLM citation tracking US EU SCCs
Stripe Payments Europe Ltd. Billing + payment processing EU (Dublin) No transfer — EU intra-region
Resend, Inc. Transactional + marketing email US (with EU pop) EU SCCs
DataForSEO LLC SEO data (keywords, backlinks, SERP) EU (Vilnius) No transfer — EU intra-region
Sentry, Inc. Application monitoring US/EU (data-resident) EU SCCs (EU pop available; enabled per Sentry DPA)

Standard generation and prompt suggestions use Cloudflare Workers AI. packages/shared/src/ai-models.ts lists only Workers AI optimization models. citation-prompt-suggest.ts uses the configured optimization model through the routing wrapper in lib/cost-tracking/anthropic.ts; that historical filename does not identify the provider actually called. Read-only production configuration on 2026-09-19 confirmed @cf/meta/llama-4-scout-17b-16e-instruct. Claude visibility measurement in citation-tracking/providers.ts explicitly selects Anthropic; OpenAI, Google Gemini and Perplexity also provide measurement responses. These API observations are not proof of an identical response in a consumer assistant UI. Provider changes require corresponding updates to the model catalog, the canonical sub-processor register and Service Terms on preferium.com, and this record.

Oppbevaringstider er avledet, ikke uavhengige. Kilden er packages/shared/src/retention.ts (RETENTION_POLICIES, konsumert av services/retention/purge.ts), og de MÅ stemme med personvernerklæringen på preferium.com/privacy — begge publiseres offentlig (denne fila på trust.preferium.com via apps/trust/src/pages/gdpr-article-30.astro, personvernerklæringen på preferium.com). Rad 1 sto på «14 dager / 90 dager» fram til 2026-08-02 mens koden gjorde 30 dager og personvernerklæringen lovet 30/7 — to live juridiske sider fra samme selskap med ulikt svar. Endrer du en oppbevaringstid: endre retention.ts FØRST, deretter begge dokumentene.

Sub-processor changes notified per the DPA §6 (preferium.com/dpa) — 30 days advance notice + objection-right within 14 days.


D. Transfers to third countries

Country Mechanism Adequacy decision?
USA DPF + EU SCCs (Module 2 + Module 3) Yes — EU-US DPF (2023)
UK UK IDTA + UK addendum to EU SCCs Yes — UK adequacy (2021)

International transfers ALL covered by either an EU Commission adequacy decision OR EU/UK standard contractual clauses. Robert reviews adequacy status at each quarterly Art. 30 review.


E. Technical and organizational measures (Art. 32)

Summary — full implementation status in enterprise-readiness.md:


F. Children’s data (Art. 8)

The Service is B2B; no part of the product is targeted at children under 16. No age-gate at sign-up because account creation is restricted to natural persons acting on behalf of a business. If a Customer publishes children’s data in their HTML, Preferium processes it as instructed by the Customer — the Customer is the data controller and bears Art. 8 responsibilities.


G. High-risk processing flags (Art. 35)

Risk category Triggers Art. 35 DPIA? Notes
Large-scale processing of special categories No We don’t process Art. 9 special categories (health, biometric, etc.)
Systematic monitoring of public areas No We crawl Customer’s site (not public areas in the GDPR sense — Customer is the controller)
Innovative use of new tech (AI generation) Yes — DPIA outstanding The DPIA on the AI optimization pipeline has not been carried out. An earlier revision of this row claimed “DPIA done” while pointing at docs/legal/dpia-ai-pipeline.md, a file that does not exist.

H. Change log

Date Round Change
2026-09-20 Continuation Correct standard prompt routing to Workers AI and retain Anthropic for Claude measurement. Reconcile backup claims with read-only production observations; distinguish legacy runs, local rehearsal and unverified provider recovery. Record authorized tenant-purge arming with natural execution still pending. No processing-policy or transfer-mechanism change.
2026-08-14 W92 Corrections against code + prod, no change in actual processing. (1) §B row 3 + §C: generative AI processor corrected to Cloudflare Workers AI (source: packages/shared/src/ai-models.ts); Anthropic reclassified to citation-prompt suggestion only; Workers AI + Browser Rendering added to the Cloudflare rows. (2) §A/§I: DPO = Robert Andre Johansen (Option A, decided 2026-08-06) — replaces “pending decision” text; vendor-pricing notes removed from this published page. (3) §E: encryption in transit corrected to TLS 1.2 minimum / 1.3 preferred (prod-verified handshake + min_tls_version: '1.2' in code); pen-test row corrected to “not yet performed”; tenant-erasure note updated — migration 0290 IS applied in prod, TENANT_PURGE_ENABLED still unarmed.
2026-08-06 P9 Three contradictions against code corrected. (1) §E “the audit trail is ANONYMIZED, never deleted” described only the Art. 17 erasure mechanism; time-based retention HARD-DELETES at 24mo / 5yr (purge_audit_rows, migration 0126) — both mechanisms now documented, with the Bokføringsloven §13 basis for the 5-year bucket written down. (2) §E tenant erasure split out and marked NOT EXECUTABLE in prod (#765; migration 0290 unapplied) instead of implying the runbook path works. (3) §E backups: the 7-year Object Lock archive is documented as designed-not-provisioned — the bucket does not exist. Row 6 retention aligned to the actual billing./sso./gdpr. prefixes; portability corrected (no /v1/exports/full).
2026-05-21 R174 Template created. Sub-processor list pulled from docs/legal/sub-processors.md (created same round). DPIA placeholder added.
2026-05-19 R157 DPA.md drafted with §9 sub-processor change notification mechanism. This Art. 30 template was the natural follow-up.

I. Operator notes

Per docs/legal/dpo-designation.md, Preferium has not appointed a DPO. Robert Andre Johansen is the operational Privacy Contact, not an independent Article 37 DPO. If the assessment or appointment changes, update §A and every public legal surface in the same legal-set version.

Where this lives:

  1. Primary canonical: docs/legal/gdpr-article-30-records.md (this file, version-controlled).
  2. Per-tenant copy: each Customer can request their own Art. 30 record extract — generated from this template + their specific use of the Service (sub-processors they’ve consented to, plan tier, custom integrations).
  3. Customer-portal download: does not exist. There is no Compliance tab and no self-service Art. 30 export in the dashboard. Requests go to the Privacy Contact by email. This record and the Trust Centre page both carried a dashboard-export promise, under two different internal round numbers, for work that was never scheduled.

When this template is updated, the change MUST be reflected in: