Data processing agreement

For services provided by Fastpath AS

This English version is a translation provided for convenience. The Norwegian version is the authoritative text; if the two differ, the Norwegian text prevails.

This data processing agreement governs how Fastpath processes personal data on behalf of the customer when providing services. The customer and Fastpath enter into the agreement by signing a customer-specific supplementary annex that identifies the applicable agreement version, normally together with the order form.

Version 1.0 · Last updated: 9 October 2026

Parties

This data processing agreement is made between - the customer named in the Supplementary Annex and in the Order Form (the "Controller"), and - Fastpath AS, org. no. 920 497 837 (the "Processor" or "Fastpath").

Introduction

This data processing agreement (the "Agreement") governs the processing of personal data that the Processor carries out on behalf of the Controller. The Agreement is made in connection with the service agreement between the parties. It is published with a version number at https://fastpath.no/en/data-processing-agreement and is entered into when both parties sign the Supplementary Annex, which refers to the applicable version. The "Main Agreement" means the entire service agreement between the Processor as supplier and the Controller as customer. It comprises Fastpath's Customer Terms in force from time to time, any Product Terms and the Order Form or Order Forms entered into, or a separate agreement for specific deliveries, for example consulting or platform services. The "Services" means the Waysayer platform and the support, consulting and platform services Fastpath delivers under the Main Agreement. The Agreement consists of: - this agreement text; - Appendix 1, default description of the processing; - Appendix 2, sub-processors; and - the Supplementary Annex, which sets out matters that apply to the individual Controller. The purpose of the processing, its duration, the nature of the processing, the types of personal data and the categories of data subjects follow from Appendix 1, as supplemented by the Supplementary Annex. In the event of conflict between the Main Agreement and the Agreement on the processing of personal data, the Agreement prevails. In the event of conflict between Appendix 1 and the Supplementary Annex, the Supplementary Annex prevails. The Supplementary Annex prevails over the agreement text only where it expressly states a deviation in its section on deviations. Terms and definitions in the Agreement have the same meaning as in the Norwegian Personal Data Act (*personopplysningsloven*) and the General Data Protection Regulation.

1. Purpose of the Agreement

The Processor processes personal data on behalf of the Controller on the basis set out above. The Agreement shall ensure that personal data is processed in accordance with the requirements in force from time to time, including the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the Personal Data Act with its regulations. The Processor shall process the personal data as described in the Agreement, and otherwise only where the parties have agreed so in writing.

2. The Processor's obligations

The Processor shall implement appropriate technical and organisational measures to ensure that all processing under the Agreement meets the requirements of the Personal Data Act and protects the rights of the data subject, including the requirements of Article 32 GDPR. See also clause 4. The Processor shall process the personal data only on documented instructions from the Controller, and shall at all times be able to document such instructions. The Controller's instructions are the Agreement, the Main Agreement, the Supplementary Annex, the use and configuration of the Services by the Controller and its users, and any other written instructions the parties agree. The Processor shall not process personal data in any other way than is necessary to carry out its assignments for the Controller, including with regard to transfers to a third country, unless required to do so by EEA law or Norwegian law to which the Processor is subject. In that case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Taking into account the nature of the processing and insofar as this is possible, the Processor shall assist the Controller by appropriate technical and organisational measures in responding to requests from data subjects. This covers both requests from data subjects to exercise their rights under Chapter III GDPR, and assistance in ensuring compliance with the obligations concerning security of processing, notification of breaches, data protection impact assessments and prior consultation under Articles 32 to 36, taking into account the nature of the processing and the information available to the Processor. The Processor shall keep a record of the processing activities carried out on behalf of the Controller, containing at least the information required under Article 30(2) GDPR. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under the Agreement and Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or by an auditor mandated by the Controller. The Controller is itself responsible for contact and communication with supervisory authorities, including the Norwegian Data Protection Authority (*Datatilsynet*). The Processor is bound by confidentiality regarding personal data it gains access to as a result of the Agreement, and shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This provision continues to apply after the Agreement ends. The Processor shall not disclose data processed for the Controller to any third party without an express instruction from the Controller. Enquiries shall be forwarded to the Controller as quickly as possible. Transfers that the Controller itself initiates or configures through the Services, for example integrations with other systems, mailings and sharing, are documented instructions from the Controller. If the Processor considers that an instruction infringes the GDPR, the Personal Data Act or other regulation, the Processor shall inform the Controller immediately.

3. Use of subcontractors for the processing of personal data ("sub-processors")

Sub-processors approved when the Agreement is made are those on the list referred to in Appendix 2 at that time, as adjusted by the Supplementary Annex, if at all. The Controller gives the Processor general authorisation to use and change sub-processors. If the Processor plans to engage new sub-processors or replace existing ones, the Processor shall inform the Controller in writing (including electronically) and give the Controller the opportunity to object to the change. The list of sub-processors is available at all times at https://fastpath.no/en/sub-processors. The Processor gives notice of planned changes by updating the list and notifying by e-mail the contact named in the Supplementary Annex, or otherwise the Controller's contact under the Main Agreement. The Controller may object to the change in writing no later than 14 days after the notice, where the objection is reasonably grounded in the protection of personal data. The objection shall state its reasons. The parties shall then seek a solution in good faith, for example that the new sub-processor is not used for the Controller's personal data, or that the change is adjusted. The Processor may implement the change when that period has expired. The Processor may nevertheless engage or replace a sub-processor at shorter notice where urgent circumstances beyond the Processor's reasonable control make this necessary for security reasons, legal requirements or to avoid a material interruption of the Services. The Processor gives notice as early as possible, before the change where possible and otherwise without undue delay afterwards. The Controller's right to object applies accordingly, counted from the notice. If the Processor decides to implement the change without accommodating a timely, reasoned objection, the Controller may terminate the Services that cannot be delivered without the new sub-processor. For ordinary changes, the Processor shall notify the Controller of this in writing and give a real opportunity to exercise the right of termination before the new sub-processor begins processing the Controller's personal data. The termination then takes effect from the time the new sub-processor would otherwise begin processing that personal data. For changes already implemented under the previous paragraph, the termination takes effect when it is received. Prepaid fees for the terminated Services for the period after the termination has taken effect are refunded pro rata. This is the Controller's sole agreed remedy arising from the change of sub-processor itself. This provision does not limit rights under mandatory law or remedies for breach of the Agreement. Sub-processors shall by contract be bound by the same data protection obligations as those set out in the Agreement, and provide sufficient guarantees of appropriate technical and organisational measures. If a sub-processor fails to fulfil its obligations, the Processor remains fully liable to the Controller. Services that the Controller itself chooses to connect to the Services, for example its own systems, identity providers or AI agents, are the Controller's own recipients or processors and not sub-processors of the Processor, unless the Processor provides them as part of the Services.

4. Security and breaches

The Processor shall meet the requirements for security measures under the Personal Data Act and its regulations, and be able to document its procedures and measures. The documentation shall be available to the Controller on request. In the event of a personal data breach, the Processor shall notify the Controller without undue delay. The notification is sent to the breach contact named in the Supplementary Annex, and otherwise to the Controller's contact under the Main Agreement. The notification shall contain at least: 1. a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned; 2. the name and contact details of a contact point where more information can be obtained; 3. a description of the likely consequences of the breach; and 4. a description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects. Where not all information can be provided in the first notification, it is provided in stages as soon as it is available. The Controller is responsible for notifying the supervisory authority. The Processor shall not send such a notification or contact the supervisory authority about the breach without an instruction from the Controller, unless the law requires it.

5. Transfers to third countries

Personal data may be transferred to countries outside the EU/EEA (third countries). A transfer requires that the requirements for security and the protection of data subjects' rights under the Personal Data Act and other legislation are met, including a valid transfer mechanism under Chapter V GDPR, for example an adequacy decision or the European Commission's standard contractual clauses. The list referred to in Appendix 2 states the location of processing and the transfer mechanism for each sub-processor.

6. Duration, order to stop processing and obligations on termination

The Agreement applies for as long as the Processor processes or has access to personal data on behalf of the Controller under the Main Agreement. In the event of a breach of the Agreement, the Personal Data Act or other relevant legislation, the Controller may order the Processor to stop further processing with immediate effect. On the Controller's instruction, the Processor shall delete or return all personal data once the services related to the processing have been delivered, and delete existing copies, unless storage is required by law. Return takes place in a commonly used, machine-readable format agreed between the parties. The obligation also applies to backups, but it is sufficient that backups expire in accordance with established backup routines, no later than 90 days after the personal data has been deleted from active systems.

7. Other obligations and rights

Other obligations and rights follow from the Main Agreement. The same contact persons apply to the Agreement as to the Main Agreement, unless the Supplementary Annex names others. Tasks carried out under the Agreement are invoiced in accordance with the Main Agreement. The Agreement does not extend the Controller's remedies, including the Processor's liability for damages, beyond what follows from the Main Agreement. This does not limit the rights of data subjects under Article 82 GDPR. If the Main Agreement is assigned to another party, the Agreement shall be assigned accordingly. The Agreement exists in Norwegian and English. In the event of conflict, the Norwegian text prevails.

Appendix 1 — Default description of the processing

This description applies unless the Supplementary Annex states otherwise.

Purpose of the processing

The purpose is to provide the Services to the Controller under the Main Agreement. The Processor processes personal data on behalf of the Controller to the extent necessary to provide the Services. This includes storing and processing the personal data the Controller uploads to, collects through or otherwise makes available in the Services, and the necessary support, operation, troubleshooting, further development and security. For support and consulting assignments, the purpose also includes carrying out the assignment as agreed.

Duration of the processing

The processing lasts for as long as the Processor provides the Services to the Controller under the Main Agreement. On termination, the personal data is deleted or returned under clause 6 of the Agreement.

Nature of the processing

The processing comprises the operations necessary to provide the Services, including collection, recording, storage, organisation, structuring, combination, search, display, transmission (for example e-mail, notifications and data exchange with systems the Controller connects), automated processing in processes and integrations the Controller configures, backup, making data available to the Controller, and deletion. The processing takes place on the Controller's instructions, including through the Controller's use and configuration of the Services.

Types of personal data

Which personal data is processed is determined and controlled by the Controller through its use of the Services. It will typically include contact details (such as name, e-mail address, telephone number and organisation), user and account data, the content of cases, requests, forms, survey responses, bookings, messages and files, data exchanged with systems the Controller connects, and a log of who did what in the Controller's workspace. The Controller shall not process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10) through the Services, unless this is specifically agreed in the Supplementary Annex and has its own legal basis.

Categories of data subjects

The categories of data subjects concerned are determined by the Controller through its use of the Services. They will typically include the Controller's users, employees, contacts, customers, members, suppliers and respondents.

Appendix 2 — Sub-processors

The Processor uses the sub-processors listed at any time at https://fastpath.no/en/sub-processors, organised by service area. The list states the service, location of processing and transfer mechanism for each sub-processor. The sub-processors for the Waysayer platform apply to the platform services. The sub-processors for support, consulting work and Fastpath's own business apply to the extent such work involves the Controller's personal data. Changes follow clause 3.

Supplementary Annex

The Supplementary Annex is completed for each Controller and sets out contacts and any deviations or additions. An amended Supplementary Annex applies when both parties have accepted it in writing.

Conclusion

The Agreement is entered into when both parties have signed the Supplementary Annex, normally together with the Order Form. An electronic signature is sufficient. The version of the Agreement that the Supplementary Annex refers to applies to the Controller.