Back

Data Processing Agreement

Last updated: 2026-09-07

1. Parties

Controller (“the customer”): the business that has created an account in SOMESimplify and accepted the terms.

Processor (“we”): Svartdal App & Web, Norwegian org. no. 926 747 452, Drammen, Norway. Email: hei@somesimplify.com.

This agreement applies from the moment the customer accepts the terms and for as long as the account exists. No separate signature is needed. A signed copy is available on request.

2. Subject matter

The customer is responsible for personal data about its own guests. We process that data only to deliver the service the customer ordered: collecting comments, messages and reviews from the customer’s own channels, drafting replies, sending the replies the customer approves, and showing statistics. We never use guest data for our own purposes, for training AI models, or to contact guests ourselves.

3. Data and data subjects

  • Guests and followers: display name and username on Instagram, Facebook and Google, the text of comments, messages and reviews, timestamps and star ratings. No email, phone or address unless the guest writes it in a message.
  • The customer’s staff: name and email of people the customer invites into the account, and what they do in the service.
  • People in photos: photos the customer uploads may show staff and guests. We do not recognise faces. The customer is responsible for having the right to use the photos.

We do not intentionally process special categories of data (health, religion, politics and similar). If a guest writes such content in a message, it stays in that message until the customer deletes it.

4. Instructions

We process data only on documented instructions from the customer. The instructions are this agreement, the terms, and the choices the customer makes in the service (for example which channels are connected and which replies are approved). If we believe an instruction breaks the law, we say so before carrying it out.

5. Confidentiality and security

  • Everyone with access to data at our end is bound by confidentiality.
  • Data is stored encrypted in the EU (Stockholm) and always transmitted encrypted (TLS). Each customer’s data is separated from other customers’ data by access rules in the database.
  • Access tokens for Instagram, Facebook and Google are stored only on the server and never sent to the browser.
  • Only the owner has administrative access. All administrative access is logged.
  • Automatic backups run every night and are kept for 30 days.

6. Sub-processors

The customer authorises the sub-processors listed below. If the list changes, we notify the customer by email at least 30 days in advance, and the customer may terminate the service at no cost if it does not accept the change. Sub-processors are bound by obligations equivalent to this agreement. Transfers outside the EEA rely on the EU Commission’s Standard Contractual Clauses (SCC).

ProviderLocationWhat they doWhich data
Supabase Inc.Stockholm (EU)Database, authentication, file storageAll service data
Vercel Inc.Frankfurt (EU)Hosting and server codeAll data in transit
Anthropic PBCUSA (SCC)AI drafts of text and repliesText of guest messages, the customer’s own texts
Resend Inc.EU regionEmail deliveryEmail addresses, notification content
Functional Software Inc. (Sentry)EU regionError monitoringTechnical error reports, no guest data
Stripe Inc.EU/USA (SCC)Subscription paymentsCustomer billing data, never guest data
Meta Platforms Ireland Ltd.Ireland (EU)Instagram and Facebook APIComments, messages, insights; the customer has its own agreement with Meta
Google Ireland Ltd.Ireland (EU)Google Business Profile APIReviews and replies; the customer has its own agreement with Google

7. Assisting the customer

If a guest asks the customer for access, rectification or erasure, we help the customer locate and delete the data within 10 working days. The customer can delete comments, messages and reviews in the service directly, and export all data from settings.

8. Data breaches

If we discover a breach affecting the customer’s data, we notify the customer by email without undue delay and no later than 48 hours after becoming aware of it, with what we know about scope, consequences and measures. The customer decides whether to notify the supervisory authority and the guests.

9. Deletion at the end of the agreement

On termination the customer can export all data until the account is deleted. We delete the customer’s data no later than 30 days after the account is closed, and backups no later than 30 days after that. We keep only what Norwegian accounting law requires (invoices), which contain no guest data.

10. Audits

The customer may request documentation that we comply with this agreement. We answer in writing within 30 days. Where justified, the customer or an auditor of its choice may carry out an audit at an agreed time and scope. The customer bears its own costs.

11. Governing law and changes

This agreement is governed by Norwegian law. If we change it, the customer is notified by email at least 30 days before the change takes effect. In case of conflict, this agreement prevails over the terms in matters concerning personal data.

Questions? hei@somesimplify.com · Privacy Policy · Terms