Skip to content
Markedsradar
This is a translation. The Norwegian version applies.

Data processing agreement for Markedsradar

Last updated 24.09.2026.

This agreement follows Article 28 of the General Data Protection Regulation (GDPR). Sections 4 to 11 cover the requirements in Article 28(3)(a) to (h).

1. Parties

The customer, the business that uses the service, is the controller. FullPeiling AS, organisation number 938 341 508, Kokstadvegen 41, 5257 Kokstad, Norway, is the processor.

The agreement is part of the terms of use of the service, and applies for as long as the customer uses the service. In case of conflict, this agreement takes precedence over the terms in matters concerning personal data.

2. What the processing covers

  • Subject matter

    The information the customer adds and creates in Markedsradar: the list of users with roles, the invitations, the watchlist with roles, reasons and the customer's own topics, and what each user has read

  • Nature

    Storage, display, changes, logging of changes to the watchlist, searches for news about the companies and topics, email to users with content from the newspaper and to the administrators about the subscription, and deletion

  • Purpose

    Provide Markedsradar as a service to the customer

  • Duration

    As long as the customer uses the service. When the trial ends without an order, the newspaper is locked, and the content is deleted after 30 days. The same applies when the subscription ends. If the customer deletes the organisation, the content is deleted 30 days later. An invitation is deleted 30 days after it has been accepted, revoked or has expired

  • Types of personal data

    Who the users are and which role they have, email address of people who are invited, which stories each user has read, and when, and who has changed the watchlist, and when. The watchlist may contain personal data when a company is a sole proprietorship, or when the customer writes it into a reason or a topic

  • Categories of data subjects

    The customer's employees and others the customer gives access to, and owners of sole proprietorships on the watchlist

The customer must not add special categories of personal data, nor topics or reasons about named private individuals.

The news stories and the information about companies from the Central Coordinating Register for Legal Entities (Enhetsregisteret) are shared by all customers. FullPeiling AS is itself the controller for them, as described in the privacy notice, and they are not part of this agreement. The same applies to the account each user signs in with, and the name and email address on it.

3. The customer's responsibility

The customer is responsible for having a lawful basis for the processing, for informing the data subjects, and for what the customer adds and passes on. The customer decides who has access, and which companies are on the watchlist.

4. Instructions (point a)

FullPeiling AS processes the personal data only to provide the service, as set out in the terms and by the customer's use of the service. This is the customer's documented instruction. If the customer asks for anything beyond this, it must be agreed in writing.

FullPeiling AS may also count overall use of the service for its own key figures, such as how many stories users open, and how many people use the newspaper per week and per month. Only daily totals go on to FullPeiling's own system, never who read what. For this, FullPeiling AS is itself the controller, as described in the privacy notice.

If the law requires us to process the data in another way, we tell the customer before it happens, unless the law forbids it.

5. Confidentiality (point b)

Everyone at FullPeiling AS who has access to the personal data is bound by confidentiality. Access is limited to what is needed for operations and support, and lookups are logged.

6. Security (point c)

FullPeiling AS carries out the measures in Article 32 of the GDPR, including:

  • Each organisation's information is kept separate from others' in the database with row-level access rules. Every access is checked against membership and role in the organisation.
  • No other customer can see which companies the customer follows. The shared tables for companies and stories never show who follows them.
  • When we search for news, we send the company or topic, never which customer follows it.
  • All transfers are encrypted, and the information is stored encrypted at the database provider.
  • Sign-in only takes place through Microsoft or Google. We store no passwords.
  • Access to the language models is stored encrypted, and every call is logged.
  • Invitations, users being added and removed, role changes, changes to the watchlist, orders, cancellations and administrator lookups are logged. For a change to the watchlist we log who made it, the company or topic and the role, never the reason or the text of the customer's own topic, and that log is deleted with the organisation.
  • Backups are taken by the database provider.

7. Sub-processors (point d)

The customer gives general authorisation for FullPeiling AS to use these sub-processors:

  • Supabase

    WhatDatabase and sign-inWhereStockholm, EU
  • Vercel

    WhatHosting of the service. The functions run in StockholmWhereVercel Inc., USA. Transfers based on the EU Standard Contractual Clauses
  • Twilio SendGrid

    WhatEmails to users during the trial, and the emails about the subscription to the administrators. Receives the recipient's name and email address. In the email sent when the newspaper is ready it receives the headlines and sources of the most important stories and the name and role of the companies they are about, including the customer's own topics. In the confirmation of a cancellation and the message that it has been undone it receives the name of the administrator who cancelled or undid it. Open and click tracking is turned offWhereTwilio Inc., USA. Transfers based on the EU Standard Contractual Clauses
  • OpenAI

    WhatSearches for news about the companies and the customer's own topicsWhereOpenAI, USA. Transfers based on a valid transfer mechanism under Chapter V of the GDPR
  • xAI

    WhatThe same as OpenAIWherexAI, USA. Transfers based on a valid transfer mechanism under Chapter V of the GDPR
  • Appit AS

    WhatOwns the Supabase and Vercel accounts, and operates them for FullPeiling ASWhereNorway

Microsoft and Google provide sign-in as independent controllers, and are not sub-processors under this agreement.

If we want to replace or add a sub-processor, we notify the customer at least 30 days in advance. The customer can object to the change, and cancel the service if we cannot find a solution. The sub-processors are bound by obligations equivalent to those in this agreement.

8. Assistance (points e and f)

FullPeiling AS helps the customer respond to requests from data subjects about access, rectification, erasure, restriction, data portability and objection, to the extent the service does not let the customer do so itself. The customer can remove users and change the watchlist itself. If the customer asks, we provide a copy of the watchlist and the list of users in a common format.

We also help the customer meet the obligations in Articles 32 to 36 on security, breaches and data protection impact assessments, based on what we know about the processing.

9. Personal data breaches

If we become aware of a personal data breach affecting the customer's data, we notify the customer without undue delay. The notice describes what happened, which data and data subjects are affected, what we have done, and whom the customer can contact. The customer decides whether the Norwegian Data Protection Authority (Datatilsynet) and the data subjects are to be notified.

10. Deletion and return (point g)

When the agreement ends, the newspaper is locked, and the personal data is deleted after 30 days. Until then, the customer can ask for a copy of the watchlist and the list of users. If the customer deletes the organisation, all personal data is deleted no later than 30 days later. The exceptions are what the law requires us to keep, and the security log of the users, the invitations and the subscription, which is kept without the changes to the watchlist until it is 12 months old. The accounts users sign in with are not part of this agreement, and are deleted as section 5 of the privacy notice says.

11. Documentation and audits (point h)

FullPeiling AS provides documentation showing that the obligations in this agreement are met, when the customer asks. The customer, or an auditor the customer appoints, may carry out an audit once a year, with at least 30 days' notice, during working hours, and at the customer's expense. We tell the customer if we believe an instruction breaches data protection law.

12. Transfers outside the EEA

Personal data is not transferred to countries outside the EEA without a valid transfer basis. See the list of sub-processors.

13. Liability, governing law and changes

The liability rules in the terms also apply to this agreement. The agreement is governed by Norwegian law. Changes to the agreement are announced in the same way as changes to the terms.

This agreement is available in Norwegian and English. The Norwegian text is binding.

14. Contact

FullPeiling AS, Kokstadvegen 41, 5257 Kokstad, Norway, hei@fullpeiling.no.