SLApulse Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the SLApulse Terms of Use between Customer, as controller, and Norsker Labs ApS, CVR no. 46545427, Lyngevej 217, 3450 Allerød, Denmark, as processor. It applies only to Customer Data containing personal data processed by Norsker Labs on Customer’s behalf.

1. Processing instructions and confidentiality

Norsker Labs will process personal data only on Customer’s documented instructions, including these Terms and the Customer’s use of the Service, unless Union or Member State law requires otherwise. Norsker Labs will ensure that authorised personnel are bound by confidentiality obligations.

2. Security and assistance

Norsker Labs will implement technical and organisational measures appropriate to the risk and will assist Customer, taking account of the nature of processing and available information, with data-subject requests, security obligations, data-protection impact assessments, prior consultation, and demonstrating compliance. Norsker Labs will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data.

3. Sub-processors and transfers

Customer gives general written authorisation for the sub-processors listed below. Norsker Labs will notify Customer of an intended addition or replacement and give Customer a reasonable opportunity to object on data-protection grounds. Norsker Labs remains responsible for its sub-processors’ relevant obligations.

Sub-processorServiceProcessing location / transfer safeguard
Railway Corp.Application and managed infrastructure hosting, including managed data stores used by SLApulse.Location and any applicable Chapter V transfer safeguard are determined by the customer’s deployed Railway region and Railway’s applicable data-processing terms.
Resend, Inc. (where configured)Transactional email delivery.Location and any applicable Chapter V transfer safeguard are determined by Resend’s applicable data-processing terms.

Norsker Labs will not transfer Customer Data outside the EEA unless a lawful Chapter V GDPR transfer mechanism applies.

4. Audits

On reasonable written request, Norsker Labs will provide information necessary to demonstrate compliance with this DPA. Customer may audit no more than once annually and only with reasonable advance notice, during normal business hours, in a manner that does not unreasonably disrupt the Service or expose other customers’ information. Current independent audit reports or certifications may satisfy an audit request where they reasonably address the request.

5. Return and deletion

On termination of the Service, Customer may use available export functionality before access ends. Norsker Labs will delete or return Customer Data in accordance with Customer’s documented instruction, unless Union or Member State law requires storage. Deletion may be completed through routine backup rotation, provided the data remains protected and is not actively processed except for restoration or legal obligations.

6. Processing details

Subject matter and durationHosting, processing, support and security of SLApulse for the subscription term and deletion/return period.
Nature and purposeReceiving configured source events, calculating and presenting SLA information, operational prioritisation, reporting, support and security.
Categories of data subjectsCustomer users, Customer personnel, and individuals represented in source-system metadata supplied by Customer.
Categories of personal dataAccount identifiers, business contact details, source-system identifiers, issue metadata, timestamps, priority and status data, SLA configuration, and security or audit data supplied or generated through use of the Service.

Customer remains responsible for determining the lawfulness, scope and retention of the personal data it instructs Norsker Labs to process.

7. Contact

Questions about this DPA may be sent to contact@slapulse.com.