Data processing agreement

The agreement under which ArktIQ IT AS processes personal data inside a SAQ workspace on behalf of the customer organization, as GDPR Article 28 requires. It is part of every SAQ subscription.

Last updated: 2026-09-19

1. Parties and definitions

1.1 This data processing agreement ("Agreement") is entered into between the customer organization that owns a SAQ workspace (the "Customer", acting as controller) and ArktIQ IT AS, org.nr. 937 045 670, Tomasjordvegen 129, 9024 Tomasjord, Norway ("ArktIQ", acting as processor).

1.2 "GDPR" means Regulation (EU) 2016/679 as implemented in Norway by the Personal Data Act (personopplysningsloven). "Personal data", "processing", "data subject", "personal data breach", and "sub-processor" have the meanings given in the GDPR. "Service" means SAQ as described at https://saq.no. "Workspace" means the Customer's isolated instance of the Service. "Customer Data" means all data the Customer, its users, its clients, and their users enter into the Workspace or that arrives in it through a mailbox, the API, or an AI agent the Customer configured.

1.3 This Agreement forms part of the subscription terms. In case of conflict on the processing of personal data, this Agreement prevails.

2. Subject matter and duration

2.1 The subject matter is ArktIQ's processing of personal data contained in Customer Data in order to provide the Service: a multi-tenant ticketing, project management, time tracking, and client billing application, including email integration and an API.

2.2 The Agreement applies for as long as ArktIQ processes Customer Data, which is the term of the subscription plus the 30-day grace period after deletion is scheduled (clause 11) and the backup retention thereafter.

3. Nature and purpose of the processing

3.1 ArktIQ stores, organizes, retrieves, transmits, and deletes Customer Data as the Service is used, and performs the automatic operations the Service consists of: matching incoming email to tickets, sending notifications and documents, computing time reports and billing runs, rendering timesheet documents, producing exports, taking backups, and enforcing the Customer's visibility rules.

3.2 The purpose is to provide the Service to the Customer. ArktIQ does not process Customer Data for its own purposes, does not use it to train models, and does not sell or share it.

4. Categories of data subjects and personal data

4.1 Data subjects: the Customer's employees and contractors who are workspace users; employees and contacts of the Customer's clients who are client users, contacts, or billing recipients; any other person who emails the connected mailbox or is named in tickets, comments, attachments, or email.

4.2 Personal data: names, email addresses, roles, consultant categories, timezones and languages; the content of tickets, comments, attachments, and email, including whatever personal data the Customer's users choose to write there; time entries with dates, durations, and notes; rate cards, billing runs, and timesheet documents that name individuals; audit records of who did what in the Workspace; IP addresses and browser identifiers in session records. Annex 1 lists the categories in detail.

4.3 Special categories: the Service is not designed for special categories of personal data (GDPR art. 9) or data about criminal convictions. The Customer shall not instruct ArktIQ to process such data and shall instruct its users accordingly. If such data nevertheless appears in tickets or email, ArktIQ processes it only as part of Customer Data under this Agreement.

5. The Customer's obligations

5.1 The Customer is responsible for the lawfulness of the processing, including having a legal basis for the personal data it and its users enter, informing data subjects, and answering their requests.

5.2 The Customer configures who may see what in the Workspace (members, client users, elevation, viewers, billing contacts, comment audiences) and is responsible for those choices. The Service enforces them.

5.3 The Customer is responsible for the mailbox it connects, including that it has the right to process the mail in it, and for the identity provider it connects.

5.4 The Customer's documented instructions are this Agreement, the subscription terms, and the use of the Service's functions by the Customer's authorized users and agents.

6. ArktIQ's obligations

6.1 ArktIQ processes Customer Data only on the Customer's documented instructions, unless required to do otherwise by EU, EEA, or Norwegian law, in which case ArktIQ informs the Customer of that requirement before processing, unless the law prohibits it.

6.2 ArktIQ informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR.

6.3 ArktIQ ensures that persons authorized to process Customer Data are bound by confidentiality. Platform staff have no access to a Workspace unless invited by the Customer; the exceptional operator access described in Annex 2 is read-only by default, two-factor and re-authentication gated, time-limited, and written to an audit log the Customer can see.

6.4 ArktIQ implements the technical and organizational measures in Annex 2 and maintains them for the term of the Agreement.

6.5 ArktIQ assists the Customer, taking into account the nature of the processing, in meeting its obligations to respond to data subject requests (clause 8), to secure the processing, to notify breaches (clause 9), and to carry out data protection impact assessments and prior consultations where the Service is concerned.

6.6 ArktIQ makes available the information necessary to demonstrate compliance with GDPR art. 28 and allows for audits as described in clause 12.

7. Sub-processors

7.1 The Customer gives general authorization for ArktIQ to use the sub-processors listed in Annex 3.

7.2 ArktIQ informs workspace owners by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the subscription for the affected Workspace without penalty and export its data before the change takes effect.

7.3 ArktIQ imposes data protection obligations on each sub-processor that are no less protective than this Agreement, and remains fully liable to the Customer for the sub-processor's performance.

7.4 Services the Customer connects itself, such as a Microsoft 365 mailbox or an OpenID Connect identity provider, are the Customer's own providers and not ArktIQ's sub-processors.

8. Data subject requests

8.1 The Service lets the Customer answer most requests itself: workspace owners and admins can view, correct, archive, delete, or redact tickets and comments, remove or pseudonymize workspace users and client users, and export the whole Workspace. Individuals can view and correct their own profile and delete their own login identity.

8.2 If a data subject contacts ArktIQ directly about data in a Workspace, ArktIQ forwards the request to the Customer without undue delay and does not answer it on the Customer's behalf unless instructed.

8.3 On request, ArktIQ produces a per-person export across the Workspaces the person belongs to, or performs a deletion the Customer cannot perform itself, within a reasonable time and at no charge for reasonable volumes.

9. Personal data breaches

9.1 ArktIQ notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification goes to the Workspace owners' email addresses and describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information that is not yet available is provided in phases.

9.2 ArktIQ cooperates with the Customer and takes reasonable steps to contain and remedy the breach. ArktIQ does not notify supervisory authorities or data subjects on the Customer's behalf unless instructed.

10. Security

10.1 The measures in Annex 2 are the measures ArktIQ has implemented in the Service. ArktIQ may improve them over time and will not reduce the overall level of protection during the term.

10.2 The public security overview describes the measures in more detail and is kept current.

11. Deletion and return of data

11.1 At any time during the term, a workspace owner can export the entire Workspace as a package of newline-delimited JSON with every attachment and document.

11.2 At the end of the subscription, or earlier at the Customer's choice, a workspace owner schedules deletion of the Workspace in the Service after taking an export. The Workspace is read-only and restorable for 30 days, then all Customer Data is purged from the production systems, including closed periods, billing history, documents, and exports. Backups containing the data age out under the 30-day backup retention, and any restore from backup replays the deletion before data is served.

11.3 ArktIQ retains after deletion only what EU, EEA, or Norwegian law requires it to retain, which for the Service is limited to bookkeeping records about the subscription itself, and the structural audit log of platform operations.

12. Audits and information

12.1 ArktIQ answers the Customer's reasonable written questions about the processing and provides documentation of the measures in Annex 2, the sub-processor list, restore drill results, and the release gate.

12.2 ArktIQ's documentation under clause 12.1 is the primary basis for demonstrating compliance. Where that documentation is not sufficient, the Customer, or an independent auditor bound by confidentiality and mandated by the Customer, may audit ArktIQ's compliance with this Agreement once every twelve months, or more often after a personal data breach or at a supervisory authority's request, on 30 days' written notice, during normal business hours, without disrupting the Service or exposing other customers' data. The Customer bears all costs of the audit, including the auditor's fees. ArktIQ may invoice the time it spends at its current hourly rates.

13. Transfers outside the EEA

13.1 ArktIQ processes and stores Customer Data on servers, object storage, and backups located in the EU, as listed in Annex 3.

13.2 ArktIQ does not transfer Customer Data to a country outside the EEA without the Customer's prior written instruction and a valid transfer mechanism under GDPR chapter V. Payment data the Customer gives to Stripe is subject to Stripe's own transfer safeguards and concerns the subscription, not Customer Data.

14. Liability, term, and law

14.1 Each party is liable under GDPR art. 82 for damage caused by processing that infringes the GDPR. The limitations of liability in the subscription terms apply to this Agreement except where the GDPR does not permit them.

14.2 This Agreement terminates when ArktIQ has deleted or returned all Customer Data under clause 11.

14.3 Norwegian law governs this Agreement. Disputes are subject to the courts of Norway, with Nord-Troms og Senja tingrett as the legal venue, unless mandatory law provides otherwise.

Annex 1: Description of the processing

Subject matter
Provision of the SAQ Service to the Customer.
Duration
Subscription term, plus 30-day deletion grace and 30-day backup retention.
Nature
Storage, organization, retrieval, transmission (notifications, email, documents, API), computation (reports, billing runs), rendering (PDF), export, backup, deletion.
Purpose
Ticketing, project management, time tracking, and client billing for the Customer and its clients.
Data subjects
Customer's staff; staff and contacts of the Customer's clients; other correspondents of the connected mailbox; persons mentioned in content.
Personal data
Identity and contact data (name, email, role, category, timezone, language); session data (IP address, browser identifier, times, method); content data (tickets, comments, attachments, email including headers and attachments, links, system events); time and billing data (entries with date, duration, notes; rates; allocations; timesheet documents); configuration containing personal data (verified domains, SSO claim mappings, SCIM users and groups, API keys and their holders); audit records (actor, action, target, reason, time).
Special categories
None intended. See clause 4.3.

Annex 2: Technical and organizational measures

Tenant isolation
Shared PostgreSQL schema with a workspace id on every tenant row and Row Level Security forced on every tenant table; the application role cannot bypass it; composite foreign keys within the workspace; cross-workspace reads only through fixed, audited platform functions on a separate database role and a private network listener.
Access control
Roles owner, admin, member, and client user with regular or elevated mode per project; visibility scoped by billing client; three comment audiences; explicit, logged viewer grants; the same authorization for the web app, email, API, and MCP; billing documents and rates behind a separate grant.
Authentication
NIST 800-63B passwords with breached-password check; passkeys; TOTP with recovery codes; two-factor mandatory for owners, admins, and operators; magic links single use and 15 minutes; OIDC single sign-on with verified domains, forced SSO, and SCIM; sessions with recorded method and assurance; re-authentication within 10 minutes for sensitive actions; API keys hashed, scoped, expiring, and revocable.
Encryption
TLS in transit; mailbox credentials and identity-provider secrets encrypted at rest with AES-256-GCM bound to the workspace; password and token hashes.
Logging and audit
Append-only audit log of privileged actions with actor, on-behalf-of, action, target, reason; descriptive payloads stored separately so redaction can purge them; email ingest log without subject, body, sender name, or attachment names; application logs without tenant identifiers in labels.
Operator access
Operators are named identities with TOTP, on a private listener; impersonation is read-only by default, needs re-authentication, shows a banner, expires, cannot mint tokens or change mailbox credentials, and is audited with a reason.
Application security
Strict Content Security Policy; Origin checks on state-changing requests; rate limits per address, identity, and key; uploads quarantined and type-checked, never served inline as HTML or SVG; Markdown and email HTML sanitized with remote images blocked; PDF rendering sandboxed without network; OWASP ASVS level 2 as reference.
Supply chain and releases
Dependency, secret, container, configuration, and static analysis scans on every change; no HIGH or CRITICAL finding ships; five-day minimum package age; images pinned by digest and signed, verified before deployment; automated accessibility and browser tests.
Availability and recovery
Continuous WAL archiving, weekly full and daily incremental backups to a separate versioned repository with 30-day retention; recovery point objective 5 minutes, recovery time objective 4 hours; quarterly restore drills; deletion and redaction manifests replayed on restore.
Data residency
Servers, object storage, and backups in EU regions.
Retention and deletion
Raw email 90 days; ingest log 180 days; export packages 7 days; deleted workspaces purged after 30 days; identity deletion by tombstone and pseudonymization; controlled redaction of documents with financial structure retained.
Organizational
Small team with named responsibility; confidentiality obligations; no analytics or third-party scripts; security reports acknowledged within two working days; changes to sub-processors announced 30 days in advance.

Annex 3: Sub-processors

Sub-processorProcessingLocation
Hetzner Online GmbH, Gunzenhausen, GermanyCloud servers, object storage (attachments, documents, exports, backups).Falkenstein, Germany, and Helsinki, Finland (EU).
Sendinblue SAS (Brevo), Paris, FranceDelivery of platform email to users: invitations, magic links, password resets, security and subscription notices.France (EU).

Stripe processes the Customer's payment data for the subscription as an independent provider, not as a sub-processor of Customer Data. Providers the Customer connects to its own Workspace (Microsoft 365, an OIDC identity provider, an IMAP host) are the Customer's providers. Gotenberg (PDF rendering) and pg-boss (job queue) run inside ArktIQ's own environment and are components of the Service, not sub-processors.