This Data Processing Agreement (“DPA”) forms part of the agreement between Kogniflow AS, Rambergveien 1, 3115 Tønsberg, Norway (“Kogniflow”), and the customer identified in the applicable order, account, or agreement (“Customer”). It is effective when the Customer accepts it, accepts terms that incorporate it, or otherwise enters into an agreement for the Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
“Covered Organization” means the organization whose accounting or related business data is processed through the Service. The Customer may be the Covered Organization itself or an accounting firm or other service provider authorized to act for a Covered Organization.
Kogniflow processes accounting and related business data to provide automated control, analysis, anomaly detection, insights, and collaboration functionality. This DPA governs that processing to the extent the data contains information relating to identified or identifiable individuals.
1. Scope and roles
This DPA applies to Kogniflow's processing of personal data on the Customer's behalf in connection with the Service (“Customer Personal Data”), whether the data concerns the Customer itself or a Covered Organization. The parties' roles depend on the Customer's relationship to the Covered Organization:
- If the Customer is the Covered Organization and determines the purposes and means of the processing, the Customer is the controller and Kogniflow is its processor.
- If the Customer processes personal data on behalf of a Covered Organization, the Customer is a processor, the Covered Organization is the controller, and the Customer appoints Kogniflow as its subprocessor.
Where Kogniflow acts as a subprocessor, references in this DPA to controller rights and instructions include the Customer's obligations to the relevant Covered Organization.
Each party will comply with applicable data-protection law, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Norwegian Personal Data Act where applicable. Kogniflow acts as an independent controller for account administration, contracting, website use, security, and other processing described in the Privacy Policy; that processing is outside this DPA.
2. Details of processing
The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are described in Annex 1. Processing continues for the term of the Service agreement and any limited period needed to return or securely delete Customer Personal Data, unless law requires longer retention.
3. Documented instructions
Kogniflow will process Customer Personal Data only on documented instructions from the Customer, including to provide, secure, maintain, and support the Service; enable Customer-selected integrations; and comply with this DPA and the Service agreement. The agreement, the Customer's configuration and authorized use of the Service, and written support requests constitute documented instructions.
Kogniflow will not use Customer Personal Data to train or improve its own or third-party AI models, or authorize its AI providers to do so. AI processing to produce the Customer's requested analyses and outputs remains subject to the Customer's documented instructions. This restriction on model training does not mean that providers retain no data; any retention must comply with this DPA and the obligations imposed on subprocessors.
Findings and recommendations are decision support. The Customer is responsible for meaningful human review before taking action affecting an individual and must not use Service outputs as the sole basis for decisions producing legal or similarly significant effects on that individual without ensuring compliance with GDPR Article 22.
If law requires other processing, Kogniflow will inform the Customer before processing unless the law prohibits notice for important grounds of public interest. Kogniflow will promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law and may suspend the affected processing until the instruction is amended or confirmed as lawful.
4. Customer obligations
The Customer is responsible for:
- ensuring that its instructions, collection, and disclosure of Customer Personal Data are lawful, fair, transparent, and limited to what is necessary;
- having an appropriate legal basis, providing required notices, and responding to data subjects and authorities as controller;
- having the necessary authority and documented instructions for each Covered Organization, including any upstream permission required to appoint Kogniflow as a subprocessor;
- configuring access and integrations appropriately and maintaining accurate instructions;
- limiting special-category data to what is necessary for the instructed processing described in Annex 1, establishing an applicable GDPR Article 9 condition and safeguards, and not submitting criminal-offence data unless its processing is separately agreed and lawful; and
- notifying Kogniflow of constraints relevant to the processing.
5. Confidentiality and personnel
Kogniflow will limit access to Customer Personal Data to authorized personnel and suppliers who need access to provide or secure the Service. Persons authorized to process the data are subject to contractual or statutory confidentiality obligations, receive appropriate instructions, and must continue to protect the data after their access or engagement ends.
6. Security measures
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Kogniflow will maintain technical and organizational measures appropriate to the risk as required by GDPR Article 32. The current control areas are summarized in Annex 2 and on the Security page. Kogniflow may update measures as technology and risks change, provided that the overall level of protection is not materially reduced.
7. Subprocessors
The Customer gives Kogniflow general written authorization to use subprocessors. The current register, including functions, relevant processing locations, and transfer mechanisms, is available on the Subprocessors page. Kogniflow will impose written data-protection obligations on each subprocessor that are no less protective, in substance, than the obligations applicable to that processing under this DPA. Kogniflow remains responsible to the Customer for a subprocessor's performance of those obligations.
Kogniflow will give at least 30 days' notice before a new or replacement subprocessor begins processing Customer Personal Data, normally through email or an in-Service notice. The Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable solution. If no solution is available, the Customer may terminate the materially affected Service before the change takes effect without an early termination charge. Kogniflow will refund prepaid fees attributable to the unused period of the terminated Service.
8. Data subject requests
Taking into account the nature of processing, Kogniflow will provide reasonable assistance through appropriate technical and organizational measures so the Customer can respond to requests to exercise rights under applicable law. If Kogniflow receives a request relating to Customer Personal Data directly from a data subject, it will forward the request to the Customer without undue delay and will not respond substantively unless instructed or legally required. The Customer remains responsible for verifying and responding to the request.
9. Compliance assistance
Taking into account the nature of processing and information available to Kogniflow, Kogniflow will provide reasonable assistance with the Customer's obligations under GDPR Articles 32–36, including security assessments, personal-data-breach notifications, data protection impact assessments, and prior consultation with supervisory authorities. The scope and cost of assistance that goes beyond standard Service functionality may be agreed separately unless the need results from Kogniflow's breach of this DPA.
10. Personal data breaches
Kogniflow will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Kogniflow will not delay the initial notice while completing its investigation and may provide information in stages without undue further delay. As information becomes available, the notice will describe the nature of the breach, likely consequences, data and data-subject categories affected, measures taken or proposed, and a contact point. Kogniflow will take reasonable steps to contain, investigate, mitigate, and document the incident and will cooperate with the Customer. Notification is not an admission of fault or liability.
11. International transfers
Kogniflow will not transfer Customer Personal Data outside the European Economic Area unless the transfer is permitted under applicable law. Where an adequacy decision does not apply, Kogniflow will use an appropriate safeguard, such as the European Commission's Standard Contractual Clauses, including Module Two for controller-to-processor transfers or Module Three for processor-to-subprocessor transfers as applicable, together with supplementary measures where required. Details for current subprocessors are shown in the Subprocessor register.
12. Return and deletion
At the Customer's choice, Kogniflow will return Customer Personal Data or delete it after the relevant Service ends, and will delete remaining copies, unless applicable law requires retention. The Customer must communicate its choice before termination or within an agreed export period. Where self-service export does not cover the requested Customer Personal Data, Kogniflow will arrange its return in a commonly used electronic format.
Kogniflow will make the applicable export period, deletion timetable, and maximum backup retention period available to the Customer on request and confirm the arrangements when handling termination. Data in protected backups may remain until that retention period expires; it will be isolated from ordinary use and remain protected. Kogniflow will confirm deletion on reasonable request.
The Customer is responsible for ensuring that it or the relevant Covered Organization retains records required by applicable bookkeeping, anti-money-laundering, or other laws. The Service does not replace the Customer's statutory archive unless expressly agreed in writing. Those obligations do not by themselves authorize Kogniflow to retain Customer Personal Data after the agreed processing ends.
13. Information and compliance audits
Kogniflow will make available information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA. The Customer may audit the relevant processing itself or through an independent auditor bound by confidentiality. Unless a personal data breach, supervisory-authority request, or reasonable evidence of non-compliance justifies otherwise, audits are limited to once per 12-month period, on reasonable advance notice, during normal business hours, and in a manner that protects other customers and does not unreasonably disrupt operations. Existing independent reports and remote documentation may be used first where they provide adequate assurance.
Audits under this section concern Kogniflow's compliance with this DPA. Relevant supporting information may include descriptions of security controls, data handling and deletion procedures, and available assurance reports, shared under appropriate confidentiality safeguards. Disclosure is limited to information necessary to demonstrate compliance; unrelated commercial information and internal pricing or cost calculations are outside the scope of these audits.
14. Term, priority, and liability
This DPA remains in force while Kogniflow processes Customer Personal Data. If this DPA conflicts with the Service agreement on data protection, this DPA controls. Liability under this DPA is subject to the exclusions and limitations in the Service agreement to the extent permitted by law. Nothing in this DPA limits a data subject's rights or either party's responsibility that cannot legally be limited.
Kogniflow will give at least 30 days' notice of proposed material changes to this DPA by email or another agreed notice channel, explaining the changes and proposed effective date. Material changes require the Customer's acceptance. If the Customer does not accept, the previously accepted DPA continues to govern ongoing processing unless the Service is ended in accordance with the agreement. Publishing a new version or continuing scheduled synchronization does not by itself constitute acceptance of a material change.
If a proposed material change reduces the Customer's data-protection rights or increases its obligations, the Customer may instead terminate the materially affected Service before the proposed effective date without an early termination charge. Kogniflow will refund prepaid fees attributable to the unused period of that Service. Changes strictly required by applicable law may be made on shorter notice where necessary to meet a legal deadline; Kogniflow will explain the requirement and give as much advance notice as practicable. Non-material corrections that do not reduce protection or change the parties' obligations may take effect on publication.
This DPA is provided in English, including when accessed through the Norwegian-language website.
15. Notices and contact
Privacy notices, instructions, and questions under this DPA should be sent to support@kogniflow.com. Formal notices may also be sent to Kogniflow AS, Rambergveien 1, 3115 Tønsberg, Norway. The Customer must keep its administrative and privacy contact details current. Each party will use the other party's designated contact for incident and subprocessor notices.
Annex 1: Description of processing
| Subject matter | Processing of accounting and related business data to provide a web-based analytics and control service, including ingestion, storage, organization, analysis, anomaly detection, presentation of findings and insights, collaboration, support, and Customer-selected integrations. |
|---|---|
| Duration | The term of the Service agreement plus the limited return, deletion, backup, or legal retention periods described in this DPA. |
| Nature and purpose | Automated and user-initiated collection, transmission, structuring, storage, retrieval, comparison, anomaly detection, analysis, generation of insights and recommendations, collaboration, support, security, and deletion, solely to provide and protect the Service under the Customer's instructions. |
| Data subjects | Customer users; employees, contractors, owners, directors, customers, suppliers, contacts, and other individuals represented in the Customer's or Covered Organizations' accounting, payroll, document, and business records. |
| Personal data | Identity and contact details; user and access data; employment and payroll-related data; customer and supplier records; transaction, accounting, tax, payment, and bank reference data; document content and metadata; communications, support records, audit trails, and technical logs. Exact content depends on the Customer's sources and configuration. |
| Special categories | Payroll, personnel-related accounting entries, and supporting documents may contain information revealing health or trade-union membership, including sickness-related payments or union deductions. Depending on the connected sources, this may be a recurring part of the records. Processing is limited to the Customer's documented instructions and requires an applicable GDPR Article 9 condition and appropriate safeguards established by the controller. The Service does not require collection of additional special-category data for its own purposes. |
| Primary hosting and storage | The Service's primary hosting and storage region is Germany in the European Economic Area, using Amazon Web Services. Subprocessor processing, including AI functionality and support, may involve other locations as described in the Subprocessor register and is subject to section 11. |
| Frequency | Continuous or recurring for connected sources and user activity, and on demand for uploads, analyses, support, exports, and deletion. |
Annex 2: Technical and organizational measures
- Access control: authenticated access, authorization by role and business need, privileged-access restrictions, and removal of access when no longer required.
- Data protection: protection of data during transmission and storage, environment separation, secret management, and controls intended to prevent unauthorized disclosure or alteration.
- Logging and monitoring: security-relevant event logging, monitoring, and investigation processes proportionate to risk.
- Secure development: controlled changes, code review, testing, dependency management, and remediation of identified vulnerabilities.
- Resilience: backup and recovery arrangements, service monitoring, and continuity measures appropriate to the Service.
- Incident response: documented escalation, containment, investigation, recovery, communication, and post-incident improvement processes.
- Supplier management: due diligence, written privacy and security obligations, access limitation, and periodic review proportionate to supplier risk.
- Data lifecycle: retention controls, secure deletion processes, and access deprovisioning at termination.
This DPA is designed to address GDPR Article 28 and reflects the Norwegian Data Protection Authority's guidance. Customers should assess whether additional instructions or safeguards are required for their particular processing.