Auftragsverarbeitungsvertrag
Gültig ab 04.08.2026
Would you like this document in your own language? Contact us at hello@lekko.tech.
1. Roles and scope
This data processing agreement (the "Agreement") forms part of the terms between NelMil AS ("NelMil", "we", "the processor") and the customer (the "Customer", "the controller"), and applies when the Customer uses Lekko to process personal data.
The Agreement is entered into pursuant to article 28 of the General Data Protection Regulation (EU 2016/679, "GDPR") and other applicable data protection legislation. In the event of a conflict between the Agreement and the terms in matters concerning the processing of personal data, the Agreement prevails.
The Customer is the controller and NelMil is the processor for personal data processed through Lekko.
2. Purpose and duration
The service. Lekko is a cloud service (SaaS) for internal control of playground equipment: distributing and carrying out inspections, registering and following up deviations, and generating documentation.
Duration. The Agreement applies for as long as the Customer's subscription lasts, and for any subsequent period during which NelMil processes personal data on the Customer's behalf.
Nature and purpose of the processing. Operation, storage, transfer and processing of personal data as necessary to deliver Lekko, including sending inspection and reminder notifications, recording completed work and deviations, and generating reports and documentation.
Categories of data subjects. The Customer's employees, contractors, board members, administrators and others who are given access to Lekko, including persons with inspection access.
Categories of personal data. Identity data (name), contact data (email address), organisational affiliation, activity and login logs with timestamps, and limited technical metadata (IP address and browser information).
3. Obligations of the processor
NelMil shall:
- Process personal data only on documented instructions from the Customer, as set out in the terms, this Agreement and the Customer's own configuration of Lekko. The instructions include operation, security, prevention of misuse, troubleshooting and maintenance of Lekko.
- Ensure that persons authorised to process the personal data are subject to a duty of confidentiality that continues after the engagement has ended.
- Implement the technical and organisational measures described in section 7.
- Use sub-processors only in accordance with section 4.
- Assist the Customer, as far as possible and taking into account the nature of the processing, in responding to requests concerning data subject rights under GDPR chapter III.
- Assist the Customer in complying with the obligations under GDPR articles 32 to 36.
- Make available to the Customer the information necessary to demonstrate compliance with the obligations under GDPR article 28.
- Notify the Customer if, in NelMil's assessment, an instruction infringes the GDPR or other applicable data protection legislation.
4. Sub-processors
The Customer gives NelMil general authorisation to use sub-processors to deliver Lekko, on the conditions set out in this section.
The list of sub-processors in force at any given time, including places of processing and transfer mechanisms, is published at lekko.tech/sub-processors and forms part of the Agreement.
NelMil shall:
- Ensure that each sub-processor is subject to data protection obligations meeting the requirements of GDPR article 28(4).
- Remain liable to the Customer for the sub-processor's performance of its obligations.
- Give advance notice of any addition or replacement of sub-processors.
If the Customer objects to a new sub-processor on reasonable data protection grounds, and the parties do not agree on a solution, the Customer may terminate the affected service in accordance with the terms.
5. International transfers
If personal data is transferred outside the EEA to a country without an adequate level of protection (an adequacy decision), NelMil shall ensure a valid transfer mechanism. Such mechanisms include the EU standard contractual clauses (SCCs), the EU-US Data Privacy Framework, or other lawful transfer mechanisms under applicable data protection legislation.
The transfer mechanism for each sub-processor is set out at lekko.tech/sub-processors.
6. Personal data breaches
NelMil shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under the Agreement.
The notification shall, to the extent the information is available, include:
- The nature of the breach, including the categories and approximate number of data subjects and records affected.
- The likely consequences of the breach.
- Measures taken or proposed to address the breach.
- A point of contact for further information.
NelMil shall cooperate with the Customer and provide reasonable assistance so that the Customer can comply with its notification obligations under GDPR articles 33 and 34.
7. Technical and organisational measures
NelMil implements technical and organisational measures to protect personal data in accordance with GDPR article 32.
Access to personal data is restricted through role-based access control. Login is by one-time link sent by email (magic link), without a password. Everyone with access to personal data is subject to a duty of confidentiality.
Personal data is encrypted in transit and at rest using recognised mechanisms. Backups are taken regularly, and administrative actions are logged. NelMil follows secure development practices, including code review and monitoring of dependencies, and has a documented process for incident handling. Sub-processors are subject to data protection obligations in line with this Agreement.
The measures may be updated over time, provided that the level of protection is not materially weakened.
8. Audit
NelMil shall make available to the Customer the information necessary to demonstrate compliance with the Agreement.
On reasonable written notice, the Customer (or an independent auditor engaged by the Customer and reasonably acceptable to NelMil) may audit NelMil's processing under the Agreement, no more than once per calendar year, unless applicable law requires otherwise or there has been a confirmed personal data breach.
NelMil may fulfil its obligations under this section by providing up to date third-party audit reports, certifications or equivalent documentation where such documentation is reasonably available.
9. Data subject rights
Taking into account the nature of the processing, NelMil shall, as far as possible, assist the Customer through appropriate technical and organisational measures so that the Customer can fulfil its obligation to respond to requests concerning data subject rights under GDPR chapter III.
If NelMil receives a request directly from a data subject regarding personal data processed on the Customer's behalf, NelMil shall forward the request to the Customer without delay, and shall not respond itself unless authorised to do so by the Customer.
10. Return or deletion of personal data
Before the subscription is terminated or expires, the Customer may export reports and documentation from Lekko using the available export functionality (PDF/CSV where offered).
After termination, the Customer may instruct NelMil either to return or to delete all personal data processed on the Customer's behalf. In the absence of such an instruction within thirty (30) days of termination, NelMil will delete the personal data within ninety (90) days thereafter.
Retention beyond this is permitted only where required by applicable law, or on documented instruction from the Customer. Personal data may remain in backups for a limited period in accordance with backup routines, and is deleted thereafter.
11. Liability
Each party's liability in connection with the Agreement is subject to the limitations and exclusions of liability set out in the terms, unless such limitations or exclusions are prohibited under applicable data protection legislation.
12. Duration and termination
The Agreement takes effect when the Customer accepts the terms, and applies for as long as the Customer's subscription lasts and for any subsequent period during which NelMil processes personal data on the Customer's behalf.
Termination of the terms automatically terminates the Agreement, subject to those obligations which by their nature survive termination, including sections 7, 10 and 11.
13. Governing law and venue
The Agreement is governed by Norwegian law. Disputes arising in connection with the Agreement fall under the jurisdiction of the Norwegian courts, with Oslo District Court as the agreed venue, unless mandatory law in the Customer's jurisdiction provides otherwise.
Contact
For questions about this data processing agreement, contact us at:
NelMil AS Terrasseveien 31 E, 1363 Høvik, Norway hello@lekko.tech