Version 1.1
Last updated: August 18, 2026
Processor: Grey Intelligence AS, organisation number 938095868 ("Grey").
Controller: the Customer identified in the applicable Order or online checkout ("Customer").
This Data Processing Agreement ("DPA") forms part of the agreement between Grey and the Customer (the "Agreement"). It applies only to the extent Grey processes Customer Personal Data on the Customer's behalf as a processor. It becomes effective when an authorised representative of the Customer accepts it during checkout or when the parties execute it separately.
1. Definitions and priority
"Applicable Data Protection Law" means the GDPR, the Norwegian Personal Data Act, and other data-protection law applicable to the processing. "Customer Personal Data" means personal data contained in Customer Data that Grey processes as a processor on the Customer's behalf. "GDPR" means Regulation (EU) 2016/679 as incorporated into EEA law. "Security Incident" means a personal data breach affecting Customer Personal Data. "Subprocessor" means another processor engaged by Grey to process Customer Personal Data.
Terms defined in the Agreement have the same meaning in this DPA. If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA prevails. The Agreement otherwise remains in effect.
2. Roles and instructions
The Customer is the controller of Customer Personal Data, or a processor acting on a controller's behalf. Grey is the processor, or a subprocessor where the Customer acts as a processor.
Grey will process Customer Personal Data only on the Customer's documented instructions, including the Agreement, this DPA, the Customer's configuration and use of the Service, and other written instructions accepted by Grey. Grey may process Customer Personal Data where required by law, in which case Grey will inform the Customer before processing unless the law prohibits notice.
Grey will promptly inform the Customer if, in Grey's opinion, an instruction infringes Applicable Data Protection Law. Grey may suspend the affected processing until the parties resolve the issue.
3. Customer obligations
The Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its processing and instructions. The Customer will establish a valid legal basis, give required notices, respond to data-subject requests, and ensure it has the rights needed to provide Customer Personal Data to Grey.
The Customer will not instruct Grey to process special-category data, criminal-offence data, national identity numbers, payment-card data, or other highly sensitive data unless the parties expressly agree in writing on appropriate safeguards.
4. Confidentiality and personnel
Grey will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only where necessary for their duties. Grey will provide appropriate data-protection and security guidance to relevant personnel.
5. Security
Grey will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The measures in Annex 2 form part of this DPA.
The Customer is responsible for securely configuring its workspace, managing authorised users and credentials, and using available security features. The Customer acknowledges that no system can guarantee absolute security.
6. Subprocessors
The Customer gives Grey general written authorisation to engage Subprocessors needed to provide and secure the Service. Grey will impose written data-protection obligations on each Subprocessor that provide at least the protection required by this DPA for the processing concerned. Grey remains responsible for its Subprocessors' performance of those obligations to the extent required by Applicable Data Protection Law.
The current Subprocessor schedule at https://grey.app/subprocessors is incorporated into this DPA and identifies each authorised Subprocessor, its function, relevant data categories, and processing location. By accepting this DPA, the Customer generally authorises the Subprocessors listed in schedule version 2026-08-18.2. Before adding or replacing a Subprocessor that may process Customer Personal Data, Grey will update the schedule and give the Customer reasonable prior notice through the registered account or billing email, sufficient to provide an opportunity to object before the Subprocessor begins processing, unless an urgent security or legal need requires shorter notice.
The Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot, Grey may avoid using the Subprocessor for that Customer or the Customer may terminate the affected Service before the Subprocessor begins processing. This is the Customer's sole remedy for an unresolved objection.
Customer-authorised integrations that the Customer contracts with or controls directly are not Grey's Subprocessors merely because the Service connects to them.
7. International transfers
Grey will not transfer Customer Personal Data outside the EEA unless the transfer complies with Applicable Data Protection Law. Where an adequacy decision does not apply, Grey will use an approved transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required.
At the Customer's reasonable request, Grey will provide information needed to assess relevant transfer safeguards, subject to confidentiality and security restrictions.
8. Data-subject requests
Taking into account the nature of the processing, Grey will provide reasonable assistance through appropriate technical and organisational measures so the Customer can respond to requests to exercise data-subject rights.
If Grey receives a request concerning Customer Personal Data directly from a data subject, Grey will refer the request to the Customer and will not respond on the Customer's behalf unless legally required or authorised by the Customer.
9. Compliance assistance
Taking into account the nature of processing and information available to Grey, Grey will provide reasonable assistance with the Customer's obligations concerning security, breach notifications, data-protection impact assessments, and prior consultation with supervisory authorities.
Grey may charge reasonable fees for assistance that is disproportionate to the Service or results from the Customer's instructions, unless the assistance is required because Grey breached this DPA.
10. Security Incidents
Grey will notify the Customer without undue delay after becoming aware of a Security Incident. The notice will include available information reasonably needed for the Customer's assessment and notifications, including the nature of the incident, affected data and data subjects where known, likely consequences, and measures taken or proposed.
Grey may provide information in phases as it becomes available. Grey's notification does not acknowledge fault or liability. The Customer is responsible for notifying supervisory authorities and data subjects unless Applicable Data Protection Law assigns that duty to Grey.
11. Return and deletion
During the Agreement, the Customer may retrieve Customer Personal Data through available Service functionality. The Customer must export data it wishes to retain before access ends.
At the Customer's choice, Grey will delete or return Customer Personal Data after the relevant Service ends and will delete remaining copies without undue delay in accordance with Grey's documented retention and deletion procedures, unless law requires retention. Customer Personal Data in protected backups may remain until overwritten or deleted through ordinary backup cycles. While retained in backups, it will remain protected, will not be used for another purpose, and will be deleted again if restored to an active system.
12. Information and audits
Grey will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer will first use current independent audit reports, certifications, security documentation, and written responses made available by Grey.
If that information is insufficient, the Customer may conduct one audit per 12-month period on reasonable prior written notice. Additional audits are permitted following a Security Incident, where the Customer has reasonable evidence of material non-compliance, or where required by Applicable Data Protection Law or a supervisory authority. Audits must occur during normal business hours unless urgency requires otherwise, avoid unreasonable disruption, protect other customers and Grey's confidential information, and be performed by an independent auditor bound by confidentiality. The Customer bears its audit costs unless the audit identifies Grey's material breach of this DPA. These procedural safeguards do not restrict audit or inspection rights that cannot lawfully be limited under Applicable Data Protection Law.
13. Term and liability
This DPA continues while Grey processes Customer Personal Data. Obligations that by their nature continue after termination, including confidentiality, deletion, and audit rights concerning prior processing, will survive.
Liability arising from this DPA is subject to the exclusions and limitations in the Agreement to the maximum extent permitted by law. Nothing limits data-subject rights or regulatory powers under Applicable Data Protection Law.
14. Governing law
This DPA is governed by the law and dispute provisions of the Agreement, except where Applicable Data Protection Law requires otherwise.
Annex 1: Processing details
Subject matter: Processing Customer Personal Data as necessary to provide, maintain, secure, and support the Service according to the Customer's instructions.
Duration: The term of the Agreement and, after it ends, until deletion or return under Section 11 is completed.
Nature and purpose: Collection, receipt, hosting, storage, organisation, retrieval, consultation, analysis, enrichment, transformation, transmission, export, synchronisation, support, security monitoring, restriction, and deletion as initiated by the Customer or necessary to provide the Service.
Data subjects: Customer personnel and authorised users; the Customer's prospects, leads, applicants, candidates, CRM contacts, business contacts, service providers, and other individuals whose personal data the Customer submits or directs Grey to process.
Personal-data categories: Names, professional contact details, employer and role information, professional profiles, company affiliations, CRM identifiers and records, uploaded file contents, Customer queries and instructions, integration data, account identifiers, and relevant usage and security information.
Special-category data: Not intended. The Customer must not submit it without a separate written agreement.
Frequency: Continuous or occasional, depending on the Customer's use of the Service.
Controller instructions and rights: As described in the Agreement, this DPA, and the Customer's documented use and configuration of the Service.
Annex 2: Technical and organisational measures
- Access control based on job responsibilities and least-privilege principles.
- Individual authentication, credential controls, and organisation-scoped authorisation.
- Encryption in transit using current transport security and encryption at rest for production data stores that hold Customer Personal Data.
- Tenant scoping and logical separation of customer workspaces.
- Logging and monitoring designed to detect unauthorised access, abuse, and operational failures.
- Secure development, dependency management, change review, and vulnerability remediation practices proportionate to risk.
- Backup, recovery, availability, and incident-response procedures proportionate to the Service.
- Data minimisation, retention controls, and secure deletion procedures.
- Confidentiality obligations and security guidance for authorised personnel.
- Periodic review of the effectiveness and appropriateness of these measures.