Data Processing Agreement

Last updated: 15 June 2026

norppa.io provides this Data Processing Agreement in several languages for convenience. In case of any conflict or ambiguity, the English version prevails.


This Data Processing Agreement (DPA) forms part of the Terms of Service between Norteris Oy (Business ID 3621127-2, Sturenkatu 26, 00510 Helsinki, Finland), operating the norppa.io service (Processor), and the subscribing organisation (Controller). It governs the processing of personal data by norppa.io on behalf of the Controller in connection with the norppa.io service, as required by Article 28 of Regulation (EU) 2016/679 (GDPR).

1. Roles and Scope

The Controller determines the purposes and means of the security intelligence programme: specifically, which supplier domains to monitor and how to act on findings. norppa.io acts as Processor by operating the technical infrastructure, running intelligence queries, and generating findings and reports on the Controller's behalf.

Where norppa.io processes personal data for its own purposes (e.g. customer account data and billing), it acts as an independent data controller and this DPA does not apply to that processing. That processing is described in our Privacy Policy.

2. Subject Matter of Processing

  • Nature: automated external intelligence queries against publicly available and threat-intelligence sources; storage and delivery of findings and reports.
  • Purpose: to provide the Controller with security findings and NIS2 compliance evidence relating to submitted supplier domains.
  • Duration: for the term of the subscription agreement, plus a 90-day post-termination data retention period.

3. Categories of Personal Data

Processing under this DPA may involve the following categories of personal data, retrieved incidentally from publicly available sources during intelligence gathering:

  • Email addresses (e.g. WHOIS records, breach datasets, paste sites)
  • Names associated with domain registrations or organisational records
  • Business contact information from public registries
  • Credential fragments appearing in breach or paste data (hashed or partial)

norppa.io does not intentionally collect special category data (Art. 9 GDPR) and will notify the Controller promptly if such data is encountered.

4. Controller's Obligations

The Controller warrants that:

  • It has a lawful basis under GDPR to instruct norppa.io to conduct intelligence queries on submitted domains.
  • Submitted domains and targets have been identified through a legitimate supply chain risk management process.
  • The Controller will respond to any data subject requests that cannot be resolved by norppa.io alone and will inform norppa.io of any regulatory inquiries related to the processed data.

5. Processor's Obligations

norppa.io commits to:

  • Process only on instructions: process personal data solely for the purpose of providing the Service and in accordance with the Controller's documented instructions. If norppa.io is required to process data by EU or Finnish law, it will inform the Controller unless prohibited by applicable law.
  • Lawful instructions: immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable EU or Member State data protection law.
  • Confidentiality: ensure that all personnel with access to personal data are bound by appropriate confidentiality obligations.
  • Security: implement and maintain appropriate technical and organisational measures as described in Section 6.
  • Sub-processors: engage sub-processors only as listed in Section 7, impose equivalent data protection obligations on them by contract, and remain fully liable to the Controller for each sub-processor's performance of its obligations.
  • Data subject rights: assist the Controller in responding to data subject requests, taking into account the nature of the processing.
  • Data breach notification: notify the Controller without undue delay (and no later than 48 hours) after becoming aware of a personal data breach affecting data processed under this DPA, providing the information required under Art. 33(3) GDPR to the extent available.
  • Data protection impact assessments: assist the Controller in carrying out data protection impact assessments and prior consultations with the supervisory authority (Art. 35–36 GDPR), insofar as the processing under this DPA is relevant.
  • Deletion or return: on termination, delete or return all personal data processed under this DPA within 90 days unless retention is required by law.
  • Audit: make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits or inspections conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality obligations.

6. Technical and Organisational Security Measures

norppa.io maintains the following measures (Art. 32 GDPR):

  • Access control: production systems accessible only via authenticated sessions; admin interfaces restricted to localhost; no inbound internet connections to scanning infrastructure.
  • Encryption in transit: all data transmitted between services uses TLS 1.2 or higher.
  • Encryption at rest: customer data, reports and backups are encrypted at rest.
  • Infrastructure isolation: assessment infrastructure is not publicly reachable and operates from stable external IP addresses; no inbound connections from the internet are accepted.
  • Data minimisation: findings are scoped to the submitted domain; no cross-customer data access is possible by design (strict customer_id isolation at application and database level).
  • Data location: core customer data stored on EU infrastructure (Frankfurt region); all edge components configured to the EU region. No data stored outside the EU.
  • Backup: daily automated encrypted backups stored offline.
  • Review: periodic internal security code reviews and dependency audits.

7. Sub-processors

norppa.io engages the categories of sub-processor listed below, for which the Controller provides general written authorisation. A complete list naming each entity is available to the Controller on request. norppa.io will give the Controller at least 30 days' prior notice of any intended addition or replacement of a sub-processor, during which the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate the affected Service.

  • EU infrastructure provider (US parent, EU-region data storage): content delivery, application hosting, session-token storage, encrypted report storage and the SAQ/customer database. All customer data is stored within EU data centres. Standard Contractual Clauses (EU 2021/914) are in place as a safeguard for any incidental administrative access by the US parent entity.
  • EU payment processor (Ireland): card payment processing and subscription management for self-service plans. Processing takes place within the EU; acts as an independent controller for billing data. No transfer to a third country.
  • EU business bank / invoicing provider (Finland): business banking and the manual invoicing of annual subscriptions paid by bank transfer. Acts as an independent controller for payment and bank-transfer data. EU only.
  • EU transactional email provider (France): delivery of transactional and notification email (authentication links, security alerts, customer communications). EU data residency; encrypted in transit (TLS). No transfer to a third country.

8. International Data Transfers

In the ordinary course, personal data processed under this Agreement does not leave the European Union or EEA. Core customer data (Frankfurt region), card payment processing (Ireland), annual invoicing (Finland) and email delivery (France) are all EU-based. The infrastructure provider stores customer data within the EU; for any incidental administrative access by its US parent, Standard Contractual Clauses (EU 2021/914) are in place. No transfer is made to a third country without an adequate safeguard under Chapter V GDPR.

9. Duration and Termination

This DPA is effective for the duration of the subscription agreement. On expiry or termination, norppa.io will, at the Controller's election, return or delete all personal data processed under this DPA within 90 days, and provide written confirmation of deletion.

10. Governing Law

This DPA is governed by Finnish law and the applicable provisions of the GDPR. Disputes shall be resolved before the District Court of Helsinki.

11. Contact

Data protection enquiries: [email protected]

Supervisory authority: Finnish Data Protection Ombudsman, tietosuoja.fi