Software Subscription Agreement
Last updated September 2026
This Software Subscription Agreement, together with its appendices and any written offer or order confirmation issued by Visense to Customer (collectively, the "Agreement") govern the Customer's software subscription and all use of software-services, and provision of related support and services to the Customer – including the Visense user portal - (collectively, the “Services”) ordered by the Customer from Visense AS ("Visense"). The “Customer” shall mean the company purchasing the Services from Visense. By purchasing a subscription to the Services, Customer agrees to be bound by the terms of this Agreement.
1. Grant of Rights
1.1 Subject to the Customer's full compliance with the Agreement and payment of all applicable fees, Visense hereby grants to the Customer, subject to the terms and conditions of the Agreement, a limited, non-exclusive, payable, non-sublicensable, non-transferrable and revocable right to use the Services until the Agreement is terminated according to Section 11.
1.2 The Customer's use of the Services shall be limited to use for internal business purposes and for its own use only, which for the sake of clarity shall not include granting access or use by any entity or person other than the legal entity identified as the Customer and its individuals authorized by Customer to use the Services on Customer’s behalf, which may include employees or contractors of the Customer’s Affiliates, on the terms and conditions of the Agreement (the “Authorized Users”), and may reassign subscription access to different Authorized Users at any time via Visense’s website or portal. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the Customer. The Customer shall be responsible for all use of the Services and adherence to the Agreement by its Authorized Users.
1.3 The Customer's use of any third-party deliverables included in the Services is governed by this Agreement and the at all times current and applicable third-party terms, to which Customer shall be considered to be bound when first assuming use of the Services.
2. Fees and payment
2.1 The fees payable for the Customer's software subscription, the available subscription levels and payment methods, and the applicable invoicing frequency are as selected by, and presented to, the Customer on Visense's website at the time the subscription is created. Unless otherwise set out in the Visense website, written offer to Customer, or invoice, all fees are listed in NOK and are exclusive of VAT or similar taxes, and payments via invoice are due fourteen (14) days after receipt of correct invoice. All fees are non-refundable.
2.2 If the Customer fails to make any undisputed payment when due, then, without limiting Visense's other remedies available under the Agreement or applicable law, Visense reserves the right to suspend or terminate the Customer's access to the Services if payment remains outstanding ten (10) days’ after written notice thereof and until full payment has been made. Visense shall also have the right to claim interest on any overdue payments pursuant to Act No. 100 of 17 December 1976 relating to Interest on Overdue Payments (Late Payment Interest Act).
2.3 Visense reserves the right to adjust the software subscription fees. Visense will provide the Customer with a minimum of one (1) month written notice detailing the nature of the change and the consequent fee adjustment.
3. Support and updates
3.1 Terms and conditions for access to support and maintenance services, as well as availability and reporting procedures are set out in the SLA, attached as Appendix 1 hereto.
3.2 The Customer accepts that, to the maximum extent allowed by applicable law, the remedies set out in the SLA and in this Section 3 shall be the sole and exclusive remedies of Customer in respect of software Service Level failures and third-party software services.
3.3 Visense is committed to the continuous improvement of the Services. Visense may, but is under no obligation to, make improvements, expand, modify or remove functionality, or correct any errors or deficiencies in the Service. This may include automatic updating or upgrading of the software provided as part of the Services without any additional notice to Customer. Visense shall not make changes that materially degrade core functionality of the Services as subscribed to by the Customer without providing the Customer at least one (1) month’s prior written notice and the right to terminate its subscription without penalty.
3.4 Visense may choose to offer additional functionality as part of the Services, that are not considered updates or patches to the Services. Such additional functionality may be subject to additional payment from Customer, if Customer wishes to acquire such functionality. If at any time the Customer wishes to include such additional functionality or change or extend its subscription to the Services beyond the scope defined in its existing subscription, such changes may be made through Visense's website/portal, to the extent made available by Visense.
4. Restrictions on use of the Services
4.1 The Customer shall always remain responsible for its conduct and Customer Data (as defined below) while using the Services and the networks, infrastructure and access credentials used to access the Services.
4.2 The Customer shall not provide Customer Data, nor use the Services for any activity, that is illegal, harmful or fraudulent. The Customer shall:
4.2.1 always use the Services in compliance with and as permitted by applicable laws;
4.2.2 not misuse the Services, including through unauthorized access or interference with normal use, and shall not attempt to bypass or circumvent any security features, limitations, or functionality of the Services imposed by Visense on Customer’s account, or engage in web scraping or data scraping on or related to the Services, including collection of information through any software that simulates human activity, bots, or web crawlers;
4.2.3 not without Visense's prior written consent, probe, scan, penetrate, exploit or test the vulnerability or the security of any part of the Services or systems, networks or components used by Visense to provide the Services;
4.2.4 not, nor attempt to, modify, alter, adapt, translate, reverse engineer, decompile, disassemble, discover the source code, underlying ideas, algorithms, file formats, internal APIs or any other part of the Services in any way; and,
4.2.5 not use the Services or Visense's confidential information for developing or facilitating competing products or services.
4.3 Visense may monitor Customer's use of the Services or specific parts of the Services to determine compliance with this Agreement and any other operating rules established by Visense from time to time.
4.4 The Customer shall be responsible for safeguarding the Customer's access credentials. Credentials shall not be shared with third parties. The Customer shall be responsible for any activity occurring the Customer's account, other than activities which Visense is responsible for under the Agreement.
5. Suspension of Services
5.1 Visense may, without liability to the Customer, modify, suspend, disable, or terminate the Services or access to Customer Data, or any parts thereof, at any time and for any reason without notice if, subject to Visense’s reasonable judgement, necessary to remedy any breach of the Agreement or for security or technical reasons, e.g. (but not limited to) events of unauthorized third-party access, security attacks and breaches, distributed denial-of-service attacks or other events that may possibly harm Visense, the Services, the Customer or other Visense customers.
6. Intellectual Property Rights
6.1 Visense retains all intellectual and industrial property rights in and to the Services, including but not limited to trademarks, design, copyrights, visual representation, software, methods, know-how, trade secrets and similar. Nothing in this Agreement transfers any such rights to the Customer, save for the limited right to use the Services granted under Section 1 above.
6.2 Visense warrants that (i) it owns or holds valid licenses to the Services and all components thereof, and (ii) it has and will maintain full power and authority to grant the Customer the rights set out in this Agreement without requiring the further consent of any third party.
6.3 Visense also retains all rights to intellectual and industrial property rights in changes, improvements, developments and modifications to the Services made by Visense, even when based on a requirement or request from the Customer. If the Customer provides to Visense suggestions, enhancement requests, recommendations, statistics or other comments or information regarding experience with the Services ("Feedback"), the Customer agrees that Visense may use all Feedback provided in any manner and without limitation, attribution, or any compensation due in any form to the Customer or the person providing such Feedback.
7. Customer Data
7.1 The Customer shall remain the owner of Customer Data. “Customer Data” means data received by Visense from the Customer or the Authorized Users, including raw data and processed data, but shall exclude any information provided to Visense by Customer for use outside of the Services, and any feedback or suggestions regarding the functionality of the Services. The Customer shall, to the extent it is not strictly required for using the Deliverables, refrain from entering personal data, as part of Customer Data.
7.2 The Customer is solely responsible for the lawfulness, reliability, integrity, and accuracy of Customer Data provided to Visense. Customer accepts and acknowledges that Customer shall remain solely responsible for maintaining, protecting, and making backups of all its Customer Data for its own business operations and other internal use.
7.3 The Customer represents and warrants that it has obtained, and will maintain throughout the term of this Agreement, all necessary rights, consents, and authorizations required to provide Customer Data to Visense and to authorize Visense to use, disclose, and otherwise process that Customer Data as contemplated by this Agreement.
7.4 Visense shall retain all rights, title, and interest in any derivative data, aggregated data, and any other data sets generated, compiled, or extracted from the Customer’s use of the Services, including analytics, databases, reports, statistics, or insights derived therefrom (collectively, “Derived Data”). Derived Data may include information derived from Customer Data but does not include the Customer Data itself, which remains the property of the Customer. Visense may use Derived Data for any purpose, but Derived Data shall not be disclosed, modified or otherwise utilized by Visense in a way which may allow third parties to identify – either directly or indirectly – any specific person, entity, address or similar personal information. To the extent that Derived Data involves or derives from personal data, Visense’s use thereof shall at all times be subject to and consistent with the Data Processing Agreement attached as Appendix 2 hereto and applicable data protection legislation, including the GDPR.
7.5 Visense may use Customer Data to provide, secure, improve and develop Visense's current and future products and services, including the Deliverables and Services, and is hereby granted a limited, worldwide, royalty-free, and sublicensable right to use the Customer Data for such purposes, provided that Visense shall not use the Customer Data for other purposes than explicitly permitted under the Agreement and not use the Customer Data in any way that compromises the confidentiality or integrity of the Customer Data. Visense may perform backups of Customer Data for its own use as granted hereabove.
8. Personal Data
8.1 Visense will take all reasonable steps to ensure the integrity and security of any personal data and information hosted on the Service in accordance with applicable law and regulations. Visense will not disclose or grant third-parties access to any such personal data for any purpose, and will not itself use such data for any other purpose, commercially or otherwise, than what is required to provide the Service hereunder. However, Visense will aggregate anonymous information, statistics and pattern analysis of use, including Derived Data and Customer Data, and is free to use such results in accordance with the use rights granted in Section 6 of this Agreement, subject to compliance with applicable personal data and information laws and regulations.
8.2 The roles and responsibilities of Visense with respect to processing of personal data is otherwise governed exclusively under the terms of a separate Data Processor Agreement entered into with the Customer upon commencement of the Service.
9. Limited Services Warranty
9.1 Visense warrants that it shall provide the Services with the degree of skill and care reasonably expected from a skilled and experienced supplier of services substantially similar to the Services.
9.2 In the event of a breach of warranty in this Section 9, the Customer shall notify Visense of the breach in writing and Visense shall attempt to remedy the breach without undue delay. If Visense fails to do so, the Customer may terminate the Agreement in accordance with the procedures set out in the Section 11, provided the breach is material.
9.3 Except as expressly provided in the Agreement and to the extent allowed by applicable law, the Services shall be provided "as is" and "as available". Visense does not make any warranties of any kind, express, implied, or statutory, including those of merchantability, fitness for a particular purpose, or any warranty regarding the availability, reliability, or accuracy of the Services except as explicitly set out in the Agreement. As the sole remedy in the event of errors, omissions or non-availability of the Services, Visense will, following the procedures of the SLA, use reasonable efforts to remedy the defect(s) to ensure the uninterrupted operations of the Services pursuant to the SLA. Customer waives, to the extent allowed by applicable law, all other claims for remedies other than those granted to Customer under the SLA and those set out in Section 9.1 of this Agreement.
9.4 The Customer shall defend, indemnify, and hold Visense harmless from any damages, third-party claims or liability resulting from use of the Customer Data, Customer’s actions or omissions related to information communicated through the Services, or Customer’s use of the Services in violation of the Agreement.
10. Confidentiality
10.1 The Parties are obliged to treat as confidential all information, know-how or other confidential material and any other material which is of such a nature that it should be considered confidential, and which is disclosed to the other Party through business activities regulated by this Agreement. Subject to compliance with the foregoing, each Party shall use the other Party’s Confidential Information solely for the purposes of: (i) performing its obligations under the Agreement; (ii) exercising its rights under the Agreement; (iii) evaluating and engaging in discussions regarding current or potential business relationships between the Parties; or (iv) such other purposes as the disclosing Party may specifically agree to in writing.
10.2 Without prejudice to Visense’s responsibilities with respect to confidential treatment, the Customer accepts that the existence of the Agreement and the identity of the Customer can be used by Visense as a reference in marketing materials and other promotion, unless otherwise is agreed in writing.
10.3 This obligation to observe confidentiality shall continue for five (5) years after the expiry or termination of the Agreement.
11. Term and Termination
11.1 The Customer's subscription to the Services commences on the date the Customer completes registration and subscribes to the Services via Visense's website or portal, on the terms (including the subscription period and invoicing frequency) presented to and accepted by the Customer at that time.
11.2 The Customer may terminate the subscription for convenience at any time via Visense's website or portal. Termination takes effect at the end of the then-current billing period, and the Customer remains liable for fees accrued up to that date.
11.3 Either Party may terminate the subscription with immediate effect by written notice if the other Party is in material breach of this Agreement and fails to remedy such breach within thirty (30) days of written notice, or becomes insolvent, bankrupt, or otherwise unable to meet its financial obligations in the ordinary course of business. In case of Customer's termination due to Visense's material breach, the Customer shall be reimbursed a proportionate amount for parts of any prepaid fees for the Services which cannot be used due to the termination.
11.4 Upon termination for any reason, (i) the Customer's right to access and use the Services ends immediately and the Customer shall cease all use of the Services and delete all copies of Documentation in its possession or control, (ii) all fees accrued but unpaid become immediately due, and (iii) any provision of this Agreement which by its nature should survive termination shall survive.
12. Liability and force majeure
12.1 With respect to parts of the Services which are delivered by third parties or sub-contractors, Visense's responsibility is limited to using reasonable endeavours to enforce Visense's rights under its agreements with such third parties and to pass onto the Customer the benefits resulting from enforcing such rights.
12.2 Visense shall not be liable for any incidental or consequential damages, including, but not limited to, the cost of labour, delay, lost profits, loss of data, or loss of goodwill arising out of the Services.
12.3 The remedies set out in the SLA and in Section 3.2 of this Agreement constitute the Customer's sole and exclusive remedy for any Service Level failure, software flaw, error, or non-availability of the Services. To the extent, Visense has any other liability for breach of this Agreement the aggregate maximum liability of Visense shall in any case be limited to the subscription fees paid by the Customer for the relevant Service during the last six (6) months prior to the event giving rise to the liability. For the avoidance of doubt, this limitation of liability shall be cumulative and not per incident.
12.4 Customer acknowledges and accepts that the Services are intended solely as an operational support tool providing data to assist the Customer in performing its own professional assessments and services, including but not limited to damage prevention, drying processes, and restoration services. All operational and professional decisions remain exclusively with the Customer and its personnel. Visense cannot be held liable for any decisions, omissions, actions or their consequences taken by Customer (including its personnel and subcontractors) based on, or in reliance upon, information, measurements, alerts, reports, or any other output issued or communicated through the Services, including the sensor platforms and related software solutions. This limitation applies regardless of whether such information was accurate, inaccurate, delayed, incomplete or unavailable.
12.5 Visense shall not be liable under the Agreement if prevented from or delayed in performing its obligations by acts or events beyond its reasonable control, including war, strike, lockout, riot, epidemic, pandemic, and natural catastrophes such as flood, fire, earthquake, hurricane, volcanic eruption, and sandstorm; utility, network or device failure external to Visense; and third-party attacks, including but not limited to distributed denial of service, directed attacks targeting Visense or its subcontractors, or impacting the Services (“Force Majeure”).
12.6 The Customer may terminate the Agreement in writing with fifteen (15) days’ notice if the Force Majeure lasts or is expected to last for more than three (3) months from the date on which the Force Majeure arose. Each of the Parties shall cover their own costs associated with such termination of the Agreement.
13. Changes
13.1 Visense may make minor changes to this Agreement, at any time without prior notice. Material changes, or changes that negatively affect the Customer's rights, shall be notified to the Customer at least one (1) month before taking effect, after which Customer may elect to terminate its subscription. The Customer's continued use of the Service after a change takes effect constitutes acceptance of that change.
13.2 Notwithstanding the above, Visense reserves the right to make changes required to comply with applicable laws, regulations, or governmental orders without any prior written approval from the Customer. Visense will use its reasonable efforts to minimize any adverse impact on the Customer arising from such changes.
14. General
14.1 This Agreement is governed by the laws of Norway, without regard to its conflicts of law principles. Any dispute arising out of or in connection with this Agreement, including tort claims, and which cannot be settled amicably, are subject to the exclusive jurisdiction of the courts of Oslo tingrett (Oslo District Court).
14.2 Visense shall be entitled to subcontract any of its obligations in respect of the Services and shall remain liable for all subcontracted obligations and its subcontractor's acts or omissions as for its own, save for as explicitly set out in this Agreement.
14.3 In the event of any conflict or inconsistency between this Software Subscription Agreement and its annexes, this Software Subscription Agreement shall prevail. Notwithstanding the foregoing, in matters concerning the processing of personal data, the Data Processing Agreement shall prevail over this Software Subscription Agreement and the SLA.
14.4 This Agreement is drawn up in the English language. If this Agreement is translated into any other language, the English version shall be the only binding document.
Appendix 1 - Service Level Agreement
This service level agreement (“SLA”) sets out the agreed service level for the Services provided by Visense to the Customer (“Service Level”).
This SLA describes which expectations the Customers can have with respect to Service availability and error correction in the event of disruption of the Service and other support requests. Additionally, this SLA is subject to and forms an integral part of the Agreement. The remedies offered to Customer in this SLA constitutes the Customer’s sole and exclusive remedy for any failure by Visense to meet the Service Level.
1. Overall responsibilities to maintain availability and performance of the Services
1.1 Visense undertakes to establish and maintain a service organisation available to assist the Customer in a timely and professional manner in the event of software malfunction or other errors to the service and/or additional service requests made by the Customer.
1.2 Even though Visense cannot guarantee that the Service will be performed error-free or uninterrupted, or that Visense will be able to remedy errors or defects that occur in the Service, Visense will use all reasonable efforts to ensure that all Customers have continued and reliable access to the Service. Consequently, Visense will respond to the Customer service inquires in accordance with the service levels and routines as described in this SLA.
2. Service availability
2.1 Visense is responsible for hosting, maintenance and supervision of the Service, including any applications deployed through the service, including technical infrastructure and functional performance. In principle, the Service shall be available for the Customer all day all year other than in the event of planned maintenance or scheduled downtime.
2.2 Any planned downtime with effect on end user applications with an expected downtime of 15 minutes or more shall be communicated to the Customer in advance without undue delay – to the extent reasonably possible for Visense. Scheduled downtime shall be planned to time periods when expected use of the Service is at a minimum (e.g., nights).
2.3 In the case of any unexpected downtime, Visense shall promptly investigate the root cause of the issue, and as soon as possible inform the Customer, including giving information about a plan of action and best estimate of time to completion.
2.4 Visense shall keep the Customer regularly informed with current status of the issue until the Service is restored. However, Visense cannot be held liable for any costs or loss, direct or indirect, that the Customer might incur as a result of lack of availability of the Service.
3. Reporting procedures
3.1 All inquiries concerning software flaws and errors under this SLA shall be reported to the Visense Service Desk via e-mail.
3.2 All inquiries shall include a clear and evident description of the situation and should thoroughly explain the behaviour of the event and its consequences for the use of the Service as well as a description of the proposed assistance needed.
4. Support
4.1 If Visense, following an assessment of a request from Customer, determines that a reported issue was caused by, or a reported inquiry is directly related to, the Services, Visense will respond to the inquiry and resolve any issues in accordance with this Section 4, at no cost for Customer. If Visense determines that the reported issue was not caused by the Services or are covered by the SLA exclusions in Section 5, Visense shall inform the Customer thereof without undue delay. Visense will have no obligation to resolve such issues. For the avoidance of doubt, the support services provided under this SLA do not trigger – or oblige Visense to conduct - any field service actions, nor impose any liability on Visense for a lack thereof.
4.2 Upon request, Visense may assist Customer with resolving issues not covered by this SLA, including requests for information or user assistance or training, subject to payment for such assistance at Visense’s then-current rates on a time and material basis, billable in 30-minute increments.
4.3 For the sake of clarity, support inquiries covered by this SLA are only meant to cover inquires directly related to the Services provided. Support inquires covered by this SLA do therefore not include inquiries regarding technical equipment, software, installations, or other products or services not directly delivered as part of the Services offered by Visense hereunder, such as – but not limited to – inquiries regarding third-party sensory equipment or guidance on damage restoration works.
4.4 Support services are provided only within normal office hours in Norway 0800-1600 CET, which does not include national holidays. Availability outside office hours may be available upon request and at applicable rates.
4.5 Visense will only provide support services as described herein within its stated office hours, unless otherwise has been agreed with the Customer in writing. Visense is obligated to respond to the Customer’s inquiry for support under this SLA during the next office day, but Visense does not guarantee that the issues will be resolved within any certain time frame.
5. SLA Exclusions
5.1 Visense is not responsible for any failure to meet any obligation under this SLA relating to software flaws, errors or unavailability for which Visense is responsible under the Agreement in the following situations:
- Where the failure is caused by planned maintenance. Planned maintenance is maintenance of which notice has been given in advance to the Customer by Visense. Usually, Visense will endeavour to give at least one (1) weeks’ notice in writing of planned maintenance, but this may not always be possible in cases of emergency or upstream vendor maintenance.
- Where the failure is caused by the Customer, through either a failure to comply with the Customer obligations in this SLA or the Agreement, or a failure of equipment or utilities supplied or controlled by the Customer, or through a failure to follow the requisite reporting obligations, hereunder where the failure is the result of circumstances controlled by the Customer.
- Where the failure is caused or extended by a failure by the Customer to fully assist Visense in fault correction (for example where the Customer’ point of contact is unreachable using the agreed contact details).
- Where the failure is attributable to errors, malfunctions, updates or similar changes in and to software systems to which the applications have been integrated.
- Where the failure is caused by any other circumstances that are beyond Visense’s reasonable control.
Appendix 2 – Data Processing Agreement
1. Purpose of the agreement
1.1 The purpose of this Data Processing Agreement (this "Attachment") is to regulate the Parties' rights and obligations under applicable data protection legislation, including the Norwegian Personal Data Act of 2018, which incorporates the EU General Data Protection Regulation 2016/679 ("GDPR") (together, "Data Protection Legislation").
2. General
2.1 The purpose of this Attachment is to regulate Visense's processing of personal data on behalf of the Customer, which Visense obtains access to through the Customer's use of the Visense sensor platform, in accordance with GDPR Article 28. For the purposes of this Attachment, Visense acts as "Data Processor" and the Customer acts as "Data Controller".
2.2 This Attachment has one schedule, which forms an integral part of this Attachment:
Schedule A contains further details of the processing of personal data, including the purpose and nature of the processing, the categories of personal data, the categories of data subjects and the duration of the processing, as well as the Data Controller's conditions for the Data Processor's use of sub-processors and a list of approved sub-processors.
2.3 This Attachment takes precedence over any corresponding provisions in other parts of the Agreement to the extent they concern the processing of personal data.
2.4 This Attachment does not relieve the Data Processor of any obligations imposed on the Data Processor under Data Protection Legislation or other applicable law.
3. Rights and obligations of the data controller
3.1 The Data Controller is responsible for ensuring that the processing of personal data takes place in accordance with Data Protection Legislation, cf. GDPR Article 24.
3.2 The Data Controller has the right and the obligation to determine the purpose of the processing of personal data and which means are to be used. The Data Controller is further responsible for ensuring that there is a valid legal basis for the processing that the Data Processor is instructed to carry out.
4. Obligations of the data processor
4.1 Instructions: The Data Processor shall only process personal data in accordance with documented instructions from the Data Controller, unless otherwise required by national or European law. The Data Processor shall promptly notify the Data Controller if the Data Processor considers that an instruction infringes Data Protection Legislation.
4.2 Confidentiality: The Data Processor may only grant access to personal data processed on behalf of the Data Controller to persons who are subject to the Data Processor's instruction authority and who have committed to confidentiality or are subject to an appropriate statutory duty of confidentiality, and only to the extent necessary.
4.3 Security: The Data Processor shall implement appropriate technical and organisational measures to achieve a level of security appropriate to the risk, cf. GDPR Article 32. The Data Processor shall assist the Data Controller in complying with the Data Controller's obligations under GDPR Article 32, including by making the necessary information available to the Data Controller.
5. Sub-processors
5.1 The Data Processor shall comply with the requirements set out in GDPR Article 28(2) and (4) where the Data Processor engages a sub-processor.
5.2 The Data Processor has the Data Controller's general authorisation to engage sub-processors in accordance with the list in Schedule A. The Data Processor shall notify the Data Controller in writing of any intended additions or replacements of sub-processors at least two weeks in advance, thereby giving the Data Controller the opportunity to object to such changes.
5.3 Where a sub-processor is engaged, the sub-processor shall be subject to the same data protection obligations as those set out in this Attachment, by way of a written agreement under national or European law.
5.4 A copy of such sub-processor agreement shall be made available at the Data Controller's request. Commercial provisions that do not affect the data protection content are not subject to this requirement.
5.5 The Data Processor shall, in the sub-processor agreement, include the Data Controller as a third-party beneficiary in the event the Data Processor becomes insolvent, so that the Data Controller may assume the Data Processor's rights vis-à-vis the sub-processor.
5.6 The Data Processor shall be fully liable for any failure by the sub-processor to fulfil its data protection obligations.
6. Transfer to third countries or international organisations
6.1 The Data Processor may only transfer personal data to third countries (states outside the EU/EEA) or international organisations on documented instructions from the Data Controller, unless the transfer is required under national or European law. Any transfer shall at all times take place in accordance with GDPR Chapter V, including being subject to a lawful transfer mechanism.
6.2 This Attachment shall not be confused with standard contractual clauses as referred to in GDPR Article 46(2)(c) and (d), and cannot constitute an independent basis for the transfer of personal data under GDPR Chapter V.
7. Assistance to the data controller
7.1 To the extent possible, the Data Processor shall assist the Data Controller in responding to requests from data subjects seeking to exercise their rights, assist with information in the event of a personal data breach, assist with data protection impact assessments, and assist in connection with prior consultations with the Norwegian Data Protection Authority.
7.2 In the event of a personal data breach, the Data Processor shall notify the Data Controller of the breach without undue delay after becoming aware of it, so that the Data Controller can comply with its obligation to report the breach to the Norwegian Data Protection Authority, cf. GDPR Article 33.
8. Liability
8.1 Each Party is liable for any financial loss it causes the other Party as a result of a breach of this Attachment. Liability between the Parties is limited to the actual and documented financial loss suffered by the injured Party, subject to the limitations of liability set out in Section 12 of the Software Subscription Agreement.
8.2 Each Party is liable to a data subject who has suffered material or non-material damage where the damage is caused by that Party acting outside of, or in breach of, this Attachment or Data Protection Legislation, cf. GDPR Article 82(1).
9. Deletion and return of personal data
9.1 Upon termination of the data processing services, the Data Processor shall, at the Data Controller's election, delete all personal data processed on behalf of the Data Controller or return all personal data and delete existing copies, unless national or European law requires otherwise.
9.2 The Data Processor undertakes to process the personal data solely for the purposes, for the duration and on the conditions set out in this Attachment.
10. Audits, including inspections
10.1 The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations under GDPR Article 28 and this Attachment. The Data Processor shall further enable and contribute to audits, including inspections, conducted by the Data Controller or another auditor authorised by the Data Controller.
11. Entry into force and termination
11.1 This Attachment enters into force on the effective date of the Agreement.
11.2 This Attachment remains in effect for as long as the data processing services continue. During this period, this Attachment may not be terminated separately from the Agreement, unless the Parties agree on other terms governing the provision of the data processing services in accordance with applicable Data Protection Legislation.
11.3 If the provision of the data processing services ceases, and the personal data has been deleted or returned to the Data Controller in accordance with Section 9 above, this Attachment may be terminated by written notice from either Party.
12. Governing law and venue
12.1 This Attachment is governed by Norwegian law, and disputes between the Parties shall be resolved by the ordinary courts. This shall also apply after termination of this Attachment. The venue is Oslo District Court.
Schedule A (Description of the processing)
A.1 Purpose of the processing
A.1.1 The Data Processor will process personal data on behalf of the Data Controller in order to provide and deliver the Visense sensor platform, including:
- monitoring of moisture and climate conditions in wood and concrete during damage restoration
- documentation of drying processes in new construction
- ongoing moisture and climate monitoring for maintenance purposes
- ongoing property monitoring over time
A.2 Nature of the processing
A.2.1 The Data Processor will process information, including personal data, associated with projects and properties registered in Visense. The processing includes the following activities:
- The Data Controller enters and edits information about projects and associated equipment, either manually or automatically. The Data Processor stores this project information on behalf of the Data Controller and keeps a record of the Data Controller's users.
- The Data Processor stores readings from sensors placed by the Data Controller at the relevant site. The purpose is to generate forecasts, monitor drying processes and produce moisture reports.
- The Data Processor stores images and floor plans of the property where these are uploaded by the Data Controller as part of the project documentation.
- The Data Processor generates reports and offers remote monitoring and analysis based on the collected information.
A.3 Categories of personal data
A.3.1 The Data Processor will typically process the following personal data:
- Contact information and workplace details for the Data Controller's employees associated with projects (name, e-mail, telephone number, role).
- Contact information for the owner, occupant or contact person for the relevant property (name, address, telephone number, e-mail).
- Images and floor plans of private or commercial property uploaded as part of the project documentation.
- Sensor data (moisture, temperature, relative humidity) associated with a named project and an identifiable property.
- Other information the Data Controller registers in Visense in connection with the relevant project.
A.3.2 The Data Processor will, as a general rule, not process special categories of personal data, cf. GDPR Article 9(1).
A.4 Categories of data subjects
A.4.1 The Data Processor will process personal data associated with:
- Employees of the Data Controller who have been granted access to the Visense platform.
- Owners, occupants or contact persons for properties registered as project sites in Visense by the Data Controller.
A.5 Duration
A.5.1 The Data Processor will process all project information, including personal data associated with the project, for as long as the customer relationship with the Data Controller continues. Upon termination of the customer relationship, the personal data will be deleted in accordance with Section 9 of this Attachment.
A.5.2 In accordance with Section 7 of the Software Subscription Agreement, the Data Processor may use aggregated and anonymised data for its own purposes relating to statistics, further development of the sensor platform and user analytics. If such information is nonetheless deemed to constitute personal data, the Data Processor shall be regarded as an independent data controller for such further use and shall ensure compliance with the requirements of Data Protection Legislation.
A.6 Approved sub-processors
A.6.1 By accepting Visense's terms and conditions, the Data Controller has approved the use of the following sub-processors for the processing activity described for each:
| Name | Company registration no. | Location | Description of the processing |
|---|---|---|---|
| Intility AS | 981 967 070 | Oslo, Schweigaards gate 39 | Platform for managing, storing and administering information about the Data Controller's customers. |