Data Processing Agreement
Last updated: May 8, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer" or "Controller") and Waybound AS (organization number 937 496 184, "SpaceMD" or "Processor") for the provision of the SpaceMD service. It governs the Processing of Personal Data by SpaceMD on the Customer's behalf in accordance with GDPR Article 28, the UK GDPR, and the revised Swiss FADP (nFADP). Where your country of habitual residence or establishment requires it, this DPA also incorporates the Standard Contractual Clauses described in §8.
1. Definitions
- "Personal Data" — Any information relating to an identified or identifiable natural person Processed by SpaceMD on behalf of the Customer.
- "Processing" — Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- "Sub-Processor" — A third party engaged by SpaceMD to Process Personal Data on behalf of the Customer.
- "Data Breach" — A breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data.
- "SCC" — The Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.
2. Scope, Roles, and Duration
Roles. The Customer is the Controller and determines the purposes and means of Processing. SpaceMD acts as the Processor and Processes Personal Data solely on the Customer's documented instructions and as necessary to provide the SpaceMD service.
Subject matter and nature. Hosting, storage, indexing, retrieval, and presentation of documents and collaboration metadata; transmission of relevant content to AI providers when AI features are used; transactional messaging.
Categories of Personal Data. Identity and contact data, authentication credentials, document content, comments and collaboration metadata, usage and device data, billing data.
Categories of data subjects. The Customer's end users, collaborators, invited guests, and other natural persons whose Personal Data the Customer chooses to upload.
Duration. This DPA applies for the term of the SpaceMD service agreement and the post-termination period set out in §10.
3. Processor Obligations
SpaceMD shall:
- Process Personal Data only on documented instructions from the Customer (including those in this DPA), unless required by applicable Union or Member State law, in which case SpaceMD will inform the Customer before Processing unless legally prohibited.
- Ensure that persons authorized to Process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures (see §5) to ensure a level of security appropriate to the risk.
- Assist the Customer with appropriate technical and organizational measures, taking into account the nature of Processing, in fulfilling its obligations to respond to data subject requests.
- Assist the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, DPIAs, prior consultation), taking into account the nature of Processing and the information available.
- At the Customer's choice, delete or return all Personal Data on termination of the service in accordance with §10.
- Make available to the Customer information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as set out in §9.
4. Sub-Processors
The Customer grants SpaceMD general written authorisation to engage Sub-Processors. The current list of Sub-Processors, including names, locations, and Processing purposes, is published at /sub-processors.
Flow-down. SpaceMD shall enter into a written agreement with each Sub-Processor imposing data protection obligations substantially equivalent to those set out in this DPA (including confidentiality, security, sub-processing controls, assistance, and audit). SpaceMD remains fully liable to the Customer for the performance of each Sub-Processor (GDPR Art. 28(4)).
Notice and objection. SpaceMD will give at least 30 days' notice (by email and/or by updating /sub-processors with a subscribe-to-updates option) of the addition or replacement of a Sub-Processor. The Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection; if no resolution is reached, the Customer may terminate the affected service for the unused portion of any pre-paid term.
5. Security Measures
SpaceMD implements at minimum the following measures (Annex II to the SCC where applicable):
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls and multi-factor authentication for administrative access.
- Regular vulnerability scanning and periodic penetration testing.
- Logging and monitoring of access to systems Processing Personal Data.
- Incident response and business continuity procedures.
- Employee security awareness training and confidentiality undertakings.
- Data minimisation and segregation between Customers.
6. Data Breach Notification
In the event of a Data Breach, SpaceMD shall:
- Notify the Customer without undue delay and in any event within 72 hours of becoming aware. Where full information is not available within 72 hours, SpaceMD will provide an initial notification with the information then known and supplement it without further undue delay.
- Provide sufficient information to enable the Customer to meet its obligations to notify supervisory authorities and affected data subjects.
- Take reasonable steps to mitigate the effects of the breach and prevent recurrence.
- Cooperate with the Customer and provide ongoing updates as further information becomes available.
7. Data Subject Rights
SpaceMD provides functionality enabling the Customer to access, correct, delete, restrict, and export Personal Data within the service. SpaceMD will assist the Customer in responding to data subject requests by providing additional information or technical measures where reasonably required, taking into account the nature of the Processing.
8. International Transfers
Where Personal Data is transferred outside the EEA, the UK, or Switzerland, SpaceMD relies, in order, on:
- An adequacy decision (including the EU–US Data Privacy Framework, the UK Extension to the DPF, and the Swiss–US DPF) where the recipient is certified;
- The SCCs, with Module 2 (controller-to-processor) applying between the Customer and SpaceMD where the Customer is a controller in the EEA, and Module 3 (processor-to-processor) applying onward to Sub-Processors where SpaceMD is itself acting as a processor of another controller. The SCCs are deemed incorporated by reference and completed as set out in Annex A below;
- The UK International Data Transfer Addendum (issued by the ICO under section 119A of the Data Protection Act 2018) for transfers from the UK;
- The Swiss FDPIC's recognised version of the SCCs for transfers from Switzerland;
- Other Article 46 GDPR safeguards and supplementary measures identified in our transfer impact assessments.
Annex A — SCC completion (summary). Data exporter: the Customer. Data importer: Waybound AS. Categories of data subjects, data, purposes, and duration: as set out in §2. Competent supervisory authority: Datatilsynet (Norway) for SpaceMD; the Customer's lead authority for the Customer. Onward transfers: only to Sub-Processors listed at /sub-processors under Module 3 of the SCCs (or successor mechanisms).
9. Audit Rights
SpaceMD shall make available to the Customer information necessary to demonstrate compliance with this DPA. The Customer may, at its own expense and on reasonable notice, audit SpaceMD's compliance no more than once per year (or more frequently where required by a competent supervisory authority or following a Data Breach), during normal business hours, and without unreasonably disrupting SpaceMD's operations. The Customer agrees to accept relevant third-party audit reports (such as SOC 2 Type II or ISO/IEC 27001) as evidence of compliance, where available, before exercising on-site audit rights.
10. Termination & Data Return
On termination of the service agreement, SpaceMD shall, at the Customer's choice expressed within 30 days, delete or return all Personal Data, subject to retention required by applicable law and the audit/log retention described in our Privacy Policy. Where no choice is communicated, SpaceMD will delete Personal Data within 90 days of termination. Encrypted backups are purged on a 30-day cycle. SpaceMD provides export functionality before termination.
11. UK & Swiss Specifics
For UK data exports, the UK International Data Transfer Addendum applies in addition to the SCCs. For Swiss data exports, the SCCs are read with the modifications recognised by the FDPIC (references to GDPR include the nFADP; competent authority is the FDPIC; reference to Member State law includes Swiss law). Where SpaceMD is required by law to designate a UK Article 27 representative or a Swiss representative under nFADP Art. 14, SpaceMD will do so and name them in our Privacy Policy.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service. SpaceMD's total liability for all claims arising under this DPA shall not exceed the cap stated in §11 of the Terms. Nothing in this section limits liability that cannot lawfully be limited or excluded under applicable mandatory law (including supervisory-authority enforcement and data-subject claims under Article 82 GDPR).
13. Contact
For questions about this DPA or data processing matters, contact us at:
Waybound AS
Organization number: 937 496 184
0763 Oslo, Norway
Email: legal@spacemd.ai
