Data Processing Agreement
Last updated: 28 August 2026Version: 2026-08-28
Data Processing Agreement between the clinic and GLØDI
The clinic is the controller for data about its own customers and patients. GLØDI is the processor and processes that data solely on the clinic's behalf and on its documented instructions. This agreement constitutes the data processing agreement required by GDPR article 28(3) and applies alongside the commercial terms for use of the platform.
Contents
Terms of the agreement
1. The parties and their roles
This agreement governs GLØDI's processing of personal data on behalf of the clinic.
Controller
The clinic using GLØDI. The clinic determines the purposes and means of processing data about its own customers and patients, and is the controller under GDPR article 4(7).
Processor
Glødi AS ("GLØDI"), company no. 838 418 082, email [email protected], which provides the platform and processes personal data on the clinic's behalf.
Relationship to other terms
In the event of conflict between this agreement and the commercial terms, this agreement prevails on matters concerning the processing of personal data.
2. Purpose and nature of the processing
GLØDI processes personal data only to deliver the platform service to the clinic, for the following purposes:
- booking, appointment management and calendar
- clinical records and treatment documentation
- payment, receipts, invoicing and settlement
- communication with the customer by email, SMS and in-app
- customer club, offers and consent-based marketing
- accounting records and statutory documentation
- operations, troubleshooting, security and support
GLØDI does not use the clinic's personal data for its own purposes, does not sell it, and does not use it to train general-purpose AI models.
3. Categories of data subjects and personal data
Data subjects
The clinic's customers and patients, the clinic's employees and practitioners, and any partners and contact persons.
Ordinary personal data
Name, contact details, date of birth, address, booking history, purchase and payment data, communications and login data.
Special categories – health data
Clinical notes, treatment documentation, medical conditions, allergies, consents, images of the treatment area and, where applicable, national identity number. This is special category data under article 9 and is processed with enhanced safeguards.
4. The clinic's obligations
- ensure a valid legal basis for the data entered into the platform
- give its own customers the required information, including through the clinic's privacy statement
- control who within the clinic has access, and remove access when no longer needed
- not enter more personal data than the purpose requires
- notify GLØDI without undue delay on suspicion of unauthorised access to the clinic's data
5. GLØDI's obligations as processor
- process personal data only on documented instructions from the clinic, including this agreement, clinic configuration, and actions in the platform
- notify the clinic before processing required by law rather than clinic instruction, unless the law prohibits notice
- stop affected processing where an instruction cannot lawfully be followed until the clinic provides a lawful instruction
- ensure everyone with access is bound by confidentiality
- implement appropriate technical and organisational measures under article 32
- assist the clinic with data protection impact assessments and prior consultation where needed
- make available the documentation necessary to demonstrate compliance
- notify the clinic if, in GLØDI's opinion, an instruction infringes data protection law
6. Sub-processors
The clinic grants GLØDI general authorisation to use the sub-processors listed in the public, versioned sub-processor register.
Agreement and responsibility
GLØDI enters into a written agreement imposing the same relevant obligations on the sub-processor and remains fully liable to the clinic for the sub-processor's performance.
Notice and objection
GLØDI gives at least 30 days' notice before a new or replacement sub-processor receives access. The clinic may object on documented privacy or security grounds. The parties seek risk-reducing measures or an alternative provider; if none is available, the clinic may terminate the affected feature without future charge.
The register at /underdatabehandlere distinguishes sub-processors from independent payment recipients and optional integrations. It is the authoritative provider list.
7. Processing location and transfers outside the EEA
The core application, database, and file storage are configured in the EEA, but some activated features or providers may involve processing or remote access from outside the EEA.
General rule
The application and database run in the Stockholm region and platform files are stored in Finland. This is the storage location for the core platform and not a statement that all support, messaging, payment, AI, or integration processing occurs exclusively in the EEA.
Exceptions
Transfers or access outside the EEA take place only under a valid GDPR Chapter V mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, plus supplementary measures where needed. Applicable countries and mechanisms appear in the sub-processor register.
8. Information security
GLØDI implements measures proportionate to the risk of processing health data, including:
- encryption of data in transit and at rest
- role-based access control so staff only see data they need
- separation of data between clinics, so one clinic cannot access another's data
- immutable logging of access to health data, retained under the Norwegian Patient Records Act
- backups and documented recovery procedures
- logging, monitoring and follow-up of security incidents
9. Personal data breaches
Notification to the clinic
GLØDI notifies the clinic without undue delay after becoming aware of a breach, and no later than 24 hours.
Content of the notification
The notification describes the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences and the measures taken.
Notification to the supervisory authority
The clinic is the controller and notifies the Norwegian Data Protection Authority within 72 hours where required. GLØDI assists with the necessary information.
10. Data subject rights
The clinic responds to the data subject. GLØDI assists through appropriate technical and organisational measures, including platform features for access, rectification, erasure, data portability and access-log transparency.
If a customer contacts GLØDI directly, we forward the request to the clinic and do not answer on the clinic's behalf without instruction.
11. Audit and documentation
- GLØDI makes available documentation demonstrating compliance with this agreement
- the clinic may audit itself or through an independent auditor on reasonable notice
- audits must not unduly disrupt operations, and each party bears its own costs
- the clinic is bound by confidentiality regarding information obtained through an audit
12. Retention, deletion and termination
During the agreement
GLØDI retains the data for as long as the clinic uses the platform and the purpose requires it.
Statutory retention
The clinic determines lawful retention and instructs return or deletion. GLØDI may retain copies after termination only where EU or Norwegian law directly requires GLØDI to do so, and the clinic is informed of the basis. The clinic's own clinical-record or bookkeeping duties do not by themselves give GLØDI an independent right to retain data against instruction.
On termination
At the end of the agreement the clinic normally has at least 60 days to retrieve data in a commonly used machine-readable format. Personal data and existing copies are then deleted or returned by GLØDI and its sub-processors at the clinic's choice, except for retention directly required by law.
13. Liability, duration and governing law
Duration
This agreement applies for as long as GLØDI processes personal data on the clinic's behalf, and ends when processing ceases and deletion has been carried out.
Right to terminate where guarantees fail
The clinic may terminate the affected processing or this agreement if GLØDI no longer provides sufficient guarantees under Article 28(1), or materially breaches this agreement and does not remedy within a reasonable period. Immediate termination is available for unlawful processing or a serious security threat.
Liability
The parties are liable under the GDPR and applicable Norwegian law. The limitations of liability in the commercial terms apply correspondingly, but do not limit liability that cannot be disclaimed by law.
Governing law and venue
This agreement is governed by Norwegian law. Disputes are to be resolved amicably, failing which they are brought before the Norwegian courts.
Questions about the agreement?
Get in touch if the clinic has questions about the processing of personal data, needs documentation for its own internal control, wants the current sub-processor list, or would like the agreement signed as a separate document.
Email:[email protected]
We normally reply within 24 hours on weekdays.