Legal · GDPR Article 28

Data Processing Agreement

This Data Processing Agreement ("DPA") governs the processing of personal data by dotspot AS ("Processor") on behalf of the Customer ("Controller") under the dotspot subscription terms. It is designed to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR") and the Norwegian Personal Data Act (personopplysningsloven).

Version
1.0
Effective
2026-01-01
Governing law
Norway (EEA)
Forum
Bergen tingrett
How to execute. This DPA forms part of the Master Subscription Agreement between the Customer and dotspot AS. By accepting the dotspot subscription terms, or by signing the signature block at the end of this document, the Customer enters into this DPA. Where a signed counterpart is preferred for the Customer's records, contact support@dotspot.ai and we will provide a counter-signed PDF.

01 Definitions

Terms used in this DPA have the meanings given to them in the GDPR unless defined otherwise below.

  • Controller — the Customer entity that determines the purposes and means of processing Personal Data using the dotspot Services.
  • Processor — dotspot AS, registered in Bergen, Norway (Norwegian organisation number pending registration; will be inserted on assignment).
  • Personal Data — any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Services.
  • Services — the dotspot platform, including capture from mobile devices, wearable cameras and connected camera systems, cloud storage, indexing, automated privacy filtering, AI analysis, and related management tools.
  • Sub-processor — any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • Data Subject, Processing, Supervisory Authority and Personal Data Breach — as defined in Article 4 GDPR.

02 Subject matter, duration, nature and purpose

The subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subjects are described in Annex I. The Processor processes Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country or international organisation, unless required to do so by Union or Member State law to which the Processor is subject.

This DPA applies for the duration of the Services and survives termination for so long as the Processor processes Personal Data on behalf of the Controller.

03 Roles of the parties

For all Personal Data processed under the Services, the Customer is the Controller and dotspot is the Processor. Where the Customer acts as a processor for a third-party controller (for example, when the Customer captures work performed at a downstream client's site), dotspot acts as a sub-processor on the same terms as set out in this DPA, and the Customer is responsible for obtaining the necessary authorisations from the third-party controller.

04 Controller's obligations

The Controller warrants that:

  • it has a valid legal basis under Article 6 GDPR (and, where applicable, Article 9) for the processing of Personal Data through the Services;
  • it has provided all required information to Data Subjects under Articles 13 and 14 GDPR, including in respect of POV video, audio and biometric-relevant capture in the workplace;
  • it has consulted with employee representatives and complied with any local works-council, co-determination or worker-information requirements applicable to wearable, body-worn or smart-glass capture;
  • its instructions to the Processor comply with applicable data protection law; and
  • it is responsible for the accuracy, quality and legality of Personal Data and the means by which the Controller acquires the Personal Data.

05 Processor's obligations

In accordance with Article 28(3) GDPR, the Processor shall:

  1. Documented instructions. Process Personal Data only on the Controller's documented instructions, including in respect of transfers, unless required to do so by Union or Member State law (in which case the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).
  2. Confidentiality. Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Security. Take all measures required pursuant to Article 32 GDPR, as further described in Annex II.
  4. Sub-processors. Respect the conditions for engaging another processor as set out in clause 06 and Annex III.
  5. Data subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests for exercising Data Subjects' rights under Chapter III GDPR.
  6. Assistance with Articles 32–36. Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor.
  7. Return / deletion. At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies unless Union or Member State law requires storage.
  8. Audit. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, as set out in clause 09.

The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

06 Sub-processors

The Controller grants the Processor a general authorisation to engage the Sub-processors listed in Annex III. The Processor shall:

  • impose on each Sub-processor, by way of contract, data-protection obligations that are no less protective than those set out in this DPA, and in particular those required by Article 28(3) GDPR;
  • remain fully liable to the Controller for the performance of each Sub-processor's obligations; and
  • notify the Controller of any intended addition or replacement of Sub-processors with at least thirty (30) days' prior notice (by updating the published list at this URL and, on request, by email).

The Controller may object to a new Sub-processor on reasonable data-protection grounds within the notice period. If the parties cannot resolve the objection in good faith, the Controller may terminate the affected portion of the Services without penalty.

07 International data transfers

Personal Data is hosted in the European Economic Area (EEA) by default. Where the Processor or a Sub-processor transfers Personal Data outside the EEA, the transfer shall be governed by:

  • an adequacy decision under Article 45 GDPR; or
  • the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 2 / Module 3, as applicable), which are hereby incorporated by reference, together with such supplementary measures as are required following the Schrems II judgment; or
  • another transfer mechanism permitted under Chapter V GDPR.

For Customers established in the United Kingdom, the UK International Data Transfer Addendum issued by the ICO applies in addition to the SCCs.

08 Personal data breaches

The Processor shall notify the Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Controller Personal Data. The notification shall include, to the extent then known:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
  • the name and contact details of the Processor's data protection contact (support@dotspot.ai);
  • the likely consequences of the breach; and
  • the measures taken or proposed to address the breach and mitigate its possible adverse effects.

Where it is not possible to provide all information at the same time, information may be provided in phases without undue further delay. The Processor shall reasonably co-operate with the Controller and any competent Supervisory Authority in the investigation, mitigation and remediation of any such breach.

09 Audit rights

The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, in the first instance through:

  • the dotspot Trust documentation (architecture overview, sub-processor list, security overview); and
  • the published compliance documentation of the Processor's Sub-processors (for example, Microsoft's and Google's public ISO/IEC 27001 and SOC 2 attestations for their cloud platforms), provided on request under a non-disclosure agreement where applicable.

Where such documentation is insufficient to demonstrate compliance with a specific concern, the Controller may, at its own cost and on reasonable prior notice of at least thirty (30) days, conduct an audit no more than once per calendar year (and additionally following a confirmed Personal Data Breach). Audits shall be conducted during business hours, with minimal disruption to the Processor's operations, and shall not require access to data of other customers, source code, or commercially sensitive information. Both parties bear their own costs unless the audit reveals a material non-compliance by the Processor.

10 Return and deletion of Personal Data

On termination or expiry of the Services, the Processor shall, at the Controller's choice, delete or return all Personal Data and delete existing copies, unless Union or Member State law requires storage of the Personal Data.

Unless the Controller instructs otherwise, the Processor shall delete all Personal Data from active systems within thirty (30) days of termination, and from back-ups in accordance with its documented retention cycle (no later than ninety (90) days). The Processor shall, on request, provide written confirmation of deletion.

11 Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Master Subscription Agreement between the parties. Nothing in this DPA limits or excludes either party's liability where such limitation or exclusion is not permitted by applicable law, including the rights of Data Subjects under Article 82 GDPR.

12 Governing law and jurisdiction

This DPA is governed by the laws of Norway, without regard to its conflict of laws provisions. The courts of Bergen (Bergen tingrett) shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to mandatory provisions of Union or Member State law that grant Data Subjects the right to bring proceedings in the courts of their habitual residence.

13 Order of precedence

In the event of a conflict between this DPA and the Master Subscription Agreement, this DPA shall prevail to the extent of the conflict in respect of the processing of Personal Data. The Standard Contractual Clauses referenced in clause 07 prevail over this DPA in respect of restricted international transfers.

Annex I — Description of processing
Art. 28(3)
Subject matter Capture, storage, indexing and AI-assisted analysis of point-of-view (POV) video and supporting telemetry of work performed by the Controller's personnel, contractors, and authorised users, in order to produce a searchable index of work steps, tools, quality checks and variations.
Duration For the term of the Customer's subscription to the Services, plus any post-termination return / deletion period set out in clause 10.
Nature of processing Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, restriction, erasure and destruction.
Purpose of processing Provision of the dotspot platform: ingestion from phones, smart glasses, chest cameras and Axis wearable cameras; automated face / privacy filtering; cloud storage and search; AI-assisted indexing of work steps, tools and quality checkpoints; private link sharing; analytics; account management and authentication.
Categories of Data Subjects
  • The Controller's employees, contractors and field operators who use dotspot to capture work;
  • Other workers, visitors or members of the public who incidentally appear in captured footage prior to automated privacy filtering;
  • The Controller's administrators and authorised viewers of captured footage.
Types of Personal Data
  • Account data: name, business email, organisation, role, language, Azure AD B2C identifier, Axis user identifier (where linked).
  • Capture data: video and audio of the work being performed; faces of workers and bystanders prior to automated blurring; voices; clothing, identifiers visible on workwear or equipment; ambient environmental information.
  • Telemetry / sidecar: device model, app version, timestamps, session and task metadata, free-text notes added by the operator, environmental tags.
  • Derived data: AI-generated transcripts, summaries, step lists, embeddings and search indices computed from the capture data.
  • Logs: sign-in events, IP address, user-agent, audit events for capture, viewing and deletion.
The Services are not intended for processing of special categories of personal data under Article 9 GDPR. The Controller must not knowingly use the Services to process such data without a documented Article 9 legal basis and prior written agreement with the Processor.
Frequency Continuous, for the duration of the subscription.
Retention
  • Enterprise customers: retention period is agreed in the Customer's subscription contract and configured per tenant.
  • Individual / single-user accounts: Personal Data is retained for two (2) years from capture by default. Data Subjects and account holders may request earlier deletion at any time via the "My recordings" workspace or by writing to support@dotspot.ai; deletion requests are actioned without undue delay.
In all cases, the Controller remains responsible for ensuring that the chosen retention period is compatible with its own legal basis and the data-minimisation principle of Article 5(1)(e) GDPR.
Annex II — Technical and organisational measures
Art. 32

The Processor has implemented and maintains technical and organisational measures designed to ensure a level of security appropriate to the risk, including the following.

1. Access control and authentication

  • Customer authentication via Azure AD B2C with support for SSO and multi-factor authentication.
  • Role-based access control inside each tenant; external users see only their own captures.
  • Just-in-time access for Processor personnel, with all privileged access logged and reviewed.

2. Encryption

  • Personal Data encrypted in transit using TLS 1.2+ for all customer-facing endpoints.
  • Personal Data encrypted at rest using AES-256 (or equivalent) on the underlying storage layer.
  • Time-bound SAS tokens (with short expiries) used for direct uploads and playback.

3. Tenant isolation

  • All Personal Data is partitioned by organisation identifier; queries and storage paths are scoped to a single organisation and validated server-side.
  • Inter-tenant access is prevented at the application layer (path prefix checks) and at the data layer (per-org partition keys).

4. Privacy-by-design controls

  • Automated face / privacy filtering applied to captured footage as part of the standard ingestion pipeline.
  • Per-user "My recordings" workspace enabling each worker to view, redact or delete their own contributions.
  • Signed chain-of-custody and audit trail for capture, viewing and deletion events.

5. Network and platform security

  • Hosting on Microsoft Azure (EEA regions by default), inheriting the platform-level security and compliance posture published by Microsoft.
  • Network segmentation, managed firewalls and DDoS protection at the platform layer.
  • Vulnerability scanning, patch management, and dependency monitoring.

dotspot does not currently hold its own ISO/IEC 27001 or SOC 2 certification. The measures in this Annex describe the controls in operation; independent certification of the Processor is on the product roadmap and this DPA will be updated when achieved.

6. Personnel

  • Background checks where permitted by law, prior to granting access to Personal Data.
  • Written confidentiality undertakings for all employees and contractors.
  • Mandatory data-protection and security training, refreshed annually.

7. Resilience and recovery

  • Encrypted, geo-redundant back-ups inside the EEA, with documented retention and deletion cycles.
  • Documented business-continuity and disaster-recovery procedures, tested at least annually.
  • Defined recovery-point and recovery-time objectives provided on request under NDA.

8. Incident management

  • 24/7 monitoring and alerting on platform health and security signals.
  • Documented incident-response playbook with defined severity levels, escalation paths and post-mortem requirements.
  • Personal Data Breach notification process meeting the 72-hour requirement under clause 08.

9. Sub-processor management

  • Pre-engagement assessment of each Sub-processor's security and data-protection posture.
  • Contractual flow-down of Article 28 obligations to every Sub-processor.
  • Annual review of Sub-processor compliance.
Annex III — Authorised sub-processors
Art. 28(2)–(4)

The following Sub-processors are authorised to process Personal Data on behalf of the Processor as of the effective date of this DPA. The current list is maintained at this URL and updated in accordance with clause 06.

Sub-processor Purpose Location of processing Transfer mechanism
Microsoft Ireland Operations Ltd. (Azure) Cloud hosting, blob storage of captured footage, Cosmos DB, identity (Azure AD B2C) EEA (default: West Europe / North Europe) EEA — no transfer; SCCs for any incidental support access from outside EEA
Google Ireland Ltd. (Gemini API) AI analysis of video content (transcription, indexing, Q&A, comparison) EEA, with possible processing in other Google regions for model serving SCCs (Module 3) + supplementary measures; data submitted to the model is not used to train Google's foundation models
Axis Communications AB Ingestion of footage from Axis wearable cameras into the dotspot platform (where the Customer uses Axis devices) EEA (Sweden) EEA — no transfer
Customer-facing transactional email and support tooling Sign-in notifications, invitations, support tickets EEA EEA — no transfer; SCCs where applicable

Last updated: 2026-01-01. Material changes to this list are notified to the Controller in accordance with clause 06. Sub-processor names, entities and locations may change — the most current list is the version published at this URL.

Signature
Execution

Acceptance of the dotspot subscription terms constitutes execution of this DPA. For Customers requiring a signed counterpart, complete the block below and return to support@dotspot.ai.

For the Controller (Customer)
Entity 
Signatory 
Title 
Date 
Signature 
For the Processor (dotspot AS)
Entitydotspot AS, Bergen, NO
Signatory 
Title 
Date 
Signature 
Request countersigned copy