How to execute. This DPA forms part of the Master Subscription
Agreement between the Customer and dotspot AS. By accepting the dotspot
subscription terms, or by signing the signature block at the end of this
document, the Customer enters into this DPA. Where a signed counterpart
is preferred for the Customer's records, contact
support@dotspot.ai and we will
provide a counter-signed PDF.
01 Definitions
Terms used in this DPA have the meanings given to them in the GDPR
unless defined otherwise below.
- Controller — the Customer entity that determines the purposes and means of processing Personal Data using the dotspot Services.
- Processor — dotspot AS, registered in Bergen, Norway (Norwegian organisation number pending registration; will be inserted on assignment).
- Personal Data — any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Services.
- Services — the dotspot platform, including capture from mobile devices, wearable cameras and connected camera systems, cloud storage, indexing, automated privacy filtering, AI analysis, and related management tools.
- Sub-processor — any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- Data Subject, Processing, Supervisory Authority and Personal Data Breach — as defined in Article 4 GDPR.
02 Subject matter, duration, nature and purpose
The subject matter, duration, nature, purpose, types of Personal Data
and categories of Data Subjects are described in Annex I.
The Processor processes Personal Data only on documented instructions
from the Controller, including with regard to transfers to a third
country or international organisation, unless required to do so by
Union or Member State law to which the Processor is subject.
This DPA applies for the duration of the Services and survives
termination for so long as the Processor processes Personal Data on
behalf of the Controller.
03 Roles of the parties
For all Personal Data processed under the Services, the Customer is
the Controller and dotspot is the Processor. Where the Customer acts
as a processor for a third-party controller (for example, when the
Customer captures work performed at a downstream client's site),
dotspot acts as a sub-processor on the same terms as set out in this
DPA, and the Customer is responsible for obtaining the necessary
authorisations from the third-party controller.
04 Controller's obligations
The Controller warrants that:
- it has a valid legal basis under Article 6 GDPR (and, where applicable, Article 9) for the processing of Personal Data through the Services;
- it has provided all required information to Data Subjects under Articles 13 and 14 GDPR, including in respect of POV video, audio and biometric-relevant capture in the workplace;
- it has consulted with employee representatives and complied with any local works-council, co-determination or worker-information requirements applicable to wearable, body-worn or smart-glass capture;
- its instructions to the Processor comply with applicable data protection law; and
- it is responsible for the accuracy, quality and legality of Personal Data and the means by which the Controller acquires the Personal Data.
05 Processor's obligations
In accordance with Article 28(3) GDPR, the Processor shall:
- Documented instructions. Process Personal Data only on the Controller's documented instructions, including in respect of transfers, unless required to do so by Union or Member State law (in which case the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).
- Confidentiality. Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security. Take all measures required pursuant to Article 32 GDPR, as further described in Annex II.
- Sub-processors. Respect the conditions for engaging another processor as set out in clause 06 and Annex III.
- Data subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests for exercising Data Subjects' rights under Chapter III GDPR.
- Assistance with Articles 32–36. Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor.
- Return / deletion. At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies unless Union or Member State law requires storage.
- Audit. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, as set out in clause 09.
The Processor shall immediately inform the Controller if, in its
opinion, an instruction infringes the GDPR or other Union or Member
State data protection provisions.
06 Sub-processors
The Controller grants the Processor a general authorisation to engage
the Sub-processors listed in Annex III. The
Processor shall:
- impose on each Sub-processor, by way of contract, data-protection obligations that are no less protective than those set out in this DPA, and in particular those required by Article 28(3) GDPR;
- remain fully liable to the Controller for the performance of each Sub-processor's obligations; and
- notify the Controller of any intended addition or replacement of Sub-processors with at least thirty (30) days' prior notice (by updating the published list at this URL and, on request, by email).
The Controller may object to a new Sub-processor on reasonable
data-protection grounds within the notice period. If the parties
cannot resolve the objection in good faith, the Controller may
terminate the affected portion of the Services without penalty.
07 International data transfers
Personal Data is hosted in the European Economic Area (EEA) by
default. Where the Processor or a Sub-processor transfers Personal
Data outside the EEA, the transfer shall be governed by:
- an adequacy decision under Article 45 GDPR; or
- the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 2 / Module 3, as applicable), which are hereby incorporated by reference, together with such supplementary measures as are required following the Schrems II judgment; or
- another transfer mechanism permitted under Chapter V GDPR.
For Customers established in the United Kingdom, the UK International
Data Transfer Addendum issued by the ICO applies in addition to the
SCCs.
08 Personal data breaches
The Processor shall notify the Controller without undue delay, and in
any event within seventy-two (72) hours of becoming
aware of a Personal Data Breach affecting Controller Personal Data.
The notification shall include, to the extent then known:
- the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- the name and contact details of the Processor's data protection contact (support@dotspot.ai);
- the likely consequences of the breach; and
- the measures taken or proposed to address the breach and mitigate its possible adverse effects.
Where it is not possible to provide all information at the same time,
information may be provided in phases without undue further delay.
The Processor shall reasonably co-operate with the Controller and
any competent Supervisory Authority in the investigation,
mitigation and remediation of any such breach.
09 Audit rights
The Processor makes available to the Controller all information
necessary to demonstrate compliance with Article 28 GDPR and this
DPA, in the first instance through:
- the dotspot Trust documentation (architecture overview, sub-processor list, security overview); and
- the published compliance documentation of the Processor's Sub-processors (for example, Microsoft's and Google's public ISO/IEC 27001 and SOC 2 attestations for their cloud platforms), provided on request under a non-disclosure agreement where applicable.
Where such documentation is insufficient to demonstrate compliance
with a specific concern, the Controller may, at its own cost and on
reasonable prior notice of at least thirty (30) days,
conduct an audit no more than once per calendar year (and additionally
following a confirmed Personal Data Breach). Audits shall be
conducted during business hours, with minimal disruption to the
Processor's operations, and shall not require access to data of
other customers, source code, or commercially sensitive information.
Both parties bear their own costs unless the audit reveals a material
non-compliance by the Processor.
10 Return and deletion of Personal Data
On termination or expiry of the Services, the Processor shall, at the
Controller's choice, delete or return all Personal Data and
delete existing copies, unless Union or Member State law requires
storage of the Personal Data.
Unless the Controller instructs otherwise, the Processor shall delete
all Personal Data from active systems within thirty (30)
days of termination, and from back-ups in accordance with
its documented retention cycle (no later than ninety (90)
days). The Processor shall, on request, provide written
confirmation of deletion.
11 Liability
Each party's liability arising out of or related to this DPA is
subject to the limitations and exclusions of liability set out in
the Master Subscription Agreement between the parties. Nothing in
this DPA limits or excludes either party's liability where such
limitation or exclusion is not permitted by applicable law,
including the rights of Data Subjects under Article 82 GDPR.
12 Governing law and jurisdiction
This DPA is governed by the laws of Norway, without regard to its
conflict of laws provisions. The courts of Bergen (Bergen tingrett)
shall have exclusive jurisdiction over any dispute arising out of or
in connection with this DPA, without prejudice to mandatory
provisions of Union or Member State law that grant Data Subjects
the right to bring proceedings in the courts of their habitual
residence.
13 Order of precedence
In the event of a conflict between this DPA and the Master
Subscription Agreement, this DPA shall prevail to the extent of the
conflict in respect of the processing of Personal Data. The Standard
Contractual Clauses referenced in clause 07 prevail over this DPA in
respect of restricted international transfers.
Annex I — Description of processing
Art. 28(3)
| Subject matter |
Capture, storage, indexing and AI-assisted analysis of point-of-view (POV) video and supporting telemetry of work performed by the Controller's personnel, contractors, and authorised users, in order to produce a searchable index of work steps, tools, quality checks and variations. |
| Duration |
For the term of the Customer's subscription to the Services, plus any post-termination return / deletion period set out in clause 10. |
| Nature of processing |
Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, restriction, erasure and destruction. |
| Purpose of processing |
Provision of the dotspot platform: ingestion from phones, smart glasses, chest cameras and Axis wearable cameras; automated face / privacy filtering; cloud storage and search; AI-assisted indexing of work steps, tools and quality checkpoints; private link sharing; analytics; account management and authentication. |
| Categories of Data Subjects |
- The Controller's employees, contractors and field operators who use dotspot to capture work;
- Other workers, visitors or members of the public who incidentally appear in captured footage prior to automated privacy filtering;
- The Controller's administrators and authorised viewers of captured footage.
|
| Types of Personal Data |
- Account data: name, business email, organisation, role, language, Azure AD B2C identifier, Axis user identifier (where linked).
- Capture data: video and audio of the work being performed; faces of workers and bystanders prior to automated blurring; voices; clothing, identifiers visible on workwear or equipment; ambient environmental information.
- Telemetry / sidecar: device model, app version, timestamps, session and task metadata, free-text notes added by the operator, environmental tags.
- Derived data: AI-generated transcripts, summaries, step lists, embeddings and search indices computed from the capture data.
- Logs: sign-in events, IP address, user-agent, audit events for capture, viewing and deletion.
The Services are not intended for processing of special categories of personal data under Article 9 GDPR. The Controller must not knowingly use the Services to process such data without a documented Article 9 legal basis and prior written agreement with the Processor.
|
| Frequency |
Continuous, for the duration of the subscription. |
| Retention |
- Enterprise customers: retention period is agreed in the Customer's subscription contract and configured per tenant.
- Individual / single-user accounts: Personal Data is retained for two (2) years from capture by default. Data Subjects and account holders may request earlier deletion at any time via the "My recordings" workspace or by writing to support@dotspot.ai; deletion requests are actioned without undue delay.
In all cases, the Controller remains responsible for ensuring that the chosen retention period is compatible with its own legal basis and the data-minimisation principle of Article 5(1)(e) GDPR.
|
Annex II — Technical and organisational measures
Art. 32
The Processor has implemented and maintains technical and
organisational measures designed to ensure a level of security
appropriate to the risk, including the following.
1. Access control and authentication
- Customer authentication via Azure AD B2C with support for SSO and multi-factor authentication.
- Role-based access control inside each tenant; external users see only their own captures.
- Just-in-time access for Processor personnel, with all privileged access logged and reviewed.
2. Encryption
- Personal Data encrypted in transit using TLS 1.2+ for all customer-facing endpoints.
- Personal Data encrypted at rest using AES-256 (or equivalent) on the underlying storage layer.
- Time-bound SAS tokens (with short expiries) used for direct uploads and playback.
3. Tenant isolation
- All Personal Data is partitioned by organisation identifier; queries and storage paths are scoped to a single organisation and validated server-side.
- Inter-tenant access is prevented at the application layer (path prefix checks) and at the data layer (per-org partition keys).
4. Privacy-by-design controls
- Automated face / privacy filtering applied to captured footage as part of the standard ingestion pipeline.
- Per-user "My recordings" workspace enabling each worker to view, redact or delete their own contributions.
- Signed chain-of-custody and audit trail for capture, viewing and deletion events.
5. Network and platform security
- Hosting on Microsoft Azure (EEA regions by default), inheriting the platform-level security and compliance posture published by Microsoft.
- Network segmentation, managed firewalls and DDoS protection at the platform layer.
- Vulnerability scanning, patch management, and dependency monitoring.
dotspot does not currently hold its own ISO/IEC 27001 or SOC 2 certification. The
measures in this Annex describe the controls in operation; independent certification of the
Processor is on the product roadmap and this DPA will be updated when achieved.
6. Personnel
- Background checks where permitted by law, prior to granting access to Personal Data.
- Written confidentiality undertakings for all employees and contractors.
- Mandatory data-protection and security training, refreshed annually.
7. Resilience and recovery
- Encrypted, geo-redundant back-ups inside the EEA, with documented retention and deletion cycles.
- Documented business-continuity and disaster-recovery procedures, tested at least annually.
- Defined recovery-point and recovery-time objectives provided on request under NDA.
8. Incident management
- 24/7 monitoring and alerting on platform health and security signals.
- Documented incident-response playbook with defined severity levels, escalation paths and post-mortem requirements.
- Personal Data Breach notification process meeting the 72-hour requirement under clause 08.
9. Sub-processor management
- Pre-engagement assessment of each Sub-processor's security and data-protection posture.
- Contractual flow-down of Article 28 obligations to every Sub-processor.
- Annual review of Sub-processor compliance.
Annex III — Authorised sub-processors
Art. 28(2)–(4)
The following Sub-processors are authorised to process Personal Data
on behalf of the Processor as of the effective date of this DPA.
The current list is maintained at this URL and updated in accordance
with clause 06.
| Sub-processor |
Purpose |
Location of processing |
Transfer mechanism |
| Microsoft Ireland Operations Ltd. (Azure) |
Cloud hosting, blob storage of captured footage, Cosmos DB, identity (Azure AD B2C) |
EEA (default: West Europe / North Europe) |
EEA — no transfer; SCCs for any incidental support access from outside EEA |
| Google Ireland Ltd. (Gemini API) |
AI analysis of video content (transcription, indexing, Q&A, comparison) |
EEA, with possible processing in other Google regions for model serving |
SCCs (Module 3) + supplementary measures; data submitted to the model is not used to train Google's foundation models |
| Axis Communications AB |
Ingestion of footage from Axis wearable cameras into the dotspot platform (where the Customer uses Axis devices) |
EEA (Sweden) |
EEA — no transfer |
| Customer-facing transactional email and support tooling |
Sign-in notifications, invitations, support tickets |
EEA |
EEA — no transfer; SCCs where applicable |
Last updated: 2026-01-01. Material changes to this list are
notified to the Controller in accordance with clause 06. Sub-processor
names, entities and locations may change — the most current list
is the version published at this URL.
Acceptance of the dotspot subscription terms constitutes execution
of this DPA. For Customers requiring a signed counterpart, complete
the block below and return to support@dotspot.ai.
For the Controller (Customer)
Entity
Signatory
Title
Date
Signature
For the Processor (dotspot AS)
Entitydotspot AS, Bergen, NO
Signatory
Title
Date
Signature