1. Parties
This Data Processing Agreement (the "Agreement") is entered into between:
- Controller: The customer that creates an account on the Scoutr platform (the "Customer").
- Processor: Norbites AS ("Scoutr").
This Agreement governs Scoutr's processing of personal data on behalf of the Customer in connection with use of the Scoutr platform.
2. Purpose and Scope
Scoutr processes personal data on behalf of the Customer for the following purposes:
- Provide Scoutr's autonomous sales execution, including research, outreach, continued dialogue, follow-up, and commercial next-step coordination.
- Store and administer the Customer's leads, contacts, and business data.
- Send emails and LinkedIn messages on behalf of the Customer.
- Analyze company data to identify relevant leads.
- Fetch and analyze website or source text when requested by the Customer.
- Send product notifications and daily summaries when such notifications are enabled.
3. Categories of Personal Data
| Category | Types of data |
|---|---|
| Business contacts | Name, email, phone, job title, LinkedIn URL |
| Company data | Organization number, company name, address, incorporation date, public roles and affiliations |
| Communication | Emails, LinkedIn messages, conversation history |
| Users | Name, email, platform role, connected sender identity, and technical access data |
Scoutr is not intended for processing special categories of personal data under GDPR article 9. The Customer must not enter such data without a separate written agreement.
4. Processor Obligations
Scoutr agrees to:
- Process personal data only in accordance with the Customer's documented instructions and this Agreement.
- Notify the Customer if, in Scoutr's opinion, an instruction violates applicable data protection law.
- Ensure that personnel processing data are bound by confidentiality obligations.
- Implement technical and organizational measures to protect personal data. See section 7.
- Not engage subprocessors without the Customer's prior authorization. See section 6.
- Assist the Customer in fulfilling data subject rights, including access, deletion, and portability.
- Assist the Customer with relevant obligations under GDPR articles 32 to 36, to the extent reasonable and possible.
- Notify the Customer without undue delay in the event of a personal data breach.
- Delete or return all personal data upon termination of the agreement.
5. Customer Instructions and Responsibilities
The Customer is the controller for its own leads, contacts, messages, playbooks, and audience selections. The Customer is responsible for ensuring that processing has a lawful basis, that recipients may be contacted lawfully, and that stop signals, reservations, and opt-outs are respected.
Scoutr processes data according to the Customer's instructions through product settings, playbook configuration, connected channels, and written agreements.
6. Subprocessors
Scoutr uses the following subprocessors. The Customer grants general prior authorization for use of these subprocessors. Changes will be notified at least 30 days in advance, and the Customer may object where there is a reasonable basis.
| Provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database and authentication | EU (Frankfurt) |
| Railway Corp. | Application hosting | EU |
| Stripe Inc. | Payment processing | EU/USA (SCC) |
| OpenAI Inc. | AI processing, not model training | USA (SCC + DPA) |
| Unipile SAS | LinkedIn/email integration | EU (France) |
| Resend Inc. | Transactional and product notifications | USA/EU (SCC + DPA) |
| Firecrawl | Website content fetching on Customer instruction | USA/EU (SCC + DPA where relevant) |
For providers outside the EU/EEA, transfers are safeguarded by the European Commission's Standard Contractual Clauses under decision 2021/914.
7. Security Measures
Scoutr has implemented the following measures:
Encryption at rest and in transit where available in the infrastructure
Role-based access control and least privilege principles
Logs for security, operations, and audit of relevant actions
Secure session and access handling
Automatic daily backups with encryption
Regular review of security measures
8. Transfers to Third Countries
Where personal data is transferred to countries outside the EU/EEA, such as OpenAI in the United States, the transfer is safeguarded through EU Standard Contractual Clauses and supplementary measures such as encryption and access control.
9. Personal Data Breach Notification
In the event of a personal data breach, Scoutr will notify the Customer without undue delay and no later than 48 hours after the breach is discovered. The notice will include:
- A description of the breach, including scope and categories of data
- Likely consequences
- Measures taken to limit harm
- A contact point for further information
10. Audit and Control
The Customer has the right to conduct audits to verify Scoutr's compliance with this Agreement. Audits must be notified at least 14 days in advance and conducted in a way that does not unreasonably disrupt Scoutr's operations.
Scoutr may provide documentation, certifications, and third-party audit reports as an alternative to on-site audits.
11. Term and Termination
- This Agreement applies for as long as the Customer uses the Scoutr platform.
- Upon termination, all personal data is deleted within 30 days unless the Customer requests return.
- Data that must be retained by law, such as invoice data, is exempt from deletion.
12. Governing Law
This Agreement is governed by Norwegian law. Disputes are settled by Oslo District Court.
13. Contact
Questions about this Agreement may be sent to:
Norbites AS
Email: personvern@scoutr.no