Scoutr
Product
Give your team more time to sell.Try Scoutr
Meeting bookingGet more relevant customer meetings.EventsBuild interest and get replies to your invitations.Direct offersTake the customer from interest to a clear offer.Product interestBuild interest in trying your product.
How it worksPricing

Data Processing Agreement

How Norbites AS processes personal data on behalf of Scoutr customers under GDPR article 28.

Last updated: August 8, 2026

Legal documentsPrivacy PolicyTerms of ServiceData Processing Agreement
Questionshello@scoutr.no

1. Parties

This Data Processing Agreement (the "Agreement") is entered into between:

  • Controller: The customer that creates an account on the Scoutr platform (the "Customer").
  • Processor: Norbites AS ("Scoutr").

This Agreement governs Scoutr's processing of personal data on behalf of the Customer in connection with use of the Scoutr platform.

2. Purpose and Scope

Scoutr processes personal data on behalf of the Customer for the following purposes:

  • Provide Scoutr's autonomous sales execution, including research, outreach, continued dialogue, follow-up, and commercial next-step coordination.
  • Store and administer the Customer's leads, contacts, and business data.
  • Send emails and LinkedIn messages on behalf of the Customer.
  • Analyze company data to identify relevant leads.
  • Fetch and analyze website or source text when requested by the Customer.
  • Send product notifications and daily summaries when such notifications are enabled.

3. Categories of Personal Data

CategoryTypes of data
Business contactsName, email, phone, job title, LinkedIn URL
Company dataOrganization number, company name, address, incorporation date, public roles and affiliations
CommunicationEmails, LinkedIn messages, conversation history
UsersName, email, platform role, connected sender identity, and technical access data

Scoutr is not intended for processing special categories of personal data under GDPR article 9. The Customer must not enter such data without a separate written agreement.

4. Processor Obligations

Scoutr agrees to:

  • Process personal data only in accordance with the Customer's documented instructions and this Agreement.
  • Notify the Customer if, in Scoutr's opinion, an instruction violates applicable data protection law.
  • Ensure that personnel processing data are bound by confidentiality obligations.
  • Implement technical and organizational measures to protect personal data. See section 7.
  • Not engage subprocessors without the Customer's prior authorization. See section 6.
  • Assist the Customer in fulfilling data subject rights, including access, deletion, and portability.
  • Assist the Customer with relevant obligations under GDPR articles 32 to 36, to the extent reasonable and possible.
  • Notify the Customer without undue delay in the event of a personal data breach.
  • Delete or return all personal data upon termination of the agreement.

5. Customer Instructions and Responsibilities

The Customer is the controller for its own leads, contacts, messages, playbooks, and audience selections. The Customer is responsible for ensuring that processing has a lawful basis, that recipients may be contacted lawfully, and that stop signals, reservations, and opt-outs are respected.

Scoutr processes data according to the Customer's instructions through product settings, playbook configuration, connected channels, and written agreements.

6. Subprocessors

Scoutr uses the following subprocessors. The Customer grants general prior authorization for use of these subprocessors. Changes will be notified at least 30 days in advance, and the Customer may object where there is a reasonable basis.

ProviderPurposeLocation
Supabase Inc.Database and authenticationEU (Frankfurt)
Railway Corp.Application hostingEU
Stripe Inc.Payment processingEU/USA (SCC)
OpenAI Inc.AI processing, not model trainingUSA (SCC + DPA)
Unipile SASLinkedIn/email integrationEU (France)
Resend Inc.Transactional and product notificationsUSA/EU (SCC + DPA)
FirecrawlWebsite content fetching on Customer instructionUSA/EU (SCC + DPA where relevant)

For providers outside the EU/EEA, transfers are safeguarded by the European Commission's Standard Contractual Clauses under decision 2021/914.

7. Security Measures

Scoutr has implemented the following measures:

Encryption

Encryption at rest and in transit where available in the infrastructure

Access control

Role-based access control and least privilege principles

Logging

Logs for security, operations, and audit of relevant actions

Authentication

Secure session and access handling

Backup

Automatic daily backups with encryption

Security review

Regular review of security measures

8. Transfers to Third Countries

Where personal data is transferred to countries outside the EU/EEA, such as OpenAI in the United States, the transfer is safeguarded through EU Standard Contractual Clauses and supplementary measures such as encryption and access control.

9. Personal Data Breach Notification

In the event of a personal data breach, Scoutr will notify the Customer without undue delay and no later than 48 hours after the breach is discovered. The notice will include:

  • A description of the breach, including scope and categories of data
  • Likely consequences
  • Measures taken to limit harm
  • A contact point for further information

10. Audit and Control

The Customer has the right to conduct audits to verify Scoutr's compliance with this Agreement. Audits must be notified at least 14 days in advance and conducted in a way that does not unreasonably disrupt Scoutr's operations.

Scoutr may provide documentation, certifications, and third-party audit reports as an alternative to on-site audits.

11. Term and Termination

  • This Agreement applies for as long as the Customer uses the Scoutr platform.
  • Upon termination, all personal data is deleted within 30 days unless the Customer requests return.
  • Data that must be retained by law, such as invoice data, is exempt from deletion.

12. Governing Law

This Agreement is governed by Norwegian law. Disputes are settled by Oslo District Court.

13. Contact

Questions about this Agreement may be sent to:

Norbites AS
Email: personvern@scoutr.no

Automatic acceptance: This Data Processing Agreement is accepted automatically when a Scoutr account is created. A copy can be provided on request to personvern@scoutr.no.

Scoutr

Your digital salesperson for more sales with the team you have.

ProductProductHow it worksPricing
Use casesMeeting bookingEventsDirect offersProduct interest
ToolsFind companiesAbout Scoutr
LegalPrivacyTermsData processing agreement
© 2026 Norbites AS. All rights reserved.Built in Norway for B2B sales.