Valuesync AS
1. How this agreement applies
1.1 This Data Processing Agreement ("DPA") forms part of the agreement between Valuesync AS ("Valuesync", "Processor") and the customer ("Customer", "Controller") for use of the Valuesync platform (the "Service"), as set out in Valuesync's Terms of Service at valuesync.ai/terms-of-service (the "Terms").
1.2 No separate signature is required. By entering into the Terms, or by using the Service, the Customer accepts this DPA. Customers who require a signed copy may request one from torbjorn.poulsen@valuesync.ai.
1.3 Customers with a negotiated agreement. Where the Customer has entered into a separate written agreement with Valuesync that includes a data processing agreement, that agreement applies in full and replaces this DPA. This DPA applies only to customers without such an agreement.
1.4 This DPA meets the requirements of Article 28 of the General Data Protection Regulation (GDPR).
1.5 In the event of conflict between this DPA and any other agreement between the parties, this DPA prevails on matters concerning the processing of personal data.
2. Scope
2.1 Valuesync processes personal data on behalf of the Customer as part of delivering the Service. The purpose, nature, duration, categories of personal data and categories of data subjects are described in Annex A.
2.2 This DPA governs the processing of personal data contained in Customer Data.
2.3 Operational Data, meaning account data about Users, usage and telemetry data, error and security logs, and billing data, is processed by Valuesync for its own purposes and under its own responsibility, as an independent controller. That processing is described in Valuesync's privacy policy at valuesync.ai/privacy-policy and falls outside this DPA.
2.4 Valuesync determines the non-essential technical and organisational means of the processing, but not its purposes or the essential means.
3. Definitions
Customer Data means all content the Customer or its Users upload, enter or generate in the Service, including documents, transaction data, notes and analysis results. Customer Data does not include Operational Data.
Operational Data means data about the operation and use of the Service that Valuesync processes for its own purposes as an independent controller, including account data about Users (name, email address, role and authentication data), usage and telemetry data, error and security logs, and billing data. Operational Data is not Customer Data.
User means a named individual at the Customer who has been granted access to the Service.
Sub-processor means a processor engaged by Valuesync to process Customer Data.
Terms not defined here have the meaning given in the GDPR or in the Terms.
4. Instructions
4.1 Valuesync processes personal data only on documented instructions from the Customer.
4.2 This DPA with its annexes, together with the functionality the Customer uses in the platform, constitutes the complete instruction.
4.3 Valuesync will notify the Customer without delay if, in Valuesync's assessment, an instruction infringes data protection law.
4.4 Valuesync does not process personal data contained in Customer Data for its own purposes.
4.5 Valuesync may process personal data beyond the instruction where required by EEA or Norwegian law. Valuesync will notify the Customer before doing so, unless such notification is prohibited.
5. Customer obligations
5.1 The Customer is responsible for ensuring a valid legal basis for the personal data entered into the platform.
5.2 The Customer is responsible for meeting its information obligations towards data subjects.
5.3 The platform is not designed for special categories of personal data (GDPR Article 9) or data relating to criminal convictions and offences (Article 10). Valuesync does not intend to process such data and offers no functionality that facilitates it. If the Customer nonetheless enters such data, the Customer is solely responsible for the legal basis.
5.4 The platform is not designed for the systematic processing of national identification numbers. The Customer shall avoid entering such data unless reasonably necessary for its permitted use of the Service.
5.5 National identification numbers may nonetheless appear incidentally in documents uploaded by the Customer, including shareholder register statements, employment contracts, land registry extracts or tax documents. Such occurrences do not constitute a breach of section 5.4.
5.6 The Customer is solely responsible for the content of documents, notes and other information entered into the platform, including its compliance with data protection and other applicable law. Valuesync has no obligation to review, edit or assess the lawfulness of such content.
6. Confidentiality
6.1 Valuesync ensures that persons with access to the personal data are bound by a duty of confidentiality.
6.2 Access is granted only to personnel with a business need, on the principle of least privilege.
6.3 The duty of confidentiality survives termination of this DPA and the end of the individual's employment.
7. Security
7.1 Valuesync implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32.
7.2 The measures implemented are described in Annex B.
7.3 Valuesync may change the security measures, provided the level of security is not reduced.
8. Sub-processors
8.1 The Customer grants Valuesync general authorisation to engage sub-processors.
8.2 A current list of Valuesync's sub-processors, including the data they process, their location and the applicable transfer basis, is published at valuesync.ai/subprocessors.
8.3 Valuesync will give the Customer reasonable advance notice before engaging a new sub-processor or replacing an existing one. Notice is given by email to the Customer's registered contact and by updating the list referred to in section 8.2.
8.4 The Customer may, before the change takes effect, submit a written and reasoned objection on grounds relating to data protection. Valuesync will work with the Customer in good faith and use commercially reasonable efforts to address the objection. If no reasonable solution is available, the Customer may, as its sole remedy, terminate the affected part of the Service, or the subscription as a whole where necessary, with effect from the date the change takes effect, against a pro rata refund of prepaid, unused fees.
8.5 Valuesync imposes on its sub-processors the data protection obligations required by Article 28(4) GDPR, and remains fully liable to the Customer for their performance.
9. Transfers outside the EEA
9.1 Customer Data is stored within the EEA. Customer Data may be processed by Valuesync and its sub-processors in the EEA and, where applicable, outside the EEA as described in the sub-processor list referred to in section 8.2.
9.2 Any transfer of personal data outside the EEA will take place only where a valid transfer mechanism under applicable data protection law is in place. The applicable recipient countries and transfer mechanisms are stated in the sub-processor list.
9.3 For transfers based on the EU Standard Contractual Clauses, Valuesync has assessed the legal position in the recipient country and implemented the necessary supplementary measures.
10. Artificial intelligence and external data sources
10.1 The Service may use large language models and other AI services supplied by the model providers identified in the sub-processor list. When the Customer uses AI functionality, relevant Customer Data may be submitted to such providers to the extent necessary to provide the requested functionality. Changes to the providers used follow section 8.
10.2 Personal data processed through the platform is not used to train or further develop AI models, either by Valuesync or by any model provider.
10.3 Content submitted to a model provider is used solely to generate the response requested. It is not used for any other purpose, except that it may be retained for a limited period for abuse monitoring in accordance with the provider's standard terms, after which it is deleted automatically. The applicable retention period for each provider is stated in the sub-processor list at valuesync.ai/subprocessors.
10.4 The processing does not involve automated decision-making producing legal or similarly significant effects for the data subject within the meaning of GDPR Article 22. The platform's outputs are decision support and presuppose human assessment.
10.5 Valuesync does not use Customer Data to train or develop general-purpose AI models, or to derive or disclose customer-specific information for the benefit of other customers or third parties. Customer Data is kept logically separated per customer and is not aggregated, benchmarked or otherwise combined across customers.
10.6 The Service may retrieve publicly available company information from external data sources. Valuesync transmits only the information reasonably necessary to perform the relevant lookup. Where an external provider processes personal data contained in Customer Data on behalf of Valuesync, that provider will be treated as a sub-processor under section 8. Information retrieved through such services forms part of Customer Data.
11. Assistance to the Customer
11.1 Valuesync assists the Customer, so far as possible, with appropriate measures enabling the Customer to fulfil data subject rights under GDPR Chapter III, including access, rectification, erasure, portability and objection.
11.2 Requests from data subjects received directly by Valuesync are forwarded to the Customer without undue delay. Valuesync does not respond to such requests on its own.
11.3 Valuesync assists the Customer in meeting its obligations under GDPR Articles 32–36, including security, breach notification and data protection impact assessments, taking into account the nature of the processing and the information available to Valuesync.
11.4 Assistance beyond what can be provided with reasonable effort may be charged at Valuesync's applicable hourly rates, subject to prior notice.
12. Personal data breaches
12.1 Valuesync will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer.
12.2 The notification will, so far as possible, include the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a point of contact.
12.3 Valuesync assists the Customer with notification to the supervisory authority and, where required, to data subjects.
12.4 Valuesync documents all breaches and the measures taken.
12.5 The Customer shall likewise notify Valuesync without undue delay of any breach affecting the platform, including compromised user accounts or credentials.
13. Audit and documentation
13.1 Valuesync makes available all information necessary to demonstrate compliance with this DPA.
13.2 The Customer may carry out an audit once per calendar year, on at least 30 days' written notice. Audits may be carried out more frequently following a personal data breach or where required by a supervisory authority.
13.3 Valuesync may discharge its documentation obligation by providing a valid third-party audit report or certification covering the relevant matters.
13.4 The Customer bears its own costs. Valuesync's time in excess of 8 hours per audit may be charged.
13.5 Audits are conducted so as not to give access to other customers' data.
14. Term, deletion and return
14.1 This DPA applies for as long as Valuesync processes personal data on behalf of the Customer.
14.2 On termination, Valuesync will, at the Customer's option, delete or return all personal data.
14.3 Unless the Customer requests deletion at an earlier point, or the parties agree otherwise:
- personal data remains available for export for 30 days after termination;
- it is thereafter deleted from active systems within 90 days;
- copies contained in backups are deleted in accordance with Valuesync's standard backup retention procedures; and
- Valuesync will, on request, confirm in writing when deletion has been completed.
Any retention required by applicable law is governed by section 14.4.
14.4 Valuesync may retain personal data where required by EEA or Norwegian law. The Customer will be informed of the scope and the basis.
15. Liability
15.1 Each party's liability under this DPA, including liability for claims arising from a breach of data protection law and for administrative fines imposed on the other party, is subject to the limitations and exclusions of liability set out in the Terms. Those limitations apply to the agreement as a whole; this DPA does not create a separate or additional cap.
15.2 This does not limit data subjects' rights under GDPR Article 82.
15.3 Where Valuesync is held liable to a data subject for damage caused wholly or partly by the Customer's breach of data protection law, the Customer shall indemnify Valuesync for the corresponding share of that liability. The same applies in reverse.
16. Changes to this DPA
16.1 Valuesync may update this DPA where necessary as a result of changes in law, in the platform or in the use of sub-processors. The current version is always available at this page.
16.2 Changes that reduce the Customer's rights or the level of protection will be notified in writing at least 30 days before they take effect, by email to the Customer's registered contact or by notice in the platform.
16.3 The Customer may, within that period, submit a written and reasoned objection. If the parties do not reach agreement, the Customer may terminate the agreement with effect from the date the change takes effect, against pro rata refund of prepaid, unused fees.
16.4 Changes to sub-processors follow section 8.
17. Governing law and venue
This DPA is governed by Norwegian law. The parties agree to Oslo District Court as venue.
Contact
Valuesync AS, org. no. 933 375 854 Gaustadalléen 21, 0349 Oslo, Norway Privacy contact: Torbjørn Poulsen, torbjorn.poulsen@valuesync.ai
Annex A: Description of the processing
A.1 Purpose
Processing is carried out to deliver the Valuesync platform to the Customer, including:
- recording and following up transactions and portfolio companies
- recording contact persons at counterparties, target companies and advisers
- AI-based analysis of documents and transaction material, including assessments of companies, ownership and management
- collaboration, task management and activity logging
- support and error correction
A.2 Nature of the processing
Collection, recording, structuring, storage, analysis using language models, making available to authorised users, compilation, deletion.
A.3 Categories of data subjects
| Category | Description |
|---|---|
| The Customer's employees | Users of the platform |
| Contact persons at target companies | Name and business contact details |
| Management and board members of target and portfolio companies | Including assessments recorded by the Customer |
| Contact persons at counterparties, sellers and advisers | Name and business contact details |
| Individuals named in documents uploaded by the Customer | Scope determined by the Customer |
A.4 Categories of personal data
| Category | Examples |
|---|---|
| Identification data | Name, title, employer |
| Contact details | Email address, telephone number |
| Professional background | Role, experience, seniority |
| Assessments recorded by the Customer | Management assessments, notes, comments |
| Data in uploaded documents | Determined by the Customer |
Not included: Account data about the Customer's Users (name, email address, role, authentication data) and technical data about use of the platform (login history, activity logs, security logs, telemetry) is Operational Data, which Valuesync processes as an independent controller in order to provide, secure and operate the platform. See section 2.3 and Valuesync's privacy policy.
Special categories (Article 9) and criminal conviction data (Article 10): the platform is not designed for such data and offers no functionality for it. National identification numbers are to be avoided so far as possible but may appear individually in uploaded due diligence material. See sections 5.3–5.6.
A.5 Duration
Processing continues for as long as the agreement is in force, with subsequent deletion under section 14.
Annex B: Technical and organisational measures
Valuesync has implemented the following measures to protect personal data processed in the platform.
Data protection
- Encryption. Customer data is encrypted at rest with AES-256 at the underlying cloud storage layer. Encryption at rest is always enabled and cannot be switched off. Backups and stored files are encrypted in the same way, in the selected region. Data in transit is protected with TLS.
- Access control. Access to customer data is role-based and granted only to personnel with a business need, on the principle of least privilege. Customer data is logically separated between customers, enforced at database level through row level security.
- Backup and recovery. Valuesync takes automated backups of customer data so that it can be restored following an incident. Recovery objectives are documented internally and available to customers on request.
- Logging. Logins and security-relevant events are logged.
- Monitoring. Valuesync monitors availability and errors on an ongoing basis in order to detect and respond to operational and security issues.
Development and change management
- Development, test and production run in separate environments. Production data is not used for testing or development.
- Changes are version controlled, reviewed before deployment, and traceable.
Organisational security
- All personnel with access to customer data are bound by a written confidentiality undertaking.
- Valuesync maintains procedures for handling security breaches and for revoking access when personnel leave.
- Valuesync maintains a record of processing activities under GDPR Article 30.
Sub-processors
- Valuesync enters into a data processing agreement with each sub-processor, imposing data protection obligations equivalent to those in this DPA.
- The security level of a sub-processor is assessed before it is engaged.
Valuesync reviews and develops these measures on an ongoing basis. Measures may be changed provided the level of security is not reduced. Further documentation is available to customers under section 13.
Version history
| Version | Date | Change | Status |
|---|---|---|---|
| 1.0 | 6 August 2026 | First published version | Current |

