Data Processing Agreement
Last updated: September 13, 2026
Why this agreement exists
Creator Space lets you record the companies you want to work with and the people you deal with there: names, job titles, email addresses, telephone numbers, and your own notes about them.
Those people are not CollabNordic users. They never gave us their data and, in most cases, will not know we hold it until a proposal reaches them. That makes this a genuine processor arrangement, and Article 28(3) of the GDPR requires it to be in writing. This is that writing.
1. Parties and roles
You, the creator, are the Controller. You are the CollabNordic user who enters contact details into Creator Space.
NiceLab AS, organisation number 936 966 497, Ålgård, Norway, is the Processor. NiceLab AS operates CollabNordic and stores that data on your behalf.
You decide which contacts to record and why. We store them, show them back to you, and send the messages you ask us to send. We do not decide what goes into your records and we do not use them for our own purposes.
This split applies only to the contact data you enter about other people. For your own account, your contracts, your payments and your public profile, we are the Controller and our Privacy Policy governs. One product, two roles, depending on whose data it is.
2. What we process, and why
Set out as Article 28(3) requires.
| Subject matter | Storage and processing of business contact details you record about companies you want to work with. |
| Duration | For as long as you keep the record, plus the deletion periods in section 7. |
| Nature and purpose | Storing your notes, showing them back to you, and delivering proposals and messages you choose to send to those contacts. |
| Categories of personal data | Name, job title, email address, telephone number, and free-text notes you write. |
| Categories of data subjects | Employees and representatives of companies you record as prospects or clients. |
| Special categories | None. Creator Space asks for none, and you must not record any (section 3). |
3. Your obligations as Controller
You confirm that:
- You have a lawful basis for holding each contact's details. In practice this will normally be your legitimate interest in a business relationship, which is what a business contact list is.
- The details are business contact details. Do not record special category data (health, religion, political opinion, trade union membership, sexual orientation, biometrics) about anyone, in any field, including notes.
- Your notes are proportionate. Notes are personal data about a named person and are subject to that person's right of access. Write nothing you would not be willing for them to read.
- You will forward to us, without undue delay, any request you receive from a contact about data held in CollabNordic, so we can help you answer it.
4. Our obligations as Processor
We will:
- Process only on your instructions. Using the product is your instruction. We will not process the contact data for any other purpose unless the law requires it, in which case we will tell you first unless we are legally barred from doing so.
- Never contact your contacts on our own behalf. We will not send them marketing, sales approaches, newsletters, product announcements or surveys, and we will not add them to any audience or mailing list of ours. The only messages they receive from CollabNordic are the ones you send. This one is deliberate and permanent, not a description of current practice.
- Never use your records to compete with you. We will not use them to approach the companies in them on our own behalf, and we will not show any part of them to another creator.
- Keep it confidential. NiceLab AS is a one-person company. Exactly one person, its sole director, can reach the systems your records live in, and no employee, contractor or support agent of ours has access. If that ever changes, this clause and section 8 change with it, and we will say so.
- Keep it secure, per Article 32 and section 8 below.
- Help you meet your obligations, including responding to access, erasure and rectification requests, and handling personal data breaches.
- Delete it when you tell us to, per section 7.
- Make available the information needed to demonstrate compliance, and allow audits per section 9.
5. Sub-processors
You give general authorisation for the sub-processors below. We will give you reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds.
| Sub-processor | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | Application hosting, database, object storage | Helsinki, Finland |
| Resend | Email delivery, transactional and marketing | Ireland |
| Cloudflare, Inc. | Network edge in front of the website, the API and media: encrypted connections, traffic protection, caching of public images and video | Global edge network, served from the location nearest the visitor |
| Stripe, Inc. / Stripe Payments Europe | Payments, escrow, payouts, identity checks | EU and USA |
| Google LLC | Map previews of a brand's address, Sign in with Google on the website, analytics on the website, push notification delivery to Android devices | EU and USA |
| Apple Inc. | Push notification delivery to iPhones, and in-app purchases made through the App Store | USA |
| Expo (650 Industries, Inc.) | Routes push notifications from us to Apple and Google for delivery to the mobile app | USA |
| OpenAI | AI drafting: the campaign generator, the Creator Tools, and suggested replies for our support team | USA |
That table covers every sub-processor CollabNordic uses. They do not all touch the same data, and the difference matters.
Sub-processors that handle the contact data you record. Three.
- Hetzner holds it. The database and object storage your records live in run on their hardware in Helsinki.
- Resend delivers it. When you send a proposal, your contact's address passes through their infrastructure in Ireland.
- Cloudflare carries it in transit. Every page you load passes through Cloudflare's network, so a record you open on screen travels through it, encrypted, on the way to your browser. Cloudflare does not store your records and has no use for them.
Sub-processors that never touch it. The rest serve the running of CollabNordic itself, on data we are the Controller for under our Privacy Policy, which is your own account rather than the people you record.
- Stripe processes payments, escrow, payouts and identity checks. That is your money and your identity, not your contacts.
- Google draws a map of a brand's business address on its public profile, provides Sign in with Google and analytics on the website, and delivers push notifications to Android devices. That is public business information and your own session, not your records.
- Apple delivers push notifications to iPhones and processes App Store purchases. Apple handles the payment itself; we receive a signed confirmation of the purchase and never see card details.
- Expo passes a notification from our servers to Apple or Google. What it carries is your device's push address and the notification itself, which can include the first line of a message sent to you.
- OpenAI drafts text in three places. The campaign generator sends the text of a business's own public website, the description that business typed, and campaign copy for translation. The Creator Tools send the professional facts you give them and, for a pitch, the name, category and public website of the company you are pitching; the contract analyzer sends the document you paste into it, and the screen says so. Our support team uses it to draft and summarise replies, so a support conversation can be sent to it. Your contacts' names, email addresses and telephone numbers, and your notes about them, are never in a prompt.
Every sub-processor above is under a written data processing agreement: Hetzner (Article 28 contract), Resend (their standard DPA, executed on signup), OpenAI (data processing addendum), and Cloudflare, Stripe, Google, Apple and Expo under the data processing terms they publish and apply to all customers. Each that processes outside the EEA incorporates the European Commission's Standard Contractual Clauses, as section 6 sets out.
6. International transfers
The contact data you record is stored in the EEA. It lives on Hetzner in Helsinki and is delivered by Resend from Ireland. Neither is a transfer out of the EEA. On its way to your screen it passes through Cloudflare, which serves each visitor from the network location nearest to them, so for a visitor in Europe it stays in Europe. Cloudflare is a United States company, so its agreement with us carries the Standard Contractual Clauses all the same.
Several sub-processors process outside it. Stripe, Google, Apple, Expo and OpenAI each serve the running of CollabNordic rather than your records, as section 5 sets out, but they do process personal data in the United States. Every one of those transfers is covered by the European Commission's Standard Contractual Clauses, incorporated into the agreement we hold with each of them.
We rely on the Clauses on purpose, and not on the Data Privacy Framework. Some of these providers are also certified under the EU-US Data Privacy Framework. Where they are, we treat that as a second layer on top of the Clauses, never as the thing holding the transfer up. The reason is history: an adequacy decision covering the United States has been struck down twice, in 2015 and 2020, and each time every transfer resting on it was left without a legal basis overnight. The current Framework is valid but under challenge at the Court of Justice. Standard Contractual Clauses are a contract between us and the provider, so they survive a decision the Framework does not. If the Framework falls, nothing in this section changes and no transfer stops.
An EU address is not by itself a guarantee. A provider hosted in Europe may still have a parent company abroad that can reach the data for support. Where that is possible, the same Standard Contractual Clauses cover it.
7. Deletion and return
- Deleting a brand record hides it immediately and deletes it, with its contacts, 30 days later. The delay is deliberate: it is the window in which you can ask us to undo an accident. After it passes the rows are gone, not flagged. That applies whatever you have done with that brand: the record is your own notes about a company, and nothing obliges anyone to keep those. Drafts you never sent go with it.
- An offer you actually sent outlives the record it was addressed from. An offer is a commercial document that reached a third party, and where it was accepted it is the agreement behind an invoiced sale, which the Norwegian Bookkeeping Act requires to be kept for five years after the end of the financial year. Deleting the brand record detaches the offer rather than destroying it, and we then delete the offer too once that period runs out.
- What the offer keeps is the minimum to still be that offer: the company name, organisation number, country and website, and the name and email address it was addressed to, exactly as they read on the day it was sent. Your stage, your tags and your notes are not part of it and do not survive the 30 days.
- On termination of your account, contact data is deleted on the same basis, subject to the same retention obligation for contracts.
- You can ask for it back instead. At any point, including on the way out, ask us and we will send you a copy of the records you hold in a structured, machine-readable file. Request it yourself under Brands and offers on our compliance page. Deletion and return are your choice, not ours.
- Backups are taken hourly and kept for 30 days, then deleted. We keep no longer-term archive, so a deletion becomes irreversible within a month rather than lingering in cold storage for years. Every backup is encrypted, and is automatically restored into a throwaway database and row-counted to confirm it is usable. If we ever restore from a backup, we re-apply every deletion request made since that backup was taken.
8. Security
We maintain measures appropriate to the risk. Concretely:
- There are no passwords. The product stores none, for anyone. Signing in is a one-time code sent to a verified email address, a single-use link, or Google. There is no password database to leak, reuse or phish.
- Two-factor authentication using an authenticator app is available on any account, with single-use recovery codes.
- Encrypted in transit, both between you and the service and between the service and its database, which requires TLS with full certificate verification.
- Separate environments. Test and production run as separate applications against separate databases. Test never holds production data.
- One person with access, as described in section 4.
- Logged and monitored. Application traces, metrics and logs go to a monitoring system with alerting, so a failure is noticed rather than discovered.
- Backups hourly, encrypted, kept 30 days, and automatically test-restored, as described in section 7.
Deliberately not claimed, because they are not true today: encryption at rest for the live database, independent penetration testing, and any security certification. We would rather this list be short and accurate than long and aspirational.
Breach notification. We will notify you without undue delay after becoming aware of a personal data breach affecting your contact data, with the information you need to meet your own Article 33 obligation.
9. Audit
We will provide the information reasonably needed to demonstrate compliance with this agreement. Where that is insufficient, you may request an audit, at your cost, on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise.
10. Liability, term and governing law
Term. This agreement takes effect when you first record a contact in Creator Space. It continues while you hold any such record, and then for as long as we still hold any of that data, including in a backup. Sections 4 and 8, on confidentiality and security, keep applying to anything we still hold after it ends.
If an instruction looks unlawful, we will say so. If something you ask us to do appears to us to breach data protection law, we will tell you before doing it. That is Article 28(3)(h), and it is a duty we owe you rather than a right we reserve.
This agreement wins on data protection. Where it and the Terms of Use disagree about the handling of the contact data you record, this agreement governs. On everything else, the Terms do.
Liability. The limitation of liability in the Terms applies to this agreement, except for a breach by us of the promises in section 4 that we will never contact your contacts on our own behalf and never use your records to compete with you. Those are the commitments this whole agreement exists to make, and a cap that made breaking them cheap would make them worthless. Nothing here limits liability that Norwegian law does not permit us to limit, including for gross negligence or intent, and nothing here affects your rights or ours under Article 82 of the GDPR.
Governing law. Norwegian law. Disputes go to Sør-Rogaland District Court (Sør-Rogaland tingrett), the court for NiceLab AS's registered seat, matching the governing law clause in the Terms. If you are a consumer, this does not deprive you of the right to bring proceedings where you live, or of any protection mandatory law gives you.
11. Contact
Questions about this agreement, or a request from someone whose details a creator has recorded, go to our contact page.