VALO Research

Data Processing Agreement

Effective 26 September 2026 · Operator: Njål Gaute Solland

Status

This is the standard DPA framework for VALO Research. It becomes operative for a customer only when incorporated into or accepted with an applicable service or pilot agreement.

Parties and roles

The customer is controller and Njål Gaute Solland, operating VALO Research, is processor where VALO processes personal data solely on the customer's documented instructions. Actual roles depend on the processing activity.

Instructions and purpose

Processing is limited to documented instructions, the agreed service purpose and applicable law. VALO will inform the controller if an instruction appears to infringe applicable data-protection law, unless prohibited from doing so.

Confidentiality and access

Access to customer personal data is limited to persons and systems requiring it for the agreed service and subject to appropriate confidentiality obligations.

Security

Appropriate technical and organisational measures are applied relative to the nature, scope, context and risk of the agreed processing. Service-specific measures may be documented in the agreement or security schedule.

Subprocessors

Subprocessors may be used as listed on the Subprocessors page or an agreed service schedule. Required contractual data-protection obligations must flow down to subprocessors.

International transfers

Transfers outside the EEA must use a lawful transfer mechanism where one is required.

Assistance

Taking account of the nature of processing, VALO will provide reasonable assistance with data-subject requests, security obligations, DPIAs and regulator enquiries where required by GDPR and relevant to the processing.

Incidents

VALO will notify the controller without undue delay after becoming aware of a personal-data breach affecting data processed on the controller's behalf, and provide available information needed for the controller's obligations.

Return and deletion

At the end of processing, customer personal data will be returned or deleted as agreed, except where applicable law requires retention.

Audit

Information reasonably necessary to demonstrate compliance will be made available subject to appropriate confidentiality, security and proportionality safeguards.

Required schedule

Before production processing, the parties must identify subject matter, duration, purpose, data types, categories of data subjects, controller instructions, retention and applicable technical and organisational measures.