Data Processing Agreement
| Item | Detail |
|---|---|
| Provider | Frostbyte Holding AS, Årdalsvegen 35, 6884 Øvre Årdal, Norway |
| Organisation number | 934 881 982 |
| Service | VOKT |
| Version | 1.0 |
| Effective date | 1 September 2026 |
| Contact | [email protected] |
This Addendum forms part of the Agreement where VOKT processes personal data on behalf of a Customer. It is designed to be read with the VOKT Terms and Conditions, Services Agreement, Privacy Policy and applicable Order Form.
1. Purpose and structure
This document combines four customer-facing documents into one operational addendum: (i) the Data Processing Agreement required where VOKT acts as a processor, (ii) the Technical and Organisational Measures applied to relevant VOKT-managed processing, (iii) the current Subprocessor List, and (iv) the Service Level terms for deployment modes to which a service level applies.
VOKT is model-agnostic. The Platform enables Customers to connect and use supported large language models and model providers. VOKT does not select the Customer's business purpose for AI use and does not make the Customer's decisions. Where the Customer independently connects a third-party model provider or its own API credentials, that provider's services, terms, output and processing are outside VOKT's control except to the extent VOKT expressly agrees otherwise in writing.
2. Relationship to the Agreement
This Addendum is incorporated into the Agreement between VOKT and the Customer. If there is a conflict concerning the processing of personal data, this Addendum takes precedence to the extent of that conflict. Commercial terms, fees, intellectual property, acceptable use and general contractual matters remain governed by the Terms and Conditions, Services Agreement and Order Form.
3. Definitions
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | The General Data Protection Regulation (EU) 2016/679 as incorporated into the EEA, and any national law implementing or supplementing it that applies to the processing. |
| Customer | The organisation entering into the Agreement with VOKT. |
| Customer Data | Data, documents, records and other content connected to, uploaded to or generated through the Services. |
| Controller | The party that determines the purposes and means of processing personal data. |
| Processor | The party that processes personal data on behalf of a Controller. |
| Personal Data | Personal data as defined by Applicable Data Protection Law. |
| Subprocessor | A third party appointed by VOKT to process Personal Data on behalf of the Customer. |
| Security Incident | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed by VOKT. |
| Services | The VOKT Platform and related services provided under the Agreement. |
4. Roles and scope
Where VOKT processes Personal Data contained in Customer Data on the Customer's behalf, the Customer is the Controller and VOKT is the Processor. Where the Customer is itself a processor for another controller, VOKT acts as a subprocessor and the same obligations apply accordingly.
The processing role depends on deployment mode. In Own Cloud or Sealed deployments, Customer Data may remain entirely within infrastructure controlled by the Customer. To the extent VOKT does not receive or access Personal Data in those deployments, VOKT is not processing that Personal Data. Any support access or other processing actually performed by VOKT remains subject to this Addendum.
5. Processing details
| Element | Description |
|---|---|
| Subject matter | Provision, operation, support and security of the VOKT Services, including connection to Customer-selected systems, databases, documents, workflows and model endpoints. |
| Duration | For the term of the Agreement and any limited period required for return, export, deletion, backup expiry, legal compliance or dispute resolution. |
| Nature of processing | Hosting where applicable, storage, retrieval, indexing, transmission, OCR/document processing, search, analysis, workflow execution, agent operation, logging, backup, support and deletion. |
| Purpose | To provide the Services in accordance with the Customer's documented instructions. |
| Categories of data subjects | Customer employees, contractors, users, clients, suppliers, prospects and other individuals whose Personal Data the Customer chooses to process through VOKT. |
| Types of Personal Data | Identity and contact data, account data, business records, correspondence, documents, system data, logs and any other Personal Data the Customer lawfully chooses to connect or upload. |
| Special categories | Not required for ordinary use. The Customer is responsible for determining whether special-category or otherwise sensitive data may lawfully be processed and for configuring the Services accordingly. |
6. Customer instructions
VOKT will process Personal Data only on documented instructions from the Customer, including instructions expressed through the Customer's configuration and use of the Services, unless processing is required by law. If law requires processing outside the Customer's instructions, VOKT will inform the Customer before processing unless prohibited by law.
VOKT will inform the Customer if, in VOKT's reasonable view, an instruction infringes Applicable Data Protection Law. VOKT is not required to determine the Customer's lawful basis, purpose or legal authority for the Customer's underlying processing.
7. Customer responsibilities
Determine the purposes of processing and ensure a lawful basis exists for Personal Data placed into or connected to the Services.
Provide required privacy notices and obtain any required permissions or consents.
Configure users, access rights, connected systems, retention and model-provider choices appropriately.
Avoid uploading data that the Customer is not authorised to process.
Assess whether its use of a selected third-party model provider is lawful and appropriate for its own context.
Ensure any independent third-party model provider connected by the Customer is covered by suitable contractual and transfer arrangements where required.
8. Confidentiality and personnel
VOKT will ensure that persons authorised to process Personal Data are subject to confidentiality obligations and receive access only to the extent reasonably required for their role. Access will be removed or changed when no longer required.
9. Security obligations
VOKT will implement and maintain technical and organisational measures appropriate to the risk of the processing under its control. The measures currently relied upon are set out in Schedule 1. VOKT may update those measures where the overall level of protection is not materially reduced.
10. Subprocessors
The Customer gives VOKT general written authorisation to use the Subprocessors listed in Schedule 2. VOKT will impose data-protection obligations on each Subprocessor that are materially consistent with VOKT's obligations under this Addendum and will remain responsible for the Subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.
VOKT will provide notice of a material new Subprocessor before that Subprocessor begins processing Customer Personal Data. The Customer may object on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable solution is available, the affected Service may be terminated in accordance with the Agreement.
11. International transfers
For VOKT-managed standard deployments described in the Agreement, Customer Personal Data is intended to be processed within the European Economic Area. If VOKT itself introduces a transfer outside the EEA, it will use a lawful Chapter V transfer mechanism and comply with Applicable Data Protection Law.
If the Customer connects its own model-provider credentials or otherwise instructs VOKT to send data to a provider outside the EEA, that transfer is initiated by the Customer's configuration and is subject to the Customer's responsibility for the selected provider and transfer basis. VOKT will present a data-residency warning or equivalent acknowledgement where the product supports such configuration.
12. Data subject requests
Taking into account the nature of the processing, VOKT will provide reasonable assistance to the Customer with requests from data subjects to exercise rights under Applicable Data Protection Law. If VOKT receives a request relating to Customer Data, VOKT will not respond substantively on the Customer's behalf unless authorised or legally required. VOKT will forward the request to the Customer without undue delay.
13. Security incidents
VOKT will notify the Customer without undue delay after becoming aware of a Security Incident affecting Personal Data processed by VOKT on the Customer's behalf. The notification will provide information reasonably available to VOKT concerning the nature of the incident, affected data, likely consequences and mitigation or remediation steps.
VOKT will take reasonable steps to contain, investigate and remediate incidents within VOKT-controlled systems. Notification does not constitute an admission of fault or liability.
14. Assistance with compliance
Taking into account the nature of processing and information available to VOKT, VOKT will provide reasonable assistance with the Customer's obligations concerning security, breach assessment, data protection impact assessments and prior consultation where required by Articles 32 to 36 GDPR.
15. Audit and information rights
VOKT will make information reasonably necessary to demonstrate compliance with Article 28 GDPR available to the Customer. Where available, VOKT may satisfy audit requests using current security documentation, architecture information, logs, assessments or independent assurance materials.
If additional audit activity is reasonably required, the Customer may request an audit no more than once per twelve-month period unless a Security Incident or regulatory requirement reasonably justifies more frequent review. Audits must be conducted during normal business hours, with reasonable notice, in a manner that protects other customers, security-sensitive information and VOKT's confidential information.
16. Return and deletion
On termination, VOKT will make Customer Data held by VOKT available for export for the period stated in the Agreement, currently thirty days unless the Order Form states otherwise. After that period, VOKT may delete Customer Data from active systems unless retention is required by law. Backup copies may remain until they expire through the normal backup lifecycle and will remain protected during that period.
For Own Cloud and Sealed deployments, data held exclusively within Customer infrastructure remains under the Customer's control and is not deleted by VOKT unless specifically instructed and technically able to do so.
Schedule 1. Technical and Organisational Measures
1. Data isolation
For VOKT-managed multi-tenant environments, Customer data is separated at the database level using controls designed to prevent one customer from accessing another customer's data. Where a dedicated Private Cloud deployment is used, the Customer receives a dedicated single-tenant instance.
2. Access control
Access to Customer Data is limited to authorised persons with a business need.
Administrative privileges are restricted and managed separately from ordinary user permissions where technically applicable.
Customer administrators control their own authorised users and workspace permissions.
Access is reviewed and removed when no longer required.
3. Authentication and account security
Accounts use authenticated access controls.
Customers are responsible for protecting credentials issued to their users.
Security-relevant authentication and activity information may be logged to investigate misuse or unauthorised access.
4. Logging and auditability
VOKT maintains activity records for meaningful actions performed within the Platform. The Platform is designed to maintain append-only audit records and cryptographically linked event history so alteration, deletion or reordering can be detected where that capability is enabled in the relevant deployment.
5. Hosting and residency
In the standard VOKT-managed configuration described by the current Agreement, application infrastructure, databases, uploaded files and backups are hosted in Helsinki, Finland. VOKT-managed model inference may run on endpoints in Finland and France. Customers may choose deployment modes in their own infrastructure, including a Sealed deployment with no internet connectivity.
6. Model data handling
VOKT does not use Customer Data to train, fine-tune or otherwise improve machine-learning models.
Where VOKT appoints an inference provider as a Subprocessor, VOKT requires contractual data-protection commitments appropriate to the service.
Where the Customer independently connects its own model provider, the Customer controls that choice and the provider's separate terms apply.
7. Vulnerability management
VOKT maintains a public Vulnerability Disclosure Policy for good-faith security research against systems within scope. Security issues may be reported to [email protected]. VOKT investigates confirmed vulnerabilities and applies remediation appropriate to their severity and risk.
8. Availability, backup and recovery
VOKT-managed infrastructure uses hosting and deployment mechanisms designed to support service continuity.
Backups are maintained for relevant VOKT-managed services in accordance with operational requirements.
Private Cloud carries the service level described in Schedule 3.
Own Cloud and Sealed availability, backup and disaster recovery depend partly or entirely on the Customer's own infrastructure and operating procedures unless separately contracted.
9. Change and development controls
VOKT may deploy software updates, security fixes and improvements. Material workflow-affecting changes are communicated with reasonable advance notice where practicable. Security fixes may be applied sooner where necessary to protect the Services.
10. Data minimisation and deletion
VOKT processes Customer Data only as necessary to provide the Services and according to Customer instructions. Customer Data is returned or deleted in accordance with Section 16 of this Addendum and the Agreement.
Schedule 2. Subprocessor List
The following list reflects the subprocessors expressly identified in VOKT's current customer documents. It should be maintained as a live register and updated before any additional provider begins processing Customer Personal Data on VOKT's behalf.
| Subprocessor | Purpose | Location / processing | Applies to |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure hosting for VOKT-managed deployments | Company established in Germany; VOKT standard infrastructure hosted in Helsinki, Finland | Shared Cloud and Private Cloud; other VOKT-managed infrastructure as applicable |
| Nebius B.V. | Model inference for VOKT-managed model endpoints | Company established in the Netherlands; endpoints described by VOKT in Finland and France | Where selected by VOKT as an inference provider for the relevant Service |
Customer-selected model providers are not automatically VOKT Subprocessors. Where a Customer independently connects its own credentials or selects an external provider outside VOKT's managed processing chain, the Customer is responsible for that provider relationship unless the parties expressly agree otherwise.
Schedule 3. Service Level Agreement
1. Scope
The 99.9% monthly uptime commitment applies to Private Cloud where stated in the Order Form or Services Agreement. Shared Cloud is provided using reasonable efforts unless a different service level is expressly agreed. Own Cloud and Sealed deployments run in Customer-controlled infrastructure and are therefore excluded from an infrastructure uptime commitment by VOKT unless separately agreed.
2. Monthly uptime percentage
Monthly Uptime Percentage means the total number of minutes in a calendar month during which the applicable Private Cloud Service is available, divided by the total number of scheduled service minutes in that month, excluding Excluded Downtime.
3. Excluded downtime
Scheduled maintenance notified in advance where reasonably practicable.
Emergency maintenance required to address a material security or reliability risk.
Outages caused by Customer systems, Customer networks, Customer configuration, Customer-selected integrations or third-party services outside VOKT's control.
Suspension permitted under the Agreement.
Force majeure events or widespread internet, telecom, hosting or infrastructure failures outside VOKT's reasonable control.
Beta, preview or non-production features.
4. Support hours
Standard support is provided by email from 08:00 to 17:00 CET, Monday to Friday, excluding public holidays applicable to VOKT, with a target acknowledgement within one business day unless the Order Form provides enhanced support.
5. Incident priorities
| Priority | Example | Target acknowledgement |
|---|---|---|
| P1 Critical | Production service unavailable for most or all authorised users, or a confirmed severe security issue materially affecting the Service | As soon as reasonably practicable during support coverage; escalated internally |
| P2 High | Major functionality unavailable with no reasonable workaround | Within one business day |
| P3 Normal | Limited defect, configuration issue, question or non-critical degradation | Within one business day |
6. Remedies
The current Services Agreement states the 99.9% Private Cloud uptime commitment but does not specify service credits. Accordingly, no automatic service-credit schedule is created by this Addendum unless an Order Form expressly adds one. Persistent material failure remains subject to the contractual remedies available under the Agreement.
7. Planned maintenance and communication
VOKT will use reasonable efforts to schedule planned maintenance to reduce disruption and to notify affected Private Cloud Customers in advance where practicable. Emergency maintenance may be performed without advance notice where necessary to protect security, integrity or availability.
Schedule 4. Model Provider and AI Responsibility Boundary
This Schedule clarifies the division of responsibility created by VOKT's model-agnostic architecture. It is not a Responsible AI Policy and does not make VOKT responsible for the independent operation, content policies, model behaviour or output quality of third-party large language models selected by a Customer.
| Area | VOKT responsibility | Customer responsibility |
|---|---|---|
| VOKT Platform | Operate the VOKT software and VOKT-managed infrastructure in accordance with the Agreement. | Configure and use the Platform lawfully and appropriately. |
| Customer Data | Process Customer Data only as instructed where VOKT acts as Processor; apply the protections in this Addendum. | Determine lawful purpose, lawful basis, data scope and user access. |
| Model selection | Enable supported model-provider connections and, where VOKT provides managed inference, manage the contracted Subprocessor relationship. | Choose which available model is appropriate for the Customer's use case. |
| Customer-connected provider | Provide the technical ability to connect supported external credentials and show residency warnings where applicable. | Contract with, assess and accept the terms, data handling and transfer implications of the selected provider. |
| Model output | Provide Platform features that may include source attribution, audit records and workflow controls where supported. | Evaluate model output before relying on it and remain responsible for decisions and actions taken from that output. |
| Automations and agents | Execute Customer-configured workflows through the Platform. | Define the purpose, permissions, boundaries and required human approval for automated actions. |
Nothing in this Schedule removes obligations VOKT has under Applicable Data Protection Law for processing actually performed by VOKT or by a Subprocessor appointed by VOKT.
Signatures / acceptance
This Addendum becomes binding when incorporated into an Order Form, accepted as part of the Agreement, or otherwise executed by the parties.
| For Frostbyte Holding AS | For Customer |
|---|---|
| Name: ______________________________ | Name: ______________________________ |
| Title: _______________________________ | Title: _______________________________ |
| Date: _______________________________ | Date: _______________________________ |
| Signature: ___________________________ | Signature: ___________________________ |