Effective Aug 10, 2026. This Data Processor Agreement is entered into between Conclude AS, business registration number 913 509 161 (the data processor), and the Customer (the data controller). It forms part of Conclude’s Terms of Service.
1. Purpose of the agreement
The purpose of the agreement is to regulate the rights and obligations under the applicable data protection legislation, and regulation (EU) 2016/679 of 27 April 2016 in respect of the protection of natural persons in connection with the processing of personal data and the free movement of such data (GDPR), and repealing Directive 95/46/EC.
The agreement is intended to ensure that personal data is not processed illegally, wrongfully, or processed in ways that result in unauthorized access, alteration, erasure, damage, loss, or unavailability.
The agreement governs the data processor’s processing of personal data on behalf of the data controller, including the use of Conclude’s services such as creating, deploying, and executing Conclude apps (“Conclude Apps”), as well as enabling and managing the connection between Slack and Microsoft Teams (“Conclude Connect”).
In the event of a conflict concerning the processing of personal data, this agreement takes precedence. In all other respects, the Terms of Service take precedence over any other agreement entered between the data processor and the data controller related to the use of Conclude’s Services. Both sentences are subject to any separate agreement signed by both parties that expressly amends a provision of this agreement or of the Terms of Service, which prevails to the extent of the amendment.
2. Purpose limitation
The purpose of the data processor’s processing of personal data on behalf of the data controller is to support creation, deployment, and operation of Conclude Apps and Conclude Connect.
Personal data that the data processor processes on behalf of the data controller may not be used for any other purpose without the data controller’s prior approval.
The data processor may not transfer personal data covered by this agreement to partners or other third parties without the data controller’s prior approval, cf. section 10 of this agreement.
3. Instructions
The data processor will follow the written and documented instructions for the processing of personal data in Conclude Apps and Conclude Connect, which the data controller has determined will apply.
The data processor is obliged to comply with all obligations under the applicable data protection legislation, including the GDPR, governing the use of Conclude Apps and Conclude Connect for the processing of personal data.
The data processor is obliged to notify the data controller if it receives instructions from the data controller that are in conflict with the provisions of the applicable data protection legislation.
4. Types of personal data and data subjects
The data processor processes personal data collected from the data controller’s collaboration platforms in order to execute Conclude Apps and synchronize data between the platforms.
As of August 1, 2026, Conclude collects information from the following collaboration platforms:
- Slack Technologies (Slack)
- Microsoft Corporation (Microsoft Teams)
- Atlassian Pty Ltd (Jira)
- Zendesk, Inc. (Zendesk)
The collected information includes:
- Information about the collaboration workspace (team), including name, avatar, and technical identifiers.
- Contact information of workspace members, including name, email address, phone number, avatar, and any other information shared in the users’ profiles.
- Information about public channel names, technical identifiers, and member lists.
- Information about private channels where at least one of the channel members has given explicit Sign In consent.
- Information shared in channels where Conclude is a channel member.
- Information about actions in channels where Conclude is a channel member, for example, when a User sets an attribute in Conclude.
- Information about Conclude Apps that Customer installs. Conclude Apps are stored in JSON format and associated with a channel in the Customer’s workspace.
- Information about emails or SMS messages sent from Conclude Apps, created by the Customer. This information is part of the audit log of Conclude Dashboard.
The data subjects are the data controller’s workspace members and channel participants, and other individuals whose personal data appears in content shared in channels where Conclude is a channel member.
5. Rights of data subjects
The data processor is obliged to assist the data controller in safeguarding the rights of data subjects in accordance with applicable data protection legislation.
The rights of data subjects include, but are not limited to, the right to information on how their personal data is processed, the right to request access to their own personal data, the right to request corrections or erasure of their own personal data, and the right to require restriction of processing of their personal data.
To the extent relevant, the data processor will assist the data controller in maintaining a data subject’s right to data portability and the right to object to automated decision-making, including profiling.
Taking into account the nature of the processing and the information available to it, the data processor shall provide reasonable assistance to the data controller in carrying out data protection impact assessments and any prior consultations with the supervisory authority pursuant to Articles 35 and 36 of the GDPR.
6. Security of processing
The data processor shall implement appropriate technical, physical, and organizational safety measures to safeguard the personal data covered by this agreement from unauthorized or unlawful access, alteration, erasure, damage, loss, or unavailability. The specific measures maintained by the data processor are set out in Annex 1 (Technical and Organizational Measures) to this agreement.
The data processor shall provide its employees with adequate information, instruction, and training in data security so that the protection of personal data processed on behalf of the controller is safeguarded.
7. Confidentiality
Only employees of the data processor, who need to access personal data that is processed on behalf of the data controller in connection with their work, will be granted such access. The data processor is required to document guidelines and routines for control of access.
The data processor shall ensure that its employees have a duty of confidentiality in respect of documentation and personal data to which they gain access in accordance with this agreement. This provision also applies after the termination of the agreement. The duty of confidentiality includes employees of third parties who perform maintenance (or similar tasks) of systems, equipment, networks, or buildings that the data processor uses to provide the service.
8. Access to security documentation
The data processor is obliged to provide the data controller, upon request, with access to all security documentation necessary for the data controller to meet its obligations under the applicable data protection legislation, and to other documentation relevant to assessing whether the data processor complies with this agreement.
Upon reasonable prior written notice and no more than once per calendar year (unless required by a supervisory authority or following a personal data breach), the data processor shall allow for and contribute to audits, including inspections, conducted by the data controller or an auditor mandated by the data controller. The data processor may satisfy this obligation by providing its current SOC 2 Type II report and other relevant third-party certifications and documentation. Audits shall be conducted during normal business hours, subject to confidentiality obligations, and in a manner that does not unreasonably disrupt the data processor’s operations.
The data controller has a duty of confidentiality regarding confidential security documentation, which the data processor makes available to the controller.
9. Duty to notify in case of a security breach
The data processor shall notify the controller without undue delay in the event that personal data processed on behalf of the controller is exposed to a breach of security.
The data processor’s notification shall, at minimum, include information that describes the security breach, which data subjects are affected, what personal data is affected by the breach, what immediate measures are implemented to address the breach and what preventive measures may have been established to avoid similar incidents in the future.
The data controller is responsible for ensuring that the competent supervisory authority is notified when required according to the applicable data protection legislation.
10. Sub-processors
The data processor is obliged to enter into separate agreements with sub-processors that govern the sub-processor’s processing of personal data in connection with this agreement.
In agreements between the data processor and sub-processors, the sub-processors shall be required to comply with all the obligations to which the data processor is subject under this agreement and according to law. The data processor is obliged to submit the agreements to the data controller on demand.
The data processor shall verify that sub-processors comply with their contractual obligations, in particular, that data security is satisfactory and that employees of the sub-processors are familiar with their obligations and fulfill them.
The data controller approves that the data processor contracts the following sub-processors to satisfy this agreement:
- Google, USA, for storing and processing Customer data.
- OpenAI OpCo, LLC, USA, with EEA data processed by OpenAI Ireland Limited, Ireland, for AI and machine learning (optional).
- Anthropic Ireland, Limited, Ireland, for AI and machine learning (optional).
- SendGrid Twilio, USA, for sending email from Conclude Apps (optional).
- Twilio, USA, for sending SMS messages from Conclude Apps (optional).
- Stripe, USA - for payment processing and billing-related data.
- ActiveCampaign, USA – for customer communication, marketing automation, and user engagement data.
The Services also connect, at the data controller’s instruction, to the following third-party platforms, which the data controller licenses and controls itself:
- Slack Technologies (Slack workspace).
- Microsoft Corporation (Microsoft Teams tenant).
- Atlassian (Jira instance, optional).
- Zendesk (Zendesk account, optional).
These platforms are not sub-processors of the data processor. The data controller contracts with them directly and authorizes the connection by installing or enabling the integration. The data processor reads and writes personal data there only on that instruction and is not responsible for those platforms’ own processing of personal data.
Where a connection is established with another organization’s workspace, personal data shared into the connected channel is disclosed to that organization, which acts as a separate data controller. Every organization that connects a workspace accepts the Terms of Service, and therefore this agreement, whether or not it is the contracting Customer.
NOTE: The sub-processors marked as optional are only used if the Customer has enabled features that use the sub-processor’s services. As an example, if the Customer has enabled incoming emails with AI-based summarization, Conclude will use the sub-processors SendGrid and OpenAI.
A sub-processor may process personal data in locations other than the country stated above, including through its own affiliates and sub-processors outside the European Economic Area, in order to provide the service. The processing locations applicable to each sub-processor are published by that sub-processor. Such transfers are made on the basis of the EU Standard Contractual Clauses or an adequacy decision, as described in section 11.
The data processor may engage additional or replacement sub-processors. The data processor shall notify the data controller at least thirty (30) days in advance of any intended change, by publishing the change on its website and, where the data controller has subscribed to such updates, by email. The data controller may object in writing to a new sub-processor on reasonable, data-protection-related grounds within the notice period. If the parties cannot resolve the objection, the data controller may terminate the affected services.
Notwithstanding the foregoing, where a new sub-processor relates solely to an optional feature that is disabled by default, the data processor will disclose the sub-processor on its website at the time the feature is made available, and the notice and objection period in the preceding paragraph runs from that publication. Such a sub-processor will process personal data only if and when the data controller enables the relevant feature, and by enabling the feature the data controller authorizes that sub-processor.
Where a sub-processor fails to fulfill its data protection obligations, the data processor remains fully liable to the data controller for the performance of that sub-processor’s obligations, in accordance with Article 28(4) of the GDPR.
11. Transfers outside the EEA
Where the data processor or its sub-processors process personal data outside the European Economic Area, the data processor shall ensure an adequate level of protection through a valid transfer mechanism under Chapter V of the GDPR, including the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or, where applicable, certification under the EU–U.S. Data Privacy Framework, together with any supplementary measures required. Documentation of the relevant transfer mechanism shall be made available to the data controller on request.
12. Security audits
The data processor shall regularly implement security audits of its work to safeguard personal data from unauthorized or unlawful access, alteration, erasure, damage, loss, or unavailability.
Such audits cover the data processor’s security objectives and strategy, its security organization, its guidelines and routines, and the technical, physical and organizational safeguards described in Annex 1.
13. Return and erasure
Upon termination of this agreement or at any time upon request, the data processor is obliged to return or erase, at the data controller’s choice, any personal data that is processed on behalf of the data controller under this agreement.
Erasure is to be carried out by the data processor within thirty (30) days of the request or of termination of the agreement. This also applies to any backups of personal data, which are erased on the data processor’s ordinary backup rotation cycle.
The data processor shall document that the erasure of personal data has been carried out in accordance with this agreement. The documentation shall be made available to the data controller on request.
The data processor shall cover all costs associated with the return or erasure of the personal data covered by this agreement.
14. Termination for breach
In case of breach of terms in this agreement caused by errors or omissions on the part of the data processor, the data controller may terminate the agreement with immediate effect. The data processor will continue to be obliged to return and erase personal data processed on behalf of the data controller pursuant to the provisions of Section 13 above.
15. Limitation of liability
The data processor is not liable for indirect financial loss. Indirect financial loss includes, but is not limited to, loss of profit, revenue, anticipated savings, goodwill, loss of or damage to data, loss caused by interruption of production, disruption of use of the Service or third-party claims (except third-party claims based on infringement of that third party’s intellectual property rights). If the data processor is nevertheless liable for losses incurred by the data controller in connection with this agreement, the data processor’s aggregate liability shall in any case be no more than 25% of the fees payable for the Services, excluding VAT, in respect of the twelve (12) month period preceding the event giving rise to the liability.
Notwithstanding the foregoing, and in place of the limitation in the preceding paragraph, the data processor’s aggregate liability for breach of its data protection obligations under this agreement, including liability for sub-processors pursuant to Article 28(4) of the GDPR and claims arising from a personal data breach, shall not exceed two (2) times the fees payable for the Services, excluding VAT, in respect of the twelve (12) month period preceding the event giving rise to the liability.
For the purposes of both limitations in this section, fees invoiced for a period longer than twelve (12) months are apportioned pro rata to that twelve-month period, so that neither limitation is affected by the frequency with which fees are invoiced.
The limitations of liability in this section do not apply to liability arising from gross negligence or willful misconduct, or to any liability that cannot be limited or excluded under applicable law.
16. Duration of the agreement
This agreement applies as long as the data processor processes personal data on behalf of the data controller.
17. Law and legal venue
The agreement is governed by Norwegian law, and the parties accept Oslo District Court as legal venue. This also applies after termination of the agreement.
Annex 1
Technical and Organizational Measures
The data processor maintains the following technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
- Encryption. All data is encrypted in transit using HTTPS with TLS 1.2 or higher, and at rest using AES-256 encryption.
- Access control. Access to personal data is restricted to authorized personnel on a least-privilege, need-to-know basis, governed by role-based access controls and multi-factor authentication. The data processor requests only the minimum platform permissions necessary to provide the service.
- Confidentiality. All personnel with access to personal data are bound by written confidentiality obligations that survive termination of their engagement.
- Monitoring and logging. The data processor employs continuous monitoring and maintains audit logs of relevant actions within the service.
- Infrastructure security. The service is hosted on Google Cloud Platform using managed database and caching services in high-availability configurations, with automated backups and point-in-time recovery.
- Business continuity. The architecture is designed for resilience, with automatic failover and redundancy to maintain availability during outages.
- Data minimization and retention. The data processor collects and retains only the personal data necessary to provide the service and deletes data within thirty (30) days of a deletion request or the end of the service period.
- Incident response. The data processor maintains an incident response process and notifies the data controller of personal data breaches without undue delay, in accordance with Section 9 of this agreement.
- Secure development and vendor management. The data processor applies secure development practices and requires sub-processors to adhere to data protection and security standards consistent with this agreement. The data processor maintains a policy governing the use of artificial intelligence tools in software development, under which personal data processed on behalf of the data controller is not placed in those tools. This is separate from the optional AI features described in section 10, which the data controller enables.
- Certifications and audits. The data processor is SOC 2 Type II certified, undergoes regular independent security audits, and maintains administrative, technical, and physical safeguards aligned with the HIPAA Security Rule. Certification status and an overview of controls are available through the data processor’s Trust Center. Audit reports are available on request, subject to confidentiality obligations. The Services are not intended for the processing of protected health information.