Legal

Data Processing Addendum

Last updated: September 2026

This Data Processing Addendum sets out the processor terms under Article 28 of the GDPR for personal data that Sightova processes on behalf of its customers. It applies automatically to every customer account — no signature is required — and a countersigned copy is available on request.

1. Roles, Scope & Precedence

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer" or "Controller") and Medienor AS, Norway, operating the Sightova platform ("Sightova", "Processor", "we"). It applies wherever Sightova processes personal data on the Customer's behalf in providing the image-analysis services, dashboard and API described in the Terms of Service or a Master Services Agreement (together, the "Services").

For the purposes of the Services the Customer acts as the controller (or as a processor acting on behalf of its own controllers) and Sightova acts as a processor. Where Sightova processes personal data for its own purposes — for example account administration, billing, security logging and legal compliance — it does so as an independent controller under the Privacy Policy.

On matters of data protection this DPA prevails over the Terms of Service and any Master Services Agreement. On all other matters, including fees and limitations of liability, the Master Services Agreement or applicable order controls.

2. Definitions

  • "GDPR" means Regulation (EU) 2016/679 as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven) and, where applicable, the UK GDPR.
  • "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given in the GDPR.
  • "Customer Content" means images, documents and any accompanying metadata the Customer submits to the Services for analysis.
  • "Analysis Records" means the structured results Sightova returns and logs for a submission (scores, labels, request identifier, timestamps, filename, dimensions, file size and the calling IP address and user-agent).
  • "Subprocessor"means a third party engaged by Sightova to process Personal Data on the Customer's behalf.

3. Details of Processing

The following constitutes the description of processing required by Article 28(3) GDPR.

Subject matterAutomated analysis of Customer Content to detect AI-generated, manipulated, explicit, violent or forged imagery, and provision of the related dashboard and API.
DurationFor the term of the Customer's use of the Services and until deletion in accordance with Section 10.
Nature & purposeReceiving, temporarily storing, analysing and scoring images; returning results; logging Analysis Records for the Customer's history, quota enforcement, abuse prevention and support.
Categories of Personal DataAny Personal Data contained in Customer Content (e.g. faces, identity documents, licence plates, embedded metadata) as determined by the Customer; Analysis Records; identifiers of the Customer's users calling the API (IP address, user-agent, API key identifier).
Special categoriesSightova does not require special-category data. Customers who submit images that may reveal such data (for example identity documents or biometric imagery) confirm they have a lawful basis under Article 9 GDPR.
Data subjectsIndividuals depicted in or identifiable from Customer Content, and the Customer's staff or end users who interact with the Services.
Processing locationEuropean Union (Hetzner Online GmbH, Nuremberg, Germany). See Section 9 for subprocessors outside the EEA.

4. Instructions & Confidentiality

Sightova processes Personal Data only on the Customer's documented instructions, which consist of this DPA, the applicable agreement, the Customer's configuration and use of the Services (including each API request), and any further written instructions the parties agree. Sightova will inform the Customer without delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

Sightova may also process Personal Data where required by EU, EEA or Norwegian law, in which case it will inform the Customer of that legal requirement before processing unless the law prohibits such disclosure on important grounds of public interest.

Sightova ensures that every person authorised to process Personal Data — employees and contractors alike — is bound by a contractual or statutory duty of confidentiality and receives appropriate data-protection training.

5. Security Measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Sightova implements the technical and organisational measures set out below (Article 32 GDPR). Current details are maintained on the Trust Center.

  • Transient image handling. Customer Content is written to an isolated temporary directory solely for analysis and deleted as soon as the request completes. Image pixels are never persisted to a database, object store or backup.
  • Encryption in transit. All connections to the Services are encrypted with TLS 1.3; plaintext HTTP is not served.
  • Credential protection. Passwords are hashed with bcrypt (work factor 12); API keys are stored only as SHA-256 hashes and shown once at creation.
  • Access control. Administrative access to production requires SSH key authentication (password login for the administrative account is disabled) and is limited to named engineers. Customer data is accessed only for support, security or legal reasons.
  • Isolation. Detection models run on Sightova-controlled infrastructure; no Customer Content is sent to third-party AI or inference APIs.
  • Input hardening. Strict file-type and size validation, protection against server-side request forgery on URL-based submissions, per-plan rate limits and quotas.
  • Logging & monitoring. Application and access logs are retained for security investigation; the team is alerted to failures and anomalous events.
  • Change management. Code is version-controlled, type-checked and linted before deployment; a database backup is taken before every production schema change.

Sightova may update these measures from time to time provided the overall level of protection is not reduced.

6. Subprocessors

The Customer provides a general written authorisation for Sightova to engage the subprocessors listed at sightova.com/subprocessors. Sightova imposes data-protection obligations on each subprocessor by written contract that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each subprocessor's obligations.

Sightova will publish any intended addition or replacement of a subprocessor on that page at least 30 days before it takes effect and, for Customers who have asked to be notified by email, will send notice to the account owner. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection in good faith, the Customer may terminate the affected Services and receive a pro-rata refund of any prepaid fees.

7. Data Subject Requests

Taking into account the nature of the processing, Sightova will assist the Customer with appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability and objection).

Because image content is deleted immediately after analysis, the Personal Data Sightova can locate for a given Data Subject is normally limited to Analysis Records tied to the Customer's account. Customers can delete their account (which removes every Analysis Record) from the dashboard, or request deletion of specific records by email; Sightova will complete verified requests within 30 days.

If Sightova receives a request directly from a Data Subject relating to Customer Content, it will not respond substantively but will promptly forward the request to the Customer where the Customer can be identified.

8. Personal Data Breaches

Sightova will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. The notification will be sent to the account owner's email address and will include, to the extent then known:

  • the nature of the breach, including categories and approximate numbers of Data Subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its effects; and
  • a point of contact for further information.

Information may be provided in phases as it becomes available. Sightova will reasonably cooperate with the Customer in the Customer's own notifications to supervisory authorities and Data Subjects. Sightova's notification is not an acknowledgement of fault or liability.

9. International Transfers

The Services are hosted and Customer Content is processed exclusively within the European Union. Norway is a member of the European Economic Area, so transfers between the Customer, Sightova and EU-based subprocessors are not restricted transfers under Chapter V GDPR.

Where a subprocessor is located outside the EEA (see the subprocessor list), Sightova relies on an appropriate safeguard under Article 46 GDPR — principally the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where the recipient is certified, the EU–U.S. Data Privacy Framework — supplemented by the transfer-impact measures documented on the subprocessor page. For UK Customers the UK International Data Transfer Addendum applies to the Standard Contractual Clauses.

Sightova will not transfer Customer Content outside the EEA for storage or analysis without the Customer's prior written consent.

10. Retention, Return & Deletion

Customer Content (images)Deleted from the temporary processing directory as soon as the analysis request completes — typically within seconds. Never retained.
Analysis RecordsRetained for the life of the Customer's account so results remain available in the dashboard, unless the Customer deletes them earlier.
Request metadata (IP, user-agent)Stored with the Analysis Record for security, abuse prevention and usage analytics; deleted together with the record.
On terminationAt the Customer's choice, Sightova will delete or return all Personal Data within 30 days of the end of the Services and delete existing copies, unless EU/EEA or Norwegian law requires continued storage (for example invoicing records under the Norwegian Bookkeeping Act, which are kept for the statutory period only).

Deletion is performed by removing rows from the production database. Copies in database backups taken for disaster recovery are overwritten on the normal backup cycle and are not restored except to recover the Services as a whole.

11. Audits & Compliance

Sightova will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Trust Center, its subprocessor list and responses to reasonable written security questionnaires.

Where that information is insufficient to satisfy a legal requirement or a documented instruction from a supervisory authority, the Customer (or an independent auditor bound by confidentiality and not a competitor of Sightova) may audit Sightova's compliance once in any 12-month period, or additionally following a Personal Data Breach, on at least 30 days' written notice, during business hours, at the Customer's expense and in a manner that does not disrupt Sightova's operations or compromise other customers' data.

12. Liability

Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Master Services Agreement or, if none applies, the Terms of Service. Nothing in this DPA limits a party's liability towards Data Subjects or supervisory authorities where such limitation is not permitted by the GDPR.

13. Term & Changes

This DPA takes effect when the Customer first uses the Services and remains in force for as long as Sightova processes Personal Data on the Customer's behalf, including the deletion period in Section 10.

Sightova may update this DPA to reflect changes in law, regulatory guidance or the Services. Material changes will be announced at least 30 days in advance on this page and, for paying Customers, by email. Continued use of the Services after the effective date constitutes acceptance; a Customer who objects may terminate under the process in Section 6.

14. Contact & Signed Copies

This DPA is incorporated by reference into every customer agreement and is binding without signature. If your procurement or legal team needs a countersigned copy — including the Standard Contractual Clauses as an annex — email us and we will return an executed PDF within a few business days.

Data protection contact

Email: hello@sightova.com

Processor: Medienor AS, Norway

Supervisory authority: Datatilsynet (the Norwegian Data Protection Authority)