✦CanvasFlow
Privacy PolicyTerms of ServiceCookie PolicyAcceptable Use PolicySub-processorsData Processing AgreementSecurity

Legal

Data Processing Agreement

Last updated 28 July 2026

If you use CanvasFlow to hold personal data about other people — colleagues, clients, research participants — then for that data you are the controller and we are your processor. Article 28 of the GDPR requires a written agreement between us. This page is that agreement, and it takes effect automatically when you use the service for such data. No signature is needed; if your procurement process needs a countersigned copy, write to admin@northem.no.

On this page

  1. 1. Roles
  2. 2. Subject matter and scope
  3. 3. Our obligations
  4. 4. Sub-processors
  5. 5. International transfers
  6. 6. Audit
  7. 7. Your obligations
  8. 8. Liability and precedence

1. Roles

You (“Customer”) are the controller. Northem (“Processor”) processes personal data on your behalf, only as needed to provide the service and only on your documented instructions — your use of the product being the primary instruction.

For your own account data — your email address, your billing details, our server logs — we are the controller, and the Privacy Policy governs it rather than this agreement.

If we are ever required by law to process beyond your instructions, we will tell you before doing so unless that law forbids the notice.

2. Subject matter and scope

Subject matterProvision of CanvasFlow, a visual board and note-taking service
DurationFor as long as your account is active, plus the retention periods in the Privacy Policy
Nature and purposeHosting, storage, transmission and display of content you create
Types of personal dataWhatever you choose to place on a board — names, contact details, notes, images, files, and the account identifiers of people you invite
Categories of data subjectYour collaborators, and anyone you write about on a board
Special category dataNot requested, not expected, and not to be uploaded without your own valid Article 9 basis

3. Our obligations

  • Process personal data only on your documented instructions.
  • Ensure that anyone authorised to process it is bound by confidentiality.
  • Implement the technical and organisational measures described on the Security page, which meet Article 32.
  • Engage sub-processors only under Section 4.
  • Assist you, taking into account the nature of the processing, in responding to data subject requests — the export and deletion tools in Settings are built for this and cover most of it.
  • Assist you with data protection impact assessments and prior consultation, where the information is ours to give.
  • Notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it.
  • On termination, delete your data on the schedule in the Privacy Policy, or return it — the export tool produces a complete machine-readable copy at any time.
  • Make available the information needed to demonstrate compliance with Article 28, and allow and contribute to audits under Section 6.

4. Sub-processors

You give general authorisation for us to engage the sub-processors listed on the Sub-processors page. We impose data protection obligations on each of them no less protective than these, and we remain fully liable to you for their performance.

We will give 30 days’ notice before adding or replacing one. You may object on reasonable data protection grounds within that period, and the consequences are set out on that page.

5. International transfers

Your content is stored in the European Union. Where a transfer outside the EEA is necessary — the content delivery edge, and Google sign-in if used — it takes place under the EU–US Data Privacy Framework where the recipient is certified, and otherwise under the European Commission’s Standard Contractual Clauses, which are incorporated into this agreement by reference with us as data exporter’s processor.

We have assessed those transfers and apply supplementary measures: encryption in transit, encryption at rest, and no storage of board content outside the EU.

6. Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will answer a reasonable security questionnaire and provide the documentation we hold about our measures and our sub-processors.

An on-site inspection is available where a supervisory authority requires it, at your cost, arranged so as not to disrupt the service or compromise the confidentiality of other customers.

7. Your obligations

You warrant that you have a lawful basis for the personal data you put on a board, that you have given the required privacy information to the people it concerns, and that your instructions to us do not put us in breach of the GDPR.

You are responsible for who you invite to a board and for what permissions you give them. We enforce the access rules; we do not decide them.

8. Liability and precedence

Liability under this agreement is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise.

Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.

Supervisory authority for Northem: Datatilsynet (the Norwegian Data Protection Authority), https://www.datatilsynet.no.

Northem, Norway · admin@northem.no

Home · All documents · Your data