Data protection
Data Processing Agreement
The standard processor terms between a customer club and Firetender.
Last updated: 15 August 2026
1. Parties and roles
The customer named in the order is controller and SPADE CONSULTING AMUND KRISTIANSEN, organisation number 915 212 352, VAT number NO 915 212 352 MVA, Bankgata 2B, 8006 Bodø, Norway is processor for personal data placed in the service by or for the customer. Each party remains independently responsible for data it controls for its own purposes.
2. Processing instructions
The processor will process personal data only to provide, secure, support, back up, export, and delete the service under the agreement and the customer’s documented instructions, unless law requires otherwise. The processor will notify the customer if an instruction appears unlawful.
3. Processing details
- Subjects: members, former members, guests, officers, users, contacts, payers, speakers, and activity participants.
- Data: identity/contact details, membership history, attendance, roles, communications, meeting/activity participation, imported transaction references, dues status, audit records, and support data.
- Purpose: club administration, communication, reconciliation, reporting, continuity, support, and security.
- Duration: the customer agreement plus the documented export, retention, and deletion period.
4. Confidentiality and security
Authorised personnel are bound by confidentiality. The processor maintains proportionate technical and organisational measures described on the Security page, including tenant-scoped access, least privilege, logging, encrypted transport, provider encryption at rest, controlled exports, vulnerability maintenance, and recovery procedures.
5. Subprocessors and transfers
The customer gives general authorisation for the published subprocessor list. Firetender will give reasonable advance notice of a material new subprocessor so the customer may object on substantiated data-protection grounds. Transfers outside the EEA use an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful mechanism.
6. Assistance
Taking account of the processing, Firetender will reasonably assist with data-subject requests, security obligations, breach assessment, DPIAs, and regulator consultations. The customer remains responsible for deciding how to answer requests and for providing lawful notices and instructions.
7. Incidents
Firetender will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and provide available information needed for the customer’s assessment and notifications. Initial information may be supplied in phases.
8. Return and deletion
On termination, Firetender will make the organisation export available during the agreed period and then delete customer personal data, including from active systems, unless retention is legally required. Backup copies are isolated from normal processing and expire through the documented rotation schedule.
9. Evidence and audit
Firetender will provide information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect other customers and security, use existing independent evidence first, and normally occur no more than once per year unless an incident or regulator requires otherwise.
10. Contact
Data-protection requests and signed DPA requests: amundskristiansen@gmail.com.