1. Parties and purpose
This agreement governs GoRabbit’s processing of personal data on behalf of the customer. The data processor is MORTEN ISEBY VON HAFENBRÄDL NICELIFE.NO ENK (NiceLife.no ENK), org. no. 934 829 131, which provides GoRabbit. The customer is the data controller. The agreement is entered into when the customer accepts the terms of service, and applies for as long as the customer relationship lasts.
2. What is processed, and why
GoRabbit processes personal data to deliver the service: planning, generating and publishing marketing content, customer dialogue, prospecting, sending email and SMS, web shop and related reporting. Processing takes place only on the customer’s documented instructions, which in practice is the customer’s use of the service.
3. Personal data and data subjects
- The customer’s contacts and recipients: name, email address, phone number, position and affiliation with a business.
- Publicly available information about businesses and their representatives, including from the Brønnøysund Register Centre.
- The customer’s own users: name, email address, phone number and login details.
- Content the customer enters, which may contain personal data.
4. The data processor’s obligations
- Processes personal data only on the customer’s instructions, and not for its own purposes.
- Ensures confidentiality for everyone with access to the data.
- Implements appropriate technical and organisational security measures, cf. section 7.
- Assists the customer with access, rectification, erasure and data portability, and with requests from data subjects.
5. Sub-processors
The customer gives general consent to the use of sub-processors. The following are used today:
- Hetzner (Germany) — servers, database and storage.
- ProISP (Norway) — web hosting and email.
- Brevo (France) — sending and tracking email.
- Twilio (USA) — sending SMS.
- Stripe (Ireland and USA) — payment and subscriptions.
- OpenAI and Anthropic (USA) — generating text and suggestions in the service.
- Whereby (Norway) — video meetings and webinars.
All sub-processors are bound by equivalent obligations. The customer is notified before new ones are used, and may object in writing.
6. Transfers outside the EEA
Processing takes place within the EEA where possible. Where a sub-processor processes data outside the EEA, the transfer is based on the European Commission’s standard contractual clauses (SCC) or another valid transfer mechanism.
7. Security
GoRabbit uses encrypted transfer, access control with least privilege, logging, backups and operational monitoring. The security work is based on recognised frameworks such as ISO 27001 and CIS Controls, without claiming full certification.
8. Incidents and breaches
In the event of a personal data breach, the customer is notified without undue delay, with a description of what has happened, which data is affected, and which measures have been taken. The customer is responsible for any notification to the Norwegian Data Protection Authority.
9. Duration and termination
The agreement applies for as long as GoRabbit processes personal data for the customer. On termination, the data is deleted or handed over within 30 days at the customer’s choice, except for what must be retained by law, such as accounting records.
10. Precedence and version
In case of conflict, this agreement takes precedence over the terms of service on matters concerning the processing of personal data. The agreement has the same version number as the terms of service. Changes are notified, and the new version is published on this page.