Last updated: 19 September 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") is available to organisations using Plenora. It takes effect when agreed between the organisation ("Data Controller", "you") and Plenora AS ("Data Processor", "we", "us") for the processing of personal data under the General Data Protection Regulation (GDPR).
1. Scope and roles
When an organisation uses Plenora to create sessions and collect responses from participants, the organisation is the Data Controller and Plenora AS is the Data Processor. This DPA governs Plenora's processing of personal data on behalf of the Controller.
For data that Plenora processes for its own purposes (e.g. account management, billing), Plenora acts as an independent data controller as described in our Privacy Policy.
2. Data processed
| Category | Details |
|---|---|
| Data subjects | Session participants, session creators, organisation members |
| Categories of data | Session responses (poll votes, text submissions, idea contributions), participant display names or identifiers (if configured), IP addresses (transient) |
| Processing activities | Storage, aggregation, display, export, and deletion of session data as instructed by the Controller through the platform |
| Duration | For the duration of the service agreement, plus the retention periods described in Section 7 |
3. Processor obligations
Plenora shall:
- Process personal data only on documented instructions from the Controller, unless required by law
- Ensure that persons authorised to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures (see Section 5)
- Not engage another processor without prior written authorisation from the Controller (see Section 4)
- Assist the Controller with data subject requests and GDPR obligations
- Delete or return all personal data upon termination of the agreement, at the Controller's choice
- Make available all information necessary to demonstrate compliance and allow for audits
Where Plenora exposes optional features that transmit Controller data to a subprocessor (for example, AI authoring features that send presentation content to OpenAI), Plenora will only invoke those features when the Controller, or a user authorised by the Controller, explicitly initiates the feature within the platform. Such initiation constitutes a documented instruction under this DPA. The Controller may disable optional subprocessor-backed features for its tenant.
4. Sub-processing
The Controller provides general written authorisation for Plenora to engage subprocessors listed on our Subprocessor List. We will notify the Controller before intended changes to subprocessors take effect, giving the Controller the opportunity to object.
Where Plenora engages a subprocessor, we ensure equivalent data protection obligations are imposed through a written agreement.
5. Security measures
Plenora implements the following technical and organisational measures:
- Encryption in transit: Connections to Plenora and between its services use TLS
- Encryption at rest: Database storage and object storage are encrypted at rest
- Access controls: Production access is limited to Plenora AS personnel
- Infrastructure isolation: Application runs in a dedicated Kubernetes namespace, separate from other application environments
- Authentication: Administrative access to the cloud providers is protected with multi-factor authentication
- Logging and incident response: Application error reports and operational logs support incident investigation
- EU hosting: Primary data is stored in EU data centres (Scaleway, currently France)
6. Data breach notification
Plenora will notify the Controller of any personal data breach without undue delay after becoming aware of it. Notification will include the information available at that time, such as the nature of the breach, affected data, likely consequences, and measures taken or proposed to address it. Further information may be provided in phases as the investigation continues.
7. Data retention and deletion
Upon termination of the agreement, Plenora will delete or return personal data processed on behalf of the Controller, according to the Controller's choice and without undue delay, unless applicable law requires retention. Backup copies may persist for up to six months and are used only to restore service after a failure. The Controller may export available data before termination using the platform's export features.
8. International transfers
Primary data processing occurs in the EU. Where subprocessors process data outside the EU/EEA, appropriate safeguards are in place (Standard Contractual Clauses). See the Subprocessor List for locations.
9. Audit rights
The Controller has the right to audit Plenora's compliance with this DPA. Audits shall be conducted with reasonable notice (at least 30 days), during business hours, and shall not unreasonably interfere with Plenora's operations. The Controller shall bear its own audit costs.
10. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
11. Governing law
This DPA is governed by the laws of Norway. For matters relating to GDPR enforcement, the supervisory authority is Datatilsynet (Norwegian Data Protection Authority).
12. Contact
For questions about this DPA or to request a signed copy, contact:
Plenora AS, org. no. 837 322 502
Sofienberggata 29C, 0558 Oslo, Norway
Email: [email protected]