Legal

Data Processing Agreement 

Version 1.1 date: 25.05.2026

This Data Processing Agreement (the "DPA") is entered into between Stellai AS, a company incorporated under the laws of Norway with company number 925 053 066 and registered office at Tordenskjolds gate 9, 4612 Kristiansand, Norway ("Stellai" or the "Processor"), and the customer identified in the given agreemant/s to which this DPA is incorporated by reference (the "Customer" or the "Controller"). Stellai and the Customer are each a "Party" and together the "Parties". 

This DPA governs the Processor's processing of Personal Data on behalf of the Controller in the course of delivering Stellai´s services (the "Services"). The Services are described in the agreemants and the Product Specification published at stell.ai/legal/product. 

This DPA is designed to satisfy Article 28 of Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR, and the Norwegian Personal Data Act, and forms an integrale part of the commercial agreement between the Parties. In the event of any conflict between this DPA and the underlying commercial agreement regarding the processing of Personal Data, this DPA shall prevail. 

Table of Contents 

1. Definitions 

2. Scope and Roles of the Parties 

3. Subject Matter, Nature and Purpose of the Processing 

4. Controller's Obligations 

5. Processor's Obligations 

6. Security of Processing 

7. Sub-processors 

8. International Transfers 

9. Data Subject Rights 

10. Personal Data Breaches 

11. Audits and Inspections 

12. Return or Deletion of Personal Data 

13. Liability, Term and Governing Law 

A. Appendix A — Processing Details 

B. Appendix B — Sub-processors 

C. Appendix C — Security Measures 


1. Definitions 

Capitalised terms used in this DPA shall have the meanings given below. Terms not defined here shall have the meaning given in the GDPR. 

  • "Applicable Data Protection Law" means the GDPR, the UK GDPR, the Norwegian Personal Data Act, and any other applicable data protection or privacy law. 
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Sub-processor", "Personal Data Breach" and "Supervisory Authority" shall have the meanings given in the GDPR. 
  • "Customer Personal Data" means any Personal Data Processed by Stellai on behalf of the Customer under the Services, as further described in Appendix A. 
  • "Order Form/agreemants" means the commercial document executed between the Parties that references this DPA. 
  • "Services" means all services delivered by Stellai, consisting of AI-based detection software, edge hardware, monitoring, and related services as set out in the Order Form/agreemant 
  • "Sub-processor" means any third party appointed by Stellai to Process Customer Data on its behalf. 

2. Scope and Roles of the Parties 

2.1 The Customer is the Controller and Stellai is the Processor with respect to the Processing of Customer Personal Data under this DPA. 

2.2 This DPA applies to all Processing of Customer Personal Data carried out by Stellai in connection with the provision of the Services. 

2.3 Each Party shall comply with its respective obligations under Applicable Data Protection Law. Neither Party may require the other to act in breach of Applicable Data Protection Law. 

3. Subject Matter, Nature and Purpose of the Processing 

3.1 The subject matter, nature, purpose, categories of Personal Data, categories of Data Subjects, and duration of the Processing are set out in Appendix A. 

3.2 Stellai Processes Customer Personal Data only for the following purposes: (i) to deliver, maintain, monitor and support the Services; (ii) to detect hazardous or non-compliant objects in the Customer's operations and provide alerts and documentation to the Customer; (iii) to improve the accuracy and performance of the AI detection models, using anonymised data only; and (iv) to comply with documented instructions from the Customer or with legal obligations applicable to Stellai. 

3.3 Stellai shall not Process Customer Personal Data for any purpose other than those described in Section 3.2, or as documented in writing by the Customer. 

4. Controller's Obligations 

4.1 The Customer shall establish and maintain a lawful basis under Article 6 of the GDPR for the Processing of Customer Personal Data, including providing any required information to Data Subjects and obtaining any required consents. 

4.2 The Customer shall ensure that its instructions to Stellai comply with Applicable Data Protection Law and shall be responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which the Customer acquired such data. 

4.3 The Customer acknowledges that Stellais solution is installed in environments where individuals may incidentally appear on camera and that the Customer is responsible for providing appropriate notices, signage, and information in accordance withApplicable Data Protection Law. 

5. Processor's Obligations 

5.1 Stellai shall Process Customer Personal Data only on documented instructions from the Customer. This DPA, and the Services documentation constitute the Customer's complete and final instructions at the time of execution. Additional or alternative instructions must be agreed in writing.  

5.2 Stellai shall promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. 

5.3 Stellai shall ensure that all personnel authorised to Process Customer Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory, and that access is granted strictly on a need-to-know basis. 

5.4 Stellai shall assist the Customer in fulfilling its obligations under Articles 32 to 36 of the GDPR, including providing reasonable information and documentation required for data protection impact assessments and consultations with Supervisory Authorities. 

6. Security of Processing 

6.1 Stellai shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful Processing, accidental loss, destruction, damage, alteration, or disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to the rights and freedoms of Data Subjects. 

6.2 The current technical and organisational measures are set out in Appendix C. Stellai may update these measures from time to time, provided the level of protection is not materially reduced. 

6.3 Stellai shall test, assess and evaluate the effectiveness of its security measures on a regular basis and shall maintain records of such assessments. 

7. Sub-processors 

7.1 The Customer grants Stellai general authorisation to engage Sub-processors to Process Customer Personal Data, subject to the terms of this Section 7. The current list of authorised Sub-processors is set out in Appendix B and maintained at stell.ai/legal/subprocessors. 

7.2 Stellai shall impose on each Sub-processor, by written contract, data protection obligations substantially equivalent to those set out in this DPA. Stellai remains fully liable to the Customer for any failure by its Sub-processors to comply with those obligations. 

7.3 Stellai shall give the Customer at least seven (7) days' prior written notice of any intended addition or replacement of Sub-processors. The Customer may object to such change on reasonable data protection grounds within the notice period. If the Parties are unable to resolve the objection, the Customer may terminate the affected Services with immediate effect. 

8. International Transfers 

8.1 Stellai Processes and stores Customer Personal Data primarily within the European Union and the European Economic Area (EU/EEA). 

8.2 Customer Personal Data may transit via the United States in the course of certain AI inference operations, but shall not be stored outside the EU/EEA by the Services or its Sub-processors. 

8.3 Where any transfer of Customer Personal Data to a country outside the EU/EEA does occur, Stellai shall ensure that such transfer is made in accordance with Chapter V of the GDPR, using an appropriate transfer mechanism (such as the EU Commission's Standard Contractual Clauses or an adequacy decision). 

9. Data Subject Rights 

9.1 Taking into account the nature of the Processing, Stellai shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR. 

9.2 If Stellai receives a request directly from a Data Subject concerning Customer Personal Data, Stellai shall promptly forward the request to the Customer and shall not respond directly, except as required by law or as instructed by the Customer. 

9.3 The Parties acknowledge that the Services are designed around data minimisation, including automatic and irreversible face anonymisation prior to storage. As a result, certain Data Subject requests — in particular access requests — may not be capable of being fulfilled, as no identifying information is retained. Stellai shall inform the Customer of such limitations on request. 

10. Personal Data Breaches 

10.1 Stellai shall notify the Customer without undue delay, and in any event within 24 hours of becoming aware, of any confirmed Personal Data Breach affecting Customer Personal Data. 

10.2 Such notification shall include, to the extent known: the nature of the breach; the categories and approximate number of affected Data Subjects and records; the likely consequences; and the measures taken or proposed to address and mitigate the breach. 

10.3 Stellai shall cooperate with the Customer and provide reasonable assistance in the Customer's fulfilment of its own notification obligations under Articles 33 and 34 of the GDPR. 

11. Audits and Inspections 

11.1 Stellai shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. 

11.2 The Customer may conduct audits of Stellai's compliance with this DPA no more than once per calendar year, on at least ten (10) business days' prior written notice. Shorter notice may apply where an audit is triggered by a confirmed or suspected Personal Data Breach, or at the direction of a Supervisory Authority. 

11.3 Audits may be carried out through documentation review, written questionnaires, remote interviews, system demonstrations or, where reasonably necessary, on-site inspections. Stellai may satisfy its audit obligations by providing an up-to-date independent certification or assurance report (such as ISO/IEC 27001 or SOC 2 Type II), unless the Customer reasonably demonstrates that such reports are insufficient for its specific compliance purposes. 

11.4 Audits shall be conducted in a manner that does not unreasonably disrupt Stellai's operations, and the Customer shall bear the costs of routine audits. Where an audit identifies a material breach of this DPA by Stellai, Stellai shall bear its own internal costs and the reasonable external costs of the audit. 

12. Return or Deletion of Personal Data 

12.1 Upon termination or expiry of the Services, Stellai shall, at the Customer's choice, delete or return all Customer Personal Data and delete existing copies, unless Union or Member State law requires continued storage. 

12.2 Stellai shall confirm in writing, on request, that deletion has been completed. Backup copies shall be deleted in accordance with Stellai's standard backup retention cycle. 

12.3 Default retention periods during the term of the Services are set out in Appendix C. The Customer may request in writing to modify these periods, subject to operational feasibility. 

13. Liability, Term and Governing Law 

13.1 This DPA shall take effect on the effective date of the Order Form and shall remain in force for as long as Stellai Processes Customer Personal Data in connection with the Services. 

13.2 Each Party's liability under or in connection with this DPA shall be subject to the liability provisions of the underlying commercial agreement between the Parties, except where mandatory provisions of Applicable Data Protection Law provide otherwise. 

13.3 This DPA shall be governed by the laws of Norway, without regard to conflict of law principles. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the ordinary courts of Norway, with Agder District Court as venue, unless otherwise required by Applicable Data Protection Law. 

13.4

(a) Stellai may amend this DPA from time to time to reflect changes in Applicable Data Protection Law, changes to Sub-processors, improvements to security measures, or other reasonable operational updates, provided that no such amendment shall materially reduce the level of protection for Customer Personal Data. 

(b) Stellai shall notify the Customer in writing of any such amendment at least fourteen (14) days before the effective date. If the Customer does not object in writing within the notice period, the amendment shall be deemed accepted and shall take effect on the stated effective date. The current version of this DPA, together with its version history, is maintained at stell.ai/legal/dpa. 

(c) If the Customer objects on reasonable data protection grounds within the notice period, the Parties shall negotiate in good faith to agree on a mutually acceptable alternative. If the Parties are unable to reach agreement within thirty (30) days of the objection, the Customer may terminate the affected Services with effect from the proposed effective date of the amendment, without further liability on either side in relation to such termination. 

(d) Notwithstanding paragraphs (a) to (c), any amendment that modifies Appendix A (Processing Details) — including the subject matter, nature, purpose, categories of Personal Data, categories of Data Subjects, or duration of the Processing — shall require the Customer's express written agreement and shall not be subject to deemed acceptance. Amendments to the list of authorised Sub-processors are governed exclusively by Section 7. 


Appendix A — Processing Details 

A.1 Subject matter and nature of the Processing 

Stellai provides the IdentifAI service to the Customer, consisting of real-time AI-based detection of hazardous or non-compliant objects in material handling and waste sorting operations. The Processing consists of capturing live video at the Customer's installation sites, running AI inference on an edge device, generating event records where the AI model detects a potential hazard, applying irreversible face anonymisation, and storing event records in the Customer's dedicated environment. 

A.2 Purposes of the Processing 

  • Delivery, operation, monitoring and support of the Services. 
  • Detection of hazardous or non-compliant objects and generation of operator alerts and documentation. 
  • Continuous improvement of the AI detection models using anonymised data. 
  • Remote troubleshooting, optimisation and technical support via secure VPN. 

A.3 Categories of Personal Data 

  • Live video frames containing individuals — processed in volatile memory (RAM) only and not stored. 
  • Event-based cropped images in which faces have been automatically and irreversibly anonymised prior to storage. 
  • Detection metadata: timestamps, object classifications, detection confidence scores, device identifiers. 
  • System logs relating to access, detections and technical events. 
  • Remote support metadata: IP addresses and device identifiers, where remote support sessions are used. 

A.4 Categories of Data Subjects 

Individuals who appear within the camera's field of view at the Customer's installation sites, typically employees, visitors, contractors or members of the public. All faces are automatically anonymised prior to storage. 

A.5 Duration of the Processing 

Processing is carried out continuously for the duration of the Services. Retention periods for each category of data are set out in Appendix C.1. 


Appendix B — Sub-processors 

The following Sub-processors are authorised by the Customer on the effective date of this DPA: 

 

Sub-processor 

Microsoft Azure (Ireland) 

Purpose 

Cloud hosting, databases, storage 

Location of processing 

One Microsoft Place, Dublin 

Country 

Ireland (EU) 

 

Sub-processor 

Microsoft Azure (Norway) 

Purpose 

Cloud hosting, regional processing 

Location of processing 

Dronning Eufemias gate 71, Oslo 

Country 

Norway (EEA) 

 

Sub-processor 

Alvir AS 

Purpose 

Frontend application development and maintenance 

Location of processing 

Sinsenterrassen 2B, Oslo 

Country 

Norway (EEA) 

 

The current list of authorised Sub-processors, including any additions or replacements, is maintained at stell.ai/legal/subprocessors. Stellai shall notify the Customer at least seven (7) days in advance of any change to the Sub-processor list in accordance with Section 7.3. 

Appendix C — Security Measures 

Stellai implements the following categories of technical and organisational measures to protect Customer Personal Data. For operational security reasons, detailed internal policy content is not disclosed to third parties; summaries and independent assurance reports are available on request subject to confidentiality undertakings. 

C.1 Data retention 


Data category 

Live video frames. 

Retention period  

Not stored. Processed in volatile memory (RAM) only. 

 

Data category 

Event images (face-blurred cropped stills). 

Retention period  

Duration of Services plus 12 mounths, to allow report downlowds for end-of-year audits and reports. 

 

Data category 

Detection metadata (timestamp, object class, confidence, device ID). 

Retention period  

Duration of Services plus 12 mounths, to allow report downlowds for end-of-year audits and reports. 

 

Data category 

Access logs and audit trails. 

Retention period  

12 months from creation. 

 

Data category 

Remote support logs. 

Retention period  

6 months from session close. 

 

Data category 

Training data (fully anonymised samples). 

Retention period  

For the duration of the Services, or as long as required for model improvement. 

 

C.2 Data minimisation and anonymisation 

  • Live video is not stored. Analysis occurs in volatile memory on the edge device. 
  • Automatic, irreversible face blurring is applied to any event image prior to storage or display. 
  • Only event-specific cropped images and the minimum metadata required for detection are retained. 

C.3 Encryption and network security 

  • Transport Layer Security (TLS 1.2 or higher) for all data in transit. 
  • Encryption at rest for all stored event data, metadata and logs. 
  • Virtual Private Network (VPN) with end-to-end encryption for remote support. 
  • Network segmentation between edge, backend and management environments. 

C.4 Access control and identity management 

  • Role-based access control with least-privilege enforcement. 
  • Multi-factor authentication for all administrative access. 
  • Quarterly access reviews and prompt revocation on role change or termination. 
  • Structured audit logging of all access to Customer environments. 

C.5 System hardening and integrity 

  • CIS Level 2 hardening baseline applied to edge devices. 
  • Continuous vulnerability monitoring and regular patching of operating systems and dependencies. 
  • Code signing and integrity verification for edge firmware updates. 

C.6 Physical and environmental security 

  • Primary Processing in EU/EEA data centres operated by certified Sub-processors. 
  • Physical security, redundancy and environmental controls managed by the data centre operator (e.g., Microsoft Azure) under applicable certifications (ISO/IEC 27001, SOC 2). 

C.7 Organisational measures 

  • Confidentiality obligations for all personnel with access to Customer Personal Data. 
  • Mandatory security awareness training on induction and annually thereafter. 
  • Documented incident response procedures with defined escalation paths. 
  • Documented change management, backup, and disaster recovery procedures. 
  • Annual review of technical and organisational measures by Stellai management. 

C.8 Testing and assurance 

  • Routine security testing and evaluation of systems and infrastructure. 
  • Regular testing of anonymisation, logging and access control functions. 
  • Independent assurance reports (where available) provided on request under confidentiality.