Skip to content
KordinertSign in
Data processing agreement

Data processing agreement

Version 2026-10 · Last updated 14 September 2026

This agreement meets the requirement of GDPR Article 28 and is made between the choir as controller and Birget AS as processor. It is accepted by whoever creates the choir, on the choir’s behalf, and we record which version was accepted, by whom, when and in which language. The version in force is always here.

1. The parties

The processor is Birget AS, org. no. 933 189 775, Oslo, Norway, contact support@kordinert.no.

The controller is the choir created in Kordinert, represented by whoever created it or whoever later holds the owner role in the choir.

This agreement supplements the terms of service. Where the two conflict, this agreement prevails on questions of personal-data processing.

2. Subject matter

The processor processes personal data on the controller’s behalf in order to deliver Kordinert: the member register and membership history, planning of seasons, productions and activities, responses and attendance, leaves of absence, repertoire, internal communication, dues, and notification by email and push.

The processing lasts for as long as the choir has an active customer relationship, and ends according to clause 9.

The data and the data subjects the processing covers are set out in Annex A.

3. Instructions

The processor processes personal data only on documented instructions from the controller. The instructions are this agreement, the terms of service, the functionality the controller itself puts to use in the service, and any later written instruction the parties agree on.

The processor does not transfer personal data to a third country beyond what follows from clause 6 and Annex B, unless required to by EEA or Norwegian law. Where it is required, the processor informs the controller before processing unless the law forbids such notice.

If the processor considers an instruction to infringe data protection law, it says so immediately.

The processor does not use the choir’s personal data for its own purposes, does not sell it, and does not use it to train models.

4. Confidentiality

Only those people at the processor who need access in order to perform the agreement are given it. They are bound by confidentiality, and access is removed when the need ends.

5. Security

The processor implements appropriate technical and organisational measures under Article 32, proportionate to the risk. The measures are described in Annex C and are updated as the risk picture changes; they are not weakened during the term.

6. Sub-processors

The controller gives general prior authorisation for the processor to engage sub-processors. Those engaged at the time of acceptance are listed in Annex B.

The processor enters into an agreement with each sub-processor imposing the same obligations as this agreement, and remains liable to the controller for the sub-processor’s performance.

Before a sub-processor is replaced or added, the processor gives at least 30 days’ notice in the service and on the website. During that period the controller may object in writing on reasonable data-protection grounds; if the parties do not agree, the controller may terminate at no cost, with the right to have its data handed over first.

Transfers outside the EEA rest on the EU Standard Contractual Clauses with the supplementary measures described in Annex C.

7. Assistance to the controller

The processor assists the controller by appropriate technical and organisational measures so that the controller can answer data subjects’ requests under Articles 12 to 22. In practice the assistance is built into the service: access reports per member, correction of profile and history, restriction of processing on a member, and deletion of a user account.

If a data subject directs their request to the processor instead of to the choir, the processor forwards it to the controller without undue delay and tells the data subject that it has done so.

The processor also assists the controller in meeting the obligations of Articles 32 to 36 — security, breach notification and data protection impact assessment — to the extent necessary and where the processor holds the information.

8. Personal data breach

If the processor becomes aware of a personal data breach affecting the choir’s data, it notifies the controller without undue delay and no later than 24 hours after the breach is discovered.

The notice describes what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken. Where not everything is known, the information is provided in stages. Notification to Datatilsynet is the controller’s to make.

9. Deletion and return

The controller exports the member list and the dues ledger as CSV itself at any time, and may ask the processor for a complete copy of the choir’s data.

On termination the data stays available for 90 days, so the choir can ask to have it reopened or to have the data handed over; both go through support@kordinert.no. The choir is then archived and the data is deleted in a subsequent clean-up.

The processor may nevertheless retain data where the law requires it, in particular accounting material for five years after the end of the financial year under section 13 of the Norwegian Bookkeeping Act. Such data is processed only for the purpose the law requires.

Backups are not rewritten on deletion. Deleted data falls out of the backups as they rotate, within 30 days, and executed deletions are re-applied if a restore from a backup ever happens.

10. Audit

The processor makes available to the controller the information necessary to demonstrate compliance with Article 28, and allows for audits.

The controller may require an audit once a year, and otherwise after a personal data breach. An audit is announced at least 30 days in advance, is carried out in working hours, and must not be an unreasonable burden on operations. If the controller uses an external auditor, the auditor must be independent of a competitor of the processor and sign a confidentiality undertaking. The controller bears its own costs.

11. Term, changes and governing law

The agreement applies for as long as the processor processes personal data on the controller’s behalf.

Changes needed to meet new requirements in law or from a supervisory authority may be made by the processor publishing a new version and giving at least 30 days’ notice in the service. Changes that affect the controller’s obligations require fresh acceptance in the service.

The agreement is governed by Norwegian law, with Oslo District Court as the venue.

Annex A — details of the processing

Purpose: delivering Kordinert to the choir. Nature of the processing: collection, recording, storage, structuring, display to the choir’s members and officers, sending of email and push, backup and deletion.

Categories of data subjects: the choir’s members and former members, its officers and employees, applicants who have registered an interest, and the emergency contacts the members supply themselves.

Categories of personal data:

  • Identity and contact: name, email address, phone number, address, birth date, pronoun and avatar.
  • Membership: voice group, status, admission, probation, leaves of absence with their reason, committees and roles.
  • Activity: responses to activities, recorded attendance and attendance history.
  • Content: posts, comments, messages, notes about members and attached files.
  • Finance: dues charges, invoices and recorded payments.
  • Emergency contact: name, phone number, email address and relation.
  • Special categories: health information a member writes into a leave reason, and — for church choirs — the fact that membership itself may reveal religious belief.

Annex B — sub-processors

The list below is the one in force at acceptance. The current list is on this page, and changes are notified under clause 6.

  • Stripe (Ireland and the USA) — card payment of the choir’s subscription. Does not see member dues.
  • Resend (USA) — outbound email: invitations, digests and dues invoices.
  • Expo, 650 Industries (USA) — delivery of push notifications to the mobile app.
  • Sentry (EU region, Frankfurt; the vendor is US-based) — error logging, with personal data scrubbed before an event is sent.
  • Anthropic (USA) — AI-assisted import and the MCP connector, only when the choir switches the feature on.

Annex C — security measures

The measures in place at acceptance:

  • The database, the files and the sign-in run on the processor’s own infrastructure within the EU/EEA.
  • Each choir is isolated with row-level security in the database; a query from one choir cannot reach another choir’s data.
  • Access inside the choir is governed by the choir’s own role and capability model, which the controller administers itself.
  • All traffic is encrypted, and storage is encrypted at rest.
  • Sign-in is passwordless, by a one-time link or one-time code sent by email.
  • Administrative actions are written to an audit trail the controller can ask to see.
  • Error logging scrubs personal data before an event is sent, IP addresses are not stored, and session replay is off.
  • Backups run daily, are kept encrypted for 30 days, and one copy is held off the production machine.
  • Transfers outside the EEA rest on the EU Standard Contractual Clauses, with encrypted transport and a data processing agreement with each vendor.