Data Processing Agreement
Last updated: 23 June 2026·Version: 1.0
How to accept: By registering for or using the MyCapsule Service, you agree to this Data Processing Agreement as incorporated into our Terms of Service. Enterprise customers may request a separately countersigned copy at morten@mycapsule.eu.
Parties
This Data Processing Agreement (“DPA”) is entered into between:
Customer — the organization that registers for and uses the MyCapsule platform (“you”, “Controller”)
MyCapsule AS (Org. no. 931084461), Gulaksvegen 31, 4345 Bryne, Norway (“MyCapsule”, “Processor”)
Together, the “Parties”. This DPA supplements the Terms of Service and applies when Processor processes Personal Data on behalf of Controller.
1. Definitions
- “GDPR” means Regulation (EU) 2016/679 and applicable national implementing legislation (including the Norwegian Personal Data Act).
- “Personal Data” means any information relating to an identified or identifiable natural person processed under this DPA.
- “Employee Data” means Personal Data about Controller's employees processed via the Service, including phone numbers, names, pulse survey responses, and related logs.
- “Service” means the MyCapsule cloud platform for workforce pulse surveys, reporting, and related features.
- “Subprocessor” means a third party engaged by Processor to process Personal Data on behalf of Controller.
- “Standard Contractual Clauses” or “SCCs” means the EU Commission's standard contractual clauses for international data transfers.
2. Subject matter, duration, and roles
2.1 Roles. Controller is the data controller for Employee Data. Processor is the data processor, processing Employee Data solely on documented instructions from Controller as described in this DPA and the Service configuration.
2.2 Duration. This DPA applies for the duration of the subscription agreement and until all Employee Data is deleted or returned in accordance with Section 12.
2.3 Nature and purpose. Processor provides the Service, enabling Controller to:
- maintain employee and department records
- send weekly pulse surveys via SMS
- collect and store survey responses
- display aggregated reports and insights
- enable authorized health partners to view aggregated data and record actions
3. Types of data and data subjects
| Category | Data | Data subjects |
|---|---|---|
| Employee directory | Phone number, optional name, department, company affiliation | Controller's employees |
| Pulse responses | Workload, energy, control, relationship, recovery (1–10); pain/discomfort flag and body area | Controller's employees |
| Survey delivery | One-time tokens, link metadata, submission timestamps | Controller's employees |
| SMS logs | Phone number, message text, delivery status | Controller's employees |
| Aggregated outputs | Department-level metrics, trends, insights | Groups of employees (not individuals in UI) |
Special category data: Pulse surveys may include health-related information (physical discomfort/pain). Controller is responsible for establishing a valid legal basis under GDPR Art. 9 before enabling these questions.
4. Controller instructions
4.1 Documented instructions. Processor shall process Employee Data only on documented instructions from Controller, including:
- this DPA and the Terms of Service
- configuration of the Service (employee lists, departments, survey settings)
- written instructions sent to morten@mycapsule.eu
4.2 Unlawful instructions. If Processor believes an instruction infringes GDPR or other data protection law, Processor shall promptly inform Controller.
4.3 Controller obligations. Controller shall:
- have a valid legal basis for all processing
- inform employees before the first survey SMS (see Employee Information Notice)
- ensure employee data uploaded is accurate and limited to what is necessary
- not use the Service to identify individual employees from aggregated reports
5. Processor obligations
Processor shall:
- process Employee Data only as instructed in Section 4
- ensure persons authorized to process Employee Data are bound by confidentiality
- implement appropriate technical and organizational measures per Section 9
- assist Controller with data subject requests per Section 10
- notify Controller of personal data breaches per Section 11
- delete or return Employee Data per Section 12
- make available information necessary to demonstrate compliance and allow audits per Section 13
6. Reporting privacy
Processor implements the following by design:
- individual pulse responses are not displayed in the application interface
- reports show aggregated data only; groups below the minimum size threshold (default: 5) are hidden
- response records do not include employee name or phone number
- direct client-side database access to individual responses is blocked (Row Level Security)
Controller acknowledges that a technical link between a response and a survey token exists on the server for operational purposes but is not exposed in dashboards.
7. Subprocessors
7.1 Authorization. Controller authorizes Processor to engage Subprocessors listed at /legal/subprocessors. The current list includes Supabase, Stripe, Twilio, Vercel, and Google.
7.2 Changes. Processor shall notify Controller at least 30 days before adding or replacing a Subprocessor that processes Employee Data. Controller may object on reasonable grounds relating to data protection by notifying morten@mycapsule.eu within 14 days. If the Parties cannot resolve the objection, Controller may terminate the affected Service.
7.3 Flow-down. Processor imposes data protection obligations on Subprocessors substantially equivalent to this DPA.
8. International transfers
Primary Employee Data is stored in West EU (Ireland). Where Subprocessors process data outside the EEA, Processor ensures appropriate safeguards (including SCCs where applicable) are in place.
9. Security measures
Processor maintains measures including, as appropriate:
- encryption in transit (TLS/HTTPS)
- role-based access control (administrator, health partner, super admin)
- Row Level Security on database tables
- aggregation thresholds before report display
- audit logging of administrative actions
- secure development and access management practices
Further details are published on our Security page and provided upon reasonable request.
10. Data subject rights
Processor shall assist Controller, taking into account the nature of processing, in fulfilling obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection).
Employees should generally contact Controller first. Controller may forward requests to morten@mycapsule.eu. Processor shall respond within 10 business days of receiving a valid request from Controller.
11. Personal data breaches
Processor shall notify Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Employee Data. The notification shall include, to the extent known:
- nature of the breach and categories/volume of data affected
- likely consequences
- measures taken or proposed to address the breach
- contact point for further information
Controller remains responsible for notifying supervisory authorities and data subjects where required.
12. Deletion and return of data
Upon termination of the Service or on Controller's written request:
- employee records are deactivated immediately
- personally identifiable Employee Data is deleted or anonymized within 30 days, unless a longer period is required by law or requested in writing by Controller
- aggregated and anonymized analytics may be retained by Processor for benchmarking and historical reporting, provided such data can no longer identify individuals
Controller may export aggregated reports before termination. Processor shall confirm deletion upon request.
13. Audits and information
Processor shall make available information reasonably necessary to demonstrate compliance with this DPA. Controller may conduct an audit no more than once per year on 30 days' written notice, during normal business hours, without unreasonably disrupting Processor's operations. Controller bears its own audit costs unless material non-compliance is found.
Processor may satisfy audit requests by providing up-to-date third-party certifications or audit reports (e.g. SOC 2, ISO 27001) where available.
14. Liability
Each Party's liability under this DPA is subject to the limitation of liability in the Terms of Service, except where mandatory law provides otherwise. Nothing in this DPA limits either Party's liability for breaches of data protection law to the extent such limitation is prohibited.
15. Governing law and disputes
This DPA is governed by the laws of Norway. Disputes shall be subject to the exclusive jurisdiction of Stavanger District Court, without prejudice to mandatory rights.
16. Order of precedence
In the event of conflict:
- this DPA prevails over the Terms of Service regarding Employee Data processing
- a separately signed enterprise agreement prevails over both if expressly stated
17. Contact
Processor contact:
MyCapsule AS
Gulaksvegen 31, 4345 Bryne, Norway
Email: morten@mycapsule.eu