Legal
Data Processing Agreement
Last updated: 21 September 2026
1. Parties and scope
This Data Processing Agreement (“DPA”) forms part of the agreement between Corinthian Venture Partners AS, org. no. 925 853 720, Edvard Storms gate 2, 0166 Oslo, Norway (“Corinthian”, “Processor”) and the customer using Corinthian's CRM/growth platform at app.corinthianvp.com (the “Service”, “Controller”). It applies whenever Corinthian processes personal data on the Controller's behalf and under the Controller's instructions in connection with the Service.
2. Subject matter and duration
The subject matter is Corinthian's provision of the Service, under which Corinthian stores and processes personal data the Controller (or its users) enters into the Service — principally data about the Controller's own leads and business contacts. Processing continues for as long as the Controller's main services agreement with Corinthian is in effect, and ends as set out in clause 10.
3. Nature and purpose of processing
Corinthian processes personal data solely to provide, maintain, secure and support the Service — storing records the Controller's users create, sending notification and transactional emails the Controller's users trigger, and (where the Controller has connected it) syncing email activity via the Controller's own Gmail/Outlook integration. Corinthian does not use the Controller's data for its own marketing, profiling, or any purpose unrelated to providing the Service.
4. Categories of data and data subjects
Personal data processed through the Service typically includes: name, job title, company, email address, phone number, and free-text notes or activity history the Controller's users record about a lead or contact. Data subjects are principally the Controller's leads and business contacts, and secondarily the Controller's own users (name, email, and login/activity metadata needed to operate their account).
5. Processor obligations
Corinthian shall:
- process personal data only on the Controller's documented instructions, including regarding international transfers, unless required to do otherwise by EU or Norwegian law;
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (see clause 8);
- assist the Controller, so far as reasonably possible, in responding to data subject rights requests and in meeting its obligations under GDPR Articles 32-36;
- not engage a sub-processor without the general authorisation described in clause 6; and
- at the Controller's choice, delete or return all personal data on termination, as set out in clause 10.
6. Sub-processors
The Controller gives Corinthian general authorisation to engage the sub-processors listed on the subprocessors page, which Corinthian will keep up to date. Corinthian will give the Controller reasonable advance notice of any new sub-processor (or replacement) so the Controller can object on reasonable data-protection grounds. Corinthian imposes data protection obligations equivalent to this DPA on every sub-processor, by contract.
7. International transfers
Where a sub-processor is located outside the EEA, the transfer is covered by the EU Standard Contractual Clauses (or another valid GDPR Chapter V transfer mechanism), supplemented by additional technical and organisational measures where needed. Details are noted per vendor on the subprocessors page.
8. Security measures
Corinthian maintains, among other things:
- encryption of data in transit (TLS) and at rest;
- row-level access control so one customer's data is never readable by another;
- rate limiting and account lockout on authentication endpoints, with optional two-factor authentication;
- an audit log of sensitive administrative actions (role changes, data exports, impersonation);
- staff access restricted to what is needed for support and operation of the Service; and
- regular dependency and configuration security review.
9. Personal data breaches
Corinthian will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, describing (to the extent known) the nature of the breach, the data and data subjects likely affected, and the measures taken or proposed to address it.
10. Deletion or return on termination
On termination of the Controller's agreement with Corinthian, Corinthian will, at the Controller's choice, delete or return all personal data processed under this DPA, except to the extent Norwegian or EU law requires continued storage (for example, accounting records), and except for data retained in encrypted backups until their normal expiry.
11. Audits
Corinthian will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on reasonable prior notice.
12. Governing law
This DPA is governed by Norwegian law, with Oslo District Court as legal venue, consistent with the main agreement it forms part of.
13. Contact
Questions about this DPA can be sent to aek@corinthianvp.com.
