ArbeidMatch

Data Processing Agreement — Recruiter Partner

Last updated: 28 August 2026

Between:

Controller: {{PARTNER_COMPANY_LEGAL_NAME}}, Org. nr.: {{PARTNER_ORG_NUMBER}}, registered at {{PARTNER_ADDRESS}} ("Controller" or "Recruiter Partner")

Processor: ArbeidMatch Norge AS, Org. nr.: {{PROCESSOR_ORG_NUMBER}}, registered at {{PROCESSOR_REGISTERED_ADDRESS}} ("Processor" or "ArbeidMatch")

Effective from: {{ACCEPTANCE_DATE}}

1. DEFINITIONS

Terms used herein shall have the meaning ascribed to them in Regulation (EU) 2016/679 ("GDPR") and the Norwegian Personal Data Act (Personopplysningsloven). "Personal Data," "Processing," "Data Subject," "Sub-Processor," and "Personal Data Breach" carry their GDPR meanings.

2. SUBJECT MATTER AND DURATION

The Processor processes Personal Data on behalf of the Controller for the sole purpose of operating the ArbeidMatch recruitment platform and facilitating placement of candidates introduced by the Controller with end-employers in Norway. This Agreement remains in effect for as long as the Controller maintains an active account on the ArbeidMatch platform and survives termination with respect to ongoing confidentiality and data return obligations.

3. NATURE AND PURPOSE OF PROCESSING

The Processor will process Personal Data exclusively to:

  • Store candidate profiles introduced by the Controller
  • Match candidates with employer requests within the platform
  • Facilitate communication between the Controller, candidates, and end-employers
  • Generate placement records and commission calculations
  • Comply with the Controller's documented instructions

The Processor shall not process Personal Data for any other purpose, including marketing, profiling unrelated to recruitment, or sale to third parties.

4. CATEGORIES OF PERSONAL DATA

  • Identification data: full name, date of birth, nationality
  • Contact data: email, phone, address
  • Professional data: CV content, employment history, qualifications, certifications, references
  • Work eligibility data: work permits, residence status, D-number/personal number where applicable
  • Communication data: messages exchanged via the platform

5. CATEGORIES OF DATA SUBJECTS

Job candidates introduced by the Controller through invitation links, manual upload, or platform-integrated channels.

6. CONTROLLER'S OBLIGATIONS

The Controller warrants that:

a) It has a valid legal basis under GDPR Article 6 for sharing each candidate's Personal Data with the Processor (typically consent or legitimate interest)
b) It has provided each candidate with a transparent privacy notice meeting GDPR Article 13/14 requirements
c) It will not introduce candidates whose Personal Data was obtained unlawfully
d) It will respond promptly to data subject requests forwarded by the Processor

7. PROCESSOR'S OBLIGATIONS

The Processor shall:

a) Process Personal Data only on documented instructions from the Controller
b) Ensure persons authorized to process Personal Data are bound by confidentiality
c) Implement appropriate technical and organizational measures (Section 9)
d) Assist the Controller in fulfilling data subject requests within 30 days
e) Assist the Controller with data protection impact assessments and consultations with supervisory authorities upon request
f) Notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of a Personal Data Breach
g) At the Controller's choice, delete or return all Personal Data after termination, save where Union or Member State law requires retention

8. SUB-PROCESSORS

The Controller grants general authorization for the Processor to engage Sub-Processors. Current Sub-Processors:

  • Supabase Inc. - database hosting (EU/Frankfurt region)
  • Vercel Inc. - application hosting (EU regions)
  • One.com A/S - email infrastructure (EU/Denmark)
  • Stripe Payments Europe Ltd. - payment processing (when commission payouts are activated)

The Processor shall maintain an updated list at https://arbeidmatch.no/subprocessors and notify the Controller of intended changes 30 days in advance via email. The Controller may object on reasonable data protection grounds; if no resolution is reached, the Controller may terminate this Agreement. The Processor remains fully liable for the acts and omissions of its Sub-Processors.

9. SECURITY MEASURES (GDPR ARTICLE 32)

The Processor implements:

  • Encryption: TLS 1.3 in transit; AES-256 at rest
  • Access control: role-based permissions, least-privilege principle, MFA for administrative accounts
  • Audit logging: all access and modifications recorded with retention of 12 months
  • Pseudonymization: applied upon erasure requests where full deletion is technically constrained
  • Backup: encrypted daily backups, retention 30 days
  • Incident response: documented procedure with 48-hour internal escalation
  • Personnel: background checks for employees with production access; mandatory data protection training

10. PERSONAL DATA BREACH NOTIFICATION

In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay and in any case within 48 hours of becoming aware. The notification shall include:

a) Nature of the breach and categories/approximate number of data subjects and records affected
b) Likely consequences
c) Measures taken or proposed to address the breach and mitigate effects
d) Contact details of the data protection contact

The Controller is responsible for any onward notification to supervisory authorities (Datatilsynet) and data subjects under GDPR Articles 33-34.

11. AUDIT RIGHTS

The Controller may, no more than once per calendar year and with 30 days' written notice, request:

a) Written confirmation of the Processor's compliance with this Agreement
b) Copies of the Processor's most recent security audit reports (e.g., SOC 2, ISO 27001) where available
c) An on-site audit conducted at the Controller's expense, subject to reasonable confidentiality obligations and during business hours

In the event of a documented Personal Data Breach affecting the Controller's data, audit rights may be exercised more frequently.

12. INTERNATIONAL TRANSFERS

Personal Data is processed within the European Economic Area (EEA). The Processor shall not transfer Personal Data outside the EEA without ensuring adequate protection through Standard Contractual Clauses or another lawful transfer mechanism, and shall notify the Controller in advance.

13. DATA RETENTION AND RETURN

Upon termination of this Agreement or upon the Controller's written request:

  • Active candidate data: returned in machine-readable format (JSON/CSV) within 30 days
  • All copies (including backups): deleted within 90 days, except where legal retention applies (e.g., financial records under Norwegian Bookkeeping Act, retained for 5 years)
  • Inactive candidates (no platform activity for 24 consecutive months): automatically anonymized

14. LIABILITY

Each party's liability under this Agreement is limited as set forth in the master ArbeidMatch Recruiter Partner Agreement. Notwithstanding any limitation, neither party may exclude liability for:

  • Willful misconduct or gross negligence
  • Breach of confidentiality obligations
  • Fines imposed by supervisory authorities directly attributable to that party's breach

15. GOVERNING LAW AND JURISDICTION

This Agreement is governed by Norwegian law. Disputes shall be submitted exclusively to the courts of Trondheim (Sør-Trøndelag tingrett), Norway.

16. ELECTRONIC ACCEPTANCE

By clicking "I accept" within the ArbeidMatch onboarding flow, the Controller acknowledges having read, understood, and agreed to be legally bound by this Agreement. This electronic acceptance constitutes a binding agreement under Norwegian contract law (Avtaleloven). The Processor records the timestamp, IP address, and user agent for evidentiary purposes. This is not a Qualified Electronic Signature under eIDAS Regulation (EU) 910/2014. For high-formality agreements requiring QES, parties may execute a separate signed addendum.

17. SIGNATURES

Controller - {{PARTNER_COMPANY_LEGAL_NAME}}
Accepted electronically by: {{PARTNER_FULL_NAME}}
Title: {{PARTNER_TITLE}}
Date: {{ACCEPTANCE_DATE}}
IP: {{ACCEPTANCE_IP}}

Processor - ArbeidMatch Norge AS
{{PROCESSOR_SIGNATORY_LINE}}

BETA

In development. Improving with you.

Our website is in a beta version. We continually improve its features, content and design. Your feedback helps us understand your needs and make the service better.

About the beta version and what to expect

During the beta period, errors, interruptions, delays or display issues may occur. Content, features and visual design may change. Illustrative images and examples do not necessarily depict a particular candidate, workplace or agreed service.

Website information, candidate presentations and estimates do not in themselves guarantee employment, candidate availability, delivery times or a particular outcome. The scope, price, deadlines and commitments for a specific service are agreed separately.

This notice does not limit mandatory legal rights or our obligations under existing agreements. Please contact us if anything is unclear or does not work as expected.