Data Processing Agreement
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between Metanoia AS ("Processor", "Metanoia", "we", "us", or "our") and the customer ("Controller", "Customer", "you", or "your") for the use of NET Backup Vault.
This DPA applies where Metanoia processes personal data on behalf of the Customer in connection with NET Backup Vault.
2. Parties
Processor
Metanoia AS
Controller
The customer organisation using NET Backup Vault.
3. Relationship Between the Parties
For customer data processed through NET Backup Vault, the Customer acts as controller and Metanoia acts as processor. Metanoia processes personal data only on documented instructions from the Customer.
For account, billing, support, security, website, and administrative data, Metanoia may act as an independent controller as described in the Privacy Policy.
4. Subject Matter of Processing
The processing concerns the provision of NET Backup Vault, a cloud-based platform for backup, restore, monitoring, export, and configuration management of Cisco Meraki environments.
Processing may include:
- Collection
- Storage
- Retrieval
- Backup
- Export
- Deletion
- Logging
- Analysis for operational and security purposes
- Support-related access where necessary
5. Duration of Processing
Metanoia processes customer data for the duration of the Customer's subscription or trial.
After cancellation or termination, customer account data, configuration backups, logs, and related service data may be retained for up to 30 days unless a longer retention period is required by law, dispute handling, security obligations, or written agreement. After the retention period, data may be permanently deleted.
6. Nature and Purpose of Processing
Metanoia processes personal data to:
- Provide NET Backup Vault
- Perform scheduled and manual backups
- Support restore operations
- Maintain audit logs
- Provide support
- Monitor service security and reliability
- Prevent misuse
- Comply with applicable legal obligations
7. Categories of Personal Data
Depending on the Customer's use of NET Backup Vault, processed data may include:
- User names
- Email addresses
- Account roles and permissions
- Login and authentication data
- IP addresses
- Audit logs
- User activity logs
- Support communication
- Device names or network names that may contain personal data
- Cisco Meraki configuration data that may contain personal data
8. Categories of Data Subjects
Data subjects may include:
- Customer administrators
- Customer employees
- Customer contractors
- Customer support contacts
- Users authorised by the Customer
- Individuals whose personal data may appear in Cisco Meraki configuration data, logs, names, labels, or metadata
9. Customer Instructions
The Customer instructs Metanoia to process personal data as necessary to provide NET Backup Vault and related services.
The Customer is responsible for ensuring that instructions are lawful, the Customer has a valid legal basis for processing, data subjects are informed where required, and NET Backup Vault is used in compliance with applicable data protection law.
Metanoia will notify the Customer if it believes an instruction infringes applicable data protection law.
10. Confidentiality
Metanoia ensures that personnel authorised to process personal data are bound by confidentiality obligations.
Access to customer data is limited to personnel who need access for service operation, support, security, or legal purposes.
11. Security Measures
Metanoia implements reasonable technical and organisational measures to protect personal data. Measures may include:
- Encryption in transit
- Encryption at rest
- Access controls
- Role-based permissions
- Audit logging
- Monitoring
- Secrets management
- Restricted internal access
- Backup and recovery procedures
- Secure development practices
- Vulnerability management appropriate to the service
No system can be guaranteed to be completely secure.
12. Subprocessors
The Customer authorises Metanoia to use subprocessors where necessary to provide NET Backup Vault. Current subprocessors may include Microsoft Azure, Render.com, and Anthropic.
Metanoia remains responsible for subprocessors used in connection with NET Backup Vault and will ensure that subprocessors are subject to data protection obligations appropriate to the processing they perform.
Metanoia may update its subprocessor list from time to time. Full details are available on the Subprocessors page. Where required by applicable law or written agreement, Metanoia will provide notice of material subprocessor changes.
13. International Transfers
NET Backup Vault is primarily hosted within the EU/EEA. Where personal data is transferred outside the EU/EEA, Metanoia will use appropriate safeguards where required by applicable data protection law, such as standard contractual clauses or another lawful transfer mechanism.
14. Assistance to the Customer
Taking into account the nature of processing and the information available to Metanoia, Metanoia will reasonably assist the Customer with:
- Data subject requests
- Security obligations
- Personal data breach notifications
- Data protection impact assessments, where relevant
- Consultations with supervisory authorities, where required
The Customer remains responsible for responding to data subjects and supervisory authorities unless otherwise required by law.
15. Data Subject Requests
If Metanoia receives a request from a data subject relating to Customer-controlled personal data, Metanoia will where appropriate notify the Customer, avoid responding directly unless required by law, and provide reasonable assistance to the Customer.
16. Personal Data Breaches
Metanoia will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data.
The notification will include available information reasonably required for the Customer to assess the breach, including where known: the nature of the breach, categories of affected data, approximate number of affected data subjects, likely consequences, and measures taken or proposed to address the breach.
17. Deletion and Return of Data
Upon termination of the service, Metanoia will delete or return Customer personal data according to the applicable retention period and product functionality.
Unless otherwise agreed, customer data may be retained for up to 30 days after cancellation or termination, after which data may be permanently deleted. The Customer is responsible for exporting required data before termination takes effect.
Metanoia may retain limited data where required by law, security obligations, dispute handling, or legitimate business records.
18. Audits and Information
Metanoia will provide information reasonably necessary to demonstrate compliance with this DPA.
Audit requests must be made in writing, limited to information relevant to NET Backup Vault, avoid disruption to Metanoia's operations, and protect confidential information and security-sensitive details.
Where appropriate, Metanoia may satisfy audit requests through written responses, security documentation, policies, or third-party documentation.
19. Customer Responsibilities
The Customer is responsible for:
- Lawful use of NET Backup Vault
- Managing user access and permissions
- Ensuring API credentials are authorised
- Ensuring Cisco Meraki configuration data is appropriate for processing in NET Backup Vault
- Informing users and data subjects where required
- Maintaining its own records of processing activities where required
- Ensuring that restore operations are properly authorised
20. Liability
Liability under this DPA is subject to the limitation of liability set out in the applicable Terms of Service or separate written agreement.
21. Order of Precedence
If there is a conflict between this DPA and the Terms of Service regarding personal data processing, this DPA takes precedence for that specific processing issue.
If a separate written agreement has been signed between Metanoia and the Customer, that agreement takes precedence for the specific scope covered by it.
22. Governing Law and Court Venue
This DPA is governed by the laws of Norway. Any disputes arising from or relating to this DPA shall be resolved by Stavanger District Court, unless mandatory law requires another venue.
23. Contact Information
Metanoia AS