Skip to content

EnglishNorsk

Data Processing Agreement

Data processing agreement (DPA) for Zonara AS’ processing of personal data on behalf of customers.

Last updated: 9 May 2026Version: 1.0

This data processing agreement («DPA») governs Zonara AS' processing of personal data on behalf of the Customer, and is entered into as an appendix to the main agreement between the Customer and Zonara on the use of the Zonara app and the products Fleet OS and Partner OS («the Service»).

The DPA is drawn up in accordance with Article 28 of the General Data Protection Regulation (GDPR).

Controller («the Customer») The company that has entered into an agreement with Zonara on the use of the Service, as specified in the main agreement.

Processor («Zonara»)

  • Legal name: Zonara AS
  • Organisation number: 933 342 522
  • Address: Drammensveien 288, 0283 Oslo
  • Managing director: Anders Eidval
  • Telephone: +47 459 67 125
  • Privacy email: personvern@zonara.no

Zonara processes personal data on behalf of the Customer in order to deliver the Service in accordance with the main agreement, including fleet management, partner administration, vehicle reservation, driving log keeping, driving licence validation and related functionality.

The DPA applies for as long as Zonara processes personal data on behalf of the Customer, that is from the entry into force of the main agreement until all personal data has been deleted or returned in accordance with section 11.

ElementDescription
Nature of the processingCollection, recording, storage, making available, use, erasure and structuring of personal data as part of delivering the Service
PurposeDelivery of fleet/partner management services to the Customer
DurationThe term of the main agreement + the erasure period after termination
Type of personal dataSee section 4
Categories of data subjectsSee section 5

Zonara processes the following categories of personal data on behalf of the Customer:

  • Name
  • National identity number (only for BankID login and driving licence validation)
  • Date of birth
  • Email address
  • Telephone number
  • Address (where needed)
  • Driving licence class
  • Validity of the driving licence
  • Result of validation against the Norwegian Public Roads Administration
  • Affiliation with the Customer's organisation
  • Role and access rights
  • Department/team
  • GPS position of vehicles
  • Driving log and driving patterns
  • Distance and time
  • Reservations and bookings
  • Fuel, battery, mileage and similar data from the vehicle's manufacturer
  • Vehicle register data from the Norwegian Public Roads Administration
  • IP address, device ID, session ID
  • Login time
  • Activity log (audit log)
  • Outgoing text messages from the service
  • Outgoing email from the service
  • The Customer's employees and users who have been given access to the Service
  • Any other persons the Customer registers in the Service within the Service's functionality

Zonara shall:

  1. Only process personal data on the Customer's documented instructions. The main agreement and this DPA constitute the Customer's basic instructions.
  2. Ensure that persons with access to personal data have a duty of confidentiality or are subject to a statutory duty of confidentiality.
  3. Implement the necessary technical and organisational measures to ensure an adequate level of security, cf. GDPR Article 32. See section 9.
  4. Assist the Customer in fulfilling the obligation to respond to requests from data subjects exercising their rights.
  5. Assist the Customer in fulfilling the obligations under GDPR Articles 32 to 36 (security, breaches, impact assessment).
  6. After the end of the processing, delete or return all personal data to the Customer, cf. section 11.
  7. Make available all information necessary to demonstrate compliance with the obligations under GDPR Article 28, and allow audits, cf. section 12.
  8. Notify the Customer immediately if, in Zonara's assessment, an instruction infringes data protection legislation.

The Customer gives Zonara general authorisation to use sub-processors («processors» under the GDPR) for the processing of personal data as part of delivering the Service.

Zonara uses sub-processors within the following categories:

CategoryLocationTransfer basis
Hosting and infrastructureEU (Microsoft Azure West Europe)DPA
Identity and login services (BankID broker)NorwayDPA
Connected services for vehicle dataEU/EEADPA
Map dataEU/EEADPA
Email deliveryUSADPA + SCC
Text message deliveryNorwayDPA
Payment processingEU (with group affiliation to the USA)DPA + SCC
Website hostingUSA (with EU edge)DPA + SCC
Domain registrationEUDPA

A specific and up-to-date list of the individual sub-processors within each category forms a separate appendix to this DPA («Sub-processor appendix»), which the Customer receives when the agreement is entered into and which is updated when changes are made.

Zonara shall notify the Customer at least 30 days before entering into an agreement with a new sub-processor, or before an existing sub-processor is given an extended role. The notice is sent to the Customer's registered contact person and updated in the Sub-processor appendix.

The Customer may object to the change in writing within 30 days of the notice. If the parties do not find a solution, the Customer may terminate the Agreement at no cost.

Zonara shall impose on sub-processors the same obligations as follow from this DPA through a written data processing agreement. Zonara is liable to the Customer for the sub-processors' performance of their obligations.

The Service itself is operated within the EU/EEA on Microsoft Azure West Europe. Customer data from the SaaS service is not transferred out of the EU/EEA.

Some supporting services involve transfer to a third country (USA). For such transfers the European Commission's Standard Contractual Clauses (SCC) are used as the transfer basis, cf. GDPR Article 46. Zonara has carried out a transfer impact assessment (TIA) and implemented the necessary supplementary measures.

Zonara has implemented the following technical and organisational measures, cf. GDPR Article 32:

  • Encryption at rest: AES-256
  • Customer-managed keys: Encryption keys are managed in a customer-managed key store
  • Encryption in transit: TLS 1.2 or newer for all data transfer
  • Access control: Role-based access control (RBAC)
  • Two-factor login: MFA required for all administrators and users
  • Identity: BankID for end-user login
  • Logging: Audit log of user actions, centralised monitoring
  • Backups: Regular backups within the EU
  • Network security: Segmentation, firewalls, DDoS protection
  • Duty of confidentiality for all employees and sub-processors
  • Access limited on a «need to know» basis
  • Training of employees in information security and data protection
  • Established routines for handling security incidents
  • Established routines for handling requests concerning the data subjects' rights

In the event of a personal data breach affecting the Customer's data, Zonara shall notify the Customer in writing without undue delay, and no later than 24 hours after the breach was discovered.

The notification shall contain:

  • A description of the nature of the breach
  • The categories and approximate number of data subjects concerned
  • The categories and approximate number of personal data records concerned
  • The likely consequences
  • The measures taken and proposed

If full information is not available at the time of notification, the information may be provided in phases.

The Customer, as controller, is responsible for notifying the Norwegian Data Protection Authority (Datatilsynet) and the data subjects concerned in accordance with GDPR Articles 33 and 34. Zonara assists the Customer with the necessary information.

On termination of the main agreement, Zonara shall, at the Customer's written choice:

  1. Delete all personal data processed on the Customer's behalf, or
  2. Return all personal data to the Customer in a commonly used and machine-readable format.

Deletion or return shall take place within 90 days of termination.

Zonara may keep personal data for longer where this is required by EU law or national law (for example the Norwegian Accounting Act). Such retention is limited to the purpose the law requires.

Backups are deleted in accordance with Zonara's ordinary deletion cycle, and are protected by the security measures in section 9 until deletion.

Zonara shall make available all information necessary to demonstrate that the obligations under this DPA have been met, including documentation of security measures and of the sub-processors' compliance.

With 30 days' written notice, the Customer may require an audit of Zonara's processing, once per calendar year. The audit may be carried out by the Customer itself or by an independent third party approved by Zonara, subject to signing a confidentiality agreement.

The audit shall be carried out in a way that does not unnecessarily disrupt Zonara's operations, and the costs are borne by the Customer, unless the audit reveals a material breach on Zonara's part.

As an alternative to an audit, Zonara may present third-party audit reports (for example ISO 27001, SOC 2, or equivalent where available).

The parties' liability under this DPA is governed by the liability provisions of the main agreement. Any administrative fine imposed by a supervisory authority and claims from data subjects are allocated between the parties in accordance with each party's liability under GDPR Article 82.

Changes to the DPA require a written agreement between the parties. Zonara may unilaterally update the DPA where necessary to comply with changes in the regulations or instructions from a supervisory authority, with 30 days' written notice.

In the event of conflict between this DPA and the main agreement, this DPA takes precedence as far as the processing of personal data is concerned.

The DPA is governed by Norwegian law. Disputes are heard by Asker og Bærum District Court.

Enquiries relating to this DPA should be directed to:

Zonara AS Drammensveien 288, 0283 Oslo Email: personvern@zonara.no Telephone: +47 459 67 125