Data Processing Agreement

Last updated: 16 July 2026

This Data Processing Agreement ("the agreement") is entered into between the customer as data controller and Eksire AS, org. no. 821 482 372, as data processor, and forms an integral part of the Terms of Service. It governs Mynto's processing of personal data on behalf of the customer under Article 28 of the GDPR.

1. Roles and purpose

The customer is the data controller for personal data entered into or retrieved by the service on the customer's behalf. Mynto processes the data solely to deliver the accounting service as described in the terms: bookkeeping, invoicing, payroll, reporting and filings with public authorities after the customer's approval.

2. Nature of processing and categories

The processing comprises storage, structuring, analysis and transfer of accounting data. Data subjects are the customer's employees, customers, suppliers and contact persons. Categories of data include names and contact details, national identity numbers (for employees in the payroll module), salary and tax information, employment details, bank account numbers and transaction data, and information contained in receipts and invoices.

3. Instructions

Mynto processes personal data only on documented instructions from the customer — the terms, this agreement and the actions the customer performs in the service constitute those instructions. Mynto will notify the customer if, in Mynto's view, an instruction infringes data protection law. Mynto may nevertheless process and disclose personal data without instructions where required by law to which Mynto is subject; in that case the customer is notified before processing, unless the law prohibits such notification (cf. GDPR Article 28(3)(a)).

4. Confidentiality and security

Mynto ensures that persons with access to the data are bound by confidentiality, and implements technical and organisational measures pursuant to Article 32 of the GDPR, including encryption in transit and at rest, access control, a traceable audit log and deletion locks on booked accounting records.

5. Sub-processors

The customer grants general prior authorisation for Mynto to use sub-processors to operate the service. An up-to-date list naming each sub-processor, its purpose, location and transfer basis is available at all times at mynto.no/underdatabehandlere. Mynto engages only sub-processors that can document technical and organisational measures at least equivalent to this agreement, storage within the EEA or a valid transfer basis under GDPR Chapter V, and written obligations mirroring Mynto's own. Before adding or replacing a sub-processor, Mynto notifies the customer at least 30 days before the change takes effect. The customer may object in writing to personvern@mynto.no within that period. If the parties do not reach agreement within 30 days of the objection, the customer may terminate the affected part of the service free of charge with effect from the date of the change. An objection not received within the deadline counts as authorisation. Mynto imposes the same obligations as in this agreement on its sub-processors and remains fully liable for their processing.

6. Assistance

Mynto assists the customer, insofar as possible, in responding to data subjects' requests for access, rectification, erasure and portability, and with the customer's obligations regarding security, personal data breaches, data protection impact assessments and prior consultation. Mynto notifies the customer without undue delay after becoming aware of a personal data breach.

7. Transfers to third countries

Personal data is stored in the EU/EEA. Any transfer to countries outside the EEA takes place only with a valid transfer mechanism under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision.

8. Deletion and return

When the customer relationship ends, the customer may export a complete archive (SAF-T and all vouchers) from the service for 90 days. Mynto then deletes all personal data processed on the customer's behalf, unless legislation requires Mynto to retain it further.

9. Audit and duration

Mynto makes available the information necessary to demonstrate compliance with the obligations in this agreement, and allows for audits conducted by the customer or an independent third party, subject to reasonable notice and without undue disruption to operations. The agreement applies for as long as Mynto processes personal data on the customer's behalf.

10. Changes to this agreement

This agreement is the customer's instruction to Mynto. Mynto therefore cannot unilaterally change what the processing covers: changes to purposes, categories of personal data or data subjects, the basis for transfers outside the EEA, deletion rules or the customer's right of audit require the customer's express acceptance, and take effect only once it is given. Changes that do not touch the instruction — clarifications, updated contact details, updated legal references and security measures that are strengthened — may be made by Mynto with notice. Each edition of the agreement carries a version number, and Mynto records which version the customer accepted, by whom and when. Changes of sub-processors follow section 5.

Data processing agreement — Mynto