# Data processing agreement

> This data processing agreement (DPA) governs the processing of personal data on the customer's behalf under Article 28 GDPR when the customer uses Hasty to produce creative work. Hasty is a trademark owned and operated by Norrhavet Group AB, Bangatan 5A, 722 28 Vasteras, Sweden, which is the contracting party and data processor. This document applies as an annex to a signed customer agreement and does not replace it. In case of conflict, the signed customer agreement and mandatory law prevail over this document.

Human view: https://hasty.se/en/juridik/databehandlingsavtal
Agent view: https://hasty.se/en/juridik/databehandlingsavtal.md

Languages: sv=https://hasty.se/juridik/databehandlingsavtal | en=https://hasty.se/en/juridik/databehandlingsavtal | no=https://hasty.se/no/juridik/databehandlingsavtal | da=https://hasty.se/da/juridik/databehandlingsavtal | fi=https://hasty.se/fi/juridik/databehandlingsavtal

Uppdaterad: 2026-09-21

## Parties and roles

The customer is the controller for personal data included in briefs, reference material and other content uploaded to Hasty Workspace. Norrhavet Group AB acts as processor and processes data only to deliver the agreed service under the Hasty brand.

Hasty is not an agency but a subscription service for creative capacity. Agencies and marketing teams may be Hasty's customers, and in such cases this agreement applies between Norrhavet Group AB and the party that is controller under the main agreement.

## Instructions for processing

Norrhavet Group AB processes personal data only on the customer's written, documented instructions, as set out in the main agreement, briefs and the customer's use of the service. Instructions given verbally must be confirmed in writing to be binding. If Norrhavet Group AB believes an instruction breaches GDPR or other data protection law, the customer is notified before processing takes place.

Norrhavet Group AB does not use customer personal data for its own purposes, marketing or to train its own AI models.

## Categories of data subjects and data

- Data subjects: the customer's employees, the customer's customers, test users and other individuals referenced in briefs or reference material.
- Categories of data: name, contact details, images, quotes, job role and other information the customer chooses to include in a project.
- Special category data must not be included in briefs or materials unless expressly agreed in writing and specific safeguards have been set up in advance.

## Customer responsibilities as controller

The customer is responsible for having a valid legal basis for all processing of personal data carried out through the customer's use of the service, including data in briefs and reference material uploaded by the customer.

The customer is responsible for providing accurate and sufficient information to data subjects about the processing, and for obtaining any consents required.

The customer warrants that it holds the necessary rights to the material provided to Norrhavet Group AB and is responsible for the content of briefs, images and other materials uploaded to the service.

## Security measures

- Encryption of data at rest and in transit.
- Access control so only staff who need access for the assignment get it.
- Logging and monitoring of access to systems containing customer data.
- Regular review of suppliers and internal routines.
- Staff training in data protection and information security.

## Sub-processors and approval

The customer grants general authorisation for Norrhavet Group AB to engage sub-processors for hosting, email, analytics, payment, support and AI services, listed in our Sub-processors document. The list is informative and may change. Norrhavet Group AB enters into agreements with sub-processors that ensure at least the same level of protection as this agreement.

Norrhavet Group AB notifies the customer with reasonable notice before engaging or replacing a sub-processor. The customer may object to a new sub-processor within that period under the terms of the Sub-processors document.

## Assistance with data subject rights and incidents

Norrhavet Group AB assists the customer in responding to requests from data subjects regarding access, rectification, erasure and other rights, to the extent possible given the nature of the processing. Assistance beyond what can reasonably be expected, such as extensive manual work, may be charged in accordance with the applicable price list or agreement.

If Norrhavet Group AB discovers a personal data breach affecting customer data, the customer is notified without undue delay, no later than within 48 hours, with available information on what happened and what measures have been taken.

## Deletion and return at termination

On termination, Norrhavet Group AB deletes or returns, at the customer's choice, all personal data processed on the customer's behalf within 90 days, unless retention is required by law.

## Audit and security review

The customer has the right, with reasonable notice and at most once a year, to verify that Norrhavet Group AB complies with this agreement, for example by reviewing relevant security documentation. Norrhavet Group AB may instead provide an independent audit report rather than a physical audit.

Any such audit must be conducted under confidentiality, must not unreasonably disrupt ongoing operations, and must take place at a time reasonably accommodated by Norrhavet Group AB. Costs for assisting with audits and security reviews beyond the annual review, and extra work caused by the review, may be charged to the customer.

## International transfers

Processing takes place primarily within the EU/EEA. If a sub-processor exceptionally processes data outside the EU/EEA, this occurs under the European Commission's Standard Contractual Clauses (SCCs) together with additional technical and organisational safeguards such as encryption and pseudonymisation.

## Healthcare and sensitive industries

Hasty is not intended for processing patient data or other sensitive personal data in briefs or materials. Such data may only be processed if a specific addendum with relevant technical and organisational safeguards has been signed in advance.

## Limitation of liability

Norrhavet Group AB's liability under this document is limited to the extent permitted by law and in accordance with the limitations of liability set out in the main agreement. Norrhavet Group AB is not liable for third-party services provided independently by sub-processors or other suppliers, nor for defects in material, instructions or data provided by the customer.

This document does not create any independent warranties beyond those following from the main agreement and mandatory law.

## Changes, governing law and disputes

Norrhavet Group AB may update this document from time to time. Changes take effect upon publication and apply prospectively, not retroactively.

This document is governed by Swedish law, without regard to conflict of law rules. Disputes shall be settled by Swedish general courts.

Questions about this document can be sent to privacy@norrhavet.com.

---

## Kontakt

- Allmänna frågor: hej@hasty.se
- Offert och nya uppdrag: christian@hasty.se
- Telefon: 08-480 04 706 (+46 8 480 04 706)
- Besöksadress: Bjurholmsplan 24, 116 63 Stockholm, Sverige
- Kontaktsida: https://hasty.se/en/kontakta-oss
- Personlig service (formulär): https://hasty.se/en/boka-demo
- Juridisk avtalspart: Norrhavet Group AB, org.nr 559258-3792, Stockholm, Sverige.
- Priser och kalkylator: https://hasty.se/en/priser

## Site maps for agents
- https://hasty.se/llms.txt
- https://hasty.se/llms-full.txt
- https://hasty.se/agents.md
- https://hasty.se/sitemap.xml

Hasty is a brand owned by Norrhavet Group AB (org.nr 559258-3792), Sweden.
