Legal
Data processing agreement
When we create and follow up campaigns for you, we sometimes process personal data on your behalf. This agreement regulates that, as required by article 28 of the General Data Protection Regulation (GDPR).
We only process data on your instructions.
We have measures to protect the data, and are working towards ISO 27001 and SOC 2.
You get to know which subprocessors we use.
We delete or return the data when the agreement ends.
Parties and purpose
You are the data controller, and Campaign Shark AS (org. no. 936 548 660, Storgata 20, 2414 Elverum, Norway) is the data processor. This agreement is part of the terms of service and applies for as long as we process personal data on your behalf.
What the processing covers
- Purpose: to create, publish and follow up ad campaigns and report results.
- Whose data: your customers and potential customers, and visitors to your website.
- Types of data: contact details from forms and enquiries, and data on usage and ad impressions, such as device data and events from tracking tools.
Our obligations
- We process personal data only on your documented instructions, such as the agreement and this data processing agreement.
- Everyone with access at our company is bound by confidentiality.
- We help you respond to requests from data subjects, and with risk assessments and contact with the data protection authority when necessary.
- We tell you if we believe an instruction conflicts with data protection rules.
Security
We use technical and organisational measures appropriate to the risk, including access control, encrypted transfer, separated customer areas and access only for those who need it. We are also working towards ISO 27001 and SOC 2 approval.
Subprocessors
You approve that we use subprocessors, for example for hosting, storage, email and artificial intelligence. They are given the same obligations as we have in this agreement. We will send you an up-to-date list on request, and notify you at least 14 days before we start using a new one. You may object if you have a reasonable ground.
The ad platforms, such as Meta and Google, process data under their own terms and are responsible for their own processing.
Transfers outside the EEA
We only transfer personal data to countries outside the EEA when there is a valid basis, such as an adequacy decision or the EU standard contractual clauses.
Personal data breaches
If we discover a personal data breach affecting your data, we will notify you without undue delay, and give you the information you need to notify the data protection authority and those affected.
Audit
You may request documentation that we comply with this agreement, and you may carry out an audit at our company once a year, or more often if there has been a breach. We agree on a time well in advance, and the audit must not unnecessarily disturb our operations.
Deletion when the agreement ends
When the agreement has ended, we delete the personal data you are the controller of, or return it to you, within 30 days. You choose which. We may keep data that we are required by law to store.
Liability and governing law
Liability follows the terms of service. The agreement is governed by Norwegian law.
Questions?
Email adrian@campaignshark.no.
Last updated: October 2026.