Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the OrgLens Terms of Service between Klokk Nettablering ("Processor", "we") and the customer entering into those Terms ("Customer", "Controller"). It reflects the metadata-only nature of OrgLens processing: OrgLens documents the structure of a connected Salesforce organisation — object, field, and relationship metadata — and does not read, store, or process Customer's end-customer records, field values, or other personal data held inside Salesforce.
1. Parties & roles
Customer is the data controller for any personal data contained within the metadata it submits to or connects through the Service. Klokk Nettablering ("OrgLens") acts as a data processor, processing that data solely on Customer's documented instructions as set out in the Terms and this DPA. Because OrgLens operates on Salesforce metadata only — not record-level data — the practical scope of personal data processed under this DPA is narrow: it is generally limited to the names of objects, fields, and relationships (which occasionally include a user's own name or email if used as an API/label name) and the account and contact data of Customer's own authorised users of the Service.
2. Subject-matter & duration of processing
The subject-matter of processing is the provision of the OrgLens Service as described in the Terms. Processing takes place for the duration of the underlying subscription and, for a limited retention period thereafter, as described in our Privacy Policy, unless a shorter period is agreed in writing or required by law.
3. Nature & purpose of processing
OrgLens connects to a Customer's Salesforce organisation via the Salesforce Metadata API and retrieves definitions of objects, fields, page layouts, flows, and their relationships. This metadata is analysed, and in part sent to our AI sub-processor, to automatically generate human-readable descriptions, documentation, and configuration-risk findings. The purpose is limited to generating and maintaining documentation and audit artefacts about Customer's Salesforce configuration — OrgLens does not use Customer Data for any other purpose, and does not use Customer Data to train foundation models.
4. Categories of data & data subjects
Categories of data processed:
- Salesforce metadata: object and field API names, labels, descriptions, data types, page layouts, flow definitions, and relationship structures;
- Account and contact data of Customer's authorised users of the Service (name, work email, role, authentication data);
- Usage and diagnostic logs generated by the Service in connection with Customer's account.
Explicitly out of scope — OrgLens does NOT process:
- Salesforce record data / field values (e.g. contact, lead, opportunity, or case records);
- End-customer personal data or other PII held within Customer's Salesforce records;
- Any bulk export of Customer's Salesforce data.
Categories of data subjects: Customer's authorised users (employees or contractors who access the Service), and, incidentally, any individual whose name happens to appear within a Salesforce metadata label or API name configured by Customer.
5. Sub-processors
Customer authorises OrgLens to engage the sub-processors listed on our Sub-processors page, which is incorporated into this DPA by reference and kept up to date. OrgLens will give Customer reasonable prior notice (via that page and, where Customer has provided a contact, by email) before engaging any new sub-processor, so that Customer may object on reasonable data-protection grounds. OrgLens remains liable for the acts and omissions of its sub-processors to the same extent it would be liable if performing their services directly, and imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA.
6. Security measures
OrgLens implements technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS 1.2+) and at rest (AES-256); PostgreSQL row-level security enforcing per-organisation, multi-tenant data isolation at the database layer (not only in application code); least-privilege access controls and role-based permissions; encrypted, tested backups; and a documented incident-response runbook. A fuller description of these controls is published on our Trust & Security page, which is incorporated into this DPA by reference.
7. International transfers
Where personal data is transferred outside the EEA, UK, or Switzerland to a sub-processor located in a third country without an adequacy decision, OrgLens relies on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (SCCs), together with supplementary technical measures such as encryption in transit and at rest, as a valid transfer mechanism. Details of sub-processor locations are set out on the Sub-processors page.
8. Assistance with data-subject requests
Taking into account the nature of processing, OrgLens will provide reasonable assistance to Customer, by appropriate technical and organisational measures, to fulfil Customer's obligation to respond to requests from data subjects exercising their rights under applicable data-protection law. Because OrgLens does not hold Customer's end-customer record data, most such requests will not concern data processed under this DPA; where a request does relate to metadata processed by OrgLens, contact [email protected].
9. Personal-data breach notification
OrgLens will notify Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal-data breach affecting Customer Data processed under this DPA. Notification will include, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. OrgLens will cooperate with Customer and provide reasonable further information as it becomes available to support Customer's own notification obligations.
10. Deletion & return of data on termination
On termination or expiry of the underlying subscription, and upon Customer's written request, OrgLens will delete or, where technically feasible and requested, return Customer Data processed under this DPA within a reasonable period, except to the extent OrgLens is required by applicable law to retain a copy, in which case OrgLens will continue to protect that data and limit any further processing to the purpose of that legal requirement.
11. Audits & information rights
OrgLens will make available to Customer, on reasonable request and no more than once per year (or following a confirmed security incident), information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through documentation such as our Trust & Security page, completed security questionnaires, or summaries of relevant certifications. Where documentation review is insufficient, the parties will agree in good faith on the scope, timing, and confidentiality terms of any on-site or remote audit, at Customer's reasonable cost.
12. Liability & order of precedence
Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Terms. In the event of any conflict between this DPA and the Terms in relation to the processing of personal data, this DPA prevails; in all other respects, the Terms continue to apply. This DPA does not replace a fully executed, countersigned version — Customers requiring a bilaterally signed copy (including any Customer-specific SCC module) should contact [email protected].