Privacy Principles

Privacy Principles for Entrusted Personal Data

Last updated 3 August 2026

1. About Ofinex

These principles explain how AS “Ofinex” (Ofinex AS), registration number 50103946451, handles personal data entrusted to it by customers in connection with its services.

2. Scope and responsibilities

These principles apply to personal data that a customer, or someone acting on the customer’s behalf, provides or makes accessible to Ofinex for an agreed assignment. They cover personal data contained in documents, correspondence, records, systems and other materials, regardless of format.

When processing entrusted personal data on a customer’s behalf, Ofinex acts as a data processor. The customer remains the data controller, responsible for determining the purposes of processing and ensuring an appropriate legal basis. Where the customer itself acts as a processor, Ofinex acts as a subprocessor under the applicable contractual arrangements and authorisations.

The relevant agreement and documented instructions define the subject matter, duration, nature and purpose of processing, categories of personal data and data subjects, and the parties’ responsibilities. These principles complement those arrangements; they do not replace a data processing agreement required under Article 28 GDPR.

These principles do not cover processing for which Ofinex independently acts as controller, such as its own accounting or business contact administration. Such processing requires its own appropriate legal basis and privacy information.

3. Processing only for the agreed purpose

Ofinex processes entrusted personal data only to carry out the agreed services and in accordance with the customer’s documented instructions, including instructions concerning disclosures and international transfers.

Ofinex does not use entrusted personal data for its own marketing, advertising, unrelated analytics or training of general-purpose AI models. It does not sell entrusted personal data or make it available to other customers.

If Union or Member State law requires processing beyond the customer’s instructions, Ofinex informs the customer of that legal requirement before processing, unless the law prohibits such notification. If Ofinex considers an instruction to infringe applicable data protection law, it informs the customer promptly.

4. Data minimisation and confidentiality

Ofinex limits the personal data it accesses, copies and otherwise processes to what is necessary for the agreed assignment. Customers should provide only the data needed for that purpose and identify any special handling requirements before providing sensitive information.

Access is limited to authorised persons who need the data to perform their responsibilities and are subject to confidentiality obligations. Those obligations continue after their involvement in the assignment ends.

Where personal data needs to be corrected, restricted or deleted, Ofinex acts on the customer’s instructions and provides reasonable assistance with implementing the change.

5. Security

Ofinex applies technical and organisational measures appropriate to the nature of the entrusted data, the processing involved and the risks to individuals. These address access control, confidentiality, secure handling and storage, protection against unauthorised disclosure or alteration, and accidental loss or destruction.

Specific security requirements, approved storage locations, access arrangements and any additional safeguards are established in the applicable agreement or documented instructions. Ofinex considers those requirements before placing entrusted data in any service or enabling synchronisation or backups.

6. Email processing and subprocessors

When a customer sends information to Ofinex by email, that information is automatically processed through Zoho and Google Workspace as part of Ofinex’s standard email and document-handling workflow. This includes personal data in the message and its attachments. These services are not activated separately for each email or document.

Provider / service Processing purpose and use
Zoho — email Automatic processing of incoming customer emails and attachments, and sending and retaining correspondence needed for the assignment.
Google Workspace — Google Drive Automatic processing of information received from customers by email as part of the document-handling workflow, including storing and handling documents needed for the assignment.
Apple iCloud — document synchronisation for backups Synchronising agreed documents for backup purposes, only where separately authorised by the customer in writing.

Customers should take this automatic processing into account before sending personal data by email. If these services are unsuitable for a particular assignment or category of data, the customer should contact Ofinex before sending that data to agree an alternative transfer and handling arrangement.

The customer’s applicable data processing agreement or other documented written authorisation must cover Zoho and Google Workspace before entrusted personal data is processed through them. This notice explains the automatic workflow; sending an email does not by itself replace the subprocessor authorisation required under Article 28 GDPR or constitute a data subject’s consent. Where the customer acts as a processor, the necessary authorisation from the relevant controller must also be in place.

Apple iCloud is not automatically authorised by the use of email. Ofinex uses it for entrusted personal data only within the scope of the customer’s separate written approval.

The applicable processing arrangements identify the relevant provider legal entities, services, processing scope and international transfer arrangements. Ofinex engages providers as subprocessors only under terms imposing the data protection obligations required by Article 28 GDPR, including appropriate confidentiality and security obligations.

New or replacement subprocessors, and uses outside the authorised scope, require prior written customer authorisation. Ofinex remains responsible to the customer for the performance of its subprocessors’ data protection obligations as required by applicable law.

7. Location and international transfers

Entrusted personal data is stored and accessed only within the arrangements agreed with the customer. Authorisation to use a named provider does not, by itself, establish a lawful basis for transferring personal data outside the European Economic Area.

Where processing involves an international transfer, including remote access where it constitutes a transfer, Ofinex ensures that the transfer follows the customer’s documented instructions and meets applicable GDPR requirements. This includes an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses and supplementary measures where necessary.

Information about the applicable processing locations and transfer safeguards is provided to the customer as part of the relevant processing arrangements.

8. Retention, return and deletion

Ofinex does not retain entrusted personal data longer than required for the agreed purpose or the period agreed with the customer, except where retention is required by applicable law.

At the end of the services, or earlier on the customer’s instructions, Ofinex returns or deletes entrusted personal data at the customer’s choice and deletes existing copies, unless Union or Member State law requires storage. Any legally required retention is limited to the relevant data and period, with access and further use restricted to that requirement.

Retention and deletion instructions also apply to email attachments, shared documents, local copies, synchronised copies and backups held by Ofinex or its authorised subprocessors. Synchronisation and backup arrangements must support the agreed retention and deletion requirements.

Where immediate deletion from a backup is technically unavailable, any residual retention must fall within the agreed deletion schedule. The data remains protected and unavailable for ordinary use until deletion. If a backup is restored, applicable deletion instructions are reapplied.

Ofinex confirms completion of return or deletion on request, identifying any legally required retention or residual copies still awaiting deletion under the agreed schedule.

9. Personal data breaches

Ofinex notifies the customer without undue delay after becoming aware of a personal data breach affecting entrusted data and follows any more specific notification commitments in the relevant agreement.

Ofinex supplies available information about the nature of the breach, affected data, likely consequences and measures taken or proposed, and provides further information as it becomes available. It assists the customer with investigation, mitigation and any required notifications to supervisory authorities or affected individuals.

10. Assistance and individuals’ rights

Taking into account the nature of the processing, Ofinex assists the customer with requests to access, correct, erase, restrict or obtain copies of personal data, and with other applicable data protection rights.

An individual whose data has been entrusted to Ofinex should normally contact the organisation responsible for that data. If Ofinex receives such a request directly, it promptly refers it to the relevant customer and assists in accordance with the customer’s instructions, unless applicable law requires otherwise.

Ofinex also provides assistance, taking into account the processing and information available to it, with security obligations, breach notifications, data protection impact assessments and prior consultation with supervisory authorities.

11. Accountability

Ofinex maintains the documentation required for its processing activities and makes available information necessary to demonstrate compliance with its processor obligations. It allows and contributes to audits and inspections by the customer or its mandated auditor under the applicable agreement and GDPR.

12. Contact and changes

Questions about these principles or the handling of entrusted personal data may be sent to info@ofinex.net.

The current version is available at ofinex.net/privacy. Updates to this page do not themselves change customer instructions, authorise subprocessors or amend agreed processing terms. Changes requiring customer agreement or authorisation are handled separately before implementation.