Touch4SafetyLegal pack

Data processing addendum & subprocessors

Version 1.0, last updated 15 August 2026. This addendum applies where it is legally needed: when an organisation, employer, school, care provider or family administrator uses Touch4Safety to protect other people, that organisation is the controller and Touch4Safety acts as processor on its behalf. It forms part of the terms of use and is accepted automatically when such an account is created. Individual consumers using Touch4Safety for themselves and their own family do not need it — the privacy notice governs that relationship, with Touch4Safety as controller.

1. Roles and scope

Controller — the customer organisation that decides which people are protected and which data is entered. Processor — Touch4Safety, operated by Strandadata (Norway, EU/EEA data protection regime). Touch4Safety processes personal data only on the controller's documented instructions, which are the configuration choices made inside the app, and never for its own purposes, advertising or model training.

2. Subject matter, duration and categories

  • Purpose — operating personal-safety check-ins, Watch Me and journey sessions, SOS escalation, notifications and the family dashboard.
  • Duration — for as long as the account is active; data is deleted on termination or on request, apart from minimal accounting or security records.
  • Data subjects — protected users, family members, and the Safety People they nominate.
  • Personal data — identity and contact details, precise location during consented sessions, device and battery metadata, notification and escalation records, and any emergency or health notes the data subject chooses to enter (GDPR Art. 9 special category data, processed on explicit consent only).

3. Security measures (Art. 32)

  • Encryption in transit (TLS) and at rest for all stored personal data.
  • Row-level security on every table so each record is reachable only by its owner, the people they explicitly share with, or a token-scoped alert link.
  • Safe words, duress words and cancel PINs are isolated in a separate secrets table, hashed where possible, and never readable by family members or administrators.
  • Single-use, expiring, email-bound tokens for invitations and public alert links, with rate limiting and logged attempts.
  • Least-privilege server functions with authenticated middleware; privileged operations are role-checked and written to an append-only audit log.
  • Administrators see aggregated metrics only; precise location visibility is restricted to named auditors and anonymous visitor locations are coarsened to roughly 11 km.
  • Automated security regression checks and dependency vulnerability scanning run on every change and weekly.

4. Subprocessors

The controller gives general authorisation for the subprocessors below. We impose the same data protection obligations on each of them, and we will announce material changes in the app before a new subprocessor starts processing, so the controller can object.

Managed hosting, database & authentication

Stores account, safety session, contact and location data; runs the app backend.

Processing region: European Union

Email delivery

Sends check-in, escalation and SOS alerts plus account emails.

Processing region: EU/US — SCCs + EU-US Data Privacy Framework

SMS & voice delivery

Delivers SMS alerts and fallback voice calls to Safety People.

Processing region: Global carrier routing — SCCs

Web push delivery

Delivers browser/PWA push alerts through the user's own browser vendor.

Processing region: Depends on the recipient's browser vendor

Payment processing

Family plan subscriptions, invoices and tax handling. We never see card numbers.

Processing region: EU/US — SCCs + DPF

AI safety assistant

Generates the Touch AI replies you request. Prompts are not used to train models and are not retained for advertising.

Processing region: EU/US — SCCs

Map tiles & address lookup

Renders maps and converts coordinates to addresses, without account identifiers.

Processing region: EU (OpenStreetMap infrastructure)

5. International transfers

Personal data is stored in the European Union. Where a subprocessor processes data outside the EU/EEA, the transfer relies on the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum for UK data, the Swiss addendum recognised by the FDPIC for Swiss data, and — where applicable — certification under the EU-US Data Privacy Framework, together with supplementary technical measures such as encryption and data minimisation. A transfer impact assessment is maintained and available on request.

SMS and voice alerts are inherently routed through the recipient's local carrier, so delivery metadata necessarily leaves the EU when the recipient is abroad. Message content is limited to what the alert needs.

6. Data subject requests, audits and assistance

Touch4Safety provides self-service export and deletion tools that let the controller satisfy access, rectification, erasure, restriction, objection and portability requests directly. If a request reaches us instead, we forward it to the controller and do not respond on their behalf. We assist with data protection impact assessments and provide the information needed to demonstrate compliance; on request, and no more than once a year unless a supervisory authority requires otherwise, we make our security documentation available for review.

7. Personal data breach notification

We notify the controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting their data, with the nature of the breach, categories and approximate number of records affected, likely consequences and the measures taken. Where Touch4Safety is controller, we notify the competent supervisory authority within 72 hours (GDPR Art. 33) and affected users where the risk is high.

8. Deletion and return

On termination, and at the controller's choice, we delete or return the personal data and delete existing copies, unless retention is required by law. Backups roll off within 30 days.

9. Liability and precedence

This addendum does not expand Touch4Safety's liability for safety outcomes: the service remains extra help only, and the limitation of liability in the terms applies in full. Where this addendum conflicts with the terms on data protection matters, this addendum prevails.

10. Signature and contact

Acceptance in-app is sufficient. If your organisation needs a countersigned copy, a named data protection contact, a specific storage region, or your own paper to be reviewed, write to lars@strandadata.no before deployment and we will confirm what we can support.