GDPR & Data Protection

Your data, handled responsibly

ProdSys is built for European SMBs by a European company. GDPR compliance is not an add-on — it is foundational to how we operate.

Last updated
14 May 2026
This page summarises how ProdSys handles personal data under the EU General Data Protection Regulation (GDPR). It is provided for transparency and is not a substitute for our Data Processing Agreement (DPA), which forms the binding legal basis of our relationship with customers.

Our role: data processor

When you use ProdSys, your company is the data controller — you decide what personal data is collected and how it is used.

ProdSys is the data processor — we process that data on your behalf, only as instructed by you, and only for the purpose of providing the service.

For data we process about you directly as a website visitor or prospect (e.g. when you book a demo), ProdSys is the controller. That processing is described in our Privacy Policy.

Where your data is stored

All ProdSys customer data is stored on servers physically located in the European Union. We use established European cloud infrastructure providers with SOC 2 and ISO 27001 certifications.

🇪🇺
EU data centers
Customer data never leaves the European Union. Primary and backup data centers are located in EU member states.
🛡
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Encryption keys are managed within the EU.
🔒
Access control
Strict role-based access control. Employee access to customer data is logged, audited and minimised by design.

Data Processing Agreement (DPA)

Every ProdSys customer receives a Data Processing Agreement that meets the requirements of GDPR Article 28. The DPA covers:

  • The subject matter and duration of processing
  • The nature and purpose of processing
  • The type of personal data and categories of data subjects
  • The rights and obligations of both parties
  • Technical and organisational security measures
  • Sub-processor list and notification of changes
  • Breach notification procedures
  • Data return and deletion at end of contract

Request a copy of our DPA from post@prodsys.com.

Your rights under GDPR

As a data subject, you have the following rights regarding personal data we process about you:

Right of access
Confirmation of whether we process your data and a copy of that data.
Right to rectification
Correction of inaccurate or incomplete personal data.
Right to erasure
Deletion of your personal data under certain conditions (the "right to be forgotten").
Right to restriction
Limitation of processing in specific circumstances.
Right to portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests or direct marketing.

If ProdSys is the processor for your data (i.e. you are an end-user of a ProdSys customer), please direct rights requests to that customer first — they control the data. If you cannot reach them, contact us at post@prodsys.com and we will help route the request appropriately.

Sub-processors

We rely on established European service providers to deliver ProdSys. These sub-processors are bound by data processing agreements that mirror our obligations to you:

Sub-processor Purpose Location
European cloud providerHosting and storageEU 🇪🇺
Email service providerTransactional email deliveryEU 🇪🇺
Backup serviceEncrypted off-site backupsEU 🇪🇺
Customer support platformSupport ticketingEU 🇪🇺

Specific provider names are listed in our Data Processing Agreement. Customers are notified in advance of any material change to sub-processors and have the right to object.

Data breaches

In the event of a personal data breach affecting your data, ProdSys will notify you without undue delay and in any case within 72 hours of becoming aware, in line with GDPR Article 33.

Our notification will include the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address it.

Data retention & deletion

During the contract: Customers retain full control over their data and can delete records at any time through the ProdSys interface or via API.

At end of contract: Customers can export all their data in machine-readable formats. After a 30-day grace period (during which the customer can change their mind), all customer data is permanently deleted from our active systems.

Backups: Encrypted backups are retained for 90 days for disaster recovery purposes, after which they are cryptographically erased.

Contact us about privacy

For any GDPR-related question — rights requests, DPA requests, security questionnaires, or general privacy inquiries — get in touch:

Postal address
PSIT Software AS, Att: Privacy
Ingvald Ystgaards veg 1
7047 Trondheim, Norway

You also have the right to lodge a complaint with your local data protection authority. In Norway this is Datatilsynet. In other EU member states, see the EDPB list of national authorities.

Have questions about how we handle data?

Our team is happy to walk through our security and compliance posture before you commit.

Book a demo → Contact us