Muuh AS
Data processing agreement
This data processing agreement applies where Muuh AS processes personal data on behalf of a business customer through SiftBrief.
Effective 2026-08-02
Roles and instructions
The customer is the controller and Muuh AS is the processor for customer personal data processed solely to provide SiftBrief. The customer instructs Muuh AS to process account, workspace, source, report, support, and related technical data for the term of the service agreement.
Muuh AS processes personal data only on documented instructions, including this agreement and configured use of the service, unless applicable law requires otherwise. Muuh AS will notify the customer if an instruction appears to infringe applicable data protection law.
People, data, purpose, and duration
Data subjects may include customer personnel, customer business contacts, website operator contacts, and persons incidentally present in selected public business sources. Data may include identity and business contact data, authentication and usage data, customer instructions, support messages, online identifiers, and bounded public-source content.
Processing includes collection, hosting, organisation, retrieval, analysis, communication, restriction, deletion, and other operations necessary to provide and secure SiftBrief. Processing lasts for the customer relationship and the deletion periods described in the Privacy Notice.
Confidentiality and security
Muuh AS ensures that authorised personnel are bound by confidentiality and access data only as needed. Appropriate technical and organisational measures include access control, encrypted managed infrastructure, private object storage, bounded collection, redacted logs, vulnerability management, backups, incident procedures, and tested deletion paths.
Subprocessors and transfers
The customer gives general authorisation for the subprocessors listed on the Subprocessors page. Muuh AS will provide reasonable advance notice of material changes and a reasonable opportunity to object on substantiated data-protection grounds.
Muuh AS imposes appropriate data-protection obligations on subprocessors and remains responsible for their processing as required by law. Restricted transfers use an applicable adequacy decision, standard contractual clauses, or another lawful mechanism.
Assistance and incidents
Taking account of the nature of processing, Muuh AS will reasonably assist the customer with data-subject requests, security obligations, breach assessment and notification, data-protection impact assessments, and regulator consultations. The customer remains responsible for responding to its data subjects.
Muuh AS will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer response.
Deletion, return, and audit
At termination or written instruction, Muuh AS will delete or return customer personal data as described in the Privacy Notice unless law requires retention. Active service data is deleted after the disclosed 30-day recovery period unless immediate deletion is validly requested, and protected backup copies expire no later than 90 days after relationship end or the accepted immediate request.
Muuh AS will make information reasonably necessary to demonstrate compliance available to the customer. Audits must protect other customers, confidentiality, security, and service continuity and should rely first on current documentation or independent reports. The customer bears extraordinary audit costs unless material non-compliance is found.
Operator and contact
Muuh AS, organisation number 998153344
Sukkevannslia 4, 4638 Kristiansand, Norway
Responsible contact: Øyvind Heggernes
General: [email protected]
Privacy: [email protected]