DPA Template — Vedlegg B / Annex B: Sub-Processors for Bilko Archive Feature

⚠️ DRAFT — pending final legal sign-off and translations (per Lexicon notes). MC #100045. 2026-05-08. Canonical-facts verified by John post-Lexicon (org.nr 932 516 136, Azure Sweden Central).


Annex B: Sub-Processors for Bilko Archive Feature

This annex applies specifically to the Bilko product when the archive feature is enabled.

B.1 Cloudflare R2 (Temporary Document Storage)

FieldDetails
Sub-processorCloudflare, Inc.
Address101 Townsend St, San Francisco, CA 94107, USA
Contactprivacyquestions@cloudflare.com
PurposeTemporary staging of documents for archive pipeline
Data Categories ProcessedContracts (PDF), Invoices (PDF), Care Plans, Incident Reports, Onboarding Documents
Categories of Data SubjectsBilko organization's customers, suppliers, patients (for care organizations)
Geographic LocationEU region (eu-west R2 storage bucket)
Processing DurationTemporary (typically < 5 minutes; documents deleted after successful transfer to Paperless-ngx)
SafeguardsEU Standard Contractual Clauses (SCC 2021/914/EU) per Cloudflare's published DPA; AES-256 encryption at rest; TLS 1.3 in transit; Cloudflare Zero Trust architecture
Sub-sub-processorsSee Cloudflare's DPA for complete list (https://www.cloudflare.com/cloudflare-customer-dpa/)

B.2 ALAI Azure VM Paperless-ngx (Long-Term Archive)

FieldDetails
Sub-processorALAI Holding AS (own infrastructure)
Org.No932 516 136
AddressTømmerrenna 1B, 2050 Jessheim, Norway
Contactdpa@alai.no
PurposeLong-term archive of business documents at archive.alai.no
Data Categories ProcessedSame as Cloudflare R2 above
Categories of Data SubjectsSame as Cloudflare R2 above
Geographic LocationEU/EEA (Microsoft Azure Sweden Central region)
Processing DurationPermanent archive per retention schedule:
• Financial documents: 7 years (accounting law RS/BA/HR)
• Care documents: 25 years (UK NHS standard, interim)
SafeguardsALAI DPA + Microsoft Azure Standard Contractual Clauses; Azure Disk Encryption (AES-256); TLS 1.3 in transit; Role-Based Access Control (RBAC); Paperless-ngx with OAuth2 authentication; Daily Azure backup with 30-day retention; Immutable audit trail in PostgreSQL
Sub-sub-processorsMicrosoft Azure (infrastructure provider — see Microsoft Customer Agreement + DPA)

B.3 Data Flow for Archival

Bilko Backend (Cloud Run)
    ↓ (POST /archive)
Cloudflare R2 (eu-west bucket)
    ← [5-minute batch job]
Cloud Run Worker
    ↓ (HTTP POST to Paperless-ngx API)
ALAI Azure VM (archive.alai.no)
    → Permanent archive (7–25 years)

B.4 Notice of Sub-Processor Changes

ALAI Holding AS commits to notifying the Data Controller at least 30 days in advance via email before:

The Data Controller may object within this period if the new sub-processor does not meet data protection requirements.


Company: ALAI Holding AS (org.nr 932 516 136)
DPA Contact: dpa@alai.no


Revision #2
Created 2026-05-08 20:07:00 UTC by John
Updated 2026-06-14 20:02:48 UTC by John