Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between SEEONDATA OÜ ("Datassier", "Processor", "we", "us") and the entity or individual agreeing to the Terms ("Customer", "Controller", "you"), collectively the "Parties".
This DPA applies to the extent that Datassier processes Personal Data on behalf of the Customer in the course of providing the Service.
1. Definitions
"Applicable Data Protection Law" means all laws and regulations relating to the processing of Personal Data applicable to the Parties, including but not limited to the GDPR, the Estonian Personal Data Protection Act (IKS), and any national implementing legislation.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
"Personal Data" means any information relating to a Data Subject that is processed by Datassier on behalf of the Customer through the Service, as defined under Article 4(1) of the GDPR.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
"Processing" means any operation or set of operations performed on Personal Data, as defined under Article 4(2) of the GDPR.
"Sub-processor" means any third party engaged by Datassier to process Personal Data on behalf of the Customer.
"Standard Contractual Clauses" ("SCCs") means the standard contractual clauses approved by the European Commission for the transfer of Personal Data to third countries.
"Supervisory Authority" means an independent public authority responsible for monitoring the application of Applicable Data Protection Law, including the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
2. Scope and Roles
2.1 The Customer acts as the Data Controller, determining the purposes and means of Processing. Datassier acts as the Data Processor, Processing Personal Data solely on behalf of and under the documented instructions of the Customer.
2.2 The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data processed, and the categories of Data Subjects are described in Annex 1 to this DPA.
2.3 This DPA applies for the duration of the Customer's use of the Service and continues until all Personal Data has been deleted or returned in accordance with this DPA.
3. Customer Obligations
3.1 The Customer shall:
- Ensure that it has a lawful basis for Processing Personal Data through the Service, including obtaining any necessary consents;
- Provide all required notices and disclosures to Data Subjects regarding the Processing;
- Ensure that its instructions to Datassier comply with Applicable Data Protection Law;
- Be responsible for the accuracy, quality, and legality of Personal Data provided to the Service.
3.2 The Customer warrants that it has the right to transfer Personal Data to Datassier for Processing in accordance with this DPA.
4. Processor Obligations
4.1 Instructions. Datassier shall process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by EU or Member State law. In such a case, Datassier shall inform the Customer of that legal requirement before Processing, unless the law prohibits such notification.
4.2 Confidentiality. Datassier shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.3 Security. Datassier shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Section 7 of this DPA and in the Security Policy at datassier.com/security.
4.4 Sub-processing. Datassier shall comply with the conditions set out in Section 6 of this DPA before engaging any Sub-processor.
4.5 Data Subject Rights. Datassier shall assist the Customer, by appropriate technical and organizational measures and insofar as possible, in fulfilling the Customer's obligations to respond to Data Subject requests to exercise their rights under Chapter III of the GDPR.
4.6 Assistance. Datassier shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of Processing and the information available to Datassier.
4.7 Deletion and Return. Upon termination of the Service, Datassier shall, at the Customer's election, delete or return all Personal Data to the Customer and delete existing copies, unless EU or Member State law requires storage of the Personal Data. Timelines for deletion are set out in Section 15 of the Terms.
4.8 Audit. Datassier shall make available to the Customer all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or a qualified third-party auditor mandated by the Customer, subject to Section 8 of this DPA.
5. Data Subject Requests
5.1 If Datassier receives a request directly from a Data Subject regarding their Personal Data, Datassier shall promptly redirect the Data Subject to the Customer and notify the Customer of the request, unless prohibited by law.
5.2 Datassier shall not respond to a Data Subject request directly unless instructed or authorized to do so by the Customer.
5.3 Datassier shall provide reasonable technical assistance to enable the Customer to respond to Data Subject requests, including requests for access, rectification, erasure, data portability, restriction of Processing, and objection.
6. Sub-processors
6.1 Authorization. The Customer grants Datassier general written authorization to engage Sub-processors for the Processing of Personal Data, subject to the requirements of this Section.
6.2 Sub-processor List. Datassier maintains a current list of Sub-processors at datassier.com/sub-processors.
6.3 Notification. Datassier shall notify the Customer at least 14 days in advance of any intended addition or replacement of a Sub-processor, providing the name, location, and nature of the Processing to be performed.
6.4 Objection. If the Customer has a reasonable objection to a new Sub-processor on data protection grounds, the Customer shall notify Datassier in writing within 14 days of receiving notification. The Parties shall negotiate in good faith to address the Customer's concerns. If no resolution is reached within 30 days, the Customer may terminate the affected Service component without penalty.
6.5 Sub-processor Agreements. Datassier shall impose on each Sub-processor, by way of a written contract, data protection obligations no less protective than those set out in this DPA. Datassier remains fully liable for the acts and omissions of its Sub-processors.
7. Security Measures
7.1 Datassier shall implement and maintain technical and organizational measures appropriate to the nature, scope, context, and purposes of Processing, including as appropriate:
- Encryption of Personal Data at rest (AES-256 or equivalent) and in transit (TLS 1.2+);
- Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services;
- Role-based access controls with least-privilege principles;
- Multi-factor authentication for administrative access;
- Regular testing, assessing, and evaluating the effectiveness of security measures;
- Logging and monitoring of access to systems containing Personal Data;
- Secure development practices and regular vulnerability assessments;
- Employee security training and awareness programs;
- Physical security measures for data center facilities (managed through infrastructure providers);
- Business continuity and disaster recovery procedures.
7.2 Datassier shall regularly review and update these measures to address evolving risks and technologies.
8. Audits
8.1 Datassier shall make available to the Customer, upon reasonable request, evidence of compliance with its obligations under this DPA, which may include:
- SOC 2 Type II reports or equivalent certifications;
- Results of penetration testing conducted by qualified third parties;
- Responses to reasonable security questionnaires.
8.2 If the Customer requires an on-site audit beyond the documentation in Section 8.1, such audit shall be:
- Conducted no more than once per year, unless required by a Supervisory Authority or following a Personal Data Breach;
- Performed by a qualified, independent third-party auditor bound by confidentiality obligations;
- Conducted during regular business hours with at least 30 days' prior written notice;
- Scoped to activities related to the Processing of the Customer's Personal Data;
- Conducted at the Customer's expense, unless the audit reveals material non-compliance.
8.3 Datassier may charge reasonable fees for audit facilitation beyond standard documentation reviews.
9. Personal Data Breach
9.1 Notification. Datassier shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting the Customer's Personal Data.
9.2 Notification Content. The notification shall include, to the extent available:
- A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned;
- The name and contact details of Datassier's data protection contact;
- A description of the likely consequences of the breach;
- A description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects.
9.3 Cooperation. Datassier shall cooperate with the Customer and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
9.4 Documentation. Datassier shall document the facts relating to each Personal Data Breach, its effects, and the remedial action taken.
10. International Data Transfers
10.1 Datassier shall not transfer Personal Data to a country outside the European Economic Area ("EEA") unless appropriate safeguards are in place as required by Chapter V of the GDPR.
10.2 Where transfers to third countries are necessary, Datassier shall ensure that one of the following mechanisms is in place:
- An adequacy decision by the European Commission under Article 45 of the GDPR;
- Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) of the GDPR;
- Binding Corporate Rules approved under Article 47 of the GDPR;
- Other legally recognized transfer mechanisms.
10.3 Datassier shall conduct transfer impact assessments where required and shall implement supplementary measures as necessary to ensure an essentially equivalent level of protection.
11. Data Protection Officer
11.1 The Customer may contact Datassier's data protection point of contact at: privacy@datassier.com.
11.2 If Datassier appoints a Data Protection Officer, their contact details will be published on our website and communicated to the Customer.
12. Duration and Termination
12.1 This DPA takes effect on the date the Customer first accesses the Service and remains in effect for the duration of the Customer's use of the Service.
12.2 Upon termination of the Service, the provisions of this DPA continue to apply until all Personal Data has been deleted or returned in accordance with Section 4.7 and the Terms.
13. Liability
13.1 The liability of each Party under this DPA is subject to the limitations and exclusions set out in Section 13 of the Terms, except that limitations of liability shall not apply to the extent prohibited by Applicable Data Protection Law.
13.2 Each Party's liability under the GDPR (including liability for fines imposed by a Supervisory Authority) is governed by the provisions of the GDPR itself.
14. Conflict
In the event of any conflict between this DPA and the Terms, this DPA shall prevail with respect to the Processing of Personal Data.
Annex 1: Details of Processing
Subject Matter: Processing of Personal Data through the Datassier platform to enable data management, synchronization, and automation services.
Duration: For the duration of the Customer's subscription to the Service, plus any post-termination retention period as set out in the Terms.
Nature and Purpose of Processing: Collection, storage, organization, structuring, retrieval, consultation, use, alignment, combination, transmission, and erasure of Personal Data as necessary to provide the Service, including data synchronization across third-party integrations.
Types of Personal Data: Determined by the Customer and may include: names, email addresses, phone numbers, postal addresses, job titles, financial data, transaction records, identifiers, and any other Personal Data the Customer uploads, creates, or synchronizes through the Service.
Categories of Data Subjects: Determined by the Customer and may include: the Customer's employees, customers, suppliers, contractors, business contacts, and end users.
Special Categories of Data: The Customer shall not process special categories of Personal Data (as defined in Article 9 of the GDPR) through the Service unless the Customer has ensured a lawful basis and has obtained explicit consent where required. Datassier does not intentionally collect or solicit special category data.