اتفاقية معالجة البيانات
DataDiwan OS — GDPR Article 28 Processor Agreement
Last updated: 30 July 2026
Effective date: 30 July 2026
Processor: DataDiwan, Y-tunnus 3641767-6, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland
Contact: info@datadiwan.com · support@datadiwan.com
Supervisory Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PL 800, 00531 Helsinki
1. Introduction and Scope
This Data Processing Agreement ("DPA") is entered into between DataDiwan (the "Processor") and the Customer (the "Controller") as defined in the Terms of Service.
This DPA supplements the Terms of Service and applies where DataDiwan processes personal data on behalf of the Customer in connection with the provision of DataDiwan OS (the "Service"). This DPA is made in accordance with Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).
By using the Service, the Customer agrees to the terms of this DPA. If the Customer does not agree, the Customer must not use the Service to process personal data.
2. Definitions
Terms used in this DPA shall have the meanings set forth in the GDPR. In addition:
- "Controller" means the Customer, who determines the purposes and means of the processing of personal data.
- "Processor" means DataDiwan, who processes personal data on behalf of the Controller.
- "Customer Data" means all personal data that the Controller uploads, inputs, or generates through the Service, including but not limited to lead information, client contact details, and business data.
- "Subprocessor" means any third party engaged by the Processor to process Customer Data.
- "Data Subject" means the identified or identifiable natural person to whom the personal data relates.
- "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
3. Details of Processing
3.1 Subject Matter
The processing concerns the operation of the DataDiwan OS platform, including AI-powered business automation tools (sales, delivery, finance, marketing, and business development agents).
3.2 Duration
The processing shall continue for the duration of the Customer's use of the Service, and for the periods specified in Section 10 (Data Retention and Return) thereafter.
3.3 Nature and Purpose of Processing
DataDiwan OS processes Customer Data to:
- Provide the SaaS platform and its features
- Operate AI agents on behalf of the Customer
- Store and retrieve Customer Data as instructed by the Customer
- Generate AI outputs (drafts, proposals, content) based on Customer instructions
- Provide customer support and service improvement
3.4 Types of Personal Data
The types of personal data processed may include:
- Contact information (names, email addresses, phone numbers)
- Professional information (job titles, company names, business roles)
- Communication content (emails, messages, notes, WhatsApp messages where integration is enabled)
- Usage data and interaction logs
- AI-generated outputs containing personal data
- Payment and billing information
3.5 Categories of Data Subjects
The categories of data subjects may include:
- The Customer's employees and authorized users
- The Customer's leads, prospects, and clients
- The Customer's business contacts
4. Processor's Obligations
4.1 Processing Instructions
The Processor shall process Customer Data only on documented instructions from the Controller, including with regard to transfers of personal data to third countries or international organizations, unless required to do so by Union or Member State law to which the Processor is subject.
The Controller's general instructions are set out in this DPA and the Terms of Service. Specific instructions may be given through the Service interface or in writing.
4.2 Confidentiality
The Processor shall ensure that persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.3 Security Measures
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data at rest (AES-256) and in transit (TLS 1.3)
- Row-level security (RLS) in PostgreSQL for tenant isolation
- Role-based access controls and OAuth 2.0 authentication
- Regular security assessments and dependency audits
- Incident response procedures
- Backup and disaster recovery measures
- Hash-chained audit logs (tamper-evident)
A detailed description of security measures is available upon request.
4.4 Subprocessors
The Processor may engage Subprocessors to process Customer Data, provided that:
- The Processor maintains an up-to-date list of Subprocessors at https://app.datadiwan.com/en/subprocessors
- The Processor notifies the Customer at least 30 days before adding a new Subprocessor
- The Customer has the right to object to a new Subprocessor on reasonable grounds within 14 days of notification
- If the Customer objects and the parties cannot resolve the issue within 14 days, the Customer may terminate the affected portion of the Service
- The Processor enters into a written agreement with each Subprocessor imposing data protection obligations substantially similar to those in this DPA
The current list of Subprocessors is set out in Annex A.
4.5 Data Subject Rights
The Processor shall assist the Controller in responding to requests from Data Subjects to exercise their rights under GDPR (access, rectification, erasure, restriction, data portability, objection). The Processor shall:
- Promptly notify the Controller of any such request received directly
- Provide the Controller with the necessary information and tools to respond
- Not respond to the Data Subject directly unless instructed by the Controller
4.6 Assistance to the Controller
The Processor shall assist the Controller in ensuring compliance with:
- The obligation to carry out data protection impact assessments (DPIA) where required
- The obligation to consult the supervisory authority prior to processing where required
- The obligation to maintain records of processing activities
4.7 Data Breach Notification
In the event of a Security Incident, the Processor shall:
- Notify the Controller without undue delay and in any case within 24 hours of becoming aware of the incident
- Provide the Controller with all information necessary to meet the Controller's obligation to notify the supervisory authority under GDPR Article 33
- Cooperate with the Controller in investigating and mitigating the incident
- Document all Security Incidents, including the facts, effects, and remedial actions taken
5. Controller's Obligations
The Controller warrants and undertakes that:
- It has a lawful basis for processing all Customer Data uploaded to the Service
- It has provided necessary privacy notices to Data Subjects
- It has obtained all required consents or authorizations
- Its instructions to the Processor comply with applicable data protection laws
- It will not upload special category data (GDPR Article 9) without explicit consent and adequate safeguards
- It will promptly notify the Processor of any changes to its processing instructions
6. International Data Transfers
6.1 General Principle
Customer Data is primarily stored and processed within the European Economic Area (EEA).
6.2 Transfers Outside the EEA
Where Customer Data is transferred outside the EEA (e.g., to LLM providers, payment processors, or authentication services in the USA), the Processor ensures appropriate safeguards are in place:
- EU Commission Standard Contractual Clauses (SCCs) for the transfer of personal data to processors established in third countries
- Additional technical and organizational measures as required by the SCCs
- Data minimization (only necessary data is transferred to LLM APIs)
- EU-region hosting for core infrastructure (database, cache, application hosting)
6.3 Data Subject Rights in Third Countries
The Processor shall ensure that Data Subjects can exercise their rights under GDPR with respect to processing in third countries, in accordance with the SCCs.
7. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA. Audits shall:
- Be conducted no more than once per calendar year, unless required by supervisory authority or following a Security Incident
- Be conducted with reasonable prior notice (at least 30 days)
- Be limited to verification of the Processor's compliance with this DPA
- Not unreasonably interfere with the Processor's business operations
- Be conducted at the Controller's expense, unless the audit reveals material non-compliance
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA.
8. Liability
8.1 Processor's Liability
The Processor shall be liable for damages caused by processing that infringes this DPA or the GDPR, to the extent required by GDPR Article 82.
8.2 Limitation
To the maximum extent permitted by Finnish law, the Processor's total liability under this DPA shall not exceed the total amount paid by the Controller to the Processor in the twelve (12) months preceding the claim.
8.3 Toiminimi Notice
DataDiwan operates as a sole proprietorship (toiminimi) under Finnish law. The proprietor has unlimited personal liability for business obligations under mandatory Finnish law. The liability limitations in this DPA apply to DataDiwan as the service provider and do not affect the proprietor's personal liability under mandatory law.
9. Term and Termination
9.1 Term
This DPA commences when the Customer starts using the Service and continues until the Terms of Service are terminated.
9.2 Effect of Termination
Upon termination of the Terms of Service:
- The Processor shall, at the Controller's choice, return or delete all Customer Data
- The Processor shall delete all copies of Customer Data unless storage is required by Union or Member State law
- The Processor shall certify the deletion to the Controller upon request
9.3 Data Retention After Termination
Notwithstanding Section 9.2, the Processor may retain Customer Data to the extent required by:
- Finnish accounting and tax laws (10 years)
- Other applicable legal obligations
- The need to establish, exercise, or defend legal claims
Any retained data shall be isolated, access-restricted, and processed only for the specific purpose of retention.
10. Governing Law and Dispute Resolution
This DPA is governed by the laws of Finland. Disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.
11. Changes to This DPA
We may update this DPA to reflect changes in law, our practices, or the Service. Material changes will be notified by email or in-app notice at least 30 days before taking effect. Continued use of the Service after the effective date constitutes acceptance.
12. Contact
For questions about this DPA, contact:
Email: info@datadiwan.com · support@datadiwan.com
Postal: DataDiwan, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland
Annex A — List of Subprocessors
Infrastructure & Hosting
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Fly.io, Inc. | Application hosting (API + Agent Worker) | EU (Amsterdam) | GDPR Art. 28 DPA, EU SCCs |
| Vercel, Inc. | Web application hosting (Dashboard) | EU (Frankfurt) | GDPR Art. 28 DPA, EU SCCs |
| Supabase, Inc. | PostgreSQL database, authentication, RLS | EU (Frankfurt) | GDPR Art. 28 DPA, EU SCCs |
| Upstash, Inc. | Redis cache, message queue, rate limiting | EU (Frankfurt) | GDPR Art. 28 DPA, EU-based |
Artificial Intelligence & Machine Learning
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google Cloud / Vertex AI | AI model inference (production) | EU + USA | Google Cloud DPA, EU SCCs, data minimization |
| Anthropic PBC | AI model inference (development only) | USA | EU SCCs, development isolation |
Payment Processing
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payment processing, billing | USA | Stripe DPA (incorporated), EU SCCs, PCI-DSS |
Communication & Authentication
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google LLC | Authentication (Google Sign-In) | USA | Google API DPA, EU SCCs |
| Meta Platforms, Inc. | WhatsApp Cloud API messaging | USA | Meta Business Tools DPA, EU SCCs |
Observability & Monitoring
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Langfuse GmbH | LLM tracing, observability | Germany (EU) | GDPR Art. 28 DPA, EU-based |
User-Connected Integrations (Not Subprocessors)
The following services are connected directly by the user to their own accounts. DataDiwan does not act as a processor for data stored in these services:
| Integration | Purpose | Controller |
|---|---|---|
| Gmail (Google LLC) | Email draft creation, send/receive metadata | The user |
| QuickBooks (Intuit Inc.) | Invoice sync, payment tracking | The user |
| Slack (Slack Technologies, LLC) | Notifications, alerts | The user |
| Google Calendar (Google LLC) | Event scheduling, availability | The user |