اتفاقية معالجة البيانات

DataDiwan OS — GDPR Article 28 Processor Agreement

Last updated: 30 July 2026

Effective date: 30 July 2026

Processor: DataDiwan, Y-tunnus 3641767-6, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland

Contact: info@datadiwan.com · support@datadiwan.com

Supervisory Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), PL 800, 00531 Helsinki


1. Introduction and Scope

This Data Processing Agreement ("DPA") is entered into between DataDiwan (the "Processor") and the Customer (the "Controller") as defined in the Terms of Service.

This DPA supplements the Terms of Service and applies where DataDiwan processes personal data on behalf of the Customer in connection with the provision of DataDiwan OS (the "Service"). This DPA is made in accordance with Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).

By using the Service, the Customer agrees to the terms of this DPA. If the Customer does not agree, the Customer must not use the Service to process personal data.


2. Definitions

Terms used in this DPA shall have the meanings set forth in the GDPR. In addition:

  • "Controller" means the Customer, who determines the purposes and means of the processing of personal data.
  • "Processor" means DataDiwan, who processes personal data on behalf of the Controller.
  • "Customer Data" means all personal data that the Controller uploads, inputs, or generates through the Service, including but not limited to lead information, client contact details, and business data.
  • "Subprocessor" means any third party engaged by the Processor to process Customer Data.
  • "Data Subject" means the identified or identifiable natural person to whom the personal data relates.
  • "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.

3. Details of Processing

3.1 Subject Matter

The processing concerns the operation of the DataDiwan OS platform, including AI-powered business automation tools (sales, delivery, finance, marketing, and business development agents).

3.2 Duration

The processing shall continue for the duration of the Customer's use of the Service, and for the periods specified in Section 10 (Data Retention and Return) thereafter.

3.3 Nature and Purpose of Processing

DataDiwan OS processes Customer Data to:

  • Provide the SaaS platform and its features
  • Operate AI agents on behalf of the Customer
  • Store and retrieve Customer Data as instructed by the Customer
  • Generate AI outputs (drafts, proposals, content) based on Customer instructions
  • Provide customer support and service improvement

3.4 Types of Personal Data

The types of personal data processed may include:

  • Contact information (names, email addresses, phone numbers)
  • Professional information (job titles, company names, business roles)
  • Communication content (emails, messages, notes, WhatsApp messages where integration is enabled)
  • Usage data and interaction logs
  • AI-generated outputs containing personal data
  • Payment and billing information

3.5 Categories of Data Subjects

The categories of data subjects may include:

  • The Customer's employees and authorized users
  • The Customer's leads, prospects, and clients
  • The Customer's business contacts

4. Processor's Obligations

4.1 Processing Instructions

The Processor shall process Customer Data only on documented instructions from the Controller, including with regard to transfers of personal data to third countries or international organizations, unless required to do so by Union or Member State law to which the Processor is subject.

The Controller's general instructions are set out in this DPA and the Terms of Service. Specific instructions may be given through the Service interface or in writing.

4.2 Confidentiality

The Processor shall ensure that persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3 Security Measures

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data at rest (AES-256) and in transit (TLS 1.3)
  • Row-level security (RLS) in PostgreSQL for tenant isolation
  • Role-based access controls and OAuth 2.0 authentication
  • Regular security assessments and dependency audits
  • Incident response procedures
  • Backup and disaster recovery measures
  • Hash-chained audit logs (tamper-evident)

A detailed description of security measures is available upon request.

4.4 Subprocessors

The Processor may engage Subprocessors to process Customer Data, provided that:

  • The Processor maintains an up-to-date list of Subprocessors at https://app.datadiwan.com/en/subprocessors
  • The Processor notifies the Customer at least 30 days before adding a new Subprocessor
  • The Customer has the right to object to a new Subprocessor on reasonable grounds within 14 days of notification
  • If the Customer objects and the parties cannot resolve the issue within 14 days, the Customer may terminate the affected portion of the Service
  • The Processor enters into a written agreement with each Subprocessor imposing data protection obligations substantially similar to those in this DPA

The current list of Subprocessors is set out in Annex A.

4.5 Data Subject Rights

The Processor shall assist the Controller in responding to requests from Data Subjects to exercise their rights under GDPR (access, rectification, erasure, restriction, data portability, objection). The Processor shall:

  • Promptly notify the Controller of any such request received directly
  • Provide the Controller with the necessary information and tools to respond
  • Not respond to the Data Subject directly unless instructed by the Controller

4.6 Assistance to the Controller

The Processor shall assist the Controller in ensuring compliance with:

  • The obligation to carry out data protection impact assessments (DPIA) where required
  • The obligation to consult the supervisory authority prior to processing where required
  • The obligation to maintain records of processing activities

4.7 Data Breach Notification

In the event of a Security Incident, the Processor shall:

  • Notify the Controller without undue delay and in any case within 24 hours of becoming aware of the incident
  • Provide the Controller with all information necessary to meet the Controller's obligation to notify the supervisory authority under GDPR Article 33
  • Cooperate with the Controller in investigating and mitigating the incident
  • Document all Security Incidents, including the facts, effects, and remedial actions taken

5. Controller's Obligations

The Controller warrants and undertakes that:

  • It has a lawful basis for processing all Customer Data uploaded to the Service
  • It has provided necessary privacy notices to Data Subjects
  • It has obtained all required consents or authorizations
  • Its instructions to the Processor comply with applicable data protection laws
  • It will not upload special category data (GDPR Article 9) without explicit consent and adequate safeguards
  • It will promptly notify the Processor of any changes to its processing instructions

6. International Data Transfers

6.1 General Principle

Customer Data is primarily stored and processed within the European Economic Area (EEA).

6.2 Transfers Outside the EEA

Where Customer Data is transferred outside the EEA (e.g., to LLM providers, payment processors, or authentication services in the USA), the Processor ensures appropriate safeguards are in place:

  • EU Commission Standard Contractual Clauses (SCCs) for the transfer of personal data to processors established in third countries
  • Additional technical and organizational measures as required by the SCCs
  • Data minimization (only necessary data is transferred to LLM APIs)
  • EU-region hosting for core infrastructure (database, cache, application hosting)

6.3 Data Subject Rights in Third Countries

The Processor shall ensure that Data Subjects can exercise their rights under GDPR with respect to processing in third countries, in accordance with the SCCs.


7. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA. Audits shall:

  • Be conducted no more than once per calendar year, unless required by supervisory authority or following a Security Incident
  • Be conducted with reasonable prior notice (at least 30 days)
  • Be limited to verification of the Processor's compliance with this DPA
  • Not unreasonably interfere with the Processor's business operations
  • Be conducted at the Controller's expense, unless the audit reveals material non-compliance

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA.


8. Liability

8.1 Processor's Liability

The Processor shall be liable for damages caused by processing that infringes this DPA or the GDPR, to the extent required by GDPR Article 82.

8.2 Limitation

To the maximum extent permitted by Finnish law, the Processor's total liability under this DPA shall not exceed the total amount paid by the Controller to the Processor in the twelve (12) months preceding the claim.

8.3 Toiminimi Notice

DataDiwan operates as a sole proprietorship (toiminimi) under Finnish law. The proprietor has unlimited personal liability for business obligations under mandatory Finnish law. The liability limitations in this DPA apply to DataDiwan as the service provider and do not affect the proprietor's personal liability under mandatory law.


9. Term and Termination

9.1 Term

This DPA commences when the Customer starts using the Service and continues until the Terms of Service are terminated.

9.2 Effect of Termination

Upon termination of the Terms of Service:

  • The Processor shall, at the Controller's choice, return or delete all Customer Data
  • The Processor shall delete all copies of Customer Data unless storage is required by Union or Member State law
  • The Processor shall certify the deletion to the Controller upon request

9.3 Data Retention After Termination

Notwithstanding Section 9.2, the Processor may retain Customer Data to the extent required by:

  • Finnish accounting and tax laws (10 years)
  • Other applicable legal obligations
  • The need to establish, exercise, or defend legal claims

Any retained data shall be isolated, access-restricted, and processed only for the specific purpose of retention.


10. Governing Law and Dispute Resolution

This DPA is governed by the laws of Finland. Disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.


11. Changes to This DPA

We may update this DPA to reflect changes in law, our practices, or the Service. Material changes will be notified by email or in-app notice at least 30 days before taking effect. Continued use of the Service after the effective date constitutes acceptance.


12. Contact

For questions about this DPA, contact:

Email: info@datadiwan.com · support@datadiwan.com

Postal: DataDiwan, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland


Annex A — List of Subprocessors

Infrastructure & Hosting

SubprocessorPurposeLocationSafeguards
Fly.io, Inc.Application hosting (API + Agent Worker)EU (Amsterdam)GDPR Art. 28 DPA, EU SCCs
Vercel, Inc.Web application hosting (Dashboard)EU (Frankfurt)GDPR Art. 28 DPA, EU SCCs
Supabase, Inc.PostgreSQL database, authentication, RLSEU (Frankfurt)GDPR Art. 28 DPA, EU SCCs
Upstash, Inc.Redis cache, message queue, rate limitingEU (Frankfurt)GDPR Art. 28 DPA, EU-based

Artificial Intelligence & Machine Learning

SubprocessorPurposeLocationSafeguards
Google Cloud / Vertex AIAI model inference (production)EU + USAGoogle Cloud DPA, EU SCCs, data minimization
Anthropic PBCAI model inference (development only)USAEU SCCs, development isolation

Payment Processing

SubprocessorPurposeLocationSafeguards
Stripe, Inc.Payment processing, billingUSAStripe DPA (incorporated), EU SCCs, PCI-DSS

Communication & Authentication

SubprocessorPurposeLocationSafeguards
Google LLCAuthentication (Google Sign-In)USAGoogle API DPA, EU SCCs
Meta Platforms, Inc.WhatsApp Cloud API messagingUSAMeta Business Tools DPA, EU SCCs

Observability & Monitoring

SubprocessorPurposeLocationSafeguards
Langfuse GmbHLLM tracing, observabilityGermany (EU)GDPR Art. 28 DPA, EU-based

User-Connected Integrations (Not Subprocessors)

The following services are connected directly by the user to their own accounts. DataDiwan does not act as a processor for data stored in these services:

IntegrationPurposeController
Gmail (Google LLC)Email draft creation, send/receive metadataThe user
QuickBooks (Intuit Inc.)Invoice sync, payment trackingThe user
Slack (Slack Technologies, LLC)Notifications, alertsThe user
Google Calendar (Google LLC)Event scheduling, availabilityThe user
نظام داتاديوان