{"id":2949,"date":"2022-03-17T13:33:05","date_gmt":"2022-03-17T11:33:05","guid":{"rendered":"https:\/\/www.lanetti.fi\/?page_id=2949"},"modified":"2024-08-12T12:06:51","modified_gmt":"2024-08-12T10:06:51","slug":"agreement-on-the-processing-of-personal-data","status":"publish","type":"page","link":"https:\/\/www.lanetti.fi\/en\/legal\/agreement-on-the-processing-of-personal-data\/","title":{"rendered":"AGREEMENT ON THE PROCESSING OF PERSONAL DATA"},"content":{"rendered":"<p>This agreement on the processing of personal data (\u201cAnnex\u201d) constitutes a part of the<br \/>\nGeneral contractual terms (\u201cAgreement\u201d) between Maximum Effort Ay (\u201cService<br \/>\nprovider\u201d)and the customer (\u201cCustomer\u201d).<\/p>\n<p><strong>1. Initial information<\/strong><br \/>\nThe purpose of this Annex is to agree on the obligations under the relevant personal data<br \/>\nregulations between the Service provider and the Customer. This Annex constitutes a written<br \/>\nagreement between the parties on the processing of personal data in accordance with the EU<br \/>\nGeneral Data Protection Regulation (679\/2016). The obligations and rights related to the EU<br \/>\nData Protection Regulation will not enter into force until the application of the EU General Data<br \/>\nProtection Regulation starts on May 25, 2018.<br \/>\nAccording to the Agreement, the Service provider provides the services (\u201cService\u201d), including, but<br \/>\nnot limited to, hosting services and\/or support services to the Customer. The service can be used<br \/>\nfor storing and\/or processing Personal data. This also applies to the Personal data of the<br \/>\nCustomer. The Customer acts as the Data controller with regards to the Personal data processed<br \/>\nin these Services. The Service provider acts as the processor for such Personal data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>2. Definition<\/strong><br \/>\nThe terms used within this Annex shall be applied according to the definitions specified in<br \/>\nthe Agreement. In addition, the following terms have a specific meaning in this Annex:<br \/>\n\u201cData controller\u201d refers to the Customer who determines the purpose and means of processing<br \/>\npersonal data.<br \/>\n\u201cRegulation\u201d refers to any national data protection law, the General Data Protection Regulation<br \/>\nof the EU (2016\/679, \u201cGDPR\u201d) from its date of application (May 25, 2018), and any future<br \/>\napplicable data protection legislation.<\/p>\n<p>\u201cModel contractual clauses\u201d refers to the standard contractual terms approved by the<br \/>\nEuropean Commission for the disclosure of personal data from EU Data controllers to<br \/>\nthird country processors (decision 2002\/16 EC).<\/p>\n<p>\u201cPersonal data\u201d refers to any information relating to an identified or identifiable natural person;<br \/>\nan identifiable natural person is a person who can be identified, directly or indirectly, in<br \/>\nparticular by means of identification data such as name, personal identification number,<br \/>\nlocation data, online identification or one or more characteristic physical, physiological, genetic,<br \/>\npsychological, economic, cultural or social factor.<\/p>\n<p>\u201cProcessor\u201d refers to the Service provider that processes personal data on behalf of the Customer.<br \/>\n\u201cProcessing\u201d refers to any activities in which Personal data is processed.<\/p>\n<p>\u201cSubcontractor\u201d refers to a processor that performs Processing in accordance with this Annex on<br \/>\nbehalf of the Service provider or Customer.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3. Responsibilities of the Service provider<\/strong><br \/>\nThe Service provider Processes the Personal data of the Customer on behalf of the Customer<br \/>\non the basis of the Agreement. The Service provider shall undertake to comply with the<br \/>\napplicable legislation, regulations and authorities\u2019 provisions and guidelines for the Processing of<br \/>\nPersonal data valid in Finland and the European Union and, if necessary, amend the provisions<br \/>\nof this Annex to comply with them.<\/p>\n<p>The Service provider does not specify the type of personal data stored by the Customer on the<br \/>\nService. The Service provider shall not be responsible for how such information is classified,<br \/>\nhow they are available or exchanged with other parties or otherwise Processed. The Service<br \/>\nprovider Processes the Personal data solely on behalf of the Customer, and only to the extent<br \/>\nand manner specified in the Agreement and Annex or as separately instructed by the Customer.<br \/>\nThe separate guidelines of the Customer shall be documented in connection with the order,<br \/>\nService description, support request or other written communication.<\/p>\n<p>If the Service provider has reasonable grounds to suspect that the guidelines provided by the<br \/>\nCustomer conflict (i) with the applicable laws or regulations, and\/or (ii) with the provisions of the<br \/>\nAgreement or this Annex, the Service provider shall inform the Customer of this without undue<br \/>\ndelay. The Service provider shall be entitled to postpone the implementation of the guidelines<br \/>\nuntil the Customer amends its guidelines or a separate agreement has been reached regarding<br \/>\nthe implementation between the Service provider and the Customer.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.1 Requests from Data subjects or authorities<\/strong><br \/>\nThe Service provider shall immediately inform the Customer about all requests from Data<br \/>\nsubjects or authorities regarding the revision, correction, deletion or Processing prohibition of the<br \/>\nPersonal data, or about other requests from Data subjects related to exercising the rights of the<br \/>\nData subject stipulated in current legislation and the EU General Data Protection regulation. The<br \/>\nCustomer shall be obliged to respond to these requests. Taking the nature of the Processing<br \/>\nactivity into account, the Service provider shall help the Customer with appropriate technical and<br \/>\norganisational measures, where possible, for fulfilling the Customer\u2019s obligation to respond to<br \/>\nthe requests of Data subjects.<\/p>\n<p>Taking the nature of the Processing of the Personal data and the data being accessible into<br \/>\naccount, the Service provider shall be obliged to assist the Customer in ensuring compliance<br \/>\nwith its statutory obligations. These obligations may include obligations relating to data security,<br \/>\nnotification of data security breaches, data security impact assessments and prior consultation.<br \/>\nThe Service provider shall be obliged to assist the Customer to the extent stipulated by the<br \/>\napplicable data protection law. Unless otherwise agreed, the Service provider shall be entitled to<br \/>\ninvoice the costs arising from the activities related to this section of the Annex in accordance<br \/>\nwith its current price list. In addition, the Service provider shall be given a reasonable time to<br \/>\nassist the Customer.<\/p>\n<p>The Service provider shall forward all inquiries from data protection authorities directly to the<br \/>\nCustomer, and the Service provider shall not have authority to represent the Customer or act<br \/>\non behalf of the Customer with the supervisory data protection authorities.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.2 Service provider and Regulatory compliance<\/strong><br \/>\nThe Service provider shall comply with the provisions applicable to its own activities and the<br \/>\nprovision of Services, privacy and security laws, as well as the obligations under this Annex.<br \/>\nHowever, the Service provider shall not be responsible for complying with the laws applicable<br \/>\nto the Customer or the industry of the Customer if that legislation is not generally applicable to<br \/>\ninformation technology providers. If required by law, the Service provider shall appoint a data<br \/>\nprotection officer who shall fulfil his or her duties in accordance with the applicable law.<\/p>\n<p>The information regarding the data protection officer shall be provided to the Customer upon<br \/>\nrequest. The Service provider shall maintain all necessary reports and, at the request of the<br \/>\nCustomer, make available all information necessary to demonstrate compliance with this<br \/>\nAnnex and the Legislation.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>4. Responsibilities of the Customer<\/strong><br \/>\nThe Customer shall undertake to comply with the applicable legislation, regulations and<br \/>\nauthorities\u2019 provisions and guidelines for the Processing of Personal data valid in Finland and the<br \/>\nEuropean Union and, if necessary, amend the provisions of this Annex to comply with them.<br \/>\nThe Customer shall be responsible for ensuring the necessary rights and consents to the<br \/>\nProcessing of Personal data under the Agreement. The Customer shall be responsible for the<br \/>\npreparation and availability of a privacy policy, and for informing the Data subjects and notifying<br \/>\ndata protection authorities.<br \/>\nThe Customer shall define the type of Personal data stored on the Services. The Customer<br \/>\nshall also determine how the Personal data is used, exchanged or otherwise Processed. The<br \/>\nCustomer shall be responsible for the integrity, security, maintenance and proper protection of<br \/>\nthe Personal data, as well as for ensuring that the Customer follows all applicable data<br \/>\nprotection, data security and security laws and provisions.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>5. Technical and organisational measures<\/strong><br \/>\nThe Service provider shall take appropriate technical and organisational measures to protect the<br \/>\nPersonal data of the Customer, taking into account the risks of the Processing, in particular<br \/>\nregarding the accidental or unlawful deletion, loss, modification, disclosure or access to<br \/>\ntransferred, stored or otherwise Processed Personal data. The implementation of security<br \/>\nmeasures shall take into account the available technical options and their costs in relation to the<br \/>\nspecific risks associated with the Processing, as well as the sensitivity of the Processed<br \/>\nPersonal data.<\/p>\n<p>The Customer shall be obliged to ensure that the Service provider is informed of all aspects<br \/>\nrelated to the Personal data provided by the Data controller, such as risk assessments and the<br \/>\nprocessing of special categories of persons who affect the technical and organisational<br \/>\nmeasures under this Annex. The Service provider shall ensure that the personnel of the Service<br \/>\nprovider or the subcontractor of the Service provider are bound by an appropriate confidentiality<br \/>\nobligation.<\/p>\n<p>The implemented data security measures are defined in the minimum data security<br \/>\nrequirements of the Service provider described in more detail on the website of the Service<br \/>\nprovider (www.domainhotelli.fi). The Customer shall be obliged to inform the Service provider of<br \/>\nany matters (including specific risks or categories of personal data) that require the definition<br \/>\nand agreement of additional technical or organisational security measures in the Agreement.<\/p>\n<p>The Customer shall be responsible for the implementation and maintenance of security<br \/>\nmeasures and other technical and organisational safeguards. The measures shall be<br \/>\nproportionate to the nature and quantity of Personal data stored and\/or otherwise Processed by<br \/>\nthe Customer. The Customer shall also be responsible for the personnel for whom the Customer<br \/>\nhas provided access to or usage rights to the Services. The Customer shall also be responsible<br \/>\nfor third parties having access to the Personal data or the Service, even if the Customer has not<br \/>\ntaken the necessary security measures, and they have not given permission to process the data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>6. Reporting a security breach<\/strong><br \/>\nThe Service provider shall inform the Customer of any breach of the Personal data without<br \/>\nundue delay after obtaining such information, or when the subcontractor of the Service provider<br \/>\nhas been informed of the breach. The Customer shall be responsible for the necessary<br \/>\nnotifications to the data protection authorities. The Customer shall also be responsible for<br \/>\nnotifying the Service provider accordingly of encountered security breaches.<\/p>\n<p>At the Customer\u2019s request, the Service provider shall, without undue delay, provide the<br \/>\nCustomer with all relevant information related to the breach. In so far as that information is<br \/>\navailable to the Service provider, the Service provider shall provide at least:<br \/>\n\u25cf a description of the security breach,<br \/>\n\u25cf a description of the likely consequences of the breach, and<br \/>\n\u25cf a description of the corrective measures that the Service provider has performed or will<br \/>\nperform to prevent such breaches in the future if the security breach has been caused<br \/>\nby the Service provider and, where appropriate, the measures for minimising the<br \/>\nadverse effects of a potential security breach.<br \/>\nThe Service provider shall document and forward the results of the report, as well as<br \/>\nthe measures taken, to the Customer.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>7. Audit<\/strong><br \/>\nThe Customer or an appointed auditor (not a competitor of the Service provider) shall be<br \/>\nentitled to audit the activities under this Annex. The parties agree on the time and other details<br \/>\nof the audit well in advance and no later than 14 working days before the audit. The audit shall<br \/>\nbe carried out in a manner that does not adversely affect the commitments of the Service<br \/>\nprovider and its subcontractors to third parties. The usual confidentiality agreements shall be<br \/>\nsigned by the representatives of the Customer and the auditor.<\/p>\n<p>The Customer shall be responsible for all costs of auditing. The Service provider shall have the<br \/>\nright to invoice the cost of the work performed in the audit to the Customer.<\/p>\n<p><strong>7. Subcontractors<\/strong><br \/>\nThe Service provider shall have the right to use subcontractors for Processing the Personal<br \/>\ndata of the Customer. The Service provider shall be responsible for the activities of the<br \/>\nsubcontractors, and prepare corresponding written agreements with the subcontractors on the<br \/>\nProcessing of Personal data. Upon request, the Service provider shall notify the Customer in<br \/>\nadvance of the subcontractors it intends to use for the Processing of Personal data under the<br \/>\nAgreement. The Customer shall have the right to object to the use of the new subcontractor for<br \/>\nlegitimate reasons. If the Customer does not oppose the addition or replacement of the<br \/>\nsubcontractor in writing, it shall be interpreted as accepting the replacement of that<br \/>\nsubcontractor. If the parties do not reach an agreement on the use of a new subcontractor, the<br \/>\nCustomer shall have the right to terminate the Agreement with a thirty (30) days\u2019 notice to the<br \/>\nextent that the subcontractor replacement affects the Processing of the Personal data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>8. Server centre location and data transfer<\/strong><br \/>\nThe server centres of the Service provider, where all personal data are stored and Processed,<br \/>\nare mainly located in Finland. However, the Service provider may transfer the Personal data to<br \/>\nany data centre located in the EU\/EEA, as well as data centres located outside the EU\/EEA, as<br \/>\ndescribed in the Service description or agreed in connection with the Agreement. The transfer of<br \/>\nPersonal data outside the EU\/EEA shall be governed by the Standard contractual clauses<br \/>\nattached to this Annex, or any other transfer mechanism permitted by the Legislation. The<br \/>\nStandard contractual clauses shall constitute a part of this Annex and supersede all the<br \/>\nprovisions of the Agreement or this Annex that are in contradiction.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>9. Other terms and conditions<\/strong><br \/>\nIf material or non-material damage is caused to a person due to an infringement of the EU data<br \/>\nprotection regulation, the Service provider shall be liable for the damage only to the extent that it<br \/>\nhas not expressly complied with the EU data protection regulation or the obligations of this Annex.<br \/>\nEither party shall be liable to pay the damages and administrative fines imposed only for the part<br \/>\ncorresponding to the liability for the damage established in the final decision of the data protection<br \/>\nsupervisory authority or the Court of Justice. In other respects, the parties\u2019 liability shall be defined<br \/>\nunder the Agreement.<\/p>\n<p>The Service provider shall inform the Customer in writing of any changes that may affect its<br \/>\nability or potential to comply with this Annex and the written instructions provided by the<br \/>\nCustomer. The parties shall agree on all additions and amendments to this Annex in writing.<\/p>\n<p>The Annex shall be valid (i) for as long as the Agreement is in force or (ii) the parties have<br \/>\nobligations to each other under the Personal data Processing activities.<\/p>\n<p>Obligations which, by their nature, are intended to remain in force irrespective of the<br \/>\nexpiry of this Annex shall remain in force after the expiry of the Annex.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#\">Download DPA<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This agreement on the processing of personal data (\u201cAnnex\u201d) constitutes a part of the General contractual terms (\u201cAgreement\u201d) between Maximum Effort Ay (\u201cService provider\u201d)and the customer (\u201cCustomer\u201d). 1. Initial information [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":2825,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"285","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"class_list":["post-2949","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/pages\/2949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/comments?post=2949"}],"version-history":[{"count":0,"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/pages\/2949\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/pages\/2825"}],"wp:attachment":[{"href":"https:\/\/www.lanetti.fi\/en\/wp-json\/wp\/v2\/media?parent=2949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}