Agreements

Data Processing Agreement

On this page you can find our Data Processing Agreement, which you agree to comply with when ordering and using our services.

Annex to: The general terms of service ·

Annex to our general terms of service

This contract annex is an integral part of the general terms of service of Hostaan Oy (hereinafter the "Service Provider"). This annex and these data protection terms apply when the Service Provider acts, in relation to its Customer, as a processor of personal data within the meaning of the EU General Data Protection Regulation (2016/679), where the Customer, as data controller, has outsourced the processing of its personal data to the Service Provider. If there is a conflict between the general terms of service and these data protection terms, the general terms of service take precedence.

Definitions

Terms used in this contract annex, such as data controller, data subject, personal data, processing, processor, and personal data breach, carry the meaning given to them in Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Data Protection Regulation").

Purpose

The Service Provider is a company providing hosting services. The Customer is a company or other organization or operator that procures hosting services from the Service Provider. Under this data protection term, the parties agree that, for the duration of the Agreement, the Service Provider, as processor, processes personal data on behalf of the Customer, who is the data controller.

The processor processes personal data only to fulfil the hosting services and any other obligations described in the Agreement, and to provide and deliver the services to the Customer in accordance with the Customer's written instructions.

The processor does not process personal data for any other purpose or on behalf of any other party. The processor has the right to transfer personal data to countries outside the EU/EEA, in compliance with the appropriate safeguards defined in the Data Protection Regulation.

Requirements concerning the processing of personal data

The processing of personal data concerns the provision and delivery to the Customer of the Service Provider's services, such as web hosting space, server space, cloud services, email services, server software, domain names, and other similar hosting services.

Because the Customer alone decides what personal data is stored in the hosting service provided by the Service Provider, and the Service Provider has neither the obligation nor the practical means to check or verify this data, the Customer may, from a technical standpoint, store any data in the service that it considers necessary.

Subprocessors

The processor has the right to use the services of another processor when processing data. Hostaan Oy uses the following subprocessors:

Let's Encrypt / ISRG (United States) — issuing SSL certificates
Google Ireland Ltd (Ireland) — Google Workspace resale, Google Ads/Analytics
Meta Platforms, Inc. (United States) — Facebook advertising
Maventa Oy (Finland) — e-invoicing
Traficom (Finland) — domain registration and maintenance
Joker.com/CSL GmbH (Germany) — domain registration and maintenance
UpCloud Oy (Finland) — cloud infrastructure, virtual servers
Hetzner Online GmbH (Germany) — cloud infrastructure, virtual servers
Plesk International GmbH (Germany/Switzerland) — control panel software
Site.pro/UAB "B1.lt" (Lithuania) — website builder software
Apple Inc. (United States) — iCloud and workstation devices
Gallant Iisalmi Oy (Finland) — accounting
Visma Solutions Oy (Finland) — Netvisor financial management
Kravia Finland Oy (Finland) — debt collection

Confidentiality

Personal data processed on behalf of the data controller is treated as confidential information of the data controller, and the processor undertakes to keep the data confidential, not to disclose it to any third party, and not to use it for any purpose other than the agreed one.

Data security

The processor implements all appropriate technical and organizational measures aimed at preventing the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

Personal data breaches

In the event of a personal data breach, the processor must notify the data controller without undue delay, and must provide sufficient information and otherwise assist the data controller so that the data controller can fulfil the notification obligations set out in the Data Protection Regulation.

Audits of data protection practices and data subject rights

To demonstrate compliance with the obligations set out in the Data Protection Regulation, the processor must make available to the data controller all information the data controller needs for this purpose. The processor allows an audit to be carried out by the data controller or a party authorized by the data controller.

The processor must, reasonably and without undue delay, help the data controller, through appropriate technical and organizational measures, to fulfil the data controller's obligation to respond to the exercise of data subject rights as set out in the Data Protection Regulation.

See also