Data Processing Agreement
Effective from 26 May 2026 · Version 1.0
This Data Processing Agreement under Article 28 of the EU General Data Protection Regulation is between Resaco Oy, Finnish business ID 3259870-5, the Processor, and the ResaHost customer, the Controller. It takes effect when the customer orders the service and forms part of the service agreement.
1. Purpose
The Processor processes personal data on behalf of the Controller to deliver ResaHost. This agreement defines the conditions for that processing as required by Article 28 GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter: personal data stored in the Controller's website, database, logs and backups within ResaHost.
- Duration: the service agreement's term. Processing ends when that agreement ends and data has been returned or deleted.
- Nature: hosting, including storage, backups, maintenance, security and support.
- Purpose: delivery of the Controller's website and related services.
3. Personal data and data subjects
Processing typically covers the Controller's customer, user and contact information, including names, email addresses, telephone numbers, IP addresses and behavioural data. It also includes WordPress accounts and metadata, information collected through forms and, where applicable, ecommerce order data.
Data subjects are website visitors, customers and other people whose information the Controller processes.
4. Processor obligations
The Processor will:
- Process personal data only on the Controller's documented instructions, unless otherwise required by law.
- Ensure that people processing personal data are bound by confidentiality.
- Apply technical and organisational security measures under Article 32, described in section 6.
- Assist the Controller with data subject rights under Articles 12–22 and obligations under Articles 32–36.
- Provide, on request, information the Controller needs to demonstrate compliance with GDPR.
- Inform the Controller promptly if an instruction infringes GDPR or other data protection legislation.
5. Subprocessors
Resaco Oy uses subprocessors to fulfil this agreement. The customer may request the current list from [email protected]. New subprocessors are notified at least 14 days before the change.
6. Security measures
| Area | Measures |
|---|---|
| Encryption | TLS 1.3 in transit; encrypted backups at rest |
| Access | Mandatory two-factor authentication for administrators, role-based permissions and least privilege |
| Logging and monitoring | Server and authentication logs; detection of unusual activity |
| Backups | Daily automatic backups, 30-day retention and restoration tests |
| Updates | WordPress core, PHP, the operating system and dependencies kept up to date |
| Separation | Technical isolation between customers |
| Procedures | Documented security incident handling processes |
7. Personal data breach notification
The Processor will notify the Controller without undue delay and no later than 24 hours after becoming aware of a personal data breach.
The notice will contain at least the information required by Article 33(3): the nature of the breach, categories and approximate number of data subjects, the contact person's details, likely consequences and measures taken or proposed.
The Processor assists the Controller with notifications to supervisory authorities and data subjects under Articles 33–34.
8. Audit rights
The Controller may audit the Processor's personal data processing no more than once per calendar year. Audits take place remotely through document requests unless there is a justified reason to agree otherwise.
On request, the Processor provides documents describing security measures, certificates and third-party audit reports. The Controller bears the audit costs unless a material breach of the agreement is found.
9. Return and deletion
When the service agreement ends, the Processor returns all personal data to the Controller and deletes copies unless retention is required by law. Data is delivered in machine-readable form, such as SQL exports and files, encrypted where necessary.
Deletion takes place within 30 days after the service agreement ends. Final backup deletion follows the backup cycle and takes place within a maximum of 90 days.
10. Liability and governing law
Liability between the parties follows the general service conditions, except where this agreement provides otherwise. Finnish law and GDPR apply. Helsinki District Court is the competent court.
11. Changes
The Processor may update this agreement following changes to legislation or operations. The Controller receives at least 30 days' notice. For a justified reason, the Controller may terminate the service agreement before a change takes effect.
Questions: [email protected] or +358 40 5611 411. See also our privacy policy.