Skip to content
FI

Data Processing Agreement

Effective from 26 May 2026 · Version 1.0

This Data Processing Agreement under Article 28 of the EU General Data Protection Regulation is between Resaco Oy, Finnish business ID 3259870-5, the Processor, and the ResaHost customer, the Controller. It takes effect when the customer orders the service and forms part of the service agreement.

1. Purpose

The Processor processes personal data on behalf of the Controller to deliver ResaHost. This agreement defines the conditions for that processing as required by Article 28 GDPR.

2. Subject matter, duration, nature and purpose

  • Subject matter: personal data stored in the Controller's website, database, logs and backups within ResaHost.
  • Duration: the service agreement's term. Processing ends when that agreement ends and data has been returned or deleted.
  • Nature: hosting, including storage, backups, maintenance, security and support.
  • Purpose: delivery of the Controller's website and related services.

3. Personal data and data subjects

Processing typically covers the Controller's customer, user and contact information, including names, email addresses, telephone numbers, IP addresses and behavioural data. It also includes WordPress accounts and metadata, information collected through forms and, where applicable, ecommerce order data.

Data subjects are website visitors, customers and other people whose information the Controller processes.

4. Processor obligations

The Processor will:

  • Process personal data only on the Controller's documented instructions, unless otherwise required by law.
  • Ensure that people processing personal data are bound by confidentiality.
  • Apply technical and organisational security measures under Article 32, described in section 6.
  • Assist the Controller with data subject rights under Articles 12–22 and obligations under Articles 32–36.
  • Provide, on request, information the Controller needs to demonstrate compliance with GDPR.
  • Inform the Controller promptly if an instruction infringes GDPR or other data protection legislation.

5. Subprocessors

Resaco Oy uses subprocessors to fulfil this agreement. The customer may request the current list from [email protected]. New subprocessors are notified at least 14 days before the change.

6. Security measures

Area Measures
Encryption TLS 1.3 in transit; encrypted backups at rest
Access Mandatory two-factor authentication for administrators, role-based permissions and least privilege
Logging and monitoring Server and authentication logs; detection of unusual activity
Backups Daily automatic backups, 30-day retention and restoration tests
Updates WordPress core, PHP, the operating system and dependencies kept up to date
Separation Technical isolation between customers
Procedures Documented security incident handling processes

7. Personal data breach notification

The Processor will notify the Controller without undue delay and no later than 24 hours after becoming aware of a personal data breach.

The notice will contain at least the information required by Article 33(3): the nature of the breach, categories and approximate number of data subjects, the contact person's details, likely consequences and measures taken or proposed.

The Processor assists the Controller with notifications to supervisory authorities and data subjects under Articles 33–34.

8. Audit rights

The Controller may audit the Processor's personal data processing no more than once per calendar year. Audits take place remotely through document requests unless there is a justified reason to agree otherwise.

On request, the Processor provides documents describing security measures, certificates and third-party audit reports. The Controller bears the audit costs unless a material breach of the agreement is found.

9. Return and deletion

When the service agreement ends, the Processor returns all personal data to the Controller and deletes copies unless retention is required by law. Data is delivered in machine-readable form, such as SQL exports and files, encrypted where necessary.

Deletion takes place within 30 days after the service agreement ends. Final backup deletion follows the backup cycle and takes place within a maximum of 90 days.

10. Liability and governing law

Liability between the parties follows the general service conditions, except where this agreement provides otherwise. Finnish law and GDPR apply. Helsinki District Court is the competent court.

11. Changes

The Processor may update this agreement following changes to legislation or operations. The Controller receives at least 30 days' notice. For a justified reason, the Controller may terminate the service agreement before a change takes effect.

Questions: [email protected] or +358 40 5611 411. See also our privacy policy.

Cookie settings

The English website does not load optional analytics or marketing tags. There are no optional cookies to choose here.

Read our cookie information for details about necessary website functionality and external services.

Read the cookie information