(DPA)
Last updated: January 2026
This Data Processing Agreement (DPA) supplements our Terms of Service and describes how we process personal data on your behalf in accordance with Article 28 of the EU General Data Protection Regulation (GDPR).
This agreement is made between:
Data Controller ("Customer")
You or your company using the vaivatta. service
Data Processor
Innovategy Oy
Y-tunnus / Business ID: 3281265-2
PL 10, 15101 Lahti, Finland
We process personal data for the following purpose:
Hosting and managing open-source business software on the vaivatta. platform on behalf of the customer.
We process the following personal data on your behalf:
Note: We do not process special categories of personal data (sensitive data) without separate agreement.
Data processing may involve the following categories of data subjects:
We (Innovategy Oy) commit to:
We use the following subprocessors for personal data processing:
| Subprocessor | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server infrastructure, data storage | Finland, Germany | EU |
| Stripe, Inc. | Payment processing | Ireland (EU) | EU |
| Twilio Inc. (SendGrid) | Email delivery | EU | SCCs |
| Fathom Analytics | Website analytics | EU | EU |
SCCs = EU Standard Contractual Clauses. We will notify you of changes to the subprocessor list at least 14 days in advance.
Your personal data is primarily stored in Finland (Tuusula). Data is not transferred outside the EU/EEA without appropriate safeguards.
If transfer outside the EU/EEA is necessary (e.g., via a subprocessor), we ensure the transfer's legality through EU Standard Contractual Clauses (SCCs) or other GDPR-compliant safeguards.
We implement the following technical and organizational security measures:
For more details about our security measures, see our Security page.
If we detect a personal data breach, we will notify you without undue delay, no later than 48 hours after becoming aware of the breach. The notification will include:
You have the right to verify our compliance with this agreement. Audits are conducted:
Alternatively, we can provide you with a summary of our security measures and compliance status.
This DPA is effective for as long as you use the vaivatta. service. Upon termination:
This DPA takes effect automatically when you accept our Terms of Service and start using the vaivatta. service.
If you need a signed version for your records or company requirements, contact:
Email: [email protected]
We will send a signed DPA in PDF format upon request.
For questions about this DPA and data protection, contact:
Data Protection: [email protected]
Legal: [email protected]
This Data Processing Agreement complies with the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and follows the EU model contract for data processing.