Cloop
Tuote
Verkkosivun ostajatAI-avustaja verkkosivun ostajille.Myynnin avustaminenOikea tieto myyjän seuraavaan siirtoon.Sovelluksen käyttäjäopastusOhjaa käyttäjää juuri oikeassa kohdassa.Asiakaspalvelun avustaminenLöydä oikea tieto ja ratkaise enemmän.
Hinnoittelu
Resurssit
BlogiAjatuksia B2B-myynnistä ja tekoälystä.VertailuMihin Cloop sopii — ja mihin ei.MuutoslokiUudet ominaisuudet ja korjaukset.
Yritys
Miksi rakennammeMiksi rakennamme Cloopia.UraAvoimet paikat Cloopilla.YhteysVaraa demo ja ota yhteyttä.
Varaa demo
Cloop

Käyttötapaukset

Verkkosivun ostajat AI-avustaja verkkosivun ostajille. Myynnin avustaminen Oikea tieto myyjän seuraavaan siirtoon. Sovelluksen käyttäjäopastus Ohjaa käyttäjää juuri oikeassa kohdassa. Asiakaspalvelun avustaminen Löydä oikea tieto ja ratkaise enemmän.
Hinnoittelu
Resurssit
Blogi Ajatuksia B2B-myynnistä ja tekoälystä. Vertailu Mihin Cloop sopii — ja mihin ei. Muutosloki Uudet ominaisuudet ja korjaukset.
Yritys
Miksi rakennamme Miksi rakennamme Cloopia. Ura Avoimet paikat Cloopilla. Yhteys Varaa demo ja ota yhteyttä.
Tietosuoja ja turvallisuus
Varaa demo
← Kaikki legal-dokumentit
GDPR · Artikla 28

Data Processing Agreement

Viimeksi päivitetty: 2.9.2026

This Data Processing Agreement ("DPA") forms part of the agreement between ROFFI Oy ("Cloop", "Processor") and the customer using Cloop Services ("Customer", "Controller").

This DPA applies where and to the extent that Cloop processes Personal Data on behalf of the Customer in connection with the provision of the Services or Professional Services.

This DPA enters into force at the same time as the service agreement between the Customer and Cloop.

If there is any conflict between this DPA and the Cloop Terms of Service regarding the processing of Personal Data, this DPA shall prevail.

1. Definitions

In this DPA:

Personal Data, Processing, Data Subject, Controller, Processor, Subprocessor, Personal Data Breach, and Supervisory Authority have the meanings given to them in Regulation (EU) 2016/679 ("GDPR").

Customer Personal Data means Personal Data processed by Cloop on behalf of the Customer in connection with the Services or Professional Services.

Services means the services defined in the Cloop Terms of Service.

Subprocessor means a third party engaged by Cloop to process Customer Personal Data on behalf of Cloop.

2. Roles of the Parties

2.1 Customer as Controller

The Customer acts as Controller to the extent that it determines the purposes and essential means of the Processing of Customer Personal Data.

The Customer is responsible in particular for:

  • the lawfulness of the Processing;
  • having an appropriate legal basis for the Processing;
  • providing required privacy information to Data Subjects;
  • obtaining consent where Processing is based on consent;
  • responding to and fulfilling Data Subject rights;
  • ensuring that instructions given to Cloop are lawful; and
  • ensuring that the Customer's use of the Services complies with applicable data protection law.

2.2 Cloop as Processor

Cloop processes Customer Personal Data solely on behalf of the Customer and in accordance with the Customer's documented instructions, including instructions arising from the Customer's configuration, use of features, integrations, settings, and other choices within the Services.

Cloop shall not process Customer Personal Data for purposes independent of the Customer's instructions unless such Processing is required by applicable European Union or Member State law.

Where Cloop is required by law to process Customer Personal Data otherwise than in accordance with the Customer's instructions, Cloop shall inform the Customer before such Processing unless prohibited from doing so by law.

If Cloop considers that an instruction from the Customer infringes the GDPR or other applicable data protection law, Cloop shall inform the Customer without undue delay.

2.3 Cloop as Independent Controller

This DPA does not apply to Processing where Cloop acts as an independent Controller.

Cloop may act as an independent Controller, for example, when Processing contact details of Customer representatives for billing, customer relationship management, security, compliance with legal obligations, or other purposes related to Cloop's own business operations.

Such Processing is governed by Cloop's Privacy Policy.

3. Subject Matter, Nature, Purpose and Duration of Processing

3.1 Subject Matter

The subject matter of the Processing is Customer Personal Data processed by Cloop on behalf of the Customer in order to provide the Services or Professional Services.

3.2 Nature and Purpose of Processing

Depending on the Services used by the Customer, Cloop may process Customer Personal Data by, for example:

  • receiving;
  • collecting;
  • recording;
  • storing;
  • organizing;
  • structuring;
  • retrieving;
  • combining;
  • analyzing;
  • classifying;
  • enriching;
  • displaying;
  • transmitting;
  • modifying;
  • using data in artificial intelligence functionality;
  • using data in automated workflows;
  • transferring data to integrations authorized by the Customer;
  • deleting; and
  • otherwise Processing Customer Personal Data as reasonably necessary to provide the Services.

The purpose of the Processing is to provide the Services and Professional Services ordered or used by the Customer.

3.3 Duration

Cloop processes Customer Personal Data for the duration of the applicable service agreement and for the post-termination retention and deletion period described in Section 12 of this DPA.

4. Categories of Data Subjects

Depending on the Customer's use of the Services, Customer Personal Data may relate to, for example:

  • the Customer's employees and other users;
  • the Customer's customers;
  • prospective customers;
  • contact persons;
  • users of websites or other digital services;
  • senders and recipients of communications;
  • business partners;
  • individuals whose Personal Data is stored in systems connected to the Services; and
  • other individuals whose Personal Data the Customer processes through the Services.

Not all categories necessarily apply to every Customer or use case.

5. Categories of Personal Data

Depending on the Customer's use of the Services, Customer Personal Data may include, for example:

  • names and contact details;
  • email addresses and other communication details;
  • company, role, position, and organizational information;
  • messages, conversations, and other communication content;
  • information obtained from systems or integrations connected by the Customer;
  • user account and access information;
  • technical identifiers;
  • session, event, and usage information;
  • behavioral and interaction data;
  • documents and other materials submitted by the Customer;
  • classifications, analyses, inferences, assessments, and metadata generated through the Services; and
  • other Personal Data submitted by the Customer or processed in accordance with the Customer's instructions.

The exact categories of Personal Data processed depend on the Services, features, integrations, and settings selected by the Customer.

6. Special Categories of Personal Data and Sensitive Information

The Services are not generally designed for the intentional collection or Processing of special categories of Personal Data under Article 9 GDPR or other highly sensitive Personal Data.

The Customer shall not intentionally configure the Services to collect or process such information unless:

  1. such Processing has been separately agreed in writing with Cloop;
  2. an appropriate legal basis exists for the Processing; and
  3. appropriate security and other safeguards have been agreed.

If a Data Subject voluntarily provides such information through the Services, Cloop shall process it on behalf of the Customer in accordance with this DPA.

7. Cloop's Obligations

7.1 Documented Instructions

Cloop shall process Customer Personal Data only in accordance with:

  • this DPA;
  • the Terms of Service;
  • the Services selected and used by the Customer;
  • settings and choices made by the Customer within the Services;
  • separately agreed Professional Services; and
  • other documented instructions provided by the Customer.

7.2 Confidentiality

Cloop shall ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations or an applicable statutory duty of confidentiality.

7.3 GDPR Compliance

Cloop shall comply with the obligations applicable to Processors under the GDPR and shall provide the Customer with information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.

7.4 Cooperation with Supervisory Authorities

Cloop shall cooperate with the competent Supervisory Authority to the extent required by applicable law.

8. Security

Cloop shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.

Such measures are intended in particular to protect Personal Data against:

  • unauthorized or unlawful Processing;
  • accidental or unlawful destruction;
  • loss;
  • alteration; and
  • unauthorized disclosure of or access to Personal Data.

Cloop's key technical and organizational security measures are described in Cloop's separate Security Overview.

Cloop may modify and improve its technical and organizational measures as the Services, technology, and security risks evolve, provided that the overall level of protection of Customer Personal Data is not materially reduced.

9. Subprocessors

9.1 General Authorization

The Customer grants Cloop general written authorization to engage Subprocessors in connection with the provision of the Services.

Cloop maintains an up-to-date list of Subprocessors in a separate Subprocessor List.

9.2 New Subprocessors

Cloop shall notify the Customer at least 30 days before engaging a new Subprocessor that will process Customer Personal Data.

Notification may be provided by email, through the Services, or by another agreed method.

The Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Cloop in writing before the end of the notice period.

The parties shall then use reasonable efforts to find a suitable solution.

If no commercially reasonable alternative is available, the Customer may terminate the part of the Services that necessarily requires the use of the relevant Subprocessor.

9.3 Subprocessor Obligations

Cloop shall enter into a written agreement with each Subprocessor imposing data protection obligations that are, in all material respects, no less protective than those contained in this DPA, to the extent required by applicable law.

Cloop remains responsible for the Processing performed by its Subprocessors in accordance with applicable law and the Cloop Terms of Service.

10. Data Subject Rights

Taking into account the nature of the Processing, Cloop shall provide reasonable assistance to the Customer through appropriate technical and organizational measures to enable the Customer to fulfill its obligations under Chapter III of the GDPR.

If Cloop receives a request directly from a Data Subject concerning Customer Personal Data, Cloop shall:

  • notify the Customer without undue delay; and
  • not respond on behalf of the Customer unless instructed to do so by the Customer or required by law.

The Services may provide functionality allowing the Customer to search, access, export, rectify, or delete Customer Personal Data.

11. Personal Data Breaches

If Cloop becomes aware of a Personal Data Breach affecting Customer Personal Data, Cloop shall notify the Customer without undue delay and shall seek to provide such notification in any event within 48 hours after becoming aware of the Personal Data Breach.

Based on information reasonably available to Cloop, the notification shall include, where possible:

  • the nature of the Personal Data Breach;
  • the categories and approximate number of affected Data Subjects;
  • the categories and approximate number of affected Personal Data records;
  • the likely consequences of the Personal Data Breach; and
  • measures taken or proposed by Cloop to address and mitigate the effects of the Personal Data Breach.

Where all information cannot be provided at the same time, Cloop may provide the information in phases as it becomes available.

Cloop shall reasonably cooperate with the Customer in investigating the Personal Data Breach and mitigating its effects.

12. Return and Deletion of Personal Data

12.1 During the Agreement

The Customer may use available functionality within the Services to access, export, modify, or delete Customer Personal Data.

12.2 Upon Termination

Upon termination of the Services, Cloop shall, at the Customer's choice, delete or return Customer Personal Data to the Customer, unless applicable European Union or Member State law requires continued retention.

Any request for return of Customer Personal Data should be made before termination of the service agreement or during any post-termination export period made available by Cloop.

Unless otherwise agreed:

  • Customer Personal Data shall be deleted from active systems within 30 days after termination; and
  • copies remaining in routine backups, if any, shall be deleted in accordance with the ordinary backup rotation cycle and in any event within 90 days after termination.

Personal Data stored in backups shall remain protected under this DPA and shall not be restored to production systems except where technically necessary as part of a legitimate restoration process.

12.3 Legal Retention

If Cloop is legally required to retain certain Customer Personal Data beyond the periods described above, Cloop shall restrict Processing to the purposes required by law and inform the Customer of such retention unless prohibited from doing so by law.

13. Assistance with GDPR Obligations

Taking into account the nature of the Processing and the information available to Cloop, Cloop shall provide reasonable assistance to the Customer in fulfilling its obligations under Articles 32–36 GDPR, including in relation to:

  • security of Processing;
  • Personal Data Breaches;
  • data protection impact assessments (DPIAs); and
  • prior consultation with a competent Supervisory Authority where required.

Where a request for assistance requires substantial Professional Services beyond the ordinary Services or Cloop's statutory obligations as Processor, the parties may agree on reasonable additional fees for such work.

14. Audits and Demonstration of Compliance

Cloop shall provide the Customer with information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.

Cloop may satisfy such requests in the first instance by providing, where available:

  • security documentation;
  • independent assessments or audit reports;
  • compliance documentation; or
  • written responses to reasonable compliance questionnaires.

The Customer or an independent auditor appointed by the Customer may carry out an audit, including an inspection, where required under the GDPR, subject to the following conditions:

  • reasonable advance notice shall be provided to Cloop;
  • the audit shall be conducted during normal business hours;
  • the audit shall not unreasonably interfere with Cloop's operations or those of other customers;
  • the auditor shall be subject to appropriate confidentiality obligations;
  • the audit shall be limited to Processing relevant to this DPA; and
  • the Customer shall bear its own audit-related costs.

Audits shall ordinarily be limited to once in any twelve (12) month period.

This limitation shall not apply where:

  • an audit is required by a competent Supervisory Authority;
  • a significant Personal Data Breach affecting Customer Personal Data has occurred; or
  • the Customer has another reasonable basis to suspect a material breach of this DPA by Cloop.

15. International Data Transfers

Cloop seeks to use solutions that process Customer Personal Data within the European Economic Area ("EEA") where reasonably appropriate for the provision of the Services.

The Subprocessors used from time to time and their relevant Processing locations are identified in the Cloop Subprocessor List.

Cloop shall not transfer Customer Personal Data outside the EEA except in accordance with the Customer's documented authorization and Chapter V of the GDPR.

Where a transfer outside the EEA is required for the provision of the Services, Cloop shall ensure that an appropriate transfer mechanism is in place before the transfer, such as:

  • an adequacy decision of the European Commission;
  • applicable Standard Contractual Clauses adopted by the European Commission; or
  • another transfer mechanism permitted under the GDPR.

Where required by applicable law, Cloop shall carry out appropriate transfer risk assessments and implement supplementary safeguards.

16. Artificial Intelligence Processing

The Services may use artificial intelligence models and AI service providers to process Customer Personal Data where necessary to provide functionality selected or used by the Customer.

AI service providers that process Customer Personal Data on behalf of Cloop shall be treated as Subprocessors under this DPA and listed in the Cloop Subprocessor List.

Cloop shall not, without the Customer's explicit written authorization, use Customer Personal Data to train general-purpose artificial intelligence models for the benefit of other Cloop customers or third parties.

Cloop shall seek to limit Customer Personal Data disclosed to AI service providers to the information reasonably necessary to provide the relevant functionality.

The specific technical implementation, AI technologies, providers, and Processing locations may change as the Services evolve, subject to this DPA and the Subprocessor notification process.

17. Liability

The contractual liability of the parties arising under this DPA shall be subject to the limitations of liability set out in the Cloop Terms of Service, except where otherwise required by this DPA or mandatory applicable law.

Nothing in this DPA limits:

  • the rights of Data Subjects under the GDPR;
  • the statutory powers of a Supervisory Authority; or
  • either party's liability for violations of the GDPR for which that party is directly responsible under applicable law.

Each party remains responsible for administrative fines or penalties imposed directly on that party by a Supervisory Authority to the extent that such liability cannot lawfully be transferred to the other party.

18. Term and Termination

This DPA shall remain in effect for as long as Cloop processes Customer Personal Data on behalf of the Customer.

Obligations relating to confidentiality, security, return, and deletion of Customer Personal Data shall survive termination of the service agreement to the extent necessary until Cloop has completed its Processing of Customer Personal Data.

19. Governing Law and Dispute Resolution

This DPA is governed by the laws of Finland.

Any disputes arising out of or relating to this DPA shall be resolved in accordance with the dispute resolution provisions of the Cloop Terms of Service.

20. Contact Details

ROFFI Oy / Cloop
Business ID: 3500046-5
Finland

Data protection inquiries:
privacy@cloop.io

Security inquiries:
security@cloop.io

Competent Supervisory Authority in Finland:
Office of the Data Protection Ombudsman
https://tietosuoja.fi/en

Annex 1 – Details of Processing

Subject matter of Processing:
Personal Data made available to Cloop by or on behalf of the Customer in connection with the Services or Professional Services.

Purpose of Processing:
Provision of the Services and Professional Services ordered or used by the Customer.

Nature of Processing:
Receiving, collecting, recording, storing, organizing, structuring, retrieving, combining, analyzing, classifying, modifying, displaying, transmitting, AI-assisted Processing, automated Processing, deleting, and other Processing activities reasonably necessary to provide the Services.

Duration of Processing:
The duration of the service agreement and the post-termination deletion and retention periods described in Section 12.

Categories of Personal Data:
The categories described in Section 5, depending on the Services used by the Customer.

Categories of Data Subjects:
The categories described in Section 4, depending on the Services used by the Customer.

Annex 2 – Technical and Organizational Measures

Cloop maintains an up-to-date description of the technical and organizational measures used to protect Personal Data in a separate Security Overview.

Such measures may include, as appropriate:

  • encryption of data in transit;
  • logical separation of data and access;
  • identity and access management;
  • authentication and authorization controls;
  • database and application-level security measures;
  • input validation and application security controls;
  • network and infrastructure protection;
  • logging and monitoring;
  • abuse prevention controls;
  • vulnerability management;
  • incident response procedures;
  • restrictions on personnel access;
  • backup and recovery procedures, where applicable; and
  • other technical and organizational measures appropriate to the risks associated with the Processing.

Kysyttävää tästä dokumentista? Vastaamme 48 tunnin sisällä, suoraan Tapiolta. tapio@cloop.io

Cloop

Cloop valmistelee, myyjä tekee päätöksen.

Ratkaisu
  • Verkkosivun ostajat
  • Myynnin avustaminen
  • Sovelluksen käyttäjäopastus
  • Asiakaspalvelun avustaminen
  • Käyttöönotto
  • Integraatiot
  • Kirjaudu
Resurssit
  • Blogi
  • Vertailu
  • Muutosloki
  • Hinnoittelu
Yritys
  • Miksi rakennamme
  • Ura
  • Yhteys
Sopimukset ja tietosuoja
  • Tietosuoja ja turvallisuus
  • Kaikki dokumentit
  • Tietojenkäsittelysopimus (DPA)
  • Tietosuojaseloste
  • Käyttöehdot
  • Evästeet
  • Alihankkijat
  • Turvallisuuskuvaus
Cloop on ROFFI Oy:n tuote · Y-tunnus 3500046-5 · Helsinki · Rakennettu Euroopassa Tietosuoja Evästeet Käyttöehdot Kaikki dokumentit