Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) forms part of and supplements Luviamo's Terms of Service. It sets out the terms on which Luviamo processes personal data on behalf of the customer. A detailed description of what the service actually processes is in the Privacy Policy, which is an annex to this agreement.
1. Parties and roles
Processor: Innovasystems Oy (business ID 3639849-5), hereinafter “Luviamo”
Controller: the customer organization using the service
When the customer brings their own customer or contact data into the service — for example newsletter recipients in the Messaging module — the customer is the controller of that data and Luviamo is the processor. The customer is responsible for having a lawful basis for processing the data it imports and for sending communications to it.
Luviamo is an independent controller for the service's own user accounts and billing. Those are covered by our Privacy Policy, not by this agreement.
2. Subject matter, duration, nature and purpose
| Subject matter | Personal data the customer brings into the service, or that arises from use of the service on the customer's behalf |
| Duration | For the term of the customer relationship. Processing ends when the account is deleted, or when the subscription ends and the account is deleted in accordance with section 9 of the Privacy Policy |
| Nature and purpose | Marketing planning, content creation, publishing and analytics: storage, organisation, retrieval, use, transfer to selected channels, and deletion |
| Categories of personal data | Contact details (email address, name), subscription status and messaging event data (send, open, click, bounce); customer-supplied content to the extent it contains personal data |
| Categories of data subjects | The customer's newsletter subscribers and contacts; the customer's own users |
Special categories of personal data (GDPR Art. 9) are not intended to be processed in the service, and the customer should not bring such data into it.
3. Processing only on documented instructions
Luviamo processes personal data only on the customer's documented instructions. Use of the service together with this agreement constitutes those instructions: when the customer imports a list, creates a campaign or sends a message, they are giving a processing instruction.
If law requires Luviamo to process data otherwise, Luviamo will inform the customer before processing unless the law prohibits such notice. If Luviamo considers an instruction to infringe data protection law, it will inform the customer.
Luviamo does not sell customer data and does not use it for its own purposes, such as targeting its own marketing or training AI models.
4. Confidentiality
Access to personal data is limited to persons who need it to provide the service. They are bound by an obligation of confidentiality that continues after their engagement ends.
5. Security (GDPR Art. 32)
Luviamo implements technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS) and at rest; integration access tokens are additionally encrypted (AES-256-GCM)
- Per-organization isolation: every database query is scoped to the customer organization
- Role-based access control and optional two-factor authentication
- A security (audit) log of write operations, retained for 12 months
- A daily backup, encrypted before transfer and stored in a separate cloud within the EU
- Recurring code audits in which security and data protection are reviewed as separate areas
6. Subprocessors
The customer gives general authorisation for the use of subprocessors. The current list of subprocessors, their role, the data processed and their location is in section 7 of the Privacy Policy and is kept up to date.
Equivalent data protection obligations are in place with each subprocessor. Luviamo remains responsible for its subprocessors' performance as for its own.
The customer will be notified at least 30 days before a new subprocessor is added or an existing one is replaced. The customer may object on reasonable data protection grounds; if no resolution is found, the customer may terminate the service without penalty.
7. Data location and transfers
Application data and media files are stored within the EU. Some subprocessors operate outside the EU; those transfers are covered by the EU Standard Contractual Clauses (SCC) and, where needed, supplementary measures. Locations per provider are listed in sections 7 and 8 of the Privacy Policy.
8. Assistance with data subject rights
The service includes functions with which the customer can fulfil data subject rights directly: viewing and editing data, exporting it in a machine-readable format, and deleting it. Where the customer needs assistance beyond these, Luviamo will assist to a reasonable extent at no additional charge.
If a data subject contacts Luviamo directly about the customer's data, Luviamo will not respond on the merits but will refer the request to the customer.
9. Assistance with breaches and impact assessments
Luviamo will notify the customer of a personal data breach that comes to its attention without undue delay and provide the information the customer needs for its own notification obligations (GDPR Art. 33–34). Luviamo will also assist to a reasonable extent with data protection impact assessments and prior consultation (Art. 35–36).
10. Return and deletion of data
The customer may export their data at any time during the customer relationship. On termination of processing the data is deleted; deletions are not reversed from backups, and backup copies expire according to their own rotation (section 9 of the Privacy Policy). Data subject to a statutory retention obligation, such as accounting records, is retained for the period prescribed by law.
11. Audits
Luviamo makes available the information necessary to demonstrate compliance with the obligations set out in this agreement. This is primarily done through documentation: the Privacy Policy, this agreement, the subprocessor list and the description of security measures. The customer may carry out or mandate an audit at reasonable intervals and at a pre-agreed time, in a manner that does not compromise the security of other customers' data.
12. Term and changes
This agreement remains in force for as long as Luviamo processes personal data on the customer's behalf. In the event of a conflict, this agreement prevails over the Terms of Service on matters concerning the processing of personal data.
A new version of this agreement will be announced in the service and must be accepted before continued use. Earlier versions remain available under their version identifier.
13. Contact
Innovasystems Oy
Pilotinkatu 48, 33900 Tampere, Finland
Data protection: [email protected]