Data processing agreement

Data processing agreement (DPA)

The addendum governing the processing of personal data in the Sutja service under GDPR Article 28.

Updated 7 September 2026

1. Purpose and parties

This data processing agreement (DPA) forms part of the Sutja service terms and applies when Sutja processes personal data on the customer's behalf in providing the service.

The customer is the data controller and plops Oy (business ID 3596026-3) acts as the data processor. In case of conflict, this agreement prevails over other terms regarding the processing of personal data.

2. Definitions

In this agreement, controller, processor, personal data, processing, data subject and sub-processor have the same meaning as in the EU General Data Protection Regulation (GDPR, 2016/679).

3. Subject matter, duration, nature and purpose

Sutja processes personal data on the customer's behalf and only on the customer's documented instructions as described in section 4. The sole purpose of the processing is to provide the service: shift planning and human resources. Sutja does not determine the purposes or means of the processing and does not use the data for its own purposes.

  • Subject matter: the personal data the customer stores in the service
  • Duration: for the term of the service agreement and until the deletion schedule in section 12 has run its course
  • Nature and purpose: storing, organising, using and otherwise processing data to deliver the service's features
  • Data subjects: the customer's employees and users, and the emergency contact persons the employees provide
  • Data categories: name and contact details, employment and shift data, working hours and absences, skills data, the basis for payroll and reimbursements (personal identity code, date of birth, address, bank account number and emergency contacts), and technical data related to use of the service

Special categories of personal data: reasons for sickness absence and the medical certificates relating to them are health data within the meaning of GDPR Article 9. As controller, the customer is responsible for ensuring that a condition under Article 9(2) applies, which in an employment relationship is usually point (b), and that the processing meets the requirements of section 5 of the Finnish Act on the Protection of Privacy in Working Life (759/2004) on who in the employer's organisation may handle health data. Sutja applies the additional safeguards set out in Appendix 1 to this data.

Personal identity code: the service collects an employee's personal identity code for two purposes. The first is payroll and the employer's statutory obligations relating to it. The second is matching reimbursements: once the customer has enabled the accounting integration, the code is used to find the correct recipient in the financial system so that a travel expense claim is not assigned to a person with the same name. Section 29 of the Finnish Data Protection Act (1050/2018) permits processing where it is necessary for handling a matter concerning an employment or other service relationship and the benefits related to it, and where unambiguous identification of the data subject is important for performing a task laid down by law. Payroll and its statutory reports are such matters, and a name is not a unique identifier. As controller, the customer is responsible for ensuring the code is not collected for any other purpose. Sutja stores the code encrypted, shows it only to the employee, their management chain and administrators, and deletes it under the published retention schedule once the membership ends, and at the latest under section 12 when the agreement ends. The same applies to the bank account number.

4. Processing on documented instructions

Sutja processes personal data only on the customer's documented instructions, including this agreement and use of the service, and does not use the data for its own purposes. Sutja informs the customer if it considers an instruction to infringe data protection law.

The customer is responsible for ensuring there is a lawful basis for the processing and that its instructions comply with data protection law.

5. Confidentiality

Sutja ensures that persons processing personal data are bound by confidentiality and that access to the data is limited to those who need it for their tasks.

6. Security

Sutja implements appropriate technical and organisational measures under GDPR Article 32, taking into account the state of the art, the cost of implementation and the nature, scope, context and risks of the processing. The measures cover at least:

  • encryption of personal data in transit and at rest
  • ensuring the confidentiality, integrity, availability and resilience of processing systems
  • the ability to restore access to data after an incident
  • role-based access control on a least-privilege basis, and logging of access and changes
  • regular testing and assessment of the measures

How each of these is implemented in concrete terms is specified in Appendix 1, which forms part of this agreement. The appendix is not published on the website, because it describes the details of the safeguards in the service: Sutja provides it to the customer on request at tietosuoja@sutja.fi at no additional charge. Sutja may change individual measures as the service develops, but not so that the level of protection is reduced. Additional safeguards under Appendix 1 apply to sensitive data and to special categories of data. Security is also described in plain language on the GDPR page.

7. Sub-processors

The customer grants Sutja general authorisation to use sub-processors. Sutja has entered into agreements containing data protection obligations with each sub-processor and remains responsible for their performance as for its own.

An up-to-date list of sub-processors is on the GDPR page. Sutja notifies the customer of intended changes in advance, and the customer may object to a change on reasonable grounds.

8. Transfers outside the EU and EEA

Personal data is not transferred outside the EU or EEA. Data is stored and processed in Finland and the EU.

9. Assistance and data subject rights

Sutja assists the customer with appropriate technical and organisational measures so the customer can respond to data subjects' requests (access, rectification, erasure, portability, restriction and objection). The service settings include a GDPR section where a workspace administrator can see the retention periods and export the workspace's data as a compressed, machine-readable JSON file; the package stays available for 7 days. Attachments are not yet included in the export package; they are downloaded from the service separately. Deletion happens through the service's own functions (removing a member, deleting a workspace and deleting a user account), each of which starts the retention schedule described in this agreement and in the privacy policy.

If a data subject contacts Sutja directly, Sutja does not respond to the request itself but directs it to the customer. Sutja also informs the customer without undue delay of any supervisory authority inquiries concerning the customer's personal data.

Sutja further assists the customer with the obligations of GDPR Articles 32–36, such as security, data protection impact assessments (DPIA) and prior consultation.

Assistance under this section is included in the service fee to the extent it can be provided through the service's standard features and Sutja's existing documentation. This covers data export, the deletion functions, the retention schedule view, delivery of this agreement and its Appendix 1, and providing the information about the service needed for a data protection impact assessment (DPIA). Sutja does not charge an hourly fee for these.

If the customer requests exceptionally extensive separate work, such as a bespoke data extraction or participation in the customer's own audit or assessment project, the work and its price are agreed in writing in advance. Sutja may not refuse to assist on the ground that no price has been agreed, where the assistance is needed for the customer to meet a statutory deadline.

10. Data breaches

Sutja notifies the customer of a personal data breach without undue delay, and within 72 hours of becoming aware of it at the latest. The notification includes the essential information available, such as:

  • the nature of the breach and the categories and approximate number of data subjects affected
  • a contact point for more information
  • the likely consequences of the breach
  • the measures taken or proposed to address the breach and mitigate its effects

Sutja acts without delay to contain the breach, documents breaches, and assists the customer in meeting its notification obligations.

The initial notification is made as soon as the breach is confirmed, even if not all of the information listed above has yet been established, and it is supplemented in phases as the investigation progresses. Sutja does not delay the initial notification in order to wait for a complete picture. The customer's own 72-hour deadline for notifying the supervisory authority starts when the customer becomes aware of the breach, so the 72 hours stated in this section is an absolute outer limit for the notification, not a target.

11. Audits

Sutja provides the customer with the information necessary to demonstrate compliance with these obligations and allows audits conducted by the customer or an auditor mandated by the customer.

Sutja meets this obligation primarily by providing the description of measures in Appendix 1 together with the available security and audit reports. If these are not sufficient for the customer to demonstrate compliance, the customer has the right to carry out or commission an on-site audit.

The auditor must be bound by confidentiality and must not carry on business competing with Sutja. Audits are carried out on reasonable terms during normal working hours with at least 30 days' advance notice. An audit may not unnecessarily disturb the operation of the service, nor give access to other customers' data or to Sutja's trade secrets to the extent these are not needed to demonstrate the customer's compliance.

Audits are carried out no more than once a year as a rule. More frequent audits are possible if data protection law or a supervisory authority so requires, or if a material deficiency was found in the previous audit. Each party bears its own costs arising from an audit. For work exceeding one audit per year Sutja may charge a reasonable fee notified in advance, unless the audit arises from Sutja's breach of contract or a confirmed personal data breach, in which case Sutja bears its own costs.

12. End of processing

When the service agreement ends, Sutja, at the customer's choice, returns or deletes the personal data within 90 days and deletes existing copies, unless law requires the data to be retained.

Deleting a workspace ends access immediately, and the data is destroyed permanently after 60 days. As the last step of that destruction, the workspace's encryption key is destroyed, after which the fields and files encrypted with it can no longer be recovered. In backups taken before the deletion, unencrypted data remains until those backups have rotated out. Backups rotate on a cycle of approximately 30 days, so copies predating the deletion are removed within that cycle at the latest. Encrypted fields and files are unreadable in backups as soon as the key has been destroyed.

13. Liability and governing law

This agreement is governed by Finnish law. The parties' liability is determined by the service agreement. Disputes are primarily resolved through negotiation.

Join the waitlist

You're on the list!

Thanks! We've sent a confirmation to your inbox and will let you know the moment Sutja opens.

Sutja is opening soon. Leave your email and we'll let you know the moment you can get in.

Something went wrong. Please try again or email us at hello@sutja.fi.

By submitting you accept our privacy policy.