Data Processing Agreement
Published 3 October 2026. Effective immediately for new business customers, and on 1 November 2026 for business customers whose accounts existed before 3 October 2026.
This Data Processing Agreement (“DPA”) applies when a business customer uses Clouden’s services to process personal data. It sets out the terms required by article 28 of the GDPR. It forms part of our Terms of Service, so you don’t need to sign it separately. If you need a signed copy for your records, email info@clouden.net.
Key Terms
| Provider | Clouden Oy (business ID 2760188-5), Kotikaivontie 2E, 00700 Helsinki, Finland, info@clouden.net |
| Customer | The business customer, as defined in the Terms of Service, that uses the Cloud Service |
| Agreement | Clouden’s Terms of Service, as accepted by Customer |
| DPA Effective Date | The date when Customer accepts the Terms of Service, or 1 November 2026 for Customers whose accounts existed before 3 October 2026 |
| Subprocessor List | clouden.net/legal/subprocessors |
| Notice of new Subprocessors | Email to the email address of Customer’s account, and an update to the Subprocessor List |
| Means of access, return and deletion | The export, editing and deletion features of the Cloud Service, or a request to info@clouden.net |
1. Definitions
1.1. “Agreement”, “DPA Effective Date” and “Subprocessor List” have the meanings given in the Key Terms.
1.2. “Audit” and “Audit Parameters” are defined in Section 9.3 below.
1.3. “Audit Report” is defined in Section 9.2 below.
1.4. “Cloud Service” means the Services, as defined in the Agreement, that Customer uses.
1.5. “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.
1.6. “Customer Data” means Your Content, as defined in the Agreement, that Customer or its users put into the Cloud Service.
1.7. “Customer Instructions” is defined in Section 3.1 below.
1.8. “Customer Personal Data” means Personal Data in Customer Data.
1.9. “Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the Finnish Data Protection Act (1050/2018), in each case as amended or replaced from time to time.
1.10. “Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.
1.11. “EEA” means the European Economic Area.
1.12. “Personal Data” means information about an identified or identifiable natural person, or information that otherwise constitutes “personal data” as defined in Data Protection Laws.
1.13. “Processing” and inflections thereof refer to any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.14. “Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.
1.15. “Restricted Transfer” means a transfer of Customer Personal Data from the EEA to a country outside the EEA that is not subject to an adequacy decision of the European Commission.
1.16. “Schedules” means the schedules at the end of this DPA:
| Schedule 1 | Subject Matter and Details of Processing |
| Schedule 2 | Technical and Organizational Measures |
| Schedule 3 | Cross-Border Transfer Mechanisms |
1.17. “Security Incident” means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data being Processed by Provider.
1.18. “Subprocessor” means any third party authorized by Provider to Process any Customer Personal Data.
1.19. “Subscription Term” means the period during which Customer has an account in the Cloud Service.
2. Scope and Duration
2.1. Roles of the Parties. This DPA applies to Provider as a Processor of Customer Personal Data and to Customer as a Controller or Processor of Customer Personal Data. It does not apply to Personal Data that Provider Processes as a Controller for its own purposes, such as Customer’s account and billing information, which is described in Provider’s Privacy Policy.
2.2. Scope of DPA. This DPA applies to Provider’s Processing of Customer Personal Data under the Agreement to the extent such Processing is subject to Data Protection Laws. This DPA is governed by the governing law of the Agreement unless otherwise required by Data Protection Laws.
2.3. Duration of DPA. This DPA commences on the DPA Effective Date and terminates upon expiration or termination of the Agreement (or, if later, the date on which Provider has ceased all Processing of Customer Personal Data).
2.4. Order of Precedence. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) any Standard Contractual Clauses or other measures referred to in Schedule 3 (Cross-Border Transfer Mechanisms), (2) this DPA and (3) the Agreement. To the fullest extent permitted by Data Protection Laws, any claims brought in connection with this DPA (including its Schedules) will be subject to the terms and conditions, including the exclusions and limitations of liability, set forth in the Agreement.
3. Processing of Personal Data
3.1. Customer Instructions.
(a) Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer Instructions or (ii) to comply with Provider’s obligations under applicable laws, subject to any notice requirements under Data Protection Laws.
(b) “Customer Instructions” means: (i) Processing to provide the Cloud Service and perform Provider’s obligations in the Agreement (including this DPA), including Processing initiated by Customer’s users through the Cloud Service, and (ii) other reasonable documented instructions of Customer consistent with the terms of the Agreement.
(c) Details regarding the Processing of Customer Personal Data by Provider are set forth in Schedule 1 (Subject Matter and Details of Processing).
(d) Provider will notify Customer if it receives an instruction that Provider reasonably determines infringes Data Protection Laws (but Provider has no obligation to actively monitor Customer’s compliance with Data Protection Laws).
3.2. Confidentiality.
(a) Provider will keep Customer Personal Data confidential and will not disclose it to third parties except as permitted by this DPA or as required by law.
(b) Provider will ensure personnel who Process Customer Personal Data either enter into written confidentiality agreements or are subject to statutory obligations of confidentiality.
3.3. Compliance with Laws.
(a) Provider and Customer will each comply with Data Protection Laws in their respective Processing of Customer Personal Data.
(b) Customer will comply with Data Protection Laws in its issuing of Customer Instructions to Provider. Customer will ensure that it has established all necessary lawful bases under Data Protection Laws to enable Provider to lawfully Process Customer Personal Data for the purposes contemplated by the Agreement (including this DPA), including, as applicable, by obtaining all necessary consents from, and giving all necessary notices to, Data Subjects.
3.4. Changes to Laws. The parties will work together in good faith to negotiate an amendment to this DPA as either party reasonably considers necessary to address the requirements of Data Protection Laws from time to time.
4. Subprocessors
4.1. Use of Subprocessors.
(a) Customer generally authorizes Provider to engage Subprocessors to Process Customer Personal Data, including those on the Subprocessor List on the DPA Effective Date.
(b) Provider will: (i) enter into a written agreement with each Subprocessor imposing data Processing and protection obligations substantially the same as those set out in this DPA and (ii) remain liable for compliance with the obligations of this DPA and for any acts or omissions of a Subprocessor that cause Provider to breach any of its obligations under this DPA.
4.2. Subprocessor List. Provider will maintain an up-to-date list of its Subprocessors, including their functions and locations, in the Subprocessor List.
4.3. Notice of New Subprocessors. Provider may update the Subprocessor List from time to time. At least 30 days before any new Subprocessor Processes any Customer Personal Data, Provider will add such Subprocessor to the Subprocessor List and notify Customer as specified in the Key Terms.
4.4. Objection to New Subprocessors.
(a) If, within 30 days after notice of a new Subprocessor, Customer notifies Provider in writing that Customer objects to Provider’s appointment of such new Subprocessor based on reasonable data protection concerns, the parties will discuss such concerns in good faith.
(b) If the parties are unable to reach a mutually agreeable resolution to Customer’s objection to a new Subprocessor, Customer, as its sole and exclusive remedy, may terminate its use of the affected Cloud Service, and Provider will refund any prepaid, unused fees for the remainder of the paid period.
5. Security
5.1. Security Measures. Provider will implement and maintain reasonable and appropriate technical and organizational measures, procedures and practices, as appropriate to the nature of the Customer Personal Data, that are designed to protect the security, confidentiality, integrity and availability of Customer Personal Data and protect against Security Incidents, as further described in Schedule 2 (Technical and Organizational Measures). Provider will regularly monitor its compliance with Schedule 2 (Technical and Organizational Measures).
5.2. Incident Notice and Response.
(a) Provider will implement and follow procedures to detect and respond to Security Incidents.
(b) Provider will: (i) notify Customer without undue delay after becoming aware of a Security Incident affecting Customer and (ii) make reasonable efforts to identify the cause of the Security Incident, mitigate the effects and remediate the cause to the extent within Provider’s reasonable control.
(c) Upon Customer’s request and taking into account the nature of the applicable Processing, Provider will assist Customer by providing, when available, information reasonably necessary for Customer to meet its Security Incident notification obligations under Data Protection Laws.
(d) Customer acknowledges that Provider’s notification of a Security Incident is not an acknowledgement by Provider of its fault or liability.
(e) Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial of service attacks or other network attacks on firewalls or networked systems.
5.3. Customer Responsibilities.
(a) Customer is responsible for reviewing the information made available by Provider relating to data security and making an independent determination as to whether the Cloud Service meets Customer’s requirements and legal obligations under Data Protection Laws.
(b) Customer is solely responsible for complying with Security Incident notification laws applicable to Customer and fulfilling any obligations to give notices to government authorities, affected individuals or others relating to any Security Incidents.
6. Data Protection Impact Assessment
Upon Customer’s request and taking into account the nature of the applicable Processing, to the extent such information is available to Provider, Provider will assist Customer in fulfilling Customer’s obligations under Data Protection Laws to carry out a data protection impact assessment or similar risk assessment related to Customer’s use of the Cloud Service, including, if required by Data Protection Laws, by assisting Customer in consultations with relevant government authorities.
7. Data Subject Requests
7.1. Assisting Customer. Upon Customer’s request and taking into account the nature of the applicable Processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, in complying with Customer’s obligations under Data Protection Laws to respond to requests from individuals to exercise their rights under Data Protection Laws, provided that Customer cannot reasonably fulfill such requests independently (including through use of the Cloud Service).
7.2. Data Subject Requests. If Provider receives a request from a Data Subject in relation to the Data Subject’s Customer Personal Data, Provider will notify Customer and advise the Data Subject to submit the request to Customer (but not otherwise communicate with the Data Subject regarding the request except as may be required by Data Protection Laws), and Customer will be responsible for responding to any such request.
8. Data Return or Deletion
8.1. During Subscription Term. During the Subscription Term, Customer may access, export or delete Customer Personal Data through the means specified in the Key Terms.
8.2. Post Termination.
(a) Following termination or expiration of the Agreement, Provider will delete all Customer Personal Data from Provider’s systems, as described in Provider’s Privacy Policy.
(b) Deletion will be in accordance with industry-standard secure deletion practices. Provider will confirm the deletion in writing upon Customer’s request.
(c) Notwithstanding the foregoing, Provider may retain Customer Personal Data: (i) as required by Data Protection Laws or other applicable laws or (ii) in its backups and logs for the periods described in Schedule 1, provided that, in either case, Provider will (x) maintain the confidentiality of, and otherwise comply with the applicable provisions of this DPA with respect to, retained Customer Personal Data and (y) not further Process retained Customer Personal Data except for such purpose(s) and duration specified in such applicable laws or in Schedule 1.
9. Audits
9.1. Provider Records Generally. Provider will keep records of its Processing in compliance with Data Protection Laws and, upon Customer’s request, make available to Customer any records reasonably necessary to demonstrate compliance with Provider’s obligations under this DPA and Data Protection Laws.
9.2. Third-Party Compliance Program.
(a) Provider does not currently hold third-party security certifications of its own. Provider’s Subprocessors, such as Amazon Web Services, maintain their own certifications and audit reports. Provider will make the reports of its Subprocessors, and any audit reports of its own (each, an “Audit Report”), available to Customer upon Customer’s written request at reasonable intervals, to the extent Provider is permitted to share them (subject to confidentiality obligations).
(b) Customer may share a copy of Audit Reports with relevant government authorities as required upon their request.
(c) Customer agrees that any audit rights granted by Data Protection Laws will be satisfied by Audit Reports, by the records under Section 9.1 and by the procedures of Section 9.3 (Customer Audit) below.
9.3. Customer Audit.
(a) Subject to the terms of this Section 9.3, Customer has the right, at Customer’s expense, to conduct an audit of reasonable scope and duration pursuant to a mutually agreed-upon audit plan with Provider that is consistent with the Audit Parameters (an “Audit”).
(b) Customer may exercise its Audit right: (i) to the extent the information provided under Sections 9.1 and 9.2 does not provide sufficient information for Customer to verify Provider’s compliance with this DPA or the parties’ compliance with Data Protection Laws, (ii) as necessary for Customer to respond to a government authority audit or (iii) in connection with a Security Incident.
(c) Each Audit must conform to the following parameters (“Audit Parameters”): (i) be conducted by Customer or an independent third party that will enter into a confidentiality agreement with Provider, (ii) be limited in scope to matters reasonably required for Customer to assess Provider’s compliance with this DPA and the parties’ compliance with Data Protection Laws, (iii) occur at a mutually agreed date and time and only during Provider’s regular business hours, (iv) occur no more than once annually (unless required under Data Protection Laws or in connection with a Security Incident), (v) cover only facilities and systems controlled by Provider, (vi) restrict findings to Customer Personal Data only and (vii) treat any results as confidential information to the fullest extent permitted by Data Protection Laws.
10. Cross-Border Transfers
10.1. Provider Processes Customer Personal Data primarily in the EEA. Provider may Process and transfer Customer Personal Data outside the EEA only to the extent necessary to provide the Cloud Service, and only through the Subprocessors on the Subprocessor List, except for transfers made at Customer’s instruction to third parties acting on their own behalf, as described in Schedule 3, section 3.
10.2. If Provider engages in a Restricted Transfer, it will comply with Schedule 3 (Cross-Border Transfer Mechanisms).
Schedule 1: Subject Matter and Details of Processing
Subject matter and nature of the Processing. Provider hosts and Processes Customer Personal Data in order to provide the Cloud Service to Customer under the Agreement. This includes storing, organizing, displaying, transmitting, backing up and deleting Customer Personal Data, and supporting Customer.
Purpose of the Processing. To provide, maintain, secure and support the Cloud Service, and to follow Customer Instructions.
Duration of the Processing. For the Subscription Term. After it ends, Customer Personal Data is deleted from active systems, and from backups within 35 days. Application logs, which may contain identifiers of Data Subjects, are kept for 1 year.
Details per service. This table shows the processing in each service.
| Service | Categories of Data Subjects | Categories of Customer Personal Data |
|---|---|---|
| Tuntikirjaus | Customer’s members and invited members (such as employees and contractors), Customer’s own customers and their contact persons, and the authors of commits in connected GitHub repositories | Names, email addresses, roles, hour entries and their descriptions, billing rates, flex hour balances, invoices, customer contact details (name, business ID, VAT number, address, email), messages to the AI assistant, GitHub usernames and commit author email addresses |
| WebCat | Registrants and other contacts of Customer’s domains, and Customer’s users | Names, organizations, email addresses, phone numbers, postal addresses, personal identity codes or dates of birth (for .fi domains of private persons), and the content of websites and files that Customer stores in WebCat’s hosting features |
Special categories of data. The Cloud Service is not designed for special categories of Personal Data (GDPR article 9) or data relating to criminal convictions. Customer should not enter such data into the Cloud Service.
DNS records. A DNS zone is published technical information: the DNS distributes it worldwide by design, and anyone can query it. Provider does not treat the records Customer enters as Customer Personal Data, and Customer should not enter personal data into them. Contact details for a domain’s registrant are a separate matter, and are listed above.
Schedule 2: Technical and Organizational Measures
Provider maintains at least the following measures:
- Hosting. Most of the Cloud Service runs on Amazon Web Services, primarily in the EU (Ireland) region, in data centers certified to standards such as ISO 27001 and SOC 2. WebCat’s server and hosting features run on a separate platform of Provider’s own, on servers from Hetzner in Germany or Finland and from UpCloud in Helsinki, Finland.
- Encryption. Data is encrypted in transit using TLS, and at rest in the databases and storage where the Cloud Service keeps it.
- Access control.
- Customer’s users authenticate with Amazon Cognito, and access to Customer Data inside the Cloud Service is controlled by organization roles and permissions.
- Access to production systems is limited to Provider’s personnel who need it, using individual credentials with multi-factor authentication.
- Separation. Each customer organization’s data is logically separated, and every request is checked against the organization it concerns. Workloads on the hosting platform are separated per customer.
- Backups and resilience. Databases on AWS have continuous backups with point-in-time recovery for 35 days. Backups of the hosting platform are kept in the EU. Customer should keep its own copies of the websites and files it stores in the hosting features.
- Logging and monitoring.
- Application and access logs are kept for 1 year, and errors are monitored.
- Provider is notified of errors and unusual events automatically.
- Secure development. Changes are reviewed and tested before they are deployed through automated pipelines, and software dependencies are kept up to date.
- Personnel. Personnel with access to Customer Personal Data are bound by confidentiality obligations.
- Incident response. Provider follows a procedure for investigating and responding to Security Incidents, and for notifying Customer as described in Section 5.2.
- Subprocessors. Provider selects Subprocessors based on their security and data protection practices, and binds them with written agreements.
Schedule 3: Cross-Border Transfer Mechanisms
- Provider is established in Finland, so transfers of Customer Personal Data from Customer to Provider are not Restricted Transfers.
- Where a Subprocessor Processes Customer Personal Data outside the EEA, the transfer is made under one of the following:
- an adequacy decision of the European Commission, such as the EU–US Data Privacy Framework for Subprocessors certified under it; or
- the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (Module 3, processor to processor), entered into between Provider and the Subprocessor.
- Where Customer instructs Provider to send Customer Personal Data to a third party outside the EEA, such as a domain registry or registrar, or a service that Customer connects to the Cloud Service, the third party acts on its own behalf. The transfer is made at Customer’s instruction, and Customer is responsible for having a legal basis for it.
Attribution and License
This DPA is adapted from the Bonterms Data Protection Addendum, Version 1.0, © 2022 Bonterms, Inc., licensed under CC BY 4.0.
Clouden made the following changes:
- replaced the DPA Setup Page with the Key Terms, so that the DPA applies through the Terms of Service;
- defined the terms that the Bonterms DPA takes from the Bonterms Cloud Terms;
- limited the Data Protection Laws to the GDPR and Finnish law;
- added its own confidentiality obligation; and
- filled in Schedules 1 to 3, and removed Schedule 4.
Bonterms does not provide legal advice, does not guarantee the enforceability or effect of these terms and has no liability relating to use of these terms.

