Data Processing Agreement

oiva.dev · Effective date: 30 July 2026 · Incorporates GDPR Art. 28

This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Customer” / “Controller”) and oiva.dev (“Processor”) and governs the processing of personal data on your behalf through the oiva.dev platform. By using the Service you accept this DPA.

1. Roles

Customer is the data controller — you determine the purposes and means of processing personal data collected through your surveys.

Oiva Software Oy (Business ID: 3642400-8), registered at Viipurinkatu 12 L 9, 00510 Helsinki, Finland, trading as oiva.dev, is the data processor — we process that data solely on your documented instructions.

2. Nature and Purpose of Processing

oiva.dev processes personal data to:

  • Store and retrieve survey configurations created by the Customer.
  • Receive, store, and display survey responses submitted by end users.
  • Provide analytics and reporting features to the Customer.

3. Categories of Data and Data Subjects

Data subjects — end users who submit responses via embedded surveys; Customer employees who access the dashboard.

Data categories — survey responses (which may include ratings, free-text feedback, and any other fields defined by the Customer); email addresses and names of Customer employees.

The Customer is responsible for ensuring that the personal data collected through surveys is limited to what is necessary and that appropriate notices are provided to respondents.

4. Customer Instructions

oiva.dev will process personal data only on documented instructions from the Customer. Use of the platform features (creating surveys, viewing responses, exporting data) constitutes documented instructions. If oiva.dev is required by EU or Finnish law to process data contrary to instructions, we will inform the Customer unless prohibited by law.

5. Confidentiality

oiva.dev personnel who process Customer data are bound by confidentiality obligations. Access to Customer data is restricted to personnel who need it to deliver the Service.

6. Security Measures

oiva.dev maintains the following technical and organisational measures:

  • TLS 1.2+ encryption for all data in transit.
  • Encrypted storage for sensitive fields.
  • Role-based access controls and principle of least privilege.
  • Regular dependency and security patching.
  • Servers located in the European Economic Area.

7. Sub-processors

oiva.dev currently uses no third-party sub-processors for Customer data. Infrastructure is self-hosted in the EEA.

We will notify the Customer at least 14 days before engaging any new sub-processor. The Customer may object in writing within that period; if we cannot accommodate the objection, either party may terminate the agreement without penalty.

8. Data Subject Rights

oiva.dev will assist the Customer in responding to data subject requests (access, rectification, erasure, portability, restriction) within the platform where technically feasible. Requests that require manual intervention should be directed to [email protected].

9. Data Breach Notification

In the event of a personal data breach affecting Customer data, oiva.dev will notify the Customer without undue delay and no later than 48 hours after becoming aware of the breach. Notification will include the nature of the breach, categories and approximate number of affected data subjects, likely consequences, and measures taken or proposed.

10. Data Transfers

Customer data is stored and processed within the EEA. oiva.dev will not transfer Customer personal data outside the EEA without the Customer's prior written consent and appropriate safeguards under GDPR Chapter V.

11. Retention and Deletion

Upon termination of the Service agreement, oiva.dev will, at the Customer's choice, delete or return all Customer personal data within 30 days, and delete existing copies unless retention is required by EU or Finnish law.

12. Audit Rights

oiva.dev will provide the Customer with all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Customer or an auditor mandated by the Customer, with reasonable notice and at the Customer's expense.