Data Processing Agreement (DPA)
This is a courtesy English translation. The Finnish version is the legally binding one.
This Data Processing Agreement (“DPA”) describes how Ritu’s service provider processes personal data on behalf of the data controller in accordance with Article 28 of the EU General Data Protection Regulation (GDPR). The DPA forms part of Ritu’s Terms of Service and supplements them with regard to the processing of personal data.
1. Parties and roles
Data controller: The family admin (a relative or person caring for a loved one) who decides what data is stored in the service and for what purpose. The data controller determines the purposes and means of the processing.
Data processor: Tuittupaa Productions Oy, business ID 3640226-3, registered office in Helsinki, Finland (the “Service Provider”), which processes personal data on behalf of the data controller in order to provide the service.
Please note: When a family uses the service purely for personal or household activity, the processing may fall under the GDPR’s household exemption (Art. 2(2)(c)). The Service Provider nevertheless undertakes to comply with the processor’s obligations and the security practices described here.
2. Definitions
The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “special categories of personal data” have the same meaning as in the GDPR. Other terms are defined in the Terms of Service.
3. Subject matter and duration of processing
The subject matter of the processing is the personal data stored in the service by the data controller. Processing continues for as long as the data controller uses the service, or until the data is deleted in accordance with section 12. The DPA remains in force for as long as personal data is processed in the service.
4. Nature and purpose of processing
The Service Provider processes personal data solely in order to provide the service: storing, displaying and synchronising data across devices, backups, and the maintenance, security and support of the service. The data is not used for the Service Provider’s own purposes, such as marketing or profiling, nor is it sold.
5. Categories of data and data subjects
Categories of data subjects: The loved one (person with a memory disorder), family members, and the service admin.
| Category of data | Examples |
|---|---|
| Basic information | Name, date of birth, family relationship |
| Content data | Events, additional details/notes, photographs |
| Identification data | Admin’s email address, login and session data, hashes of PIN/invite codes |
| Technical data | Device and log data, IP address for delivering the service |
| Special categories of personal data (Art. 9) | Health-related data may arise indirectly (e.g. a memory disorder, the content of photos or notes). The data controller is responsible for the legal basis of the processing, such as explicit consent. |
6. Obligations of the processor
The Service Provider undertakes to:
- process personal data only in accordance with the data controller’s documented instructions (as set out in these terms and the functionality of the service), unless required otherwise by law;
- ensure that persons processing the data are committed to confidentiality;
- implement the technical and organisational security measures set out in section 7;
- engage sub-processors only under the conditions set out in section 8;
- assist the data controller in fulfilling data subjects’ rights and security obligations;
- delete or return the data once processing has ended (section 12);
- make available the information necessary to demonstrate compliance with the obligations under Article 28.
If the Service Provider considers that an instruction infringes data protection law, it will notify the data controller.
7. Security measures (Art. 32)
The Service Provider implements technical and organisational measures appropriate to the risk, including:
- storage of data on servers located in the EU;
- encrypted data transmission (TLS) and encryption of data at rest;
- family-specific data isolation using database row-level security (RLS) access rules;
- protection of login and PIN codes with strong hashing (bcrypt);
- rate limiting of login attempts (lockout after repeated failed attempts);
- access control and data minimisation on a need-to-know basis.
8. Sub-processors
The data controller grants a general authorisation to engage sub-processors in order to provide the service. The Service Provider enters into an agreement with each sub-processor that imposes equivalent data protection obligations. Current sub-processors:
| Sub-processor | Task | Location |
|---|---|---|
| Supabase | Database, authentication and file (image) storage | EU region |
| Vercel | Delivery of the application (static content) and technical logs | EU / global CDN |
The Service Provider will give advance notice of any new or replacement sub-processors. The data controller has the right, on reasonable data protection grounds, to object to a change; in that case the parties will seek a solution, or the data controller may cease using the service.
9. Rights of data subjects
The Service Provider assists the data controller, through appropriate technical and organisational measures, in responding to data subjects’ requests (rights of access, rectification, erasure, restriction and portability). The service’s features allow the admin to edit and delete data directly. If a data subject contacts the Service Provider directly, the request will be forwarded to the data controller.
10. Personal data breaches (Art. 33)
Upon becoming aware of a personal data breach, the Service Provider will notify the data controller without undue delay after becoming aware of it, and will provide the reasonably available information about the breach and the measures taken in response, so that the data controller can fulfil its own notification obligations.
11. Assistance with impact assessments
The Service Provider assists the data controller, to a reasonable extent, with data protection impact assessments (Art. 35) and any prior consultations with the supervisory authority (Art. 36), taking into account the nature of the processing and the information available.
12. Return and deletion of data
Upon the end of processing, the Service Provider will, at the data controller’s choice, delete or return the personal data and delete existing copies, unless the law requires the data to be retained. Within the service, the admin can also clear the family’s data or leave the family themselves.
13. Audits
The Service Provider makes available to the data controller the information necessary to demonstrate compliance with the obligations under Article 28 and allows for reasonable, pre-agreed audits. Compliance is primarily demonstrated through documentation and the certifications of sub-processors.
14. International data transfers
Personal data is stored and processed primarily within the EU/EEA. If a sub-processor processes data outside the EEA (e.g. in relation to technical logs), the Service Provider ensures appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCC).
15. Liability and term
The liability of the parties is subject to the limitations set out in the Terms of Service and in mandatory law. In the event of a conflict, this DPA prevails over the Terms of Service with regard to the processing of personal data. The DPA remains in force until the processing of personal data in the service ends.
16. Contact details
Data protection enquiries: tuulia.virhia@gmail.com
Service Provider: Tuittupaa Productions Oy (business ID 3640226-3) · registered office in Helsinki, Finland
Data Protection Officer (if appointed): none appointed