Data processing agreement
Updated 10.10.2026
Translation. The Finnish version prevails.
Draft. This text is under legal review and may still change.
This agreement is made between the client (controller) and Selko Consulting (processor, below we). It supplements the order and the terms of delivery insofar as the delivery processes personal data on the client's behalf.
The agreement is signed or accepted in writing before we get access to a single real personal data item. In the build and test phase we primarily use invented or anonymised material.
The agreement is based on Article 28 of the EU General Data Protection Regulation (2016/679, below the GDPR). The terms used (personal data, controller, processor, processing, personal data breach) mean the same as in the Regulation.
1. Parties and order of precedence
Controller: the client identified in the order. Processor: Selko Consulting. Business ID 3660597-6, VAT number FI36605976. Atlantinkatu 7 B 77, 00220 Helsinki. Contact for data protection matters: info@selkoconsulting.com.
The client decides which personal data is processed and for what purpose. We process personal data only on the client's behalf and under the client's documented instructions.
In a conflict concerning the processing of personal data, this agreement takes precedence over the order and the terms of delivery. In other matters the order of precedence is that of the terms of delivery. If a mandatory provision of the GDPR conflicts with this agreement, the Regulation applies.
The agreement covers all the client's orders in which we process personal data, unless agreed otherwise per order. The description of each order's processing is recorded in Annex 1.
2. Subject, nature, purpose and duration of the processing
The subject, nature, purpose and duration of the processing, the categories of personal data and the categories of data subjects are described per order in Annex 1 (section 12). Typical processing includes classifying customer service messages and drafting replies, converting internal documents into a searchable form, transferring data between systems and compiling reporting views.
We process personal data only to the extent that building, testing, handing over and the agreed maintenance of the delivery require. We do not process special categories of personal data (for example health data or trade union membership) or data on criminal convictions unless expressly agreed in Annex 1 and unless the client has shown a lawful basis for the processing.
The processing lasts for the duration of the order and the related maintenance, and for the deletion or return period under section 7.
3. Obligations of the processor
We process personal data only under the client's documented instructions. The order, this agreement and Annex 1 are the client's instructions. Further instructions are given in writing, and email is enough. If we consider an instruction to infringe the GDPR or other law, we notify the client without delay and may suspend the processing under that instruction until the matter is resolved.
If EU or Member State law requires us to process personal data otherwise than under the client's instructions, we notify the client before the processing, unless the law prohibits the notification.
We keep personal data confidential. Only those who work on the delivery have access to personal data, and they are bound to confidentiality. If we use another person to help, that person commits to written confidentiality before getting access to the data, and we notify the client in advance.
We implement the technical and organisational measures under Article 32 of the GDPR. At least the following are always in place:
- Least privilege: we request only the access the delivery requires and ask for its removal when the need ends.
- The client's own accounts: the delivery is built by default on the client's own accounts, so the data stays under the client's control. The exception is Care Plus, where the accounts are ours and this is agreed separately in the order.
- Draft first: the delivery produces drafts that a person approves before action. Automatic sending is enabled only on the client's written request.
- Logging: the processing actions of the delivery are logged on the platform, where the client can review them.
- Multi-factor authentication on every account with access to personal data.
- Encryption in transit and at rest as implemented by the platforms used. We do not use platforms that do not encrypt data in transit.
- Stop capability: the delivery can be stopped immediately by both the client and us.
- No local copies: the agent products' data and their backups are not stored on our own devices. In custom deliveries we do not download personal data to our own devices beyond what testing strictly requires, and such copies are deleted after acceptance.
- Test data: in the build and test phase, invented or anonymised material is used whenever possible.
4. Sub-processors
The client gives a general prior authorisation to use the sub-processors listed in Annex 2 (section 13). The sub-processors used per order are named in Annex 1, and only those are used in that delivery.
We notify the client in writing of a new sub-processor or a change of sub-processor at least 14 days before the sub-processor gets access to personal data. The client may object to the change in writing within that time for a justified data protection reason. If no reasonable solution to the objection is found, the client may terminate the delivery or maintenance concerned to end without a notice period insofar as the change affects it.
We conclude a written contract with every sub-processor that imposes on the sub-processor data protection obligations at least equivalent to this agreement. We are liable to the client for the sub-processor's actions as for our own.
When the delivery is built on the client's own accounts, the client has its own contract with the platform (for example Make or Anthropic), and the platform is then the client's own processor, not our sub-processor. We help the client accept the platform's data processing agreement and settings.
5. Assistance with data subject requests and impact assessments
If a data subject presents us a request concerning data processed on the client's behalf, we forward the request to the client without delay and do not answer it ourselves unless the client instructs otherwise.
We assist the client in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) insofar as possible considering the nature of the processing. In practice this means searching for data, delivering an extract or deleting data from the systems the delivery processes.
We assist the client in implementing security under Article 32, in notifications under Articles 33 and 34, in a data protection impact assessment under Article 35 and in prior consultation under Article 36 by providing the information about the processing available to us.
Assistance that is part of the delivery's normal documentation is free of charge. Other assistance, for example an extensive impact assessment or repeated extensive data requests, is invoiced at the hourly rate agreed in the order or, if none is agreed, according to a reasonable amount of work agreed in writing first.
6. Personal data breaches
We notify the client of a personal data breach without undue delay and at the latest within 48 hours of becoming aware of it. The notification is made to the contact person the client has named in Annex 1, by email and if needed by phone.
The notification contains what we know at the time of the notification, and we supplement it as the investigation proceeds:
- what happened, when, and how it was detected,
- which categories of personal data and data subjects the breach concerns and an estimate of their number,
- which systems or sub-processors the breach concerns,
- the likely consequences of the breach,
- the measures we have taken or propose to limit the breach and prevent recurrence,
- a contact person for further information.
7. Deletion or return of data
When the delivery or maintenance ends, we delete or return, at the client's choice, all personal data processed on the client's behalf within 30 days of the end and delete existing copies, unless EU or Member State law requires the data to be kept.
When the delivery is on the client's own accounts, the data is already under the client's control. In that case we remove our own access and any test copies and confirm this in writing.
On the Care Plus tier we return the configuration and data to the client in an exportable form before deletion. The platforms' own backups expire according to the platforms' own retention periods.
On request we deliver written confirmation of the deletion.
8. Audits
We give the client all information needed to demonstrate compliance with the obligations under Article 28. The primary audit method is written: the client presents questions, and we answer within 14 days and deliver the necessary documents, such as a description of security measures, sub-processor agreements and the platforms' certificates or equivalent reports.
If a written report is not enough, the client or an independent auditor authorised by the client may carry out an audit on site or remotely at most once a year, by notifying in writing at least 30 days in advance. The audit takes place during normal working hours, is limited to the processing of the client's personal data and must not endanger other clients' data. The auditor commits to confidentiality.
The client bears the audit costs, including our reasonable working time at the hourly rate agreed in the order. If the audit reveals a material deficiency that is ours to fix, we bear our own working time.
An audit may be carried out more than once a year if a supervisory authority requires it or if a personal data breach gives a justified reason.
9. Transfers outside the EEA
The agent products' data and backups are stored in the EU: the database in Supabase's service in Stockholm and the encrypted backups in the Cloudflare R2 storage service, with the location restricted to the EU. They are not stored on our own devices.
We process personal data in the EU and the EEA. We transfer personal data outside the EEA, or give access to it from outside the EEA, only under the conditions of Chapter V of the GDPR: on the basis of a Commission adequacy decision (including the EU-US Data Privacy Framework for companies certified under it) or on the basis of the Commission's standard contractual clauses supplemented by the necessary additional measures.
The platforms listed in Annex 2 are partly US companies. Their transfer basis is marked in the annex. Language model APIs process the content sent to them in the United States unless EU data residency has been chosen and agreed in Annex 1.
The client may prohibit a specific transfer in Annex 1. In that case we limit the delivery to platforms that meet the client's requirement, and the effect on the content and price of the delivery is agreed in the order.
10. Liability
Liability for a breach of this agreement follows the limitations of liability in the order and the terms of delivery. The limitations of liability do not limit a data subject's right to compensation under Article 82 of the GDPR, nor the allocation of liability between the parties insofar as the Regulation mandatorily provides for it.
Each party is responsible for any administrative fines imposed on it.
If a data subject or an authority presents a claim, the parties notify each other without delay and cooperate in handling the claim.
11. Term
The agreement enters into force when both parties have accepted it in writing and remains in force as long as we process personal data on the client's behalf. The agreement ends when the deletion or return under section 7 has been done and confirmed.
Changes to the agreement are made in writing. Changes to the sub-processor list are made under section 4.
The agreement is governed by Finnish law, and disputes are settled as provided in the terms of delivery.
12. Annex 1: Description of the processing (filled in per order)
This annex is filled in for every order and attached to the offer. It is the client's documented instruction for the processing.
| Item | Content |
|---|---|
| Order | Filled in per order: the offer's identifier and date. |
| Subject of the processing | Filled in per order: for example customer service email messages. |
| Nature of the processing | Filled in per order: for example reading, classifying, drafting a reply, transferring from one system to another, storing in a searchable form. |
| Purpose of the processing | Filled in per order: for example shortening customer service response times. |
| Duration of the processing | Filled in per order: the duration of the delivery and maintenance. |
| Categories of personal data | Filled in per order: for example name, email address, message content, order history. |
| Categories of data subjects | Filled in per order: for example the client's customers, the client's staff, suppliers' contact persons. |
| Special categories of personal data | Not processed. If processed: which categories and the lawful basis shown by the client. |
| Platforms and sub-processors used | Filled in per order: from the list in Annex 2; it is marked whether the accounts are the client's or ours. |
| Transfers outside the EEA | Filled in per order: permitted transfers and their basis, or a prohibition. |
| Automatic sending | Not in use. If in use: the client's written request, the permitted actions and the responsible person. |
| The client's contact person for data breaches | Filled in per order: name, email, phone. |
| Deletion or return at the end | Filled in per order: deletion or return, and the format. |
13. Annex 2: Approved sub-processors
The following sub-processors are approved under a general prior authorisation. Only those named in Annex 1 are used in an order. When the delivery is built on the client's own accounts, the platform is the client's own processor (section 4), and the table is then for information. In the agent products (for accounting firms, property management firms and trades), the client's messages are handled by the rows whose purpose mentions the agent products.
| Service | Purpose | Location | Transfer basis |
|---|---|---|---|
| Make (Celonis) | Automation platform: running workflows and connecting systems | The EU server region is chosen for the account; the parent company Celonis Inc. is a US company | EU-US Data Privacy Framework (Celonis Inc.) or the EU standard contractual clauses |
| Anthropic PBC | Language model API in the agent products and in custom deliveries: classification, summaries, reply drafts | United States | EU standard contractual clauses. No training on customer data. Inputs and outputs are deleted by default within 30 days. |
| OpenAI | Embedding models in knowledge search | United States; EU data residency is chosen when available | EU standard contractual clauses. No training on API data by default. Retention at most 30 days or zero retention. |
| Supabase Inc. | The agent products' database: messages, drafts, tasks and the data the client imports. Also the database and files in internal tools and knowledge search. | Stockholm, Sweden; a US company | EU-US Data Privacy Framework or the EU standard contractual clauses |
| Cloudflare, Inc. (Workers) | Hosting and server functions of the agent products' application. Also hosting of internal tools and reporting views. | Cloudflare's network: server functions primarily in Northern Europe; a US company | EU-US Data Privacy Framework (Cloudflare is certified) and the EU standard contractual clauses in Cloudflare's data processing agreement |
| Inbound email relay service: Resend Inc. or Cloudflare, Inc. (Email Routing) | Agent products: receives the email forwarded to the agent and passes it to the application. One of the two is used, and it is named in Annex 1. Taken into use before the first client. | The message passes through the service and is not stored there permanently; US companies | EU-US Data Privacy Framework or the EU standard contractual clauses |
| Cloudflare, Inc. (R2) | Storage of the encrypted backups of the agent products' database. Taken into use before the first client. | EU: the storage location is restricted to the EU (R2's EU jurisdiction); a US company | The data is stored in the EU. Possible access from outside the EU: EU-US Data Privacy Framework or the EU standard contractual clauses. The copies are encrypted with a key held only by the processor. |
| Resend Inc. | Agent products: an alert message to the processor about an error or a message classified as urgent. Only if the feature is switched on. | United States | EU standard contractual clauses |
| Google or Microsoft | Email, calendar and documents when the client's systems are in these | EU data centres according to the client's account settings; US companies | EU-US Data Privacy Framework or the EU standard contractual clauses |
| Netvisor or Procountor | Accounting APIs when the client's bookkeeping is in these | Finland | No transfer outside the EEA |
14. Annex 3: Technical and organisational measures
The measures listed in section 3 are always in place. In addition we follow these:
- Access review: we review our own access to the client's systems at the acceptance of every delivery and ask for the removal of unnecessary access.
- Passwords and keys: API keys and credentials are kept in a password manager, not in email, messages or code.
- Devices: work devices are encrypted and locked, and operating system updates are kept current.
- Backups: an encrypted backup (AES-256-GCM, key held only by the processor) of the agent products' database is taken every night to the Cloudflare R2 storage service, with the location restricted to the EU. The copies are deleted after 14 days. Backups are not stored on the processor's own devices. Backups are taken into use before the first client.
- Use of language models: only the part of the data the task requires is sent to the language model. Personal data is not sent to consumer versions, only to APIs covered by a data processing agreement.
- Change management: changes to a delivery in production are tested first and recorded in the documentation.
- Breach handling: a detected anomaly is recorded, the delivery is stopped if necessary, and the client is notified under section 6.