Global controller–processor terms

Data Processing Agreement

This DPA applies automatically when Odoo Upgrade Done processes personal data contained in a business customer's database, filestore, addons, or other project material.

1. Parties and scope

This DPA is between the Customer identified in an accepted submission or Order (“Customer”) and Keski-Suomen Otto ja Pano Oy, Business ID 2376890-1, Finland (“Processor”). It governs Processor's Processing of Customer Personal Data to quote, migrate, test, preview, support, secure, and deliver the services.

“Customer Personal Data” means Personal Data contained in or derived from the database, filestore, addons, source code, logs, exports, configuration, or other project materials that Customer provides or makes available. It excludes contact, contract, billing, security, and website data for which Processor acts as an independent Controller under the Privacy Notice.

“Applicable Data Protection Law” means privacy and data-protection law applicable to the Processing, including as relevant the EU GDPR, Finnish Data Protection Act, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, Brazil's LGPD, and US state privacy laws. Capitalised terms such as Controller, Processor, Personal Data, Process, Data Subject, and Personal Data Breach have the meanings in applicable law.

2. Roles and Customer instructions

Customer is Controller or a Processor authorised by the relevant Controller. Processor will Process Customer Personal Data only on Customer's documented instructions, unless law requires otherwise. The Service Terms, accepted submission, Order, Customer's use of the service, support requests, and written project directions are documented instructions.

Processor will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits notice. Processor may suspend the affected Processing while the parties resolve the issue. If law requires Processing beyond Customer's instructions, Processor will inform Customer before Processing unless legally prohibited.

Customer instructs Processor to use the subprocessors and transfer mechanisms described in this DPA and on the Subprocessors page.

3. Customer obligations

Customer is responsible for:

4. Processor obligations

Processor will:

5. Security

Processor will maintain technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Annex 2 describes the current measures.

Customer acknowledges that the service is a temporary migration workspace, not Customer's backup, production environment, disaster-recovery system, or permanent archive. Customer must retain independent source and production backups. Processor may update measures without materially reducing the overall level of protection during an active Order.

6. Confidentiality and personnel

Processor limits Customer Personal Data access to personnel and approved contractors who require access for the service. They are bound by contractual or statutory confidentiality obligations and informed of relevant security and privacy duties. Confidentiality survives the end of the service.

7. Subprocessors

Customer gives general written authorisation for the subprocessors listed at www.odooupgradedone.com/legal/subprocessors/. Processor will impose data-protection obligations on each subprocessor that are no less protective in substance for the relevant Processing than this DPA requires, including confidentiality, security, deletion, and assistance duties. Processor remains responsible to Customer for its subprocessor's performance to the extent required by Applicable Data Protection Law.

Processor will give active Customers at least 30 days' prior notice of an intended new or replacement subprocessor where reasonably possible. Customer may object during that period on specific, reasonable data-protection grounds. The parties will seek a commercially reasonable alternative. If none is available, either party may terminate the affected unperformed part of the service without penalty. Customer's objection does not excuse payment for accepted deliverables.

8. International transfers

Processor is established in Finland. If Processor or a subprocessor transfers Customer Personal Data from the EEA, United Kingdom, Switzerland, or another jurisdiction that restricts transfers, Processor will ensure a valid transfer basis, such as an adequacy decision, binding rules, approved certification, the applicable Standard Contractual Clauses, or another lawful mechanism.

For a restricted EEA transfer to a recipient in a country without adequacy, the parties incorporate the then-current European Commission Standard Contractual Clauses as needed, using the controller-to-processor or processor-to-processor module appropriate to the parties' roles. The optional docking clause applies, subprocessor authorisation is general with notice under section 7, Finland is the governing Member State, and Finnish courts are selected. Annexes 1–3 of this DPA supply the corresponding annex information. If this DPA conflicts with those clauses, the clauses control for that transfer.

For a restricted UK transfer, the applicable UK International Data Transfer Addendum is incorporated with the same annex information. For Switzerland, references are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority where required. Processor will assess transfers and implement supplementary measures where legally required.

9. Data Subject requests

Taking account of the nature of Processing, Processor will provide reasonable technical and organisational assistance for Customer to respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Processor receives a request directly and can identify Customer, Processor will forward it without undue delay and will not respond substantively except on Customer's instructions or where required by law.

Routine assistance included in the service will not be separately charged. Processor may charge reasonable documented costs for unusually burdensome, repetitive, or legally complex assistance not caused by Processor's breach, after informing Customer.

10. Personal Data Breach

Processor will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Notice will include, as information becomes available: the nature of the breach; affected data and Data Subjects; likely consequences; measures taken or proposed; and a contact for follow-up.

Processor will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will provide information reasonably needed for Customer's notification duties. Processor's notice is not an admission of fault. Customer is responsible for notices to authorities and Data Subjects unless law requires Processor to notify directly.

11. Compliance assistance

Considering the nature of Processing and information available, Processor will reasonably assist Customer with security duties, breach assessment, data-protection impact assessments, and prior consultation with regulators. Customer remains responsible for determining whether an assessment or consultation is required.

12. Return and deletion

During the delivery period, Processor will make agreed deliverables available to Customer. At the end of Processing, Processor will delete or return Customer Personal Data at Customer's choice where reasonably practicable, unless law requires retention. If Customer gives no choice, Processor will follow the retention periods in the Privacy Notice: generally within 30 days after quote expiry for quote-only content and within 30 days after confirmed delivery/download or 60 days after delivery, whichever occurs first, for paid project content.

Data in a backup or immutable security record may remain until the normal cycle expires, provided it is isolated from ordinary use and remains protected. Processor may retain minimal evidence of instructions, acceptance, deletion, and compliance without retaining the project database or addons.

13. Information and audits

On reasonable written request, no more than once in any 12-month period unless a breach or regulator requires more, Processor will provide information reasonably necessary to demonstrate compliance. The parties will first use current documentation, questionnaires, independent reports, and a remote review.

If that is reasonably insufficient, Customer or an independent auditor bound by confidentiality may conduct a targeted audit during normal business hours with at least 30 days' notice. An audit must avoid access to other customers' data, security-sensitive details, and unreasonable service disruption. Customer pays its and Processor's reasonable audit costs unless the audit identifies a material breach by Processor. Nothing requires Processor to disclose another customer's information, privileged material, trade secrets unrelated to compliance, or information that would weaken security.

14. Government requests

Unless prohibited by law, Processor will notify Customer of a legally binding request for Customer Personal Data. Processor will review the request, disclose only what it reasonably believes is legally required, and challenge an unlawful or disproportionate request where reasonable. Processor will document requests as required by law.

15. US state service-provider and contractor terms

To the extent a US state privacy law applies and Customer discloses Personal Data to Processor as a service provider, contractor, or processor, Processor will:

Customer may monitor compliance through section 13. The parties acknowledge that Customer discloses the data for business purposes and not for monetary or other valuable consideration.

16. Priority, liability, and term

This DPA begins when Customer first submits Customer Personal Data under accepted Service Terms and continues until Processor deletes all Customer Personal Data, subject to legally required retention. It terminates automatically with the last applicable Order after deletion obligations are complete.

If there is a conflict, mandatory Applicable Data Protection Law controls, followed by an applicable transfer mechanism, this DPA, the Order, and the Service Terms. The single aggregate liability cap and excluded-loss clauses in sections 17 and 18 of the Service Terms apply fully to this DPA and all Customer claims involving Customer Personal Data, including confidentiality, privacy, security, breach, loss, corruption, deletion, restoration, unauthorised access or disclosure, and subprocessors. These terms do not limit Data Subject rights or regulatory powers that cannot be limited by contract.

17. Contact

Privacy and security notices under this DPA should be sent to support@odooupgradedone.com with the Customer name and project reference.

Annex 1 — Processing details

Annex 2 — Technical and organisational measures

Annex 3 — Approved subprocessors

The current list, functions, locations, and safeguards at www.odooupgradedone.com/legal/subprocessors/ is incorporated into this Annex 3.