Global controller–processor terms
Data Processing Agreement
This DPA applies automatically when Odoo Upgrade Done processes personal data contained in a business customer's database, filestore, addons, or other project material.
This DPA is incorporated into the Service Terms. Customer accepts it when Customer accepts those terms through the upload form, a written Order, or a payment checkout. No separate signature is required unless applicable law or an Order requires one.
1. Parties and scope
This DPA is between the Customer identified in an accepted submission or Order (“Customer”) and Keski-Suomen Otto ja Pano Oy, Business ID 2376890-1, Finland (“Processor”). It governs Processor's Processing of Customer Personal Data to quote, migrate, test, preview, support, secure, and deliver the services.
“Customer Personal Data” means Personal Data contained in or derived from the database, filestore, addons, source code, logs, exports, configuration, or other project materials that Customer provides or makes available. It excludes contact, contract, billing, security, and website data for which Processor acts as an independent Controller under the Privacy Notice.
“Applicable Data Protection Law” means privacy and data-protection law applicable to the Processing, including as relevant the EU GDPR, Finnish Data Protection Act, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, Brazil's LGPD, and US state privacy laws. Capitalised terms such as Controller, Processor, Personal Data, Process, Data Subject, and Personal Data Breach have the meanings in applicable law.
2. Roles and Customer instructions
Customer is Controller or a Processor authorised by the relevant Controller. Processor will Process Customer Personal Data only on Customer's documented instructions, unless law requires otherwise. The Service Terms, accepted submission, Order, Customer's use of the service, support requests, and written project directions are documented instructions.
Processor will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits notice. Processor may suspend the affected Processing while the parties resolve the issue. If law requires Processing beyond Customer's instructions, Processor will inform Customer before Processing unless legally prohibited.
Customer instructs Processor to use the subprocessors and transfer mechanisms described in this DPA and on the Subprocessors page.
3. Customer obligations
Customer is responsible for:
- the lawfulness, fairness, transparency, accuracy, and minimisation of Customer Personal Data and the instructions;
- having a valid legal basis and providing all notices required for the migration and related disclosure to Processor;
- ensuring it has authority to appoint Processor and, where Customer is a Processor, authorisation from the relevant Controller;
- identifying before upload any special-category, sensitive, criminal-offence, children's, health, financial, or other specially regulated data;
- not providing data prohibited by section 11 of the Service Terms without prior written approval;
- limiting the supplied snapshot to what is reasonably needed and masking unnecessary data where practical; and
- handling Data Subject requests, regulatory notices, impact assessments, and production security as Controller.
4. Processor obligations
Processor will:
- Process Customer Personal Data only for the subject matter, purposes, duration, and operations in Annex 1 and Customer's documented instructions;
- not sell Customer Personal Data, share it for behavioural advertising, use it to advertise, or use it to train a general-purpose AI model;
- ensure persons authorised to Process it are bound by confidentiality and receive access only as needed;
- implement and maintain the measures in Annex 2, taking account of the state of the art, cost, scope, context, purposes, and risk;
- assist Customer as described in this DPA; and
- make available information reasonably necessary to demonstrate compliance with this DPA.
5. Security
Processor will maintain technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Annex 2 describes the current measures.
Customer acknowledges that the service is a temporary migration workspace, not Customer's backup, production environment, disaster-recovery system, or permanent archive. Customer must retain independent source and production backups. Processor may update measures without materially reducing the overall level of protection during an active Order.
6. Confidentiality and personnel
Processor limits Customer Personal Data access to personnel and approved contractors who require access for the service. They are bound by contractual or statutory confidentiality obligations and informed of relevant security and privacy duties. Confidentiality survives the end of the service.
7. Subprocessors
Customer gives general written authorisation for the subprocessors listed at www.odooupgradedone.com/legal/subprocessors/. Processor will impose data-protection obligations on each subprocessor that are no less protective in substance for the relevant Processing than this DPA requires, including confidentiality, security, deletion, and assistance duties. Processor remains responsible to Customer for its subprocessor's performance to the extent required by Applicable Data Protection Law.
Processor will give active Customers at least 30 days' prior notice of an intended new or replacement subprocessor where reasonably possible. Customer may object during that period on specific, reasonable data-protection grounds. The parties will seek a commercially reasonable alternative. If none is available, either party may terminate the affected unperformed part of the service without penalty. Customer's objection does not excuse payment for accepted deliverables.
8. International transfers
Processor is established in Finland. If Processor or a subprocessor transfers Customer Personal Data from the EEA, United Kingdom, Switzerland, or another jurisdiction that restricts transfers, Processor will ensure a valid transfer basis, such as an adequacy decision, binding rules, approved certification, the applicable Standard Contractual Clauses, or another lawful mechanism.
For a restricted EEA transfer to a recipient in a country without adequacy, the parties incorporate the then-current European Commission Standard Contractual Clauses as needed, using the controller-to-processor or processor-to-processor module appropriate to the parties' roles. The optional docking clause applies, subprocessor authorisation is general with notice under section 7, Finland is the governing Member State, and Finnish courts are selected. Annexes 1–3 of this DPA supply the corresponding annex information. If this DPA conflicts with those clauses, the clauses control for that transfer.
For a restricted UK transfer, the applicable UK International Data Transfer Addendum is incorporated with the same annex information. For Switzerland, references are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority where required. Processor will assess transfers and implement supplementary measures where legally required.
9. Data Subject requests
Taking account of the nature of Processing, Processor will provide reasonable technical and organisational assistance for Customer to respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Processor receives a request directly and can identify Customer, Processor will forward it without undue delay and will not respond substantively except on Customer's instructions or where required by law.
Routine assistance included in the service will not be separately charged. Processor may charge reasonable documented costs for unusually burdensome, repetitive, or legally complex assistance not caused by Processor's breach, after informing Customer.
10. Personal Data Breach
Processor will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Notice will include, as information becomes available: the nature of the breach; affected data and Data Subjects; likely consequences; measures taken or proposed; and a contact for follow-up.
Processor will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will provide information reasonably needed for Customer's notification duties. Processor's notice is not an admission of fault. Customer is responsible for notices to authorities and Data Subjects unless law requires Processor to notify directly.
11. Compliance assistance
Considering the nature of Processing and information available, Processor will reasonably assist Customer with security duties, breach assessment, data-protection impact assessments, and prior consultation with regulators. Customer remains responsible for determining whether an assessment or consultation is required.
12. Return and deletion
During the delivery period, Processor will make agreed deliverables available to Customer. At the end of Processing, Processor will delete or return Customer Personal Data at Customer's choice where reasonably practicable, unless law requires retention. If Customer gives no choice, Processor will follow the retention periods in the Privacy Notice: generally within 30 days after quote expiry for quote-only content and within 30 days after confirmed delivery/download or 60 days after delivery, whichever occurs first, for paid project content.
Data in a backup or immutable security record may remain until the normal cycle expires, provided it is isolated from ordinary use and remains protected. Processor may retain minimal evidence of instructions, acceptance, deletion, and compliance without retaining the project database or addons.
13. Information and audits
On reasonable written request, no more than once in any 12-month period unless a breach or regulator requires more, Processor will provide information reasonably necessary to demonstrate compliance. The parties will first use current documentation, questionnaires, independent reports, and a remote review.
If that is reasonably insufficient, Customer or an independent auditor bound by confidentiality may conduct a targeted audit during normal business hours with at least 30 days' notice. An audit must avoid access to other customers' data, security-sensitive details, and unreasonable service disruption. Customer pays its and Processor's reasonable audit costs unless the audit identifies a material breach by Processor. Nothing requires Processor to disclose another customer's information, privileged material, trade secrets unrelated to compliance, or information that would weaken security.
14. Government requests
Unless prohibited by law, Processor will notify Customer of a legally binding request for Customer Personal Data. Processor will review the request, disclose only what it reasonably believes is legally required, and challenge an unlawful or disproportionate request where reasonable. Processor will document requests as required by law.
15. US state service-provider and contractor terms
To the extent a US state privacy law applies and Customer discloses Personal Data to Processor as a service provider, contractor, or processor, Processor will:
- Process the data only for the limited and specified business purposes in Annex 1 and Customer's instructions;
- not sell or share the data, retain/use/disclose it outside those purposes or the direct business relationship, or combine it with personal data from another source except as legally permitted to provide the service;
- provide the same level of privacy protection required of Customer for the Processing;
- notify Customer if Processor determines it can no longer meet an applicable obligation;
- allow Customer to take reasonable and appropriate steps to stop and remediate unauthorised use; and
- require subprocessors to meet corresponding restrictions.
Customer may monitor compliance through section 13. The parties acknowledge that Customer discloses the data for business purposes and not for monetary or other valuable consideration.
16. Priority, liability, and term
This DPA begins when Customer first submits Customer Personal Data under accepted Service Terms and continues until Processor deletes all Customer Personal Data, subject to legally required retention. It terminates automatically with the last applicable Order after deletion obligations are complete.
If there is a conflict, mandatory Applicable Data Protection Law controls, followed by an applicable transfer mechanism, this DPA, the Order, and the Service Terms. The single aggregate liability cap and excluded-loss clauses in sections 17 and 18 of the Service Terms apply fully to this DPA and all Customer claims involving Customer Personal Data, including confidentiality, privacy, security, breach, loss, corruption, deletion, restoration, unauthorised access or disclosure, and subprocessors. These terms do not limit Data Subject rights or regulatory powers that cannot be limited by contract.
17. Contact
Privacy and security notices under this DPA should be sent to support@odooupgradedone.com with the Customer name and project reference.
Annex 1 — Processing details
| Parties | Customer is the Controller or Customer Processor identified in the accepted submission or Order. Processor is Keski-Suomen Otto ja Pano Oy, c/o Joona Heino, Herneaho 84, FI-41120 Puuppola, Finland; support@odooupgradedone.com. |
|---|---|
| Subject matter | Assessment, migration, modification, restoration, testing, preview, verification, support, packaging, transfer, and deletion of a customer-supplied Odoo system copy and related materials. |
| Duration | From first upload or access until deletion under section 12, ordinarily the quote and Order period plus the short delivery/retention window. |
| Nature and operations | Receive, record, organise, store, inspect, query, restore, compare, alter, test, retrieve, transmit to authorised recipients, restrict, and delete. Processing is temporary and occurs as needed for the project. |
| Purposes | Feasibility analysis and fixed quote; performing the agreed Odoo version migration; adapting included addons; creating a safe preview; verifying acceptance criteria; troubleshooting; delivering the result; security and incident response; legal compliance. |
| Data Subjects | Customer's employees, workers, applicants, contractors, users, administrators, contacts, leads, customers, prospects, suppliers, partners, visitors, account holders, dependants, and other persons represented in the supplied system. |
| Personal Data | Identity and contact details; user accounts and identifiers; employment and HR records; CRM, sales, purchase, inventory, project, support, website, and communication records; invoices, accounting and transaction records; device and log data; free-text notes; attachments; metadata; and other fields configured by Customer. |
| Sensitive data | Only if present and disclosed by Customer: payroll, financial, government identifier, trade-union, health, disability, biometric, criminal-offence, children's, or other special-category/sensitive data. Such data is not required by the service as a category and should be minimised or masked where practicable. |
| Frequency | Intermittent during quote analysis and the migration Order; automated storage and technical operations plus human access as needed. |
| Customer instructions | The accepted submission, Service Terms, Order, documented support/project communications, and Customer's permitted use of service functions. |
| Retention | As stated in section 12 and the Privacy Notice, unless the Order records a different lawful period. |
Annex 2 — Technical and organisational measures
| Area | Measures |
|---|---|
| Data minimisation and isolation | Project-scoped object paths and identifiers; collection limited to quote and migration needs; no production access in the standard service; separation of customer job materials. |
| Transfer security | HTTPS/TLS for website, API, preview, and object transfer; time-limited signed upload URLs; large files sent directly from the browser to protected object storage; multipart upload URLs limited to the specific object and part. |
| Storage and secrets | Protected EU object storage for Customer Content; infrastructure-provided storage encryption where configured; credentials and service secrets kept out of public source and supplied through protected environment configuration. |
| Access control | Need-to-know access for authorised personnel; unique provider accounts where supported; strong authentication and multifactor authentication where available; confidentiality duties; no collection of passwords through free-text forms. |
| Safe testing | Migration and testing on copies; outbound email, scheduled jobs, payment actions, and external callbacks disabled or neutralised where appropriate for a preview; production deployment remains with Customer. |
| Availability and recovery | Customer retains authoritative backups; temporary project storage is not represented as a backup service; interrupted multipart uploads can be aborted; migration work can be repeated from Customer's source copy where feasible. |
| Logging and monitoring | Technical and security logs appropriate to the intake and infrastructure; job records capture submission and terms version; access and incident investigation records retained only as needed. |
| Incident management | Process for identifying, containing, investigating, mitigating, documenting, and notifying confirmed incidents; contact channel for reports; cooperation with Customer's legal notification assessment. |
| Deletion | Project closure and purge process; deletion from active project locations under the stated schedule; expired signed URLs; isolated backup expiry under provider cycles; minimal compliance records retained separately. |
| Vendor management | Review of subprocessor purpose and safeguards; data-protection terms; restricted data sharing; public subprocessor list and change process. |
| Review | Periodic review of relevant access, dependencies, security configuration, retention, and incident procedures; remediation proportionate to risk. |
Annex 3 — Approved subprocessors
The current list, functions, locations, and safeguards at www.odooupgradedone.com/legal/subprocessors/ is incorporated into this Annex 3.