Cansome
  • Sites
  • Boss
  • Social
  • Sales
Back to sales

Cansome Sales

Data processing agreement for Cansome Sales

Effective date: 10.11.2025. Updated 9.10.2026 for Cansome Sales.

This Data Processing Agreement supplements the terms between the Customer (controller) and Cansome Oy (processor) for Cansome Sales.

1. Roles

GDPR definitions apply. The Customer decides why and how personal data is processed and is responsible for having a lawful basis. The Provider processes that data on the Customer’s instructions and is responsible for processing it securely.

2. Details of processing

Subject. Personal data in the customer data entered into the Service.

Duration. For the agreement, plus the retention period in the terms (at most 90 days after the end, unless the law requires longer).

Nature and purpose. undefined

Data subjects. The Customer’s users, and the Customer’s clients, prospects, or contacts whose data the Customer stores, and any other person whose data the Customer uploads.

Types of data. Contact details, usage metadata, and content the Customer enters that identifies a person.

3. Processor duties (GDPR Article 28)

The Provider processes personal data only on documented instructions, including these terms, unless EU or Finnish law requires otherwise. People who handle the data are under a confidentiality duty. The Provider uses access control and other technical and organisational measures appropriate to the risk.

The Provider does not engage a sub-processor without a prior general written authorisation. A list of sub-processors is available on request. The Customer may object to an intended change. A sub-processor is bound by terms equivalent to this DPA.

4. Location

Storage and processing under this DPA take place in the EU or EEA, currently in Germany, with the option to use another EU or EEA location. The Provider does not use a non-EEA cloud component that would transfer customer personal data outside the EU or EEA.

5. Assistance

Taking into account the nature of the processing, the Provider assists the Customer, at the Customer’s cost, with data-subject requests, breach notification, and data protection impact assessments where the GDPR requires that help.

6. Audit, return, and deletion

The Provider makes available the information needed to show compliance and allows audits on reasonable notice and under confidentiality. When the agreement ends, the Provider deletes or returns personal data at the Customer’s choice, and deletes copies, unless EU or Finnish law requires retention. Data may be kept for at most 90 days after the end so the Customer can retrieve it.

7. General

Amendments follow the change process in the terms. The Provider will not unilaterally change this DPA in a way that breaches Article 28 or materially reduces the protection described here. This DPA is governed by the laws of Finland.

Questions: timo@cansome.com. Privacy: Privacy Policy.

  • Sites
  • Boss
  • Social
  • Sales
  • Terms
  • Privacy
  • DPA
  • Withdrawal
  • Cookies

LinkedIn Facebook Instagram YouTube

© 2026 Cansome Oy (3328471-6). Hosted in Europe.