Legal · GDPR Article 28

Data Processing Agreement.

How Transtar processes personal data on behalf of its customers, under EU law and EU data residency.

Last updated · June 2026

This Data Processing Agreement ("DPA") forms part of the service agreement ("Agreement") between Transtar Networks Oy (business ID 3407638-8, Hitsaajankatu 6 A 40, 00810 Helsinki, Finland — "Transtar", the "Processor") and the customer ("Customer", the "Controller"). It reflects the parties' agreement on the processing of personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable EU data protection law.

01 · Definitions

Definitions

Terms such as Personal Data, Processing, Controller, Processor, Data Subject, Supervisory Authority, Personal Data Breach, and Special Categories of Personal Data carry the meanings given in the GDPR.

Subprocessor means any third party engaged by Transtar to process Personal Data on behalf of the Customer. Services means the services Transtar provides under the Agreement. Standard Contractual Clauses (SCCs) means the clauses adopted by the European Commission under Implementing Decision (EU) 2021/914.

02 · Roles and scope

Roles and scope

The Customer is the Controller and Transtar is the Processor for Personal Data processed under the Agreement, except where the Customer acts as a processor for a third-party controller, in which case Transtar acts as a subprocessor. Each party complies with its obligations under data protection law.

The subject matter, duration, nature and purpose of processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.

03 · Processing on documented instructions

Processing on documented instructions

Transtar processes Personal Data only on the Customer's documented instructions, including for international transfers, unless required otherwise by EU or member-state law — in which case Transtar informs the Customer before processing, unless legally prohibited. The Agreement, this DPA, and the Customer's use of the Services constitute the Customer's complete documented instructions.

Transtar informs the Customer if, in its opinion, an instruction infringes data protection law. Transtar does not sell Personal Data and does not use it for any purpose other than providing the Services. Customer Personal Data is never used to train shared or third-party AI models.

04 · Confidentiality

Confidentiality

Transtar ensures that persons authorised to process Personal Data are bound by confidentiality, and that access is limited to personnel who require it to perform the Agreement, on a least-privilege basis.

05 · Security of processing

Security of processing

Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, together with the risk to Data Subjects, Transtar implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with Article 32 GDPR. The measures in place are described in Annex II.

06 · Subprocessors

Subprocessors

The Customer provides general authorisation for Transtar to engage Subprocessors, listed in Annex III. Transtar informs the Customer of any intended addition or replacement at least thirty (30) days in advance, allowing the Customer to object on reasonable data protection grounds.

Transtar binds each Subprocessor by written contract to data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Subprocessor's performance.

07 · Assistance to the Customer

Assistance to the Customer

Data Subject rights. Taking into account the nature of processing, Transtar assists the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise Data Subject rights under Chapter III GDPR.

Security, breach and DPIA. Transtar assists the Customer in complying with Articles 32 to 36 GDPR — security, breach notification, data protection impact assessments, and prior consultation — taking into account the nature of processing and the information available to Transtar.

08 · Personal Data Breach

Personal Data Breach

Transtar notifies the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification describes, to the extent available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Transtar cooperates with the Customer to mitigate and remediate.

09 · Return and deletion of data

Return and deletion of data

On termination or expiry of the Services, and at the Customer's choice, Transtar deletes or returns all Personal Data and deletes existing copies within thirty (30) days, unless EU or member-state law requires retention.

10 · Audits

Audits

Transtar makes available all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allows for and contributes to audits and inspections by the Customer or a mandated auditor, no more than once per twelve (12) months — save where required by a Supervisory Authority or following a Personal Data Breach — subject to reasonable notice, confidentiality, and minimal disruption. Transtar may satisfy audit obligations through relevant third-party certifications or reports where available.

11 · International transfers

International transfers

Transtar processes Customer Personal Data within the EU and does not transfer it to a third country in its standard deployment. Where a transfer is necessary and instructed by the Customer, it is governed by an appropriate mechanism under Chapter V GDPR, including the Standard Contractual Clauses and, where required, a Transfer Impact Assessment.

12 · Term and precedence

Term and precedence

This DPA takes effect on the effective date of the Agreement and remains in force for as long as Transtar processes Personal Data on behalf of the Customer. Where this DPA conflicts with the Agreement on data protection, this DPA prevails. Liability is subject to the limitations set out in the Agreement.

Annex I · Details of processing

Details of processing

Subject matter
Provision of the Transtar Services to the Customer.
Duration
For the term of the Agreement and any agreed retention period.
Nature & purpose
Hosting, processing, analysis and retrieval of regulatory and compliance data; provision of regulatory intelligence, reporting and related services.
Types of data
Authorised-user identifiers, names, business email addresses, account and authentication data, and usage data. The Services are not designed to process Special Categories of Personal Data.
Data subjects
The Customer's authorised users and personnel.
Frequency
Continuous, for the duration of the Services.
Annex II · Technical & organisational measures

Technical & organisational measures

  • Encryption — Personal Data encrypted in transit (TLS 1.2+) and at rest; key management via FIPS 140-2 Level 3 hardware security modules.
  • Access control — role-based, least-privilege access; multi-factor authentication for administrative access; centralised audit logging.
  • Data residency — processing within EU regions only; no transfers outside the EU in the standard deployment.
  • Isolation — logical separation of customer environments; customer data not used to train shared models.
  • Resilience — backups, monitoring, and a documented disaster-recovery process.
  • Incident response — documented breach-notification and response process aligned to GDPR, DORA and NIS2.
  • Personnel — confidentiality obligations and security awareness for personnel with access to Personal Data.
Annex III · Approved subprocessors

Approved subprocessors

SubprocessorPurposeLocation
Google Cloud EMEA LimitedCompute, vector index, model inferenceEU regions
Microsoft Ireland Operations LimitedCompute, key management (HSM)EU regions
Amazon Web Services EMEA SARLCompute, managed model inference (Bedrock)EU regions
Questions

Data protection enquiries

Contact our team directly.

admin@transtarnetworks.eu