How Transtar processes personal data on behalf of its customers, under EU law and EU data residency.
This Data Processing Agreement ("DPA") forms part of the service agreement ("Agreement") between Transtar Networks Oy (business ID 3407638-8, Hitsaajankatu 6 A 40, 00810 Helsinki, Finland — "Transtar", the "Processor") and the customer ("Customer", the "Controller"). It reflects the parties' agreement on the processing of personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable EU data protection law.
Terms such as Personal Data, Processing, Controller, Processor, Data Subject, Supervisory Authority, Personal Data Breach, and Special Categories of Personal Data carry the meanings given in the GDPR.
Subprocessor means any third party engaged by Transtar to process Personal Data on behalf of the Customer. Services means the services Transtar provides under the Agreement. Standard Contractual Clauses (SCCs) means the clauses adopted by the European Commission under Implementing Decision (EU) 2021/914.
The Customer is the Controller and Transtar is the Processor for Personal Data processed under the Agreement, except where the Customer acts as a processor for a third-party controller, in which case Transtar acts as a subprocessor. Each party complies with its obligations under data protection law.
The subject matter, duration, nature and purpose of processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.
Transtar processes Personal Data only on the Customer's documented instructions, including for international transfers, unless required otherwise by EU or member-state law — in which case Transtar informs the Customer before processing, unless legally prohibited. The Agreement, this DPA, and the Customer's use of the Services constitute the Customer's complete documented instructions.
Transtar informs the Customer if, in its opinion, an instruction infringes data protection law. Transtar does not sell Personal Data and does not use it for any purpose other than providing the Services. Customer Personal Data is never used to train shared or third-party AI models.
Transtar ensures that persons authorised to process Personal Data are bound by confidentiality, and that access is limited to personnel who require it to perform the Agreement, on a least-privilege basis.
Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, together with the risk to Data Subjects, Transtar implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with Article 32 GDPR. The measures in place are described in Annex II.
The Customer provides general authorisation for Transtar to engage Subprocessors, listed in Annex III. Transtar informs the Customer of any intended addition or replacement at least thirty (30) days in advance, allowing the Customer to object on reasonable data protection grounds.
Transtar binds each Subprocessor by written contract to data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Subprocessor's performance.
Data Subject rights. Taking into account the nature of processing, Transtar assists the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise Data Subject rights under Chapter III GDPR.
Security, breach and DPIA. Transtar assists the Customer in complying with Articles 32 to 36 GDPR — security, breach notification, data protection impact assessments, and prior consultation — taking into account the nature of processing and the information available to Transtar.
Transtar notifies the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification describes, to the extent available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Transtar cooperates with the Customer to mitigate and remediate.
On termination or expiry of the Services, and at the Customer's choice, Transtar deletes or returns all Personal Data and deletes existing copies within thirty (30) days, unless EU or member-state law requires retention.
Transtar makes available all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allows for and contributes to audits and inspections by the Customer or a mandated auditor, no more than once per twelve (12) months — save where required by a Supervisory Authority or following a Personal Data Breach — subject to reasonable notice, confidentiality, and minimal disruption. Transtar may satisfy audit obligations through relevant third-party certifications or reports where available.
Transtar processes Customer Personal Data within the EU and does not transfer it to a third country in its standard deployment. Where a transfer is necessary and instructed by the Customer, it is governed by an appropriate mechanism under Chapter V GDPR, including the Standard Contractual Clauses and, where required, a Transfer Impact Assessment.
This DPA takes effect on the effective date of the Agreement and remains in force for as long as Transtar processes Personal Data on behalf of the Customer. Where this DPA conflicts with the Agreement on data protection, this DPA prevails. Liability is subject to the limitations set out in the Agreement.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud EMEA Limited | Compute, vector index, model inference | EU regions |
| Microsoft Ireland Operations Limited | Compute, key management (HSM) | EU regions |
| Amazon Web Services EMEA SARL | Compute, managed model inference (Bedrock) | EU regions |