Data Processing Agreement (DPA)
Last Updated: July 14 2026
Last Updated the Subprocessors page: July 04 2026
This DPA outlines the terms under which we process personal data on your behalf.
This Data Processing Agreement (Agreement) outlines the obligations and conditions under which Petitions.com Group Oy (Service Provider) processes personal data on behalf of the petition author (Petition Author or Data Controller) in the provision of online petition hosting services (Services).
Modification of Terms
We reserve the right to change or modify these Terms at any time without prior notice.
Definitions and Roles
- Service Provider: Petitions.com (Petitions.com Group Oy), acting as the Data Processor, processes personal data on behalf of the Data Controller as necessary to deliver the Services.
- Data Controller: The Petition Author, who determines the purposes and means of the processing of personal data collected from the signatories of their petition. As the author of a petition hosted on Petitions.com, you are considered the Data Controller. You decide the content of the petition, what is asked from the signatories, the purposes for processing their personal data, and the duration for which the personal data is stored. Petitions.com provides an online platform for creating and hosting petitions, facilitating your role as Data Controller with the autonomy to shape the petition's data collection and usage according to your objectives and legal obligations.
Scope of Processing
The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. The scope of processing activities is limited to hosting, managing, and facilitating online petitions.
As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.
The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.
Data Protection
The Service Provider commits to implementing technical and organizational measures to ensure the security of personal data against unauthorized access, loss, or damage.
Prohibited Data Collection
It is prohibited to request personal identification numbers (such as national ID numbers) from signatories.
Subprocessors
The Service Provider may engage subprocessors to assist in providing the Services. The Service Provider will ensure subprocessors comply with data protection obligations consistent with this DPA. You acknowledge and agree that The Service Provider retain the discretion to select and replace subprocessors as needed to provide the Services efficiently.
List of the subprocessors. (Last Updated: July 04 2026)
Data Controller Responsibilities
The Data Controller is responsible for ensuring that the collection, processing, and handling of personal data comply with all applicable laws and regulations.
Data Controller Identification
Under the General Data Protection Regulation (GDPR), it is required that the identity of the data controller is clearly stated. The following provisions are made for petition authors using our website:
Individual Petition Authors
If you, as an individual, are creating a petition, you are required to provide your full legal name. This serves as your identification as the data controller for the purposes of the GDPR.
Organizational Petition Authors
If a petition is created on behalf of an organization, the organization's full legal name must be provided. Additionally, the organization should designate and provide contact details of a representative responsible for data processing activities, such as a Data Protection Officer (DPO) or similar.
Data Subject Rights
The data controller must ensure that data subjects (petition signatories) can exercise their rights under the GDPR, such as the right to access, rectify, or erase their data, or to lodge a complaint with a supervisory authority.
Handling Data Subject Erasure Requests from Signatories
The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.
Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.
When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.
The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.
Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.
Technical logs may contain personal data, such as IP addresses or email delivery metadata. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.
The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.
Handling Rectification Requests from Signatories
The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.
Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.
The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.
Notifying Recipients
Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.
Accountability and Compliance
The data controller must be able to demonstrate compliance with the GDPR, including responding to data subjects' requests regarding their personal data.
Privacy Policy or Notice
A clear and accessible privacy policy or notice must be provided, outlining how personal data is processed, the purposes of processing, and how data subjects can exercise their rights.
Notification of Changes
Petition authors are required to notify Petitions.com (Petitions.com Group Oy) of any changes in their status as a data controller or in their representative's contact details.
Annual Review of Data Processing
The Petition Author is required to conduct an annual review to ascertain whether there is still a valid reason for the continued processing of the personal data of the signatories. This review should assess the necessity and relevance of the data in relation to the purpose of the petition. If the Petition Author determines that there is no longer a valid reason to continue processing the data, they must take appropriate steps to cease the processing and initiate the deletion of the data in accordance with applicable data protection laws.
Use of Up-to-Date Signature Data
Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.
Data Retention and Deletion
Should the Data Controller (the author of the petition) breach any terms of the Data Processing Agreement (DPA), including but not limited to failure in conducting an annual review of data processing activities or providing a valid justification for ongoing processing of signatories' personal data, the Service Provider reserves the right to remove or delete the personal data associated with their petition.
Limitation of Liability
In no event shall the total liability of the data processor to the data controller for all damages, losses, and causes of action, whether in contract, tort (including negligence), or otherwise, exceed the total amount paid by the data controller to the data processor under this agreement.
Applicable law
This Agreement shall be governed by the laws of Finland.