Tiuha

Legal

Data processing agreement

Article 28 terms for customers who use Tiuha to email their own subscribers.

Last updated 19 August 2026

This DPA forms part of the Terms of Service between Puida Oy (“Processor”) and the customer (“Controller”). It applies whenever we process personal data on your behalf. Where it conflicts with the Terms, this document wins on data protection.

1. Roles

You are the controller of your subscribers' personal data. We are your processor. You decide the purposes; we act only on your documented instructions, of which using the service as designed is one.

We are an independent controller only for our own account and billing data, and for the marketing described in our privacy policy.

2. Scope

Subject matterCollecting subscribers, storing consent, and delivering email on the Controller's behalf
DurationWhile the Controller holds an account, plus the deletion window in section 9
Nature and purposeStorage, segmentation, rendering and transmission of email; recording consent and delivery outcomes
Categories of dataEmail address; name where supplied; language; custom fields the Controller defines; consent evidence including IP address, user-agent, timestamp and the consent wording shown; delivery, bounce, complaint, open and click events; message content authored by the Controller
Data subjectsThe Controller's subscribers, customers and enquirers
Special categoriesNone. The service is not designed for special-category data and it must not be uploaded.

3. Our obligations

4. Sub-processors

You give general authorisation for the sub-processors below. We give reasonable notice before adding or replacing one, and you may object on reasonable data-protection grounds; if the objection cannot be resolved you may terminate the affected service.

Sub-processorPurposeLocation
Amazon Web Services — Amazon SESOutbound email delivery and delivery eventsEU — eu-north-1, Stockholm
Tilus (Puida Oy)Application hosting, database, object storage, CDNEU — Finland

Both are in the EU, so routine processing involves no third-country transfer. If that changes we will put an appropriate transfer mechanism in place and tell you which one.

5. Security

6. Personal data breach

We notify you without undue delay after becoming aware of a breach affecting your data, with what we know at the time and updates as we learn more. Notifying supervisory authorities and data subjects is yours to do as controller; we give you what you need to do it.

7. Data subject requests

If a data subject contacts us directly about data you control, we do not answer on your behalf — we point them to you and tell you it happened. The service provides export and erasure so you can act without waiting for us. Erasure keeps only a suppression record, so the address cannot be accidentally re-imported later; that record exists to protect the subject.

8. Audit

On reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise, we will answer reasonable written questions about our processing and provide the documentation we hold.

9. Deletion and return

You can export at any time. Within 30 days of termination we delete your personal data from live systems, except what law requires us to keep, and let backups age out on their normal cycle. Suppression records may be retained where deleting them would risk re-contacting someone who asked not to be contacted.

10. Liability

The limits in the Terms of Service apply to this DPA, except where the GDPR imposes liability that cannot be limited by agreement.