Legal
Data processing agreement
Article 28 terms for customers who use Tiuha to email their own subscribers.
Last updated 19 August 2026
This DPA forms part of the Terms of Service between Puida Oy (“Processor”) and the customer (“Controller”). It applies whenever we process personal data on your behalf. Where it conflicts with the Terms, this document wins on data protection.
1. Roles
You are the controller of your subscribers' personal data. We are your processor. You decide the purposes; we act only on your documented instructions, of which using the service as designed is one.
We are an independent controller only for our own account and billing data, and for the marketing described in our privacy policy.
2. Scope
| Subject matter | Collecting subscribers, storing consent, and delivering email on the Controller's behalf |
|---|---|
| Duration | While the Controller holds an account, plus the deletion window in section 9 |
| Nature and purpose | Storage, segmentation, rendering and transmission of email; recording consent and delivery outcomes |
| Categories of data | Email address; name where supplied; language; custom fields the Controller defines; consent evidence including IP address, user-agent, timestamp and the consent wording shown; delivery, bounce, complaint, open and click events; message content authored by the Controller |
| Data subjects | The Controller's subscribers, customers and enquirers |
| Special categories | None. The service is not designed for special-category data and it must not be uploaded. |
3. Our obligations
- Process only on your documented instructions, including for transfers, unless law requires otherwise — in which case we tell you first unless that law forbids it.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Apply the security measures in section 5.
- Respect the sub-processor conditions in section 4.
- Help you answer data subject requests, taking account of what the service can do — export and erasure are built in and self-serve.
- Help you with security, breach notification and impact assessments, given the information available to us.
- Delete or return the data at the end, per section 9.
- Make available what you need to demonstrate compliance with Article 28.
4. Sub-processors
You give general authorisation for the sub-processors below. We give reasonable notice before adding or replacing one, and you may object on reasonable data-protection grounds; if the objection cannot be resolved you may terminate the affected service.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services — Amazon SES | Outbound email delivery and delivery events | EU — eu-north-1, Stockholm |
| Tilus (Puida Oy) | Application hosting, database, object storage, CDN | EU — Finland |
Both are in the EU, so routine processing involves no third-country transfer. If that changes we will put an appropriate transfer mechanism in place and tell you which one.
5. Security
- Encryption in transit on all connections, and opportunistic TLS on outbound mail.
- Tenant isolation enforced in the application and reinforced by row-level security in the database.
- Scoped API keys stored only as a peppered hash; the plaintext is shown once and is never recoverable.
- Administrative access behind a single sign-on identity provider.
- Least-privilege credentials for the mail provider.
- Automated, durable backups of application data.
6. Personal data breach
We notify you without undue delay after becoming aware of a breach affecting your data, with what we know at the time and updates as we learn more. Notifying supervisory authorities and data subjects is yours to do as controller; we give you what you need to do it.
7. Data subject requests
If a data subject contacts us directly about data you control, we do not answer on your behalf — we point them to you and tell you it happened. The service provides export and erasure so you can act without waiting for us. Erasure keeps only a suppression record, so the address cannot be accidentally re-imported later; that record exists to protect the subject.
8. Audit
On reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise, we will answer reasonable written questions about our processing and provide the documentation we hold.
9. Deletion and return
You can export at any time. Within 30 days of termination we delete your personal data from live systems, except what law requires us to keep, and let backups age out on their normal cycle. Suppression records may be retained where deleting them would risk re-contacting someone who asked not to be contacted.
10. Liability
The limits in the Terms of Service apply to this DPA, except where the GDPR imposes liability that cannot be limited by agreement.