When you bring your event speakers' data into Deckhandoff, you are the controller and Deckhandoff the processor. Article 28 of the GDPR requires a written data processing agreement between them. Below is a ready agreement with Deckhandoff's details filled in.
How to make the agreement
- Copy the agreement and fill in the parts in square brackets: your organisation's details and contact person.
- Sign the agreement and send it as a PDF to asiakaspalvelu@deckhandoff.fi.
- You get the agreement signed by Deckhandoff back by email.
DATA PROCESSING AGREEMENT
Parties
Controller: [Customer name], business ID [business ID], [address], contact person [name, email] ("Customer")
Processor: Tmi Oskari Järvelin (Deckhandoff), business ID 3284249-9, Kaislatie 11 L 54, 90150 Oulu, Finland, asiakaspalvelu@deckhandoff.fi ("Deckhandoff")
1. Purpose and scope
This agreement covers the personal data that Deckhandoff processes on the Customer's behalf when the Customer uses the Deckhandoff service to collect, check and deliver its event speakers' presentation files to the technical partner. It supplements the use of the service and applies for as long as Deckhandoff processes personal data on the Customer's behalf. Deckhandoff processes data about the customer relationship and billing as a controller, and this agreement does not cover it.
2. Description of the processing
Nature and purpose: reading the schedule from the Customer's sheet; sending personal upload links and invitations, confirmations, reminders and notices; storing, checking, naming and delivering uploaded files to the event's Google Drive folder; creating thumbnails; maintaining the manifest; and showing the status to the Customer, speakers and the technical partner.
Data subjects: the event's speakers, the technical partner's contact persons and the Customer's staff who use the service.
Personal data:
- speakers: first and last name, email address, language, sessions (date, time and title), the upload link's token (stored as a hash and encrypted), when the link was last used, uploaded files and their content, original file names, versions and upload times, check results, answers to the sound question, the own-computer declaration with notes, and a log of messages sent (recipient, message type and time)
- the technical partner's contact persons: name or company name, email address for notices, when the view was last used, and fetch and confirmation marks
- the Customer's staff: the email address used to sign in and to mark versions uploaded on a speaker's behalf, sign-in times and organisation membership
- technical logs: server request data, which may include an IP address.
Special categories of data: the service is not intended for processing them. Deckhandoff does not interpret the content of presentations; the checks only read the file's structure. If presentations contain special category data, the Customer is responsible for the legal basis for processing it.
Duration: for as long as the service is used and until the deletion described in section 10 is complete.
3. Customer's obligations
The Customer is responsible for having a lawful basis for the processing, for providing data subjects with a privacy notice, and for bringing only necessary data into the service. The Customer gives its processing instructions through the service settings (for example the retention period, naming pattern and Drive folder) and this agreement.
4. Deckhandoff's obligations
Deckhandoff
- processes personal data only on the Customer's documented instructions, including with regard to transfers, unless required to do so by law
- informs the Customer if, in its opinion, an instruction infringes data protection law
- ensures that persons processing the data have committed to confidentiality
- implements the technical and organisational security measures in the annex
- assists the Customer in responding to data subject requests and carries out corrections and deletions the Customer asks for without undue delay
- assists the Customer in meeting its obligations regarding security, breach notification, impact assessments and prior consultation
- makes available to the Customer the information needed to demonstrate compliance with this agreement.
5. Staff access to data
Deckhandoff's administrator may process the Customer's event data for customer support at the Customer's request, or where strictly necessary to keep the service working, for example to investigate a failed delivery.
6. Sub-processors
The Customer gives general authorisation to use sub-processors. At the time of signing, the sub-processors are:
- Cloudflare, Inc. – servers, background jobs and file storage (files in Western Europe). Transfers outside the EU/EEA are based on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
- Supabase Inc. – database (Ireland). Transfers outside the EU/EEA are based on the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914).
- Google (Google Ireland Limited and Google LLC) – Google Drive, Sheets and Slides: delivering files to the event's Drive folder, the manifest, reading the schedule and thumbnails. Transfers are based on the EU–US Data Privacy Framework or standard contractual clauses.
- Proton AG – sending email (Switzerland, which has a European Commission adequacy decision).
Deckhandoff notifies the Customer of changes to sub-processors at least 30 days in advance. The Customer may object to a change on reasonable grounds and, if necessary, stop using the service. Deckhandoff binds sub-processors to equivalent data protection obligations and is responsible for their performance.
7. Transfers outside the EU/EEA
Data may be transferred outside the EU/EEA only on the grounds described in section 6 or another ground under Chapter V of the GDPR.
8. Personal data breaches
Deckhandoff notifies the Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware of it. The notification includes the known information on the nature of the breach, the data subjects and amount of data concerned, the likely consequences and the measures taken.
9. Audits
On request, Deckhandoff provides the information the Customer needs to verify compliance with this agreement. The Customer may, at its own cost, audit the processing or have it audited by an independent auditor at most once a year, with 30 days' notice.
10. Deletion of data
The service deletes the event's files and thumbnails from its own storage and anonymises the event's personal data automatically when the retention period chosen in the Customer's settings (90 days by default) has passed since the last day of the event. The schedule structure and statistics, which cannot identify anyone, are kept.
The event's Google Drive folder (delivered files and the manifest) is not deleted automatically. If the folder is in the Customer's own Google Drive, the Customer is responsible for keeping and deleting it. If the folder is in Deckhandoff's shared drive, Deckhandoff transfers it to the Customer or deletes it within 30 days of the Customer's request. Temporary copies made for thumbnails are moved to the trash at once, and Google deletes them from the trash within 30 days.
When the use of the service ends, Deckhandoff deletes the Customer's remaining personal data within 30 days of the Customer's request, unless required by law to retain it. Data is removed from backups as part of the normal backup rotation, and technical logs are deleted within 7 days.
11. Liability and governing law
The parties' liability is determined under Article 82 of the GDPR. This agreement is governed by Finnish law. Disputes are settled in the Oulu District Court.
Annex: technical and organisational security measures
- Data in transit is encrypted (HTTPS/TLS, HSTS).
- Files are uploaded from the browser directly to private storage with short-lived signed URLs. Storage and the database also encrypt data at rest.
- The database cannot be reached from the browser or through a public API: all queries go through the server, and row-level security is on with no public permissions.
- Speakers and the technical partner use unguessable personal links. Of a link's token only a SHA-256 hash is stored, plus an encrypted copy (AES-GCM) for re-sending the invitation. A link can be renewed or revoked, and the old one stops working at once. A partner sees only their own event.
- Organisers sign in with a single-use link sent by email, valid for 20 minutes. The session is in an HttpOnly cookie, only its hash is stored, and it ends after 30 days or on sign-out. Every request checks that the user is a member of the event's organisation, and other organisations' events cannot be opened.
- Link pages are not indexed by search engines or stored in caches, and no referrer is passed to other sites.
- The service account can only access the service's own Drive folders and the sheets shared with it.
- Secret keys are kept as server environment secrets, not in source code.
- Presentations are checked in code by reading the file's structure. Content is not processed with AI or disclosed to third parties.
- Personal data is deleted or anonymised automatically when the retention period ends.
Signatures
Customer: [place and date] [name and position] [signature]
Deckhandoff: [place and date] Oskari Järvelin [signature]What the agreement covers
- Which data and whose is processed, and how Deckhandoff may process it: only on your instructions.
- Sub-processors (Cloudflare, Supabase, Google and Proton), the grounds for transfers and notice of changes 30 days in advance.
- Breach notification, audits, and deleting data after the retention period and when the agreement ends.
- An annex with the service's technical and organisational security measures.
Speakers are told about the processing in the privacy notice: Privacy notice for speakers.
The template is not legal advice. If your organisation has its own data processing agreement template, you can send it to the same address for review.