Skrivunder.com

Databehandlingsavtal (DPA)

Senast uppdaterad: 2026-07-24

Senast uppdaterad underleverantörer-sidan: 2026-07-24

Detta DPA beskriver villkoren under vilka vi behandlar personuppgifter för din räkning.

Detta personuppgiftsbiträdesavtal (Avtal) beskriver skyldigheterna och villkoren under vilka Petitions.com Group Oy (Tjänsteleverantör) behandlar personuppgifter på uppdrag av namninsamlingens författare (Namninsamlingsförfattare eller Personuppgiftsansvarig) vid tillhandahållande av tjänster för värdtjänster av namninsamlingar online (Tjänster).

Ändring av villkor

Vi förbehåller oss rätten att ändra eller modifiera dessa villkor när som helst utan föregående meddelande.

Definitioner och Roller

  • Tjänsteleverantör: Skrivunder.com (Petitions.com Group Oy), agerar som Personuppgiftsbiträde och behandlar personuppgifter på uppdrag av Personuppgiftsansvarig för att tillhandahålla tjänsterna.
  • Personuppgiftsansvarig: Namninsamlingens författare, som bestämmer ändamålen och medlen för behandlingen av personuppgifter som samlas in från signatärerna av deras namninsamling. Som författare av en namninsamling som är värd på Skrivunder.com anses du vara personuppgiftsansvarig. Du bestämmer innehållet i namninsamlingen, vad som begärs från undertecknarna, ändamålen för behandlingen av deras personuppgifter och hur länge personuppgifterna lagras. Skrivunder.com tillhandahåller en onlineplattform för att skapa och vara värd för namninsamlingar, vilket underlättar din roll som Personuppgiftsansvarig med möjligheten att utforma namninsamlingens datainsamling och användning enligt dina mål och juridiska skyldigheter.

Bearbetningens omfattning

The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Omfattningen av behandlingsaktiviteterna är begränsad till att vara värd för, hantera och underlätta online namninsamlingar.

As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.

The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.

Dataskydd

Tjänsteleverantören förbinder sig att genomföra tekniska och organisatoriska åtgärder för att säkerställa säkerheten för personuppgifter mot obehörig åtkomst, förlust eller skada.

Förbjuden insamling av data

Det är förbjudet att begära personnummer (såsom nationella ID-nummer) från undertecknarna.

Underbiträden

Tjänsteleverantören kan anlita underbiträden för att bistå med att tillhandahålla tjänsterna. Tjänsteleverantören kommer att säkerställa att underbiträden uppfyller dataskyddsförpliktelser i enlighet med detta personuppgiftsbiträdesavtal (DPA). Du bekräftar och godkänner att tjänsteleverantören behåller rätten att välja och ersätta underbiträden efter behov för att tillhandahålla tjänsterna effektivt.

Lista över underbiträden. (Senast uppdaterad: 2026-07-24)

Personuppgiftsansvarigs Ansvar

Personuppgiftsansvarig är ansvarig för att säkerställa att insamling, bearbetning och hantering av personuppgifter följer alla tillämpliga lagar och förordningar.

Personuppgiftsansvarigs identitet

Enligt dataskyddsförordningen (GDPR) krävs det att den personuppgiftsansvariges identitet anges tydligt. Följande bestämmelser gäller för namninsamlingsförfattare som använder vår webbplats:

Individuella namninsamlingsförfattare

Om du som individ skapar en namninsamling måste du ange ditt fullständiga juridiska namn. Detta fungerar som din identifiering som personuppgiftsansvarig enligt GDPR.

Organisationsnamninsamlingsförfattare

Om en namninsamling skapas på uppdrag av en organisation, måste organisationens fullständiga juridiska namn anges. Dessutom ska organisationen utse och tillhandahålla kontaktuppgifter till en representant som är ansvarig för databehandlingsaktiviteter, såsom en dataskyddsombud (DPO) eller liknande.

Registrerades rättigheter

Personuppgiftsansvarig måste säkerställa att registrerade (namninsamlingsundertecknare) kan utöva sina rättigheter enligt GDPR, såsom rätten att få tillgång till, rätta eller radera sina uppgifter, eller att lämna in ett klagomål hos en tillsynsmyndighet.

Hantering av begäranden från undertecknare om radering av registrerades uppgifter

The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.

Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.

When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.

The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.

Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.

Tekniska loggar kan innehålla personuppgifter, såsom IP-adresser eller metadata för e-postleverans. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.

The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.

Handling Rectification Requests from Signatories

The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.

Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.

The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.

Notifying Recipients

Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.

Ansvarsskyldighet och efterlevnad

Personuppgiftsansvarig måste kunna visa efterlevnad av GDPR, inklusive att svara på registrerades förfrågningar om deras personuppgifter.

Integritetspolicy eller meddelande

En tydlig och lättillgänglig integritetspolicy eller -meddelande måste tillhandahållas, som beskriver hur personuppgifter behandlas, ändamålen med behandlingen och hur registrerade kan utöva sina rättigheter.

Meddelande om Ändringar

Författare av namninsamlingar är skyldiga att meddela Skrivunder.com (Petitions.com Group Oy) om eventuella ändringar i deras status som personuppgiftsansvarig eller i deras representants kontaktuppgifter.

Årlig granskning av databehandling

Namninsamlingsförfattaren måste genomföra en årlig översyn för att fastställa om det fortfarande finns en giltig anledning för fortsatt behandling av de undertecknades personuppgifter. Denna granskning bör bedöma nödvändigheten och relevansen av uppgifterna i förhållande till syftet med namninsamlingen. Om namninsamlingens författare fastställer att det inte längre finns en giltig anledning att fortsätta behandlingen av uppgifterna, måste de vidta lämpliga åtgärder för att upphöra med behandlingen och initiera radering av uppgifterna i enlighet med tillämpliga dataskyddslagar.

Use of Up-to-Date Signature Data

Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.

Dataskydd och radering

Om personuppgiftsansvarig (författaren av namninsamlingen) bryter mot några villkor i avtalet om databehandling (DPA), inklusive men inte begränsat till underlåtenhet att genomföra en årlig granskning av databehandlingsaktiviteter eller att tillhandahålla en giltig motivering för fortsatt behandling av undertecknarnas personuppgifter, förbehåller sig tjänsteleverantören rätten att ta bort eller radera personuppgifter som är associerade med deras namninsamling.

Ansvarsbegränsning

Under inga omständigheter ska dataprocessorns totala ansvar gentemot datakontrollanten för alla skador, förluster och rättsliga åtgärder, vare sig enligt avtal, skadestånd (inklusive vårdslöshet) eller annat, överstiga det totala belopp som betalats av datakontrollanten till dataprocessorn enligt detta avtal.

Tillämplig lag

Detta avtal ska regleras av finsk lag.