Databehandleraftale (DPA)
Sidst opdateret: 2026-07-14
Sidst opdateret underdatabehandleres side: 2026-07-04
Denne Databehandleraftale beskriver vilkårene under hvilke vi behandler personoplysninger på dine vegne.
Denne databehandleraftale (aftale) skitserer forpligtelserne og betingelserne, under hvilke Petitions.com Group Oy (tjenesteudbyder) behandler personoplysninger på vegne af underskriftindsamlingens forfatter (underskriftindsamlingens forfatter eller dataansvarlig) i forbindelse med levering af online hostingtjenester til underskriftindsamlinger (tjenester).
Ændring af Vilkår
Vi forbeholder os retten til at ændre eller modificere disse vilkår til enhver tid uden forudgående varsel.
Definitioner og roller
- Tjenesteudbyder: Skrivunder.net (Petitions.com Group Oy), der handler som Databehandler, behandler personoplysninger på vegne af Dataansvarlig som nødvendigt for at levere Tjenesterne.
- Dataansvarlig: Underskriftindsamlingens forfatter, som fastlægger formålene med og midlerne til behandling af personoplysninger indhentet fra underskriverne af deres underskriftindsamling. Som forfatter til en underskriftindsamling, der hostes på Skrivunder.net, betragtes du som dataansvarlig. Du bestemmer indholdet af underskriftindsamlingen, hvad der spørges fra underskriverne, formålet med behandlingen af deres personoplysninger, og hvor længe personoplysningerne opbevares. Skrivunder.net leverer en online platform til oprettelse og hosting af underskriftindsamlinger, hvilket muliggør din rolle som Data Controller med autonomi til at forme underskriftindsamlingens datainnsamling og brug i overensstemmelse med dine mål og juridiske forpligtelser.
Omfang af Behandling
The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Omfanget af behandlingsaktiviteter er begrænset til hosting, administration og facilitering af online underskriftindsamlinger.
As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.
The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.
Databeskyttelse
Tjenesteudbyderen forpligter sig til at implementere tekniske og organisatoriske foranstaltninger for at sikre personoplysninger mod uautoriseret adgang, tab eller skade.
Forbudt Databehandling
Det er forbudt at anmode om personlige identifikationsnumre (såsom nationale ID-numre) fra underskrivere.
Underbehandlere
Tjenesteudbyderen kan engagere underdatabehandlere til at hjælpe med at levere Tjenesterne. Tjenesteudbyderen vil sikre, at underdatabehandlere overholder databeskyttelsesforpligtelser, der er i overensstemmelse med denne DPA. Du anerkender og accepterer, at Tjenesteudbyderen har ret til at vælge og udskifte underdatabehandlere efter behov for at levere Tjenesterne effektivt.
Liste over underdatabehandlere. (Sidst opdateret: 2026-07-04)
Dataansvarliges Ansvar
Den dataansvarlige er ansvarlig for at sikre, at indsamling, behandling og håndtering af personoplysninger overholder alle gældende love og regler.
Dataansvarlig Identifikation
I henhold til General Databeskyttelse Regulation (GDPR) kræves det, at dataansvarliges identitet tydeligt angives. Følgende bestemmelser gælder for forfattere af underskriftindsamlinger, der bruger vores hjemmeside:
Individuelle underskriftindsamlingsforfattere
Hvis du som individ opretter en underskriftindsamling, er du forpligtet til at oplyse dit fulde juridiske navn. Dette fungerer som din identifikation som dataansvarlig i henhold til GDPR.
Organisatoriske underskriftindsamlingsforfattere
Hvis en underskriftindsamling oprettes på vegne af en organisation, skal organisationens fulde juridiske navn oplyses. Derudover skal organisationen udpege og angive kontaktoplysninger på en repræsentant, der er ansvarlig for databehandlingsaktiviteter, såsom en databeskyttelsesrådgiver (DPO) eller lignende.
Registreredes rettigheder
Den dataansvarlige skal sikre, at registrerede (underskriftindsamlingsdeltagere) kan udøve deres rettigheder i henhold til GDPR, såsom retten til adgang, berigtigelse eller sletning af deres data, eller til at indgive en klage til en tilsynsmyndighed.
Håndtering af anmodninger om sletning fra registrerede fra underskriftsindsamlere
The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.
Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.
When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.
The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.
Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.
Tekniske logfiler kan indeholde personoplysninger, såsom IP-adresser eller metadata om levering af e-mails. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.
The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.
Handling Rectification Requests from Signatories
The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.
Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.
The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.
Notifying Recipients
Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.
Ansvarlighed og Overholdelse
Den dataansvarlige skal kunne demonstrere overholdelse af GDPR, herunder besvare forespørgsler fra registrerede vedrørende deres personoplysninger.
Fortrolighedspolitik eller Meddelelse
En klar og tilgængelig privatlivspolitik eller meddelelse skal gives, der beskriver, hvordan personoplysninger behandles, formålene med behandlingen og hvordan registrerede kan udøve deres rettigheder.
Meddelelse om Ændringer
Underskriftindsamlingsforfattere er forpligtet til at underrette Skrivunder.net (Petitions.com Group Oy) om eventuelle ændringer i deres status som dataansvarlig eller i deres repræsentants kontaktoplysninger.
Årlig gennemgang af databehandling
Underskriftindsamlingens forfatter er forpligtet til at gennemføre en årlig gennemgang for at fastslå, om der fortsat er en gyldig grund til at fortsætte behandlingen af underskrivernes personoplysninger. Denne gennemgang bør vurdere nødvendigheden og relevansen af dataene i forhold til formålet med underskriftindsamlingen. Hvis underskriftindsamlingens forfatter fastslår, at der ikke længere er en gyldig grund til at fortsætte behandlingen af dataene, skal de tage passende skridt for at ophøre behandlingen og igangsætte sletningen af dataene i overensstemmelse med gældende databeskyttelseslove.
Use of Up-to-Date Signature Data
Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.
Opbevaring og sletning af data
Skulle den dataansvarlige (forfatteren af underskriftindsamlingen) bryde nogen vilkår i databehandleraftalen (DPA), herunder men ikke begrænset til manglende gennemførelse af en årlig gennemgang af databehandlingsaktiviteter eller manglende leverance af en gyldig begrundelse for den fortsatte behandling af underskrivernes personoplysninger, forbeholder tjenesteudbyderen sig retten til at fjerne eller slette de personoplysninger, der er tilknyttet deres underskriftindsamling.
Ansvarsbegrænsning
Under ingen omstændigheder skal databehandlerens samlede ansvar over for den dataansvarlige for alle skader, tab og sagsanlæg, uanset om det drejer sig om kontrakt, erstatningsansvar (herunder uagtsomhed) eller andet, overstige det samlede beløb betalt af den dataansvarlige til databehandleren under denne aftale.
Gældende lovgivning
Denne aftale er underlagt finsk lovgivning.