Effective date: February 2026
Between:
JPu Engineering (J. Puska, sole proprietorship)
Muinaistie 33, 96460 Rovaniemi, Finland
Business ID: 3581353-8
("Processor", "we")
And:
The Customer organization using the Erppi ERP service ("Controller", "you")
This Data Processing Agreement ("DPA") supplements the Terms of Service and applies to the extent that the Processor processes personal data on behalf of the Controller in connection with providing the Erppi ERP service ("Service").
The Processor processes personal data solely for the purpose of providing the Erppi ERP service to the Controller, including:
Processing continues for the duration of the Controller's subscription plus 30 days after termination, during which the Controller may export their data. After this period, all Customer Data will be permanently deleted.
The Processor shall:
Process personal data only on the documented instructions of the Controller, including as set out in the Terms of Service and this DPA, unless required to do so by EU or Finnish law (in which case the Processor shall inform the Controller of that legal requirement before processing, unless prohibited by law).
Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Assist the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligation to respond to data subject requests. The Service provides built-in tools for:
Notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach. The notification shall include:
Provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities, where required.
At the Controller's choice, delete or return all personal data after the end of the provision of services, and delete existing copies unless EU or Finnish law requires storage.
Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes GDPR or other EU/Finnish data protection law.
The Controller shall:
The Controller hereby provides general written authorization for the Processor to engage the following sub-processors:
| Sub-Processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Cloudflare, Inc. | Network tunnel, DDoS protection, DNS | EU (traffic routed through EU data centers); USA (EU-US DPF certified) | Network traffic metadata, IP addresses |
| Stripe, Inc. | Payment processing | USA (EU-US DPF certified) | Customer email, name, payment data |
The Processor shall inform the Controller at least 30 days in advance of any intended changes to the list of sub-processors. The Controller may object to the change within 14 days. If the Controller objects and the parties cannot resolve the objection, the Controller may terminate the Service with immediate effect.
The Processor shall ensure that each sub-processor is bound by data protection obligations no less protective than those in this DPA.
All primary data processing occurs within the EU/EEA.
Where personal data is transferred to a sub-processor outside the EU/EEA, the Processor ensures that appropriate safeguards are in place:
The Processor shall inform the Controller if it becomes aware that a transfer safeguard is invalidated or may no longer be relied upon.
The Processor is not required to appoint a Data Protection Officer under GDPR Article 37, given the nature and scale of processing activities. The Processor's contact for data protection matters:
Email: [email protected]
Liability under this DPA is subject to the limitations set out in the Terms of Service, except that these limitations do not apply to breaches of this DPA resulting from the Processor's:
This DPA enters into force when the Controller begins using the Service and remains in effect for the duration of the service relationship. Provisions that by their nature should survive termination will survive, including obligations regarding data deletion, confidentiality, and cooperation with audits.
This DPA is governed by the laws of Finland. Any disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.
This DPA may be updated to reflect changes in applicable law or our processing activities. The Controller will be notified of material changes at least 30 days in advance.
Processor: JPu Engineering
Name: Jani Puska
Title: Yrittaja
Controller: [Customer Organization]
Name: [Name]
Title: [Title]
For SaaS customers, this DPA is accepted electronically upon acceptance of the Terms of Service.
© JPu Engineering. All rights reserved.