Legal
Data processing agreement (DPA)
Updated 3 May 2026
This English translation is provided for convenience. If the versions differ, the Finnish version prevails.
An agreement under Art. 28 GDPR that is signed as part of every Umasvoice subscription agreement. You can read the template here and request a PDF version for signature by email before subscribing.
1. Purpose of the agreement and the parties
Controller: the customer company (you).
Processor: Umas Oy (Business ID 3604932-4).
This DPA supplements the Umasvoice terms of service to the extent that the processor processes personal data on behalf of the controller. If there is a conflict between this agreement and the terms of service in data protection matters, this agreement applies.
2. Subject matter, duration and nature of the processing
- Subject matter: the information conveyed by telephone by the customers of the controller.
- Duration: for the term of the subscription agreement plus no more than 90 days after the agreement ends (deletion or anonymisation).
- Type: answering, automatic real-time processing (ASR, LLM, TTS), transcription, relaying to the controller, deletion. Call audio is not stored permanently by the processor or by its sub-processors.
- Purpose: handling calls on behalf of the controller, making bookings, summaries.
3. Categories of personal data and data subjects
- Data subjects: the customers and the prospective customers of the controller who call the number.
- Categories of personal data: name, telephone number, address (where needed), a text transcript and structured metadata (time, duration, category). Call audio is not stored.
- Special categories of data (Art. 9 GDPR) are not collected intentionally. If a caller discloses such data on their own initiative, it is removed from the transcript during the processing.
4. Obligations of the processor (Art. 28.3)
- Processes personal data only on the documented instructions of the controller.
- Ensures that the personnel of the processor are bound by confidentiality.
- Implements the technical and organisational security measures required by Art. 32 (encryption in transit and at rest in line with standard industry practice, two-factor authentication, an access log, EU routing as the primary option; transfers outside the EU under the standard contractual clauses).
- Does not use sub-processors other than through the procedure agreed in this agreement (see §5).
- Assists the controller in answering requests from data subjects (Art. 12 to 23).
- Assists in meeting the obligations of Art. 32 to 36 (personal data breach, DPIA, advice).
- Returns or deletes all personal data when the processing ends, at the choice of the controller.
- Makes available to the controller all information necessary to demonstrate compliance with the statutory obligations, and allows audits.
- AI transparency (EU AI Act Art. 50): the processor has programmed the Umasvoice service to tell the caller at the start of the call that they are speaking with an AI assistant. The controller undertakes not to remove this notice or otherwise prevent it from working.
5. Sub-processors
The processor uses sub-processors, which are listed and kept up to date in the privacy policy. The controller gives its general consent to these sub-processors by signing this agreement. The processor gives notice by email at least 30 days in advance before a new sub-processor is added or a current one is replaced. The controller has the right to object to the change on justified grounds, in which case the parties negotiate a solution or the agreement may be terminated.
6. Right of audit
The controller has the right to audit the processing of personal data by the processor once a year at its own cost, with reasonable advance notice (30 days). The audit may be carried out as a written questionnaire, remotely or, with the consent of the processor, on site. On request, the processor provides up-to-date security reports and self-assessments.
7. Personal data breach (Art. 33)
The processor notifies the controller of a personal data breach without undue delay and no later than 72 hours after becoming aware of the breach. The notification states the nature of the breach, the estimated effects and the corrective measures taken or proposed.
8. Return and deletion of data
When the agreement ends, the processor deletes or returns all personal data within 90 days, at the choice of the controller. After that, the data disappears from the backups in line with the rotation cycle within no more than 35 days.
9. Service level (SLA)
Umasvoice targets 99.5 % availability per month, excluding maintenance windows announced in advance. Availability is calculated as the proportion of the total time of the calendar month during which the service is available to callers. If availability falls below 99.5 %, the controller is entitled to a refund of the monthly fee in reasonable proportion to the shortfall, and the details are recorded in the agreement to be signed.
10. Applicable law and jurisdiction
This agreement is governed by Finnish law and by the EU General Data Protection Regulation (2016/679). Disputes are heard in Espoon käräjäoikeus (the District Court of Espoo).
11. Version for signature
The DPA template for signature is provided as a PDF on request. Enquiries: info@umasity.com. The agreement is signed on behalf of both parties before the service is taken into production use.