vakka.aivakka.ai

Data processing agreement

Updated: 23 August 2026

This is Vakka AI Oy's standard data processing agreement under Article 28 GDPR. It forms part of every customer agreement, and this page is its public version: the same text is provided for signature as an annex to the customer agreement. On request we will also review a customer's own template — write to tietoturva@vakka.ai.

1. Parties, scope and precedence

The customer is the controller and Vakka AI Oy (business ID 3621436-9) is the processor. This agreement applies to all processing of personal data we carry out on the customer's behalf in providing the service.

On questions of personal data processing, this agreement prevails over the general terms of the customer agreement. The subject matter, duration, nature and purpose of the processing, and the categories of data subjects and personal data, are described in Annex A.

2. The processor's obligations

  • We process personal data only on the customer's documented instructions. The customer agreement, this agreement and the customer's own settings in the service constitute those instructions.
  • We tell the customer if we consider an instruction unlawful, and we do not carry it out until the matter is resolved.
  • We do not process the customer's personal data for our own purposes and do not use it to train AI models.
  • Only people whose work requires it have access to personal data, and they are bound by confidentiality.
  • We assist the customer to a reasonable extent with data subject requests, data protection impact assessments and any prior consultations.

3. The controller's obligations

  • The customer is responsible for the lawfulness of the processing, for the legal basis and for informing data subjects.
  • The customer decides what material is stored in the service and is responsible for having the right to store it.
  • The customer defines its users' roles and permissions, reviews them regularly and removes users who no longer need access.
  • The customer classifies sensitive attachments using the service's classifications (confidential, or archive-only) before storing them.

4. Special categories of personal data

On the standard packages (Light and Pro), AI analysis does not cover special categories of personal data under Article 9 or criminal conviction data under Article 10, because the data processing agreement with the language model provider used on those packages does not cover those categories.

Such material can be handled in the service in two ways: by marking the attachment archive-only, in which case AI never processes it, or by using the Enterprise package, where AI analysis is performed by a subprocessor whose data processing agreement does cover special categories.

The customer is responsible for classification. Removing identifiers does not change the nature of the data as a special category, so a confidential marking alone is not a sufficient basis for AI analysis of such material on the standard packages.

5. Security

We implement the technical and organisational measures required by Article 32 GDPR. They are described in Annex B. We may change an individual measure as long as the level of protection does not fall.

6. Subprocessors

  • The customer gives general prior authorisation to the subprocessors listed in Annex C.
  • We give at least 30 days' notice of a new or changed subprocessor to the email address the customer has provided, and we update Annex C.
  • The customer may object on reasonable data protection grounds within 30 days of the notice. If we cannot find a workable solution, the customer may terminate the service to the extent the change affects it, without a termination charge arising from the change.
  • We put equivalent processing terms in place with our subprocessors and remain responsible for their performance as for our own.

7. Access and change logging

The service records in an audit log: sign-ins, creation, modification and deletion of contracts, addition and download of attachments, approval decisions, and the granting and revoking of permissions. An audit row states who did what and when — it contains no document content, no field values and no request bodies.

Reads of attachments marked confidential are always logged. If the log entry cannot be written, the read is refused.

An extract from the log is provided on request. The service does not currently offer a self-service log view for customers.

8. Data subject rights

The service lets the customer search, correct, export and delete material itself, so most data subject requests can be handled without our involvement.

Where the customer needs help, we assist within a reasonable time and scope. If a data subject approaches us directly, we forward the request to the customer and do not answer it ourselves without the customer's instruction.

9. Personal data breaches

We notify the customer of a personal data breach without undue delay after becoming aware of it. The notice contains what we know about the nature of the breach, the categories of data affected, the likely consequences and the measures taken or proposed.

We assist the customer with notifications to the supervisory authority and to data subjects. A notice is not in itself an admission that the breach was caused by us.

10. Audits

  • On request we provide the information needed to demonstrate compliance with this agreement. The primary route is documentation and answering a security questionnaire.
  • The customer additionally has the right to an audit once per 12 months, on 30 days' notice, during business hours and under a confidentiality undertaking, carried out so that it does not disrupt production.
  • The customer bears the cost of the audit unless the audit reveals a material deviation from this agreement.
  • We do not grant direct access to production systems, because they are shared by several customers and access would put other customers' data at risk.

11. Transfers outside the EU/EEA

Personal data is not transferred outside the EU or EEA. All persistent storage and all AI processing takes place in the EU. Should a transfer become necessary, it is agreed with the customer in advance and implemented under the Commission's standard contractual clauses with any necessary supplementary measures.

12. Return and deletion of material

  • When the customer agreement ends we return the customer's material within 30 days in a machine-readable structured format (JSON), together with the original documents in their original file formats.
  • After the return we delete the material within 30 days, backups included, and provide a deletion certificate on request.
  • We do not delete material to the extent legislation requires us to retain it. The obligations of this agreement continue to apply to any such material.
  • The customer may also request deletion during the term; deletion is carried out within the same 30-day period.

13. Liability

Liability for breach of this agreement is determined by the limitations of liability in the customer agreement, unless mandatory law provides otherwise.

14. Term and changes

This agreement remains in force for as long as we process personal data on the customer's behalf. We may update it as legislation or the service changes, on 30 days' notice; the customer's right to object to a change of subprocessor is set out in section 6.

Annex A — Description of the processing

  • Subject matter: processing the customer's contract management material in order to provide the service.
  • Duration: the term of the customer agreement plus the return and deletion periods in section 12.
  • Nature and purpose: storing and organising material, search, AI-assisted extraction and summarisation, management of tasks and approvals, email notifications, backups, and access and change logging.
  • Categories of data subjects: the customer's users, contact persons at the customer's counterparties, individuals named in contracts such as signatories and responsible persons, and counterparties who are private individuals.
  • Categories of personal data: name, role and organisation, contact details, user identifier and permissions, sign-in and action logs, personal data contained in contract documents, and the national identity number of a counterparty who is a private individual (stored in full, displayed masked in the user interface).
  • Special categories of personal data: see section 4.

Annex B — Technical and organisational measures

  • Encryption: TLS in transit, encryption at rest for stored data. Attachments marked confidential are encrypted with a customer-specific key.
  • Authentication: multi-factor authentication (TOTP) mandatory for every user and every operator. Email addresses are verified at onboarding.
  • Authorisation: role-based access control where rights are inherited through the organisation structure and checked on every request in a single central place.
  • Tenant isolation: a customer's documents are stored in a customer-specific storage bucket, and database queries are scoped by the customer identifier.
  • Confidential attachments: identifiers are stripped from the text before a single analysis pass, the content never reaches a search index or a conversation context, storage is immutability-protected, and every read is logged — if the log write fails, the read is refused.
  • Archive-only attachments: no AI processing at all.
  • AI response screening: every response is screened before it is displayed. National identity numbers and bank account numbers are always blocked; in conversations about confidential contracts, email addresses, phone numbers and company identifiers are blocked as well. Blocks are logged.
  • Prompt injection defence: customer-authored AI instructions and document content are isolated technically, and the tools available to the AI are restricted by a per-instruction allow list.
  • Usage governance: per-organisation AI spend caps and rate limits, plus a usage log showing vendor, model, purpose and cost.
  • Logging: access and change logging as described in section 7, without document content.
  • Operations: production access is restricted to named operator roles that require multi-factor authentication. Exceptional actions, such as deleting immutability-protected material, require a separate role and a documented justification.
  • Backups: continuous point-in-time recovery for the database and versioning on document storage.
  • Environment separation: development and production environments are separate, and production data is not used in development or testing.
  • Software delivery: changes pass through version control, review and automated tests before they reach production.
  • Vulnerability reports: tietoturva@vakka.ai, answered within one business day.

Annex C — Subprocessors

This list is kept current on this page. Changes are notified as described in section 6.

  • Amazon Web Services EMEA SARL (Luxembourg) — cloud infrastructure, document and database storage, authentication, email delivery and text recognition. Processing location: EU (Sweden; text recognition and embedding computation in Germany).
  • Amazon Web Services EMEA SARL (Luxembourg) — Amazon Bedrock: embedding computation on all packages and language model analysis on the Enterprise package. Processing location: EU. The model developers receive no access to the material.
  • Mistral AI SAS (France) — language model services on the Light and Pro packages. Processing location: EU.
  • Paytrail Oyj (Finland) — payment processing and card tokenisation. Processing location: Finland. No access to customer contract material.
  • A data processing agreement is in force with each of the above, and none of them uses customer material to train AI models.