Data Processing Agreement
1. Introduction
This Data Processing Agreement ("DPA") is entered into between you, the customer ("Controller"), and KO Data Oy ("Processor", "KO"), and forms part of the Terms of Service for the KO platform.
This DPA governs the processing of personal data that the Controller submits to or through the KO platform, in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws.
2. Roles & Responsibilities
- Controller — The customer who determines the purposes and means of data processing. You decide what data is connected to KO and how it is used.
- Processor — KO Data Oy, which processes personal data on behalf of the Controller, strictly to deliver the agreed Service.
KO processes data only on documented instructions from the Controller, as set out in this DPA and the Terms of Service. If KO is required by law to process data beyond these instructions, it will notify the Controller in advance unless prohibited by law.
3. Scope of Processing
Subject matter
KO processes personal data to provide marketing intelligence, revenue attribution, and reporting services connecting the Controller's advertising, CRM, and analytics data.
Nature of processing
Collection via API, storage, aggregation, analysis, and display of data within the platform.
Categories of data subjects
- Leads and prospects in the Controller's CRM
- Customers and contacts whose data is stored in connected systems
- End users whose behavioral data flows through connected ad and analytics platforms
Categories of personal data
- Contact information (names, email addresses, company details)
- Marketing interaction data (ad clicks, form submissions, UTM data)
- CRM data (deal stages, pipeline values, close dates)
- Analytics events (page views, session identifiers, conversion events)
Duration
For the duration of the active subscription, plus 30 days following termination.
4. Infrastructure & Data Location
All personal data processed under this DPA is stored and handled on self-hosted, privately managed server infrastructure. Our hosting provider is Hetzner Online GmbH, operating within the European Union (data centers in Germany and Finland).
KO does not use third-party SaaS data warehouses to store Controller data. Data remains within infrastructure that KO directly controls and manages.
Data is not transferred outside the EEA unless explicitly required by an integration the Controller configures (e.g., connecting to a platform whose API is hosted outside the EU). In such cases, the Controller is responsible for ensuring appropriate legal bases for the transfer.
5. Sub-processors
KO relies on the following sub-processors to deliver the Service. All sub-processors are bound by written agreements ensuring equivalent data protection standards.
| Sub-processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Primary hosting & infrastructure | Germany / Finland (EU) |
| External platform APIs (Meta, Google, LinkedIn, TikTok, HubSpot, Pipedrive, GA4, etc.) | Data source integrations authorized by the Controller | Varies (Controller's responsibility to authorize) |
KO will notify the Controller of any intended changes to sub-processors with reasonable advance notice. The Controller may object to new sub-processors within 14 days of notification.
6. Technical & Organisational Security Measures
KO implements the following measures to protect personal data:
- Encryption of all data in transit using TLS 1.2 or higher
- Encryption of data at rest on production servers
- Role-based access control limiting data access to authorized personnel only
- Regular security patching and vulnerability management
- Isolated server environments — no shared multi-tenant data storage
- Logging of access to production systems
- Incident response procedures for detecting, reporting, and managing data breaches
KO does not guarantee absolute security. No system is entirely risk-free. In the event of a personal data breach, KO will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, in line with GDPR Article 33.
7. Data Subject Rights
KO will assist the Controller in responding to data subject requests under the GDPR (access, rectification, erasure, restriction, portability, objection). Where technically feasible, KO provides tooling to support these workflows. For requests that require manual intervention, KO will respond within 10 business days of receiving the request from the Controller.
8. Confidentiality
KO ensures that all personnel authorized to process personal data are bound by confidentiality obligations, either by contract or by applicable law. Access is granted on a need-to-know basis only.
9. Audits & Compliance
KO will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA. The Controller may request an audit of KO's data processing practices with at least 30 days' written notice. Audits are conducted at the Controller's expense and must not unreasonably disrupt KO's operations.
10. Termination & Data Deletion
Upon termination of the Service agreement, KO will:
- Retain the Controller's data for 30 days to allow for recovery or export
- Securely and permanently delete all personal data within 30 days of the end of that retention period
- Provide written confirmation of deletion upon request
If the Controller requests earlier deletion, KO will complete it within 14 business days.
11. Governing Law
This DPA is governed by Finnish law and forms an integral part of the KO Terms of Service. In the event of conflict, this DPA takes precedence with respect to data processing obligations.
12. Contact
For DPA-related inquiries, contact us at hello@kodata.pro.
KO Data Oy — Helsinki, Finland