Data Processing Addendum | Happeo
Data Processing Addendum
Last updated on December 6, 2025
This Data Processing Addendum (“DPA”) is subject to the terms and conditions of the Agreement between Happeo Oy (“Processor”) and the Customer entity that is a party to the Agreement for the purchase of Happeo Services (“Controller”).
This DPA and any schedules or appendices thereto, is incorporated into and form an integral part of the Agreement. For the avoidance of doubt, all references to the “Agreement” shall include this DPA (including the SCCs (where applicable), as defined herein).
In the course of providing the Services to Controller under the Agreement, Processor and its Affiliates may process Personal Data on behalf of Controller, and the Parties agree to comply with the following provisions with respect to processing of Personal Data, each acting reasonably and in good faith.
1. DEFINITIONS
“ Agreement” means Happeo’s Terms of Service available at https://www.happeo.com/tos or other written or electronic agreement, which govern the provision of the Service to Controller, as such terms or agreement may be updated from time to time.
“ Personal Data” means any information relating to an identified or identifiable natural person and shall also mean Personal Information, where applicable;
“ Controller” means the entity which determines the purposes and means of the processing of Personal Data and shall also mean Business, where applicable;
“ Processor” means the entity that processes Personal Data on behalf of the Controller and shall also mean Service Provider or Contractor, where applicable;
All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement. Terms defined in the Data Protection Legislation but not in this DPA shall have the meaning given to them in the Data Protection Legislation, or if not defined therein, in the GDPR specifically. In the event of a conflict in the meanings of these terms, the meaning from the law applicable to processing of the Personal Data of the relevant Data Subject shall apply.
2. ROLES AND SCOPE OF PROCESSING
2.1 The Parties agree that in the course of provision of the Services,
(a) Controller is the data controller, as defined in the Data Protection Legislation, and shall define the purposes and means of the processing of Personal Data; and
(b) Processor shall process Controller Data as a data processor as set out in the Data Protection Legislation.
3. CONTROLLER’S RESPONSIBILITIES
3.1 Controller is responsible for the lawful collection, processing, use and accuracy of Controller Data, as well as for preserving the rights of the individuals concerned (Data Subjects) as required by the Data Protection Legislation. If and to the extent required by applicable Data Protection Legislation, Controller shall inform the Data Subjects about the processing of their Personal Data by Processor and obtain consents of the Data Subjects, or otherwise ensure that it has a valid legal basis for its processing.
3.4 Controller will not provide (or cause to be provided) to Processor any data that falls within the definition of “special categories of data” under applicable Data Protection Laws (“Sensitive Data”) for processing under the Agreement, and Processor will have no liability for such data. For the avoidance of doubt, this DPA will not apply to Sensitive Data.
4. PROCESSOR’S RESPONSIBILITIES
4.1 Processor shall process Controller Data as further described in Annex 1 (Details of Personal Data Processing) in accordance with this DPA and only in accordance with Controller’s documented lawful instructions, or as otherwise agreed in writing by the Parties or as necessary to comply with applicable law.
4.4 Processor shall promptly notify Controller if it determines that it can no longer meet its obligations under applicable Data Protection Legislation. Upon receiving notice from Processor in accordance with this subsection, Controller may direct Processor to take reasonable and appropriate steps to stop and remediate unauthorized use of Controller Data.
4.8 In case any individual or supervisory authority makes a request for assistance directly to Processor concerning Controller Data, such as a request for access, rectification or erasure, Processor shall inform Controller of such request as soon as reasonably possible and as allowed by the applicable laws.
5. SUB-PROCESSORS
5.1 General authorization. Controller gives its general authorization to allow Processor to engage Processor’s affiliated companies and subcontractors as sub-processors to process Controller Data in connection with the provision of the Services (“Sub-processors”). The Sub-processors currently engaged by Processor are detailed in the Sub-processor List (trust.happeo.com/subprocessors).
6. LOCATION AND INTERNATIONAL TRANSFER OF PERSONAL DATA
6.1 The primary processing location for Controller Data is in the EEA. Processing may also take place within Permitted Processing Locations and other locations as provided in this DPA.
7. AUDITS
7.1 Upon the reasonable request of Controller, Processor shall make available to Controller all information in Processor’s possession necessary to demonstrate Processor’s compliance with Section 4.3.
8. PERSONAL DATA BREACHES
8.1 Processor shall, without undue delay after having become aware of it, inform Controller in writing about any Personal Data Breach relating to Controller Data.
9. DATA RETENTION
9.1 Processor will upon termination of the Agreement for thirty (30) days, provide Controller with the ability to export Controller Data from the platform.
10. OTHER TERMS
10.1 This DPA shall be governed by the terms and conditions of the Agreement, including without limitations its liability limitations and clauses relating to applicable law and jurisdiction. This DPA will remain in force as long as the Processor processes Personal Data on behalf of the Controller under the Agreement.
Annex 1: Details of Personal Data Processing
Nature and purpose of the processing
Processor will process Personal Data on behalf of Controller in order to provide the Services to Controller under the Agreement, including but not limited to processing to deploy and provide Controller a solution for enterprise communications on the Happeo platform (“Happeo Platform”) and services relating thereto.