Data Processing Addendum
1. Parties and role
This Data Processing Addendum (“DPA”) is between the customer identified in the applicable written agreement (“Customer”) and YardMate Oy, Business ID 2826525-4, Ahdenkallionkatu 3, 05820 Hyvinkää, Finland (“YardMate”). Privacy enquiries may be sent to kari.harkonen@yardmate.fi or through the contact form.
This DPA applies when Customer is a controller or processor and YardMate processes personal data on Customer's documented instructions to provide the Service. Each party remains responsible for processing it performs as an independent controller.
2. Instructions and compliance
YardMate will process Customer Personal Data only to provide, secure and support the Service, comply with the agreement and follow Customer's documented lawful instructions, unless EU or Member State law requires otherwise. YardMate will inform Customer if an instruction appears to violate applicable data protection law.
3. Confidentiality and security
YardMate will ensure that people authorised to process Customer Personal Data are bound by confidentiality and will maintain technical and organisational measures appropriate to the risk. The measures include role-based access, authentication and multi-factor authentication support, rate limiting, secure-cookie support, encrypted private messages and attachments, malware scanning, access-controlled downloads, security-event records, backups, recovery procedures and deletion tooling.
The current Security section of the Privacy Notice, together with the measures described in this section, forms the public security schedule for this DPA. YardMate may improve or replace individual controls as technology and risk change, but will not materially reduce the overall protection of Customer Personal Data during the agreement term.
4. Subprocessors
Customer gives general written authorisation for YardMate to use the providers identified in the current subprocessor list. YardMate will impose written data-protection obligations appropriate to each subprocessor's work and remain responsible for the performance of its processor obligations under this DPA.
YardMate will give Customer at least 30 days' advance notice by email or service notice before a material addition or replacement. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection, including by using a reasonable alternative where available. If no reasonable resolution is available, either party may terminate the affected Service in accordance with the applicable agreement.
5. Assistance
Taking into account the nature of processing and information available, YardMate will reasonably assist Customer with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultations. Customer remains responsible for deciding how to respond to a request and for its own legal compliance.
6. Personal data breaches
YardMate will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide available information needed for Customer's assessment and notification duties. Notification does not constitute an admission of fault.
7. Return and deletion
At Customer's choice following termination of the affected Service, YardMate will delete or make available for return Customer Personal Data in a commonly used format, unless applicable law requires continued retention. Customer must request a return before the account and data become eligible for permanent deletion.
The time limits in the Retention section of the Privacy Notice are the default deletion timetable under this DPA. A deletion removes a supported record from normal use immediately. The production maintenance process checks for expired retention periods at application startup and every 24 hours thereafter and permanently removes eligible records in controlled batches. Deleted database data may remain in access-controlled daily backups for up to 30 days. If a backup is restored for disaster recovery, applicable deletion requests and retention rules are reapplied.
8. Audits and information
YardMate will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow proportionate audits by Customer or an independent auditor mandated by Customer. Audits must protect other customers, confidential information and system security, be preceded by reasonable notice and should ordinarily use current reports and documentation before an on-site inspection. Customer bears its audit costs unless the audit identifies a material breach of this DPA by YardMate.
9. International transfers
Core application hosting is in Finland. Processing locations and possible international processing by supporting providers are described in the subprocessor list. YardMate will not transfer Customer Personal Data outside the EEA without a lawful transfer mechanism and appropriate supplementary safeguards where required. If the European Commission's Standard Contractual Clauses are required, the controller-to-processor module or processor-to-processor module applies according to the parties' roles, together with the processing details and safeguards in this DPA. The clauses prevail over conflicting terms for the relevant transfer.
Annex I — Processing details
| Subject matter | Providing YardMate membership, marketplace, messaging, document and support features selected by Customer. |
|---|---|
| Duration | For the agreement term and documented deletion period. |
| Nature and purpose | Collection, hosting, organisation, retrieval, transmission, protection and deletion needed to provide the Service. |
| Data subjects | Customer personnel and representatives, authorised users associated with member companies, professional supplier and buyer contacts, and other business contacts whose data Customer submits. |
| Data types | Identity, professional contact, account, organisation, marketplace, message, document, technical, security and support data, plus prompts, source material and generated output when Customer uses an AI-assisted feature. |
| Special categories | Not intended. Customer must not submit special-category or criminal-offence data unless expressly agreed with additional safeguards. |
Annex II — Customer-specific details
The applicable order, membership agreement or other written agreement supplies Customer's legal name, business identifier, address and authorised contact. Customer's documented instructions consist of its configuration and lawful use of the selected Service features, together with written instructions accepted by YardMate.
Unless the applicable agreement expressly states otherwise:
- the subject matter, duration, nature, purposes, data subjects and data types are those in Annex I;
- special-category and criminal-offence data are not approved for processing;
- the security schedule in section 3 applies;
- the subprocessor authorisation in section 4 applies;
- the return and deletion timetable in section 7 applies; and
- no additional Customer-specific processing instructions or security requirements have been agreed.
Any Customer-specific deviation must be recorded in a written agreement signed or otherwise accepted by authorised representatives of both parties.