Punasaari Research · Y-tunnus 3580452-7 · Varistonkuja 2, 01660 Vantaa, Finland
GDPR and Data Processing Agreement
Controller/processor responsibilities and the current DPA.
- Effective
- 28 July 2026
- Version
- 2.0
1. Roles
The Customer is controller for personal data it instructs Somemind to process in workspace content and connected accounts. Punasaari Research is processor for that data and controller for account, billing, security and legal-compliance data.
2. Instructions and purpose
Somemind processes data only on documented Customer instructions to generate, store, schedule, publish and analyze authorized content, unless EU or Finnish law requires otherwise.
3. Security and confidentiality
Authorized personnel and subprocessors are bound by confidentiality. Technical and organizational measures include access control, encryption, tenant isolation, backups, logging, incident response and deletion workflows.
4. Subprocessors and transfers
The current service stack includes Supabase, Vercel, Cloudflare, Stripe, Resend, Google, FAL, Meta and TikTok where the Customer enables the related function. Appropriate GDPR transfer safeguards are used for restricted transfers.
5. Assistance and incidents
Somemind assists with data-subject requests, DPIAs and supervisory inquiries to the extent reasonably required. Confirmed personal-data breaches are communicated without undue delay so the Customer can meet applicable 72-hour duties.
6. Return, deletion and audit
At the end of processing, Customer data is deleted or returned unless retention is legally required. Reasonable compliance information is provided subject to confidentiality, security and proportionality. DPA acceptance is recorded per workspace with version and document hash.