1. Parties and roles
This Data Processing Agreement ("DPA") forms part of every agreement under which Sixty Four OÜ (registry code 12354921, Kolde pst 23, 10412 Tallinn, Estonia) provides the ukulabs Service. The customer is the controller and Sixty Four OÜ is the processor of personal data processed in the Service. If a customer contract has its own data-processing terms, those terms take precedence.
2. Subject matter and details of processing
| Subject and purpose | Providing, hosting, supporting and maintaining the ukulabs Service, including data migration requested by the customer |
|---|---|
| Duration | The subscription term plus the 30-day export period |
| Categories of data subjects | The customer's users and agents, and persons who submit service requests or are mentioned in customer content |
| Types of personal data | Name, work e-mail, username, phone, organisational unit, role, login and audit logs, and content entered by the customer (tasks, comments, attachments, pages, requests) |
| Special categories | Not intended. The customer will not enter special categories of data unless agreed in writing. |
3. Processor obligations
- Process personal data only on the customer's documented instructions, including these terms and the use of the Service's configuration.
- Make sure that persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Art. 32 GDPR), see section 6.
- Assist the controller with data-subject requests and with obligations under Articles 32–36 GDPR.
- Make available the information needed to demonstrate compliance and allow audits, with at least 14 days' notice, no more than once a year unless an incident or a supervisory authority requires otherwise.
- Inform the controller without delay if an instruction appears to infringe data-protection law.
4. Sub-processors
The controller gives general authorisation to use the following sub-processor:
| Sub-processor | Service | Location of data |
|---|---|---|
| Google Cloud EMEA Ltd (Google Cloud Platform) | Infrastructure hosting, storage, backups | EU — europe-north1 (Finland) |
Sixty Four OÜ will notify customers at least 30 days before adding or replacing a sub-processor. The customer may object on reasonable grounds. Sub-processors are bound by data-protection obligations equivalent to this DPA.
5. International transfers
Personal data is stored and processed in the EU/EEA. No transfer outside the EU/EEA takes place without the customer's prior written consent and an appropriate safeguard under Chapter V GDPR.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access control, single sign-on and MFA for administrative access
- Logical separation of customer data, plus audit logging of administrative actions
- Daily backups kept for at least 30 days, with restore tests
- Patch and vulnerability management, with security updates applied promptly
- Least-privilege access by provider staff, which is logged and reviewed
7. Personal data breaches
Sixty Four OÜ will notify the controller without undue delay, and in any case within 24 hours, after becoming aware of a personal data breach. The notice will include the information available under Article 33(3) GDPR.
8. Deletion and return
When the Service ends, the customer can export all data during 30 days. After that, Sixty Four OÜ deletes the personal data, including backups within their retention cycle, unless EU or member-state law requires storage. Deletion is confirmed in writing on request.
9. Contact
Data protection contact: henrik.aavik@sixtyfour.ee, Sixty Four OÜ, Kolde pst 23, 10412 Tallinn, Estonia.