Data Processing Agreement (DPA)
Last updated: 31 July 2026
This Data Processing Agreement ("DPA") forms an integral part of the Säuts Terms of Service and governs the processing of Personal Data pursuant to Article 28 of Regulation (EU) 2016/679 (the "GDPR").
Whenever Cloudexp OÜ processes Personal Data on behalf of a User in connection with the use of the Säuts Service, this DPA automatically applies.
1. Parties
Data Controller
For the purposes of this DPA, the Data Controller is the company or sole trader using the Säuts Service and determining the purposes and means of processing Personal Data.
Hereinafter referred to as the "Customer".
Data Processor
Cloudexp OÜ
Registry Code: 16263842
Registered Address:
Juurdeveo tn 18-9
Kesklinn, Tallinn
Harju County 11313
Estonia
Email:
Website:
Hereinafter referred to as the "Processor".
The Customer and the Processor are collectively referred to as the "Parties".
2. Purpose
The purpose of this DPA is to ensure that the Processor processes Personal Data solely:
- for the purpose of providing services to the Customer;
- in accordance with Article 28 of the GDPR;
- in accordance with the Customer's documented instructions;
- in compliance with applicable data protection laws.
This DPA does not grant the Processor any right to use the Customer's Personal Data for its own independent purposes.
3. Definitions
Unless otherwise defined in this DPA, terms shall have the meanings assigned to them under the GDPR.
In addition, the following definitions apply.
Service means the Säuts software-as-a-service platform.
Customer Data means all data submitted to the Service by the Customer.
Personal Data has the meaning given in Article 4 of the GDPR.
Processing means any operation performed on Personal Data.
Data Subject means the individual whose Personal Data is processed.
Personal Data Breach has the meaning set out in Article 4(12) of the GDPR.
4. Subject Matter of the Processing
The Processor processes Personal Data solely for the purpose of providing the Säuts Service to the Customer.
Processing activities may include, among others:
- storing Customer Data;
- sending SMS review invitations;
- tracking message delivery;
- maintaining technical logs;
- ensuring system security;
- creating backups;
- providing customer support;
- diagnosing and correcting technical issues.
The Processor does not determine the purposes or means of processing Personal Data on behalf of the Customer.
5. Duration of Processing
This DPA remains in effect for as long as the Processor processes Personal Data on behalf of the Customer.
This DPA terminates upon:
- termination of the Customer's use of the Service;
- termination of the Terms of Service;
- deletion or return of all Customer Personal Data, unless retention is required by applicable law.
6. Categories of Personal Data
In providing the Service, the Processor may process the following categories of Personal Data.
User Account Information
- full name;
- email address;
- telephone number;
- company name;
- company registration number.
Customer Data
Depending on the information submitted by the Customer, this may include:
- first name;
- telephone number;
- date of service;
- SMS delivery status;
- review invitation status;
- communication history.
The Processor does not intentionally request or require the processing of special categories of Personal Data.
If the Customer uploads special category Personal Data without necessity, the Customer remains solely responsible for ensuring that such processing is lawful.
7. Categories of Data Subjects
The Personal Data processed under this DPA may relate to, among others:
- the Customer's existing customers;
- the Customer's employees;
- authorised users of the Customer;
- sole traders;
- business contacts.
8. Customer Responsibilities
The Customer represents and warrants that:
- it has a lawful basis for processing all Personal Data submitted to the Service;
- it has complied with all applicable transparency and information obligations under the GDPR;
- it provides only lawful instructions to the Processor;
- it is responsible for the accuracy and lawfulness of all Personal Data submitted to the Service.
The Customer is solely responsible for ensuring that the Service is used in accordance with applicable law.
9. General Obligations of the Processor
The Processor shall:
- process Personal Data only on the documented instructions of the Customer unless otherwise required by applicable law;
- ensure that access to Personal Data is limited to personnel and contractors who require such access for the performance of their duties;
- ensure that all persons authorised to process Personal Data are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures in accordance with Article 32 of the GDPR;
- provide reasonable assistance to the Customer in fulfilling its obligations under the GDPR as described in this DPA.
The Processor shall not sell, rent, disclose or use the Customer's Personal Data for its own marketing purposes or any independent commercial purpose.
10. Security Measures
The Processor shall implement appropriate technical and organisational measures in accordance with Article 32 of the GDPR, taking into account:
- the state of the art;
- the costs of implementation;
- the nature of the processing;
- the scope of the processing;
- the context of the processing;
- the purposes of the processing; and
- the risks to the rights and freedoms of natural persons.
Such measures may include, among others:
- encrypted communications (TLS);
- access controls;
- role-based permissions;
- multi-factor authentication;
- secure backups;
- security logging;
- continuous system monitoring;
- vulnerability management;
- regular security updates;
- disaster recovery and system restoration capabilities.
The Processor shall regularly review and improve these security measures in light of technological developments and evolving security risks.
11. Sub-processors
The Customer grants the Processor a general authorisation to engage Sub-processors within the meaning of Article 28(2) of the GDPR.
The Processor may engage, among others, the following categories of Sub-processors:
- cloud infrastructure providers;
- SMS delivery providers;
- authentication service providers;
- payment service providers;
- analytics providers;
- email service providers;
- backup and disaster recovery providers;
- monitoring and logging service providers.
The Processor shall ensure that each Sub-processor is bound by a written agreement imposing data protection obligations that are no less protective than those contained in this DPA.
The Processor remains responsible for the performance of its Sub-processors to the extent required by the GDPR.
Where reasonably practicable, the Processor will provide advance notice of material changes relating to Sub-processors.
12. International Transfers of Personal Data
The Processor shall not transfer Personal Data outside the European Economic Area ("EEA") unless:
- instructed by the Customer;
- necessary for providing the Service; or
- otherwise permitted under the GDPR.
Where Personal Data is transferred internationally, the Processor shall implement appropriate safeguards, including where applicable:
- an adequacy decision adopted by the European Commission;
- the European Commission's Standard Contractual Clauses (SCCs);
- any other transfer mechanism recognised under the GDPR.
13. Confidentiality
The Processor shall ensure that all persons authorised to process Personal Data:
- are bound by confidentiality obligations;
- receive appropriate data protection training where necessary;
- access Personal Data only to the extent necessary for the performance of their duties.
These confidentiality obligations continue after the termination of employment or any other contractual relationship.
14. Personal Data Breaches
The Processor shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer's Personal Data.
Where reasonably available, the notification shall include:
- the nature of the breach;
- the categories of affected Personal Data;
- the approximate number of affected Data Subjects;
- the measures taken or proposed to mitigate the breach;
- contact details for obtaining further information.
The Processor shall reasonably cooperate with the Customer to mitigate the effects of the breach and to assist the Customer in fulfilling its obligations under the GDPR.
15. Assistance with GDPR Compliance
Taking into account the nature of the processing and the information available to the Processor, the Processor shall provide reasonable assistance to the Customer in fulfilling its obligations under the GDPR, including assistance relating to:
- Data Subject rights requests;
- Data Protection Impact Assessments (DPIAs);
- prior consultation with supervisory authorities where required;
- security measures;
- the management of Personal Data Breaches.
Where a request requires substantial additional work outside the ordinary provision of the Service, the Processor may charge a reasonable fee unless prohibited by applicable law.
16. Data Subject Requests
If the Processor receives a request directly from a Data Subject regarding the exercise of their GDPR rights, the Processor shall not respond to the request on its merits unless authorised by the Customer or required by applicable law.
The Processor shall forward the request to the Customer without undue delay.
The Processor shall provide reasonable assistance to enable the Customer to fulfil its obligations under the GDPR.
17. Audits and Demonstration of Compliance
Upon reasonable prior notice, the Customer may request information necessary to demonstrate the Processor's compliance with this DPA and Article 28 of the GDPR.
The Processor may satisfy such requests by providing, where appropriate:
- security certifications;
- independent audit reports;
- compliance attestations;
- summaries of security policies;
- other reasonable documentation demonstrating compliance.
If the Customer requests an on-site audit, the Parties shall agree in advance on the scope, timing and practical arrangements for such audit.
Any audit must not unreasonably interfere with the Processor's business operations or compromise the confidentiality, security or Personal Data of other customers.
Unless the audit identifies a material breach of this DPA by the Processor, the Customer shall bear the reasonable costs associated with conducting the audit.
18. Return and Deletion of Personal Data
Upon termination of this DPA or the Customer's use of the Service, the Processor shall, at the Customer's choice, delete or return all Personal Data processed on behalf of the Customer, unless retention is required by applicable law.
If the Customer does not provide instructions regarding the return of Personal Data within a reasonable period following termination, the Processor may securely delete the Personal Data in accordance with its standard data retention and deletion procedures.
Personal Data contained in backup systems shall be deleted in accordance with the Processor's normal backup rotation schedule, unless a longer retention period is required by law.
19. Liability
Each Party shall remain responsible for complying with its respective obligations under the GDPR and other applicable data protection laws.
The Processor shall be liable only for damages arising from:
- a breach of this DPA;
- a breach of GDPR obligations that apply directly to the Processor;
- failure to comply with the Customer's lawful documented instructions.
The Processor shall not be liable for damages resulting from, among other things:
- unlawful instructions provided by the Customer;
- inaccurate or unlawfully collected Personal Data submitted by the Customer;
- the Customer's relationship with its own customers;
- the Customer's failure to comply with applicable law.
Nothing in this DPA excludes or limits liability where such exclusion or limitation is prohibited by applicable law.
20. Indemnification
The Customer agrees to indemnify and hold harmless the Processor against reasonable losses, damages, liabilities, claims and costs arising from:
- the Customer's breach of applicable law;
- unlawful instructions issued by the Customer;
- unlawful processing of Personal Data submitted by the Customer;
- the Customer's breach of this DPA or the Terms of Service.
This provision shall not apply to the extent that the damage was caused by the Processor's own unlawful conduct, wilful misconduct or gross negligence.
21. Amendments to this DPA
Cloudexp OÜ may amend this DPA where necessary in order to:
- comply with changes in applicable legislation;
- implement guidance issued by supervisory authorities;
- reflect changes to the Service;
- update security measures;
- accommodate changes to Sub-processors or the underlying technical infrastructure.
Where required by applicable law, the Customer will be provided with reasonable notice of any material amendments before they become effective.
Continued use of the Service after the effective date of the amendments constitutes acceptance of the revised DPA unless applicable law provides otherwise.
22. Governing Law and Dispute Resolution
This DPA shall be governed by and construed in accordance with the laws of the Republic of Estonia and the General Data Protection Regulation (GDPR).
The Parties shall first attempt to resolve any dispute arising out of or relating to this DPA through good-faith negotiations.
If the dispute cannot be resolved amicably, it shall be submitted to Harju County Court, unless mandatory applicable law provides otherwise.
23. Severability
If any provision of this DPA is held to be invalid, illegal or unenforceable, the remaining provisions shall remain in full force and effect.
Where possible, the invalid or unenforceable provision shall be replaced by a valid provision that most closely reflects the original legal and commercial intent of the Parties.
24. Entire Agreement
This DPA, together with the following documents, constitutes the entire agreement between the Parties concerning the processing of Personal Data:
- the Säuts Terms of Service;
- the Säuts Privacy Policy;
- any written instructions provided by the Customer to the Processor;
- any other documents expressly incorporated by reference into this DPA.
In the event of any conflict between this DPA and the Terms of Service regarding the processing of Personal Data, the provisions of this DPA shall prevail.
25. Contact
For any questions regarding this DPA or the processing of Personal Data, please contact:
Cloudexp OÜ
Registry Code: 16263842
Registered Address:
Juurdeveo tn 18-9
Kesklinn, Tallinn
Harju County 11313
Estonia
Email:
Website:
This Data Processing Agreement becomes effective upon its publication on the Säuts Website and remains in force for the duration of the Customer's use of the Service unless otherwise agreed in writing by the Parties.