Perjanjian Pemprosesan Data (DPA)
Kali Terakhir Dikemas Kini: 2026-07-24
Kali Terakhir Dikemaskini halaman Subpemproses: 2026-07-24
DPA ini menggariskan terma-terma di mana kami memproses data peribadi bagi pihak anda.
Perjanjian Pemprosesan Data ini (Perjanjian) memperincikan kewajiban dan syarat di mana Petitions.com Group Oy (Penyedia Perkhidmatan) memproses data peribadi bagi pihak penulis petisyen (Penulis Petisyen atau Pengawal Data) dalam penyediaan perkhidmatan hos petisyen dalam talian (Perkhidmatan).
Pengubahsuaian Terma
Kami berhak untuk mengubah atau meminda Terma-terma ini pada bila-bila masa tanpa notis terlebih dahulu.
Definisi dan Peranan
- Penyedia Perkhidmatan: Petitions.com (Petitions.com Group Oy), bertindak sebagai Pemproses Data, memproses data peribadi bagi pihak Pengawal Data seperti yang diperlukan untuk menyampaikan Perkhidmatan.
- Pengawal Data: Penulis Petisyen, yang menentukan tujuan dan cara pemprosesan data peribadi yang dikumpulkan daripada penandatangan petisyen mereka. Sebagai pengarang petisyen yang dihoskan di Petitions.com, anda dianggap sebagai Pengawal Data. Anda menentukan kandungan petisyen, apa yang diminta dari penandatangan, tujuan untuk memproses data peribadi mereka, dan tempoh penyimpanan data peribadi tersebut. Petitions.com menyediakan platform dalam talian untuk mencipta dan mengehoskan petisyen, memudahkan peranan anda sebagai Pengawal Data dengan autonomi untuk membentuk pengumpulan dan penggunaan data petisyen mengikut objektif dan kewajipan undang-undang anda.
Skop Pemprosesan
The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Skop aktiviti pemprosesan adalah terhad kepada hos, mengurus, dan memudahkan petisyen dalam talian.
As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.
The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.
Perlindungan Data
Penyedia Perkhidmatan berkomitmen untuk melaksanakan langkah-langkah teknikal dan organisasi untuk memastikan keselamatan data peribadi daripada akses tanpa kebenaran, kehilangan, atau kerosakan.
Pengumpulan Data Yang Dilarang
Adalah dilarang untuk meminta nombor pengenalan peribadi (seperti nombor ID nasional) daripada penandatangan.
Pemproses Bawah
Penyedia Perkhidmatan boleh melibatkan subpemproses untuk membantu dalam menyediakan Perkhidmatan. Penyedia Perkhidmatan akan memastikan subpemproses mematuhi kewajipan perlindungan data yang selaras dengan DPA ini. Anda mengakui dan bersetuju bahawa Penyedia Perkhidmatan mempunyai budi bicara untuk memilih dan menggantikan subprosesor mengikut keperluan bagi menyediakan Perkhidmatan dengan cekap.
Senarai subprosesor. (Kemas Kini Terakhir: 2026-07-24)
Tanggungjawab Pengawal Data
Pengawal Data bertanggungjawab memastikan bahawa pengumpulan, pemprosesan, dan pengendalian data peribadi mematuhi semua undang-undang dan peraturan yang berkenaan.
Pengenalpastian Pengawal Data
Di bawah Peraturan Perlindungan Data Umum (GDPR), adalah diperlukan bahawa identiti pengawal data dinyatakan dengan jelas. Peruntukan berikut disediakan untuk pengarang petisyen yang menggunakan laman web kami:
Pengarang Petisyen Individu
Jika anda, sebagai individu, membuat petisyen, anda dikehendaki memberikan nama penuh anda yang sah. Ini berfungsi sebagai pengenalan anda sebagai pengawal data untuk tujuan GDPR.
Penulis Petisyen Organisasi
Jika petisyen dibuat bagi pihak sebuah organisasi, nama penuh undang-undang organisasi tersebut mesti disediakan. Selain itu, organisasi harus melantik dan menyediakan maklumat hubungan wakil yang bertanggungjawab ke atas aktiviti pemprosesan data, seperti Pegawai Perlindungan Data (DPO) atau yang seumpamanya.
Hak Subjek Data
Pengawal data mesti memastikan bahawa subjek data (penandatangan petisyen) boleh menjalankan hak mereka di bawah GDPR, seperti hak untuk mengakses, membetulkan, atau memadam data mereka, atau untuk membuat aduan kepada pihak berkuasa penyeliaan.
Mengendalikan Permintaan Pemadaman Subjek Data daripada Penandatangan
The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.
Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.
When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.
The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.
Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.
Log teknikal mungkin mengandungi data peribadi, seperti alamat IP atau metadata penghantaran e-mel. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.
The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.
Handling Rectification Requests from Signatories
The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.
Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.
The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.
Notifying Recipients
Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.
Akauntabiliti dan Pematuhan
Pengawal data mesti boleh menunjukkan pematuhan dengan GDPR, termasuk memberi respons kepada permintaan subjek data mengenai data peribadi mereka.
Dasar atau Notis Privasi
Dasar privasi atau notis yang jelas dan mudah diakses mesti disediakan, yang menggariskan bagaimana data peribadi diproses, tujuan pemprosesan, dan bagaimana subjek data boleh menggunakan hak mereka.
Pemberitahuan Perubahan
Penulis petisyen dikehendaki memaklumkan Petitions.com (Petitions.com Group Oy) tentang sebarang perubahan dalam status mereka sebagai pengawal data atau dalam butiran hubungan wakil mereka.
Kajian Tahunan Pemprosesan Data
Penulis Petisyen dikehendaki menjalankan kajian tahunan untuk memastikan sama ada masih terdapat alasan yang sah untuk meneruskan pemprosesan data peribadi penandatangan. Kajian ini harus menilai keperluan dan relevansi data berkenaan dengan tujuan petisyen. Jika Penulis Petisyen menentukan bahawa tidak ada lagi alasan yang sah untuk meneruskan pemprosesan data, mereka mesti mengambil langkah-langkah yang sewajarnya untuk menghentikan pemprosesan dan memulakan penghapusan data sesuai dengan undang-undang perlindungan data yang berkenaan.
Use of Up-to-Date Signature Data
Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.
Penyimpanan dan Pemadaman Data
Sekiranya Pengawal Data (penulis petisyen) melanggar mana-mana terma dalam Perjanjian Pemprosesan Data (DPA), termasuk tetapi tidak terhad kepada kegagalan dalam mengadakan kajian tahunan terhadap aktiviti pemprosesan data atau memberikan justifikasi yang sah untuk pemprosesan berterusan data peribadi penandatangan, Penyedia Perkhidmatan berhak untuk menghapuskan atau memadamkan data peribadi yang berkaitan dengan petisyen mereka.
Had Tanggungan
Dalam keadaan apa pun, jumlah keseluruhan liabiliti pemproses data kepada pengawal data untuk semua kerosakan, kerugian, dan sebab tindakan, sama ada dalam kontrak, tort (termasuk kecuaian), atau sebaliknya, tidak akan melebihi jumlah keseluruhan yang dibayar oleh pengawal data kepada pemproses data di bawah perjanjian ini.
Undang-undang yang terpakai
Perjanjian ini akan ditadbir oleh undang-undang Finland.