Annex 1 – Processing of personal data on behalf of the Customer

Data Processing Agreement (DPA)

Contracting party

Koll Group Oy

Joensuunkatu 7

24100 Salo

Finland

Business ID
3410913-5
Contract matters
hannu.nissinen@koll.to
Version
2.0
Effective from
28 July 2026
Governing law
Laws of Finland
Dispute resolution
Southwest Finland District Court

These terms are intended solely for agreements between businesses (B2B). They do not apply to consumer customers.

This Data Processing Agreement is Annex 1 to Koll's business services terms and conditions. It fulfils the requirements for a processing agreement under Article 28 of the EU General Data Protection Regulation.

1. Scope and roles

This Data Processing Agreement (the "DPA") applies when Koll processes personal data on behalf of the Customer in order to provide the Service. The DPA forms part of the parties' agreement and fulfils the requirements for a processing agreement under Article 28 of the EU General Data Protection Regulation.

The Customer is the controller and Koll is the processor for the processing described in this DPA. If the Customer acts as a processor for another controller, Koll acts as the Customer's sub-processor, and the Customer represents that it is authorised to give the instructions described herein.

Koll acts as an independent controller for contract, user, billing, security and abuse-prevention data whose purposes and means of processing Koll determines independently. This DPA does not apply to such processing.

2. Customer instructions and responsibilities

Koll processes personal data only in accordance with the Customer's documented instructions, including the Agreement, the Order Confirmation, the Service's settings and the Customer's lawful actions within the Service, unless required otherwise by European Union or Member State law. In such a case, Koll will notify the Customer of the legal requirement in advance, unless the law prohibits such notice.

If Koll considers that a Customer instruction infringes data protection law, Koll will notify the Customer and may suspend implementation of the instruction until it is amended or its lawfulness is demonstrated.

The Customer is responsible for:

  • the lawfulness of the processing of personal data and of its instructions;
  • the legal basis for processing, informing data subjects, and obtaining necessary consents;
  • data minimisation, accuracy and retention periods;
  • ensuring that special categories of personal data, data relating to criminal convictions, or other high-risk data are not entered into the Service without Koll's prior written approval and appropriate additional safeguards; and
  • primary handling, as controller, of data subject requests and supervisory authority demands.

3. Subject matter, nature, purpose and duration of processing

Subject matter and purpose. Provision of the Service, transmission of information related to messages and calls, management of the company profile and user rights, implementation of integrations, technical support, security of the Service, and other actions in accordance with the Customer's instructions.

Nature of processing. Receiving, collecting, storing, organising, retrieving, viewing, using, transferring, disclosing, combining, restricting, deleting, and other processing operations necessary to provide the Service.

Duration. Processing continues for the term of the agreement and thereafter only for the time needed to return or delete data, complete backup rotation, or comply with statutory retention.

Data subjects. The Customer's Users, employees, contractors, contact persons, customers, prospective customers, job applicants, partners, service providers and other persons whom the Customer contacts via the Service, or whose data the Customer transfers to the Service.

Categories of personal data. Names, job titles, organisations, phone numbers, email addresses, user identifiers, roles, company profile and brand information, customer and contact data, reasons for calling, message content, timestamps, delivery and call metadata, integration identifiers, log data, and other information the Customer submits to the Service.

The Service is not intended for processing special categories of personal data, data relating to criminal convictions, payment card data, passwords, or official identification documents, unless agreed in writing in advance.

4. Koll's general obligations

Koll:

  • processes personal data only within the agreed scope and in accordance with documented instructions;
  • ensures that persons processing personal data are bound by a statutory or contractual duty of confidentiality;
  • maintains, as applicable, a record of processing activities under Article 30 of the GDPR;
  • provides the Customer with reasonably necessary information to demonstrate compliance with the DPA's obligations;
  • assists the Customer as described in this DPA; and
  • does not sell personal data it processes on the Customer's behalf, nor uses it for its own direct marketing.

5. Security measures

Koll implements technical and organisational measures appropriate to the risk of processing, taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as risks to data subjects' rights. The measures include, as applicable:

  • the principle of least-privilege access, personal credentials, and restriction of administrative rights;
  • strong or multi-factor authentication for relevant administration and maintenance functions;
  • encryption of data in transit using generally accepted methods and, as applicable, at rest;
  • appropriate separation of development, test and production environments;
  • management of vulnerabilities, updates, logs, backups and incidents;
  • security and data protection training for personnel, and confidentiality obligations;
  • business continuity and recovery procedures to the extent required by risk;
  • risk-based assessment of service providers' security; and
  • regular review and development of security measures.

Koll may update security measures provided the overall level of protection for processing is not materially reduced. The Customer is responsible for the security of its own user credentials, devices, integration keys and systems.

6. Sub-processors

The Customer grants Koll general written authorisation to use sub-processors of personal data. Koll maintains an up-to-date list of material sub-processors on its website or otherwise makes it readily available to the Customer.

Koll will notify the Customer of the addition or material replacement of a sub-processor at least fourteen (14) days before the change, unless an urgent security, continuity or legal reason requires a faster change. The Customer may object to a change for a justified data protection reason within the notice period.

The parties will seek to resolve an objection through reasonable efforts. If no resolution is found, Koll may decline to engage the sub-processor, offer an alternative solution, or either party may terminate only the part of the Service affected by the objection. The Customer will then be refunded the prepaid, unused portion relating to that part.

Koll enters into a written agreement with the sub-processor imposing data protection obligations that are materially equivalent to those in this DPA. Koll remains responsible for its sub-processor's compliance with its data protection obligations as if they were its own.

7. Transfers outside the EEA

Koll does not transfer personal data processed on the Customer's behalf outside the European Economic Area without a transfer mechanism valid under data protection law. Available mechanisms include, for example, an adequacy decision of the European Commission, approved standard contractual clauses, and, where necessary, supplementary safeguards.

Koll will, on request, provide the Customer with reasonable information on the applicable transfer mechanism to the extent disclosure is not restricted by confidentiality or security obligations.

8. Data subject rights

If Koll receives a data subject request concerning data processed on the Customer's behalf, Koll will not respond independently unless authorised by the Customer or required by law. Koll will forward the request to the Customer without undue delay.

Koll will assist the Customer with reasonable technical and organisational measures in fulfilling data subjects' rights of access, rectification, erasure, restriction, objection and portability, taking into account the nature of the processing and the Service's functionalities.

9. Personal data breaches

Koll will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf. Notice will be given to the data protection or contract contact designated by the Customer.

The notice will include, to the extent available:

  • a description of the nature of the breach and, where possible, the categories and approximate numbers of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to remedy the breach and mitigate its effects; and
  • a contact point for further information.

Information may be provided in phases as it becomes available. The Customer, as controller, is responsible for notifying the supervisory authority and data subjects. Koll will not make notifications on the Customer's behalf without express authorisation, unless required by law. A breach notice does not constitute an admission of liability.

10. Assistance and impact assessments

Koll will provide the Customer with reasonable assistance in fulfilling obligations relating to security, personal data breaches, data protection impact assessments, and prior consultation with a supervisory authority, to the extent the need for assistance relates to processing performed by Koll and Koll has the necessary information.

Koll may charge a reasonable fee for assistance exceeding normal support for the Service, if the need for assistance does not result from Koll's breach of the agreement. Koll will notify the estimated costs in advance where reasonably possible.

11. Audits and demonstrating compliance

Koll will, on request, provide the Customer with available independent audit reports, certifications or other reasonable information demonstrating compliance with the DPA. These will be used as the primary means of verification.

If such information is not reasonably sufficient, or a competent authority requires an audit, the Customer or its independent, non-competing auditor bound by confidentiality may conduct an audit no more than once every twelve (12) months, with at least thirty (30) days' advance notice, during normal business hours. This restriction does not apply to an audit based on a justified security incident or a regulatory requirement.

An audit must not jeopardise other customers' data, Koll's security, trade secrets or the continuity of the Service. The Customer is responsible for its own and the auditor's costs. If an audit reveals a material breach of the DPA by Koll, Koll will bear reasonable direct audit costs within the limitation of liability under section 20 of the Terms.

12. Return and deletion of data

On termination of the agreement, Koll will, at the Customer's request, return personal data processed on the Customer's behalf in an agreed or commonly used format and delete remaining copies, unless European Union or Member State law requires retention.

Data in active systems will be deleted or anonymised without undue delay, normally no later than ninety (90) days after termination of the agreement.

Data in backups will be removed in the normal rotation cycle, remains protected in accordance with this DPA, and will not be processed for another purpose unless restoration is necessary in a security or continuity situation.

Koll may retain, separately, data it is required by law to retain, only for the period and purpose required by law.

13. Liability, term and precedence

The parties' liability for breach of the DPA is determined in accordance with data protection law and section 20 of the Terms. The DPA does not limit statutory rights of a data subject or supervisory authority under mandatory law.

The DPA takes effect at the same time as the agreement and remains in force for as long as Koll processes personal data on the Customer's behalf. If the DPA and the general Terms conflict on a matter concerning the processing of personal data, the DPA prevails.