Dátaviðgerðarsamtykki (DPA)
Seinast dagført: 2026-07-24
Seinast dagført undirgreinarasíðuna: 2026-07-24
Hetta DPA lýsir treytirnar, undir hvørjum vit viðgera persónsupplýsingar fyri teg.
Hetta dátuviðgerðaravtalan (Avtalan) lýsir skyldur og treytir, undir Petitions.com Group Oy (Tænastuveitari) fer fram við persónsupplýsingar á vegnum fyri petition-høvundin (Petition-høvundur ella Dátueftirlitara) í veitingini av tænastum fyri at hýsa netinnar petitions-umsóknum (Tænastur).
Broyting av treytum
Vit áskilja okkum rættin til at broyta ella tillaga hesi treytir í hvørjum tíð sum helst uttan ávaring frammanundan.
Ásetingar og Leiklutur
- Tænastuveitari: Petitions.com (Petitions.com Group Oy), ið virkar sum dátuheindari, viðger persónsupplýsingar vegna dátuábyrgdara eftir tørvi fyri at levera tænasturnar.
- Dátustjóri: Peningaundirskrivarin, sum ásetur endamál og hættir fyri viðgerð av persónsupplýsingum, sum verða innsavnaðar frá undirskrivarum av teirra peningaundirskrift. Sum høvundur av eini áheitan, ið verður hýst á Petitions.com, verða tú mettur sum dátueftirlit. Tú avgert innihaldið í áheitanini, hvat verður spurt frá undirstskrivarunum, endamálini við at viðgera teirra persónsupplýsingar, og tíðina, sum persónsupplýsingarnar verða goymdar. Petitions.com veitir eina talgilda pall fyri at stovna og hýsa uppropum, og lættir tína leiklut sum Dátueftirlit við sjálvsavgerðarrætti at forma savning og nýtslu av dátunum í samsvari við tínar mál og lógarkrøv.
Viðgerðarøki
The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Umfarið av gagnaviðgerðarvirksemi er avmarkað til at hýsa, stýra og lætta um talgildar undirskriftainnsavningar.
As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.
The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.
Dátuvernd
Tænastuveitarin góðtekur at seta í verk tøkniligar og skipanarligar ásetingar fyri at tryggja persónsupplýsingar móti óheimilaðum atgongd, tapi ella skaða.
Forboðað dátusavnan
Tað er bannað at biðja um persónligar samleikanummur (so sum tjóðskaparnummur) frá undirskrivarum.
Undirviðgerðarar
Tænastuveitarin kann seta undirfyritøkur undir til at hjálpa við at veita tænasturnar. Tænastuveitarin fer at tryggja, at undirviðgerðarar fylgja dátuverndarskyldum, sum eru í samsvari við hetta DPA. Tú staðfestir og góðtekur, at Tænastuveitarin hevur fullan ræði á at útvelja og skifta útrunrutænarar eftir tørvi fyri at veita Tænasturnar á ein skilagóðan hátt.
Yvirlit yvir undirviðgerðarar. (Síðst dagført: 2026-07-24)
Ábyrgd Dátustjóra
Dátueftirlitið er ábyrgdarpersónur fyri at tryggja, at innsamling, viðgerð, og handfaring av persónsupplýsingum samsvara við allar galdandi lógir og reglugerðir.
Dátueftirlitsfólk Identifikatión
Undir Almennu reglugerðini um dátuvernd (GDPR) er tað krav, at samleiki dátustýringsfólksins verður týðiliga ávístur. Ásetingarnar niðanfyri eru gjørdar fyri undirskriftasavnarar, ið brúka heimasíðu okkara:
Einstakir ÁheitanarHøvundar
Um tú, sum persónur, skapar eina undirskriftainnsavnan, ert tú kravdur at geva títt fulla løgfrøðiliga navn. Hetta tænir sum títt samleikaprógv sum dátustjóri í sambandi við GDPR.
Felagsskaparskrivstovuleiðarar
Um ein undirskriftainnsavnan verður stovnað vegna eina felagsskap, skal felagsskapurin viðhefta sítt fulla løgfrøðiliga navn. Harumframt eigur felagið at tilnevna og veita sambandstøl hjá einum umboði, ið er ábyrgd fyri dátuviðgerð, so sum einum dátuverndarfólki ella líknandi.
Rættindi hjá dátuevnum
Dátustjórin skal tryggja, at dátueindir (undirskrivarar av áheitan) kunnu útinna sínar rættindi sambært GDPR, so sum rættin til atgongd, rætting, ella striking av teirra dátum, ella at leggja klagu til eina eftirlitsmyndugleika.
Handfaring av áheitan frá skrásettum um striking av persónsupplýsingum frá undirskrivarum
The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.
Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.
When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.
The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.
Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.
Tekniskar skráir kunnu innihalda persónsupplýsingar, so sum IP-bústaðir ella metadata frá teldupostútbering. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.
The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.
Handling Rectification Requests from Signatories
The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.
Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.
The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.
Notifying Recipients
Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.
Ábyrgd og Eftirliti
Dátustjórin skal kunna vísa til at samsvarar við GDPR, íroknað svara fyrispurningum frá dátuevnunum viðvíkjandi teirra persónsupplýsingum.
Persónuverndarpolitikkur ella Fráboðan
Ein greið og atkomulig persónsdateyingarpolitikkur ella -fráboðan skal veitast, sum lýsir, hvussu persónsupplýsingar verða viðgjørdar, endamálini við viðgerðini, og hvussu dátuverndarpersónar kunnu útinna sín rættindi.
Fráboðan um Broytingar
Pettitiónshøvundar skulu kunngera Petitions.com (Petitions.com Group Oy) um nakrar broytingar í teirra støðu sum dátustýrari ella í teirra umboðshaviðra kontaktupplýsingum.
Árliga Viðgerð av Dátaửviðgerð
Upphavsmanninum av áheitanini er kravt at gera eina árliga gjøgnumgongd fyri at sannkenna, um enn er ein galdandi grund til framhaldandi viðgerð av persónsupplýsingum hjá undirskrivarunum. Henda ummælisviðgerðin skal meta um neyðsyn og viðkomu dátunnar í mun til endamálið með áheitanini. Um Undirskrivastovun avgerð, at eingin galdandi grund er longur fyri at halda fram við viðgerð av dátunum, skulu tey taka hóskandi stig til at steðga viðgerðini og seta í verk strikking av dátunum í samsvari við viðkomandi dátafræðsilógir.
Use of Up-to-Date Signature Data
Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.
Goymslu og Striking av Dátum
Um Dátueftirlitið (hövundur av undirskriftainnsavningini) brýtur nakrar treytir í Dátueftiransingarsáttmálanum (DPA), íroknað men ikki avmarkað til manglandi árliga endurskoðan av dátueftiransingarvirksemi ella at veita eina gildaða grundgeving fyri framhaldandi viðgerð av persónligum upplýsingum hjá undirskriftarum, hevur veitandi av tænastuni rætt til at strika ella sletta persónligar upplýsingar knýttar at teirra undirskriftainnsavning.
Ábyrgdaravmarking
Í ongum føri skal samlaða ábyrgdin hjá dátuviðgeranum til dátustýraran fyri allar skaðar, tap og grundir til krøvum, um tað er í sáttmála, skaðabót (harímillum vanrøkt) ella annað, fara upp um samlaða upphæddina, ið dátustýraran hevur goldið dátuviðgeranum undir hesi avtalu.
Galdandi lóg
Henda semja verður hjáð undir sett undir finska lóggávu.