数据处理协议 (DPA)
上次更新日期:2026-07-24
最近更新的分处理者页面:2026-07-24
本《数据处理协议》概述了我们代表您处理个人数据的条款。
此数据处理协议(以下简称“协议”)概述了Petitions.com Group Oy(以下简称“服务提供商”)在提供在线请愿托管服务(以下简称“服务”)过程中,代表请愿发起人(以下简称“请愿发起人”或“数据控制者”)处理个人数据的义务和条件。
条款修改
我们保留随时更改或修改这些条款的权利,恕不另行通知。
定义和角色
- 服务提供者:Petitions.com(Petitions.com Group Oy),作为数据处理者,根据需要代表数据控制者处理个人数据以提供服务。
- 数据控制者:请愿书作者,决定从请愿签名者处收集的个人数据处理目的和方式。 作为托管在Petitions.com上的请愿书的作者,您被视为数据控制者。 您决定请愿书的内容,向签署人询问的问题,处理其个人数据的目的,以及存储个人数据的期限。 Petitions.com 提供一个在线平台用于创建和托管请愿,帮助您作为数据控制者,根据您的目标和法律义务自主决定请愿的数据收集和使用。
处理范围
The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. 处理活动的范围仅限于托管、管理和促进在线请愿。
As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.
The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.
数据保护
服务提供商承诺实施技术和组织措施,以确保个人数据免受未经授权的访问、丢失或损坏。
禁止的数据收集
禁止向签名者索要个人识别号码(如国家身份证号码)。
子处理器
服务提供商可以聘请分处理器以协助提供服务。 服务提供商将确保分处理器遵守与本数据处理协议一致的数据保护义务。 您确认并同意,服务提供商保留酌情选择和更换次处理器的权利,以高效提供服务。
分处理者列表。 (最后更新日期:2026-07-24)
数据控制者义务
数据控制者负责确保个人数据的收集、处理和处理符合所有适用的法律和法规。
数据控制者识别
根据《通用数据保护条例》(GDPR),必须明确说明数据控制者的身份。 以下是对使用我们网站的请愿书作者的规定:
个别请愿发起人
如果您作为个人发起请愿,您需要提供您的全名。 这将作为您根据GDPR规定的数据控制者的身份识别。
组织请愿书作者
如果请愿书是代表某个组织创建的,则必须提供该组织的全称。 此外,组织应指定并提供负责数据处理活动的代表的联系方式,例如数据保护官(DPO)或类似人员。
数据主体权利
数据控制者必须确保数据主体(请愿签署者)能够行使其在GDPR下的权利,例如访问、纠正或删除其数据的权利,或者向监督机构提出投诉的权利。
处理签署人要求删除数据主体信息的请求
The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.
Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.
When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.
The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.
Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.
技术日志可能包含个人数据,例如IP地址或电子邮件发送元数据。 These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.
The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.
Handling Rectification Requests from Signatories
The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.
Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.
The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.
Notifying Recipients
Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.
责任与合规
数据控制者必须能够证明符合GDPR的要求,包括回应数据主体关于其个人数据的请求。
隐私政策或声明
必须提供明确且易于访问的隐私政策或通知,说明如何处理个人数据、处理目的以及数据主体如何行使其权利。
变更通知
请愿书作者必须通知Petitions.com(Petitions.com Group Oy)他们作为数据控制者的身份或其代表的联系方式的任何变更。
数据处理年度审查
请愿书作者须进行年度审查,以确定是否仍然有合法理由继续处理签署者的个人数据。 此审核应评估数据与请愿目的之间的必要性和相关性。 如果请愿发起者确定不再有继续处理数据的合法理由,则必须采取适当措施停止处理,并根据适用的数据保护法律启动数据删除程序。
Use of Up-to-Date Signature Data
Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.
数据保留与删除
若数据控制方(请愿书的作者)违反任何数据处理协议(DPA)的条款,包括但不限于未能进行年度数据处理活动审查或未能为继续处理签署人的个人数据提供有效的理由,服务提供商有权删除或移除与其请愿书相关的个人数据。
责任限制
在任何情况下,无论是合同、侵权行为(包括过失)或其他原因,数据处理者对数据控制者的所有损害、损失和诉讼原因的总责任均不得超过数据控制者根据本协议支付给数据处理者的总金额。
适用法律
本协议受芬兰法律管辖。