Data Processing Addendum (DPA)

Published: October 2, 2026

The latest version of this document is always available at gesento.ai/en/dpa.

This Data Processing Addendum (“DPA”) forms an integral part of the main agreement (service agreement/order/terms of service) between Nordic Learning Intelligence Oy (Business ID 3599307-3, Helsinki; “Company”) and the Customer Organization purchasing the service (“Customer Organization”).

This DPA defines the data protection obligations of the parties in accordance with Article 28 of the EU General Data Protection Regulation (GDPR 2016/679), applying to the corporate use of the Gesento.ai service. This DPA does not apply to Consumer Users.

1. Roles and Controllership

In a corporate customer relationship, personal data is divided into two distinct datasets:

  • Coaching Data (videos, analyses, feedback): The Company is the sole and independent controller of this data. The Customer Organization has no access to the Authorized User's Coaching Data. This processing is governed by the Company's Privacy Policy and Terms of Service.
  • Administrative Data (activation status, number of uploaded videos, name, email): The Customer Organization acts as the controller, and the Company acts as a processor on behalf of the Customer Organization. This DPA applies exclusively to the processing of this Administrative Data.

2. Subject Matter, Duration, and Nature of Processing

The Company processes Administrative Data solely to provide the Customer Organization with activation and usage statistics for the duration of the service agreement and Terms of Service. Details are set out in Annex 1.

3. Obligations of the Company as Processor (Art. 28(3) GDPR)

  1. Compliance with Instructions: The Company processes Administrative Data only in accordance with the documented instructions of the Customer Organization and this DPA, unless required otherwise by applicable EU or Member State law.
  2. Confidentiality: The Company ensures that persons authorized to process personal data have committed themselves to appropriate confidentiality obligations.
  3. Data Security: The Company implements appropriate technical and organizational security measures (Art. 32 GDPR) to protect data, including encryption in transit and at rest. The measures are described in Annex 3.
  4. Assistance Obligation: The Company assists the Customer Organization through reasonable measures, against reimbursement of reasonable additional costs, in fulfilling data subject rights and in complying with obligations under Articles 32–36 of the GDPR.
  5. Deletion or Return of Data: The Company deletes or returns all Administrative Data at the choice of the Customer Organization thirty (30) days after the termination of the service agreement, unless retention is required by law.
  6. Demonstrating Compliance: The Company makes available to the Customer Organization the information necessary to demonstrate compliance with obligations under Article 28 of the GDPR.
  7. Unlawful Instructions: The Company shall immediately inform the Customer Organization if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions.

4. Sub-processors

The Customer Organization grants a general authorization to the Company to engage sub-processors in processing Administrative Data. Current sub-processors are listed in Annex 2.

The Company shall impose on each sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures. The Company remains fully liable to the Customer Organization for the performance of its sub-processors' obligations.

The Company shall notify the Customer Organization in advance of adding or replacing a sub-processor by giving notice via email or through the Service. The Customer Organization has the right to object to a new sub-processor for compelling and justified data protection reasons within fourteen (14) days of notification. If the parties cannot reach agreement, the Company has the right to offer an alternative technical solution, or the parties may agree to limit the feature operating under the sub-processor in question.

5. International Data Transfers

Administrative Data is processed and stored within the EU/EEA. If a transfer of data outside the EU/EEA becomes necessary in the future, it will be executed in compliance with transfer mechanisms under Chapter V of the GDPR (such as the European Commission's Standard Contractual Clauses, SCCs) and necessary supplementary safeguards.

6. Personal Data Breaches

The Company shall notify the Customer Organization without undue delay and, where feasible, within 48 hours after becoming aware of a personal data breach affecting Administrative Data. The Company shall provide the Customer Organization with reasonably available information to investigate the incident and make necessary authority notifications.

7. Data Subject Requests

If an Authorized User submits a data protection request regarding Administrative Data directly to the Company, the Company shall forward the request to the Customer Organization without undue delay. Requests regarding Coaching Data shall be handled directly and independently by the Company as controller.

8. Audits and Inspections

The Customer Organization's right to inspect compliance with this DPA shall primarily be fulfilled through a written security report provided by the Company, certificates of the Company's sub-processors (such as cloud service providers), or other documentation prepared by the Company.

If the Customer Organization or an independent auditor authorized by it (who is not a competitor of the Company) wishes to conduct an on-site inspection, it may be performed no more than once per year with reasonable prior notice (at least 30 days). The audit must be conducted during normal business hours without disrupting the Company's business operations or compromising the security of other customers or the Company's trade secrets.

The Customer Organization shall bear all of its own and third-party costs arising from the audit and shall reimburse the Company for reasonable working time incurred by the audit (according to the current price list), unless a material and proven breach of contract by the Company is identified during the audit.

9. Liability, Governing Law, and Order of Precedence

This DPA is governed by the laws of Finland, and any disputes arising from it shall be resolved in the District Court of Helsinki.

In the event of a conflict between this DPA and the service agreement/Terms of Service regarding the processing of personal data, the provisions of this DPA shall prevail. Total liability and damages under this DPA are subject to the limitations of liability agreed upon in the main agreement/Terms of Service.

Annex 1 — Processing Details

SubjectDetails
Subject matter of processingTracking the activation and usage volume of Customer Organization licenses.
Duration of processingValidity period of the service agreement + 30 days deletion window.
Nature of processingCollection, storage, reporting, and deletion of Administrative Data.
Categories of personal dataName, work email address, activation status (yes/no), number of uploaded videos.
Categories of data subjectsAuthorized Users of the Customer Organization who have been assigned a license.
Special categories of personal dataNot processed on behalf of the Customer Organization.

Annex 2 — Authorized Sub-processors

Sub-processorProcessing TaskLocation
Google Cloud Platform (GCP)Hosting and system infrastructureEU/EEA
BrevoSystem and email communicationFrance (EU)

Annex 3 — Technical and Organizational Security Measures

  • Hosting: Data is hosted on Google Cloud Platform in EU/EEA regions.
  • Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).
  • Access control: Access to personal data is restricted by role-based access rights and granted only to authorized personnel who need it for their duties.
  • Confidentiality: Personnel with access to personal data are bound by confidentiality obligations.
  • Logging and monitoring: Administrative activity and security events are logged. Audit and security logs are retained for up to 400 days.
  • Backups: Automated backups are overwritten and permanently deleted on a rolling cycle within 30 days.
  • Data minimization: Only the Administrative Data listed in Annex 1 is reported to the Customer Organization. Coaching Data is never shared with the Customer Organization.
  • Deletion: Administrative Data is deleted or returned after the termination of the service agreement as set out in Section 3.