Data Processing Agreement
This is a data processing agreement within the meaning of Article 28 of the General Data Protection Regulation (EU) 2016/679, referred to below as this agreement. It is between Weirix OÜ (registry code 12596481, Tallinn, Estonia), referred to as we, and the user of evaluation.ee, referred to as the customer.
No signature is needed
This agreement forms part of the terms of service and applies automatically to every customer from the moment they begin using the service. There is nothing to sign — Article 28's requirement of a written contract is met by this.
If your organisation nevertheless needs a countersigned copy, write to info@evaluation.ee and we will send one.
Who is who
The customer is the controller of all personal data they put into the service or that evaluations produce: the accounts they create or invite, the answers to evaluations, and the free text their assessors write. The customer decides what is collected and why.
We are the processor of that data. We process it only to provide the service, and on the customer's instructions.
For two things we are the controller in our own right, and this agreement does not cover them: the customer's billing details, which we need in order to invoice and to keep our books, and the contact details somebody writes to us themselves. Those are described in the privacy policy.
Our instructions are the customer's
We process personal data only on the customer's documented instructions. Those instructions are the terms of service, this agreement, and the customer's own use of the product — which questionnaire they build, which locations and assessors they add.
If we believe an instruction breaks the law, we will say so and will not act on it until the position is clear.
We do not use customer data to develop our product, to produce analytics, or to train models. We do not sell it or share it with anyone.
Confidentiality
Only those of our people who need access in order to run the service have it. They are bound to keep the data confidential, and that obligation outlasts their employment.
Security measures
We apply technical and organisational measures under Article 32. They are listed in Annex 2. They may be updated, but not in a way that lowers the level of protection.
Sub-processors
The customer gives general authorisation for the use of sub-processors. The current list is Annex 3, and that is the only place it is kept.
We give at least 30 days' notice before adding a sub-processor or replacing one: we update this page and write to the billing contact. A customer with reasonable grounds to object may cancel before the change takes effect, at no charge.
Every sub-processor is under a contract placing the same obligations on them that this agreement places on us. We remain liable to the customer for what they do.
Data subject rights
If someone approaches us to exercise their rights but the data belongs to a customer's workgroup, we do not answer ourselves — we pass the request to the customer, because the decision is the controller's.
We give the customer reasonable help in answering: producing an extract, correcting, deleting. Much of that the customer can also do in the product themselves. The help is free unless the volume is unreasonable.
Reporting a breach
If we become aware of a personal data breach we tell the customer without undue delay and within 72 hours of becoming aware. The notice describes what happened, who and what data it affects, and what we have done about it.
Notifying the supervisory authority and the individuals themselves is the controller's task, so the customer's. We provide the information needed for it.
Deletion and return
After a subscription ends the data stays readable for at least 90 days so that the customer can download it. We then delete it. On written request we delete it sooner.
The exception is accounting records — invoices and payments — which we are required by law to keep. Those cannot be deleted, and they are not evaluation data.
Audits and information
We give the customer whatever information is needed to demonstrate compliance with Article 28. Most of it is written here and in the privacy policy.
The customer may audit, or appoint an independent auditor: on reasonable notice, during working hours, no more than once a year (except following a breach), and without disrupting the service for other customers. The customer bears the cost.
Where the data is
All data is stored and processed within the European Economic Area. We do not transfer it to third countries. Were that ever to change it would be a sub-processor change and would follow the clause above — 30 days' notice, with the legal basis stated.
Liability and governing law
The limitation of liability in the terms of service applies. Where the two conflict, this agreement prevails on questions of personal data and the terms prevail on everything else.
Estonian law applies and disputes are heard by Harju County Court.
Annex 1 — details of the processing
Subject matter and duration
The subject matter is hosting and running evaluation.ee. Processing lasts as long as the subscription does, and ends with the deletion described above.
Nature and purpose
Storing, retaining, displaying and aggregating data into reports, generating PDFs, sending e-mail and taking backups — all so that the customer can carry out evaluations and read the results.
Categories of data subject
- The customer's users: administrators, managers and assessors.
- People the customer has invited who have not yet joined.
- People an assessor describes or names in free text — in practice most often the customer's own service staff.
Types of personal data
- Account: name, e-mail address, language, role in the workgroup.
- Evaluations: answers, points, percentage, the date and time of the visit, the location and the assessor.
- Free text and comments written by an assessor. This is the one field that can contain anything at all — including somebody's name or a description of them.
- Billing: company name, registry code, VAT number, address, e-mail.
Special categories
The product is not intended for special categories of personal data within the meaning of Article 9 — health, trade union membership, religious or political belief, criminal offences. No field asks for them, and the customer undertakes not to enter them.
The one place such data could land is an assessor's free text. So we recommend writing observations about behaviour rather than about a person — "there was no greeting" says everything that needs knowing without creating a named record about anybody.
Annex 2 — security measures
The measures we apply under Article 32. The list describes what exists, not what is intended.
Transmission and storage
- All traffic runs over TLS. HTTP is redirected, and HSTS covers all three hostnames.
- The database is not reachable from the public network: every service is bound to the machine's own interface, behind a firewall.
- Data is stored and processed only within the European Economic Area.
Access
- Separation between workgroups is built into the routing layer: a request for another workgroup's address never reaches a permission check at all, it answers "not found".
- Roles and scope: administrator, manager and assessor, and a membership can be narrowed to a group of locations. Access defaults to narrower, not wider.
- Only the people who operate the service can reach the server, and access is by SSH key rather than by password.
Accounts
- Passwords are hashed (bcrypt) and are not readable by us.
- A password must be at least 10 characters and is checked against known breach corpora — without the password itself being sent anywhere.
- A session is bound to the password: changing it ends every other session. A session expires on inactivity.
- Sign-in and code entry are rate limited, keyed to the address and the IP together, so nobody can lock somebody else out of their own account.
Backups
- The database is backed up every night.
- The backup is encrypted before it reaches the disk, and the private key is not kept on the server — a stolen disk yields nothing.
- It is copied off the machine, within the European Economic Area.
- Restores are rehearsed and the result recorded. "Backups are taken" and "a backup has been restored" are two different claims.
Logs and data minimisation
- Application logs are kept for 14 days. Evaluation content, comments and codes are never written to them.
- An account consists of a name, an e-mail address and a language. We do not collect a phone number, an address, or a history of IP addresses.
- There is no web analytics, no advertising network and no third-party script in the product. There is no cookie banner because there are no cookies that need consent.
Development
- Every change goes through an automated test suite against two different database engines, static analysis, and a dependency vulnerability check.
- Security headers, including a Content-Security-Policy, are in place on all three sites.
- A vulnerability can be reported to info@evaluation.ee; see also security.txt.
Annex 3 — sub-processors
The current list. Changes are notified 30 days in advance, as described above.
Sub-processors
- [TO FILL IN: hosting provider] — the servers and database the product runs on. Location: [TO FILL IN: country], European Economic Area.
- [TO FILL IN: e-mail provider] — sending the service's e-mail: confirmation codes, password resets, invoices and weekly summaries. Receives the e-mail address and the contents of the message. Location: [TO FILL IN: country], European Economic Area.
Other recipients
These are not sub-processors, because they do not process customer data on our behalf. They are listed so that the picture is complete.
- Google Ireland Limited — only where a user chooses to sign in with Google. Google is an independent controller for that sign-in. Google does not see evaluation data. For anyone who does not use it, nothing reaches Google at all.
- The European Commission's VIES — checking that a VAT number is valid. Only the number itself is sent, and only for business customers.
Contact
Weirix OÜ, registry code 12596481, Tallinn, Estonia.
E-mail: info@evaluation.ee
This data processing agreement applies from