Data Processing Agreement (draft)

Data Processing Agreement (DPA)

Draft — for review with early-access organizations; not yet a signed agreement.

This page shows the data processing agreement we intend to sign with schools, therapy practices, and municipalities when the Moi organization package launches. We are publishing it early so you can read it, question it, and improve it with us before anything is signed. Nothing on this page creates a contract by itself.


1. Who this agreement is between

Processor: My Own Company Oy Ab, business ID 3434307-9, Turku, Finland (“Moi”, “we”, “us”). We build and operate Moi Calendar.

Controller: the organization signing this agreement — a school, therapy practice, municipality, or similar body (“you”, “the organization”) that uses Moi Calendar with the children and families in its care.

Under the EU General Data Protection Regulation (GDPR), you decide why and how personal data is processed; we process it only on your instructions. This agreement is written to satisfy Article 28(3) GDPR.

Definitions

Terms like personal data, processing, data subject, personal data breach, and supervisory authority have the meanings given in Article 4 GDPR. Subprocessor means another processor we engage to process personal data on your behalf. Services means Moi Calendar (iOS and Android apps) together with the optional cloud sync and backup service.


2. One thing to understand first: offline means offline

Moi Calendar is an offline-first app. When an account is used purely offline, all data stays on the device. There is no server, no sync, no processing by us at all. This agreement only becomes relevant for accounts that turn on the optional cloud sync / backup service (currently in beta), which stores data on servers in the EU.

If your organization never enables sync, we never see the data. We think that’s worth saying plainly, because it is the simplest privacy guarantee we can offer.


3. Subject matter and duration

Subject matter: the personal data your organization and its users put into Moi Calendar when cloud sync/backup is enabled, plus the account and diagnostic data needed to run the service.

Duration: this agreement applies for as long as your organization’s service agreement with us is in force, and for as long afterwards as we still hold personal data on your behalf (see section 12 on return and deletion).


4. Nature and purpose of processing

We process personal data only to:

  • provide cloud sync and backup of calendar content between the devices your organization and its families use;
  • operate user accounts (sign-in, subscription status);
  • keep the service running: error monitoring, support, transactional email (e.g. sign-in and account emails);
  • measure product usage in aggregate so we can improve the app.

We do not:

  • profile children or any other users;
  • use personal data for advertising;
  • train AI models on user content;
  • sell or share personal data for any commercial purpose.

5. Categories of data and data subjects

Data subjects

  • Children whose schedules and daily lives are organized in Moi Calendar.
  • Guardians, family members, teachers, therapists, and other staff who use the app with them.

Categories of personal data (when sync is enabled)

CategoryExamplesNotes
Account identifiersEmail addressNeeded for sign-in and account emails
Calendar contentEvents, notes, and attached photos, audio, and videoMay depict or describe children. This is the heart of the product and the reason this agreement exists — we treat it as the most sensitive data we hold
Device and diagnostic dataDevice model, OS version, error reports, usage eventsUsed only to keep the service working

Children’s data

Moi Calendar exists for children’s ecosystems, so children’s data is not an edge case — it is the point. Two things follow from that:

  1. You provide the lawful basis. As controller, the organization (or the guardian, where the organization’s setup delegates this) is responsible for the legal ground for processing children’s data and for any consents or authority required under the GDPR and national law.
  2. We minimize. We only process what sync requires, we never use children’s data for anything beyond providing the service, and analytics events never contain calendar content.

6. Your obligations and ours (the Article 28(3) checklist)

The controller (you) will:

  • ensure there is a lawful basis for the data entered into Moi Calendar;
  • give us processing instructions that comply with the law (using the app as documented counts as your instruction);
  • inform data subjects — families, staff — as the GDPR requires;
  • tell us promptly if you believe an instruction or a behavior of the service breaches data protection law.

The processor (we) will:

  • process only on your documented instructions (Art. 28(3)(a)), including for any transfer of data outside the EU/EEA, unless EU or member-state law requires otherwise — in which case we tell you before processing, unless that law forbids it;
  • keep confidentiality: everyone authorized to process the data is bound by confidentiality (Art. 28(3)(b)). Today, access is limited to the developer (see section 8);
  • implement appropriate security measures under Article 32 (Art. 28(3)(c), detailed in section 8);
  • respect the subprocessor rules in section 7 (Art. 28(3)(d));
  • help you answer data subject requests (Art. 28(3)(e), section 9);
  • assist you with security, breach notification, data protection impact assessments, and consultations with supervisory authorities, taking into account the nature of the processing and the information available to us (Art. 28(3)(f));
  • delete or return all personal data at the end of the services, at your choice (Art. 28(3)(g), section 12);
  • make available the information needed to demonstrate compliance and allow and contribute to audits (Art. 28(3)(h), section 11);
  • maintain a record of processing activities carried out on your behalf (Art. 30(2)).

If we ever think one of your instructions infringes the GDPR, we will tell you immediately rather than quietly comply.


7. Subprocessors

You give us general written authorization to use the subprocessors listed below. We impose data protection obligations on each of them that are no weaker than the ones in this agreement, and we remain fully liable to you for their performance.

Current subprocessor list

SubprocessorEntity / countryPurposeWhere the data lives
Hetzner Online GmbHGermanyServer hosting and object storage (the sync backend and media storage)Germany / Finland
Sentry (Functional Software, Inc.)USA (EU data region)Error monitoringEU region (de.sentry.io)
PostHogUSA (EU cloud)Product analytics — usage events only, never calendar contentEU cloud
Crisp IM SARLFranceSupport chatEU
Mailgun (Sinch)USA / Sweden groupTransactional email (sign-in, account emails)EU region, as configured by us

Not a subprocessor: our website analytics run on Plausible, self-hosted on our own Hetzner infrastructure. No third party is involved and no app data flows there.

Changes to this list

Before we add or replace a subprocessor, we will notify you (email to your named contact) at least 30 days in advance. If you object on reasonable data protection grounds and we cannot offer a workable alternative, you may terminate the affected services. We will also keep the current list published on this page.


8. Security measures (Article 32)

We describe our measures plainly, without certification badges we don’t hold. What we actually do:

  • Encryption in transit: all traffic between the app and our servers uses TLS.
  • Encryption at rest: data stored on Hetzner infrastructure is encrypted at rest.
  • EU-only hosting: all server-side storage and processing happens in the EU (Germany and Finland).
  • Access control: production access is limited to the developer. There is no support staff with database access, no offshore team, no third-party contractors with access to user data.
  • Data minimization by architecture: offline use involves no server processing at all; analytics events are designed to exclude calendar content; error reports go to the EU Sentry region directly from the device.
  • Deletion semantics: the app has soft-delete (“trash”) with restore, so accidental deletions by children or stressed parents are recoverable; permanent deletion genuinely removes server copies.

We hold no ISO 27001 or SOC 2 certification. We are a small company and will not pretend otherwise; what we offer instead is a small attack surface, EU infrastructure, and an architecture where the most private mode — offline — involves us not at all. We will reassess formal certifications as the organization business grows, and we welcome your security questionnaires in the meantime.


9. Helping with data subject rights

If a parent, staff member, or other data subject exercises their GDPR rights (access, rectification, erasure, restriction, portability, objection), that request is yours to answer as controller — but we will help:

  • If a request reaches us directly, we will forward it to you without undue delay and will not answer it ourselves except to point the person to you.
  • We will provide the technical assistance needed to fulfil requests — export, correction, or deletion of the relevant data — insofar as you cannot do it yourself through the app (most rights can be exercised directly in-app: content can be viewed, edited, and deleted by its users).

10. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any case within 72 hours of becoming aware of it. The notification will include, to the extent known:

  • what happened and when;
  • the categories and approximate number of data subjects and records affected;
  • the likely consequences;
  • what we have done and plan to do about it;
  • a contact for follow-up.

If we can’t provide everything at once, we send what we have and follow up as we learn more. We will document all breaches and our responses, and we will assist you with your own notification duties towards the supervisory authority and data subjects (Articles 33–34).


11. Audit rights

You may verify our compliance with this agreement:

  • First line: we answer written audit questionnaires and provide documentation of our measures within a reasonable time, free of charge.
  • If that is not enough: you (or an independent auditor you mandate, who is not a competitor of ours) may audit the relevant processing, on at least 30 days’ notice, during business hours, no more than once per year unless a supervisory authority requires it or a breach has occurred. Both sides bear their own costs.

We will contribute to audits honestly. Given our size, an audit will usually mean talking to the person who built the system — we consider that a feature.


12. Term, termination, and what happens to the data

This agreement lasts as long as we process personal data for you.

When your subscription or service agreement ends:

  • Data on devices stays on devices. Moi is offline-first; ending the service never wipes local data. Families keep their calendars.
  • Server copies: at your choice, we return the data (export in a machine-readable format) and/or delete the server-side copies. If you give no instruction within 90 days of termination, we will notify you and then delete the server copies.
  • We delete data from backups on the backup rotation schedule.
  • We may retain data only where EU or Finnish law requires it, and only for as long as that law requires.

During the agreement: deletion requests are honoured on request. In-app deletion follows the trash/restore semantics described in section 8; emptying the trash or account deletion removes server copies.


13. International transfers

Our infrastructure is EU-only. Hosting and storage are in Germany and Finland. We do not transfer your personal data outside the EU/EEA to run the service.

One honest nuance: two of our subprocessors — Sentry and PostHog — are US-headquartered companies operating EU data regions. Your data is stored and processed in the EU, but because the contracting entity is a US company, GDPR treats the arrangement cautiously: limited access from outside the EU (for example, by the vendor’s own support or operations staff) cannot be categorically ruled out. Both vendors contractually commit to EU data residency and provide GDPR transfer safeguards (standard contractual clauses) in their data processing terms for any such residual access. The same applies to Mailgun (part of the Sinch group), which we configure to the EU region.

If this nuance matters to your organization — and for some municipalities it will — raise it with us. Error monitoring and analytics are the two services we could most easily bring in-house or replace with EU-owned alternatives, and organizational demand is exactly what would make us do it.


14. Liability and precedence

Liability follows the service agreement between us. Where this DPA and the service agreement conflict on data protection matters, this DPA prevails. Nothing in this agreement limits either party’s obligations directly imposed by the GDPR or the rights of data subjects.

This agreement is governed by Finnish law, without prejudice to mandatory provisions of the GDPR.


15. Contact

My Own Company Oy Ab Business ID 3434307-9 Turku, Finland

Data protection contact: reachable through the support channels listed on this website. For anything concerning this DPA — questions, objections to a subprocessor, breach follow-up, audit requests — write to us and you will be answered by a human who knows the system.

Supervisory authority for us: the Office of the Data Protection Ombudsman, Finland (tietosuoja.fi).


This is a draft. Legal review pending. Talk to us and we’ll shape it together.