You are the controller. We are the processor.
The written terms under which Fidanet Solution Oy processes personal data on behalf of a Fizzy customer, as required by Article 28 of the GDPR.
Summary
You decide what happens to the personal data in your account. We only act on your written instructions, we keep it in the European Union, we tell you before a sub-processor changes, and we help you answer requests from the people whose data it is. When the contract ends, you get an export and we delete the rest.
This agreement sets out how we process personal data on your behalf when you use Fizzy, as required by Article 28 of the GDPR. It forms part of the Terms of Service. You are the controller. We are the processor.
Parties
Controller: the customer named in the subscription agreement. Processor: Fidanet Solution Oy, business ID 3497432-1, Marinkallio 6b, 02320 Espoo, Finland.
Subject matter and duration
We process personal data only to provide Fizzy and the support that comes with it, for as long as the subscription is in force, plus the deletion window described under Retention, return and deletion.
Nature and purpose of processing
Recording and sealing sales, processing and reconciling payments, producing reports and statutory exports, providing multilingual assistance from your own data, hosting, backup, security monitoring, and support at your request.
Categories of data subject
- Your staff and other authorised users of the service.
- Your customers, to the extent their data reaches the service, for example a name on an order, a loyalty identifier, contact details for a receipt, or a booking.
- Your business contacts, where you record them.
Categories of personal data
- User account data: name, work email, role, permissions, and sign-in events.
- Operational identity data: the staff identity attached to each sealed entry, which is what makes the ledger auditable.
- Transaction data where it relates to an identifiable person, for example an order under a customer's name or a receipt sent to an address.
- Payment metadata: masked card details, authorisation and reconciliation references. Full card data is handled by Worldline and does not reach our systems.
- Support correspondence you send us, including anything you attach to it.
Fizzy is not designed for special categories of personal data under Article 9. Do not put them into the service.
Our obligations
- We process personal data only on your documented instructions. Your use of the service, and its configuration, constitute those instructions. If we believe an instruction breaches data protection law, we will tell you.
- Everyone with access is bound by confidentiality and has access only where their role requires it.
- We implement appropriate technical and organisational measures, described under Security measures.
- We assist you, taking account of the nature of the processing, with data subject requests, with security obligations, with breach notification, and with impact assessments.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it.
- We make available the information you reasonably need to demonstrate compliance, and we allow audits as described under Audit.
Your obligations
You ensure there is a lawful basis for the data you put into the service, that your own privacy notices cover it, and that your users are authorised. You control what data enters Fizzy, including how much customer detail you choose to record.
Security measures
- Encryption of data in transit, and at rest in our hosting environment.
- Logical separation between tenants, so one customer cannot reach another's data.
- Role-based access control, least privilege, and individual accounts for our personnel.
- An append-only, hash-chained ledger, so alteration of a sealed record is detectable by construction rather than by policy.
- Audit logging of administrative and support access.
- Regular backups, with restoration tested.
- Segregated environments, so development and testing do not run on live customer data.
Retention, return and deletion
On termination you may export your data in the formats described in the documentation. After the export window agreed in your subscription, we delete your personal data from live systems, and backups age out on their normal cycle. We keep only what law requires us to keep, and it stays protected under this agreement while we do.
The sealed ledger is append-only. Where erasure of an individual entry would destroy a statutory sales record, we work with you on what the law actually permits, which is usually restriction rather than deletion.
Audit
We answer reasonable written questions about our processing, and we provide the documentation we hold. Where that is not enough for your obligations, an audit may be arranged on reasonable notice, during business hours, at most once a year unless a supervisory authority requires otherwise, subject to confidentiality and without disrupting other customers.
Sub-processors
You give general authorisation for us to use sub-processors. Each one is bound by written terms no less protective than these, and we remain responsible for their performance. Current categories are cloud hosting and backup, payment processing, email and messaging delivery, error monitoring, and our accounting provider. The named, current list is available through the Trust Center or from legal@fizzy.fi. We give notice before adding or replacing one, and you may object on reasonable data protection grounds.
International transfers
Processing takes place in the European Union. If a transfer outside the EEA becomes necessary, we will inform you and put an appropriate transfer mechanism in place, such as the European Commission's standard contractual clauses together with any supplementary measures required.
Liability and order of precedence
Liability under this agreement follows the Terms of Service. Where this agreement and the terms conflict on data protection, this agreement prevails. Where a signed agreement between us conflicts with this page, the signed agreement prevails.
Contact
Data protection queries: legal@fizzy.fi · Fidanet Solution Oy, Marinkallio 6b, 02320 Espoo, Finland.
We aim to write our legal documents in language a shop owner can read without a lawyer. If something here is unclear, tell us and we will rewrite it. That is part of the job, not a favour.