Data Processing Agreement
Last updated: 2026
This Data Processing Agreement (DPA) forms part of the Culture State Terms of Service. It sets out the GDPR Article 28 terms under which Islenord processes personal data on behalf of the customer organization.
Parties and roles The customer organization is the controller of assessment and account data. Islenord (private trader, Business ID 3650802-5, Mariabergintie 3 F 28, 02820 Espoo, Finland) is the processor of that data. Processing takes place only on the controller's documented instructions, which comprise the use of the service and these terms.
Payment processing described separately Payment processing is separate from assessment-data processing. For supported transactions, Stripe (including Link) acts as merchant of record and processes the buyer's billing and payment data as its own independent controller, not as Islenord's processor. Islenord is not a processor for that activity and does not receive card details. This does not change the controller and processor roles for assessment data set out above.
Subject matter and duration Subject matter: providing the Culture State service (culture assessments, group-level reporting and support). Duration: the term of the agreement plus the agreed retention period afterwards (24 months by default).
Nature and purpose of processing Running surveys, storing anonymous responses, calculating group-level results, producing reports, managing accounts and subscriptions, and providing technical support.
Categories of data and data subjects Data subjects: the customer organization's users (contacts) and the employees who take part in assessments. Data: account data (name, work email, role, organization), billing reference data, and optional follow-up contact details (an email address). Survey responses are stored without any respondent identifier and cannot be linked to an individual.
Special categories The service is not intended for special categories of personal data. The customer undertakes not to enter such data into the service.
Processor obligations We process data only on instructions, ensure that persons authorised to process are bound by confidentiality, implement the technical and organisational measures required by Article 32, assist with data subject requests and with the obligations in Articles 32–36, and make available the information needed to demonstrate compliance.
Security measures Data is encrypted in transit and at rest. Access is role-based and limited to what is necessary. Individual responses are not accessible to any human user. Results are reported at group level only, and a group is reported only once the minimum response threshold is met. Activity is logged for security purposes. Backups are held within the EU.
Sub-processors The customer gives general prior authorisation for the use of the sub-processors listed below. We give advance notice of intended changes and the customer may object on reasonable grounds. Sub-processors are bound by equivalent obligations.
Current sub-processors: · Lovable Labs Incorporated — application hosting, database, authentication and transactional email delivery. Personal data is stored in the EU. · Cloudflare, Inc. — content delivery, edge request handling and protection against attacks. EU edge locations; no application data is stored. Stripe and Link are not assessment-data sub-processors, because they neither receive nor process assessment data on the customer's behalf. They are described separately under "Independent payment and business-service providers".
This list is updated before any new sub-processor is taken into use. Questions about this list: contact@culturestate.fi.
Independent payment and business-service providers The providers below are not sub-processors of assessment data.
· Stripe, Inc. and its group companies, including Link — Managed Payments: checkout, payment processing, billing, supported indirect taxes, transaction-level payment support, fraud prevention and disputes. · Stripe (including Link) acts as merchant of record for supported transactions. · Stripe (including Link) processes billing and transaction data separately from the service's other processing, as its own independent controller and not as Islenord's sub-processor. · Stripe (including Link) does not receive assessment responses, participant data, OCHI or OCCI scores, report findings, reports, organization structure, Alignment data or Monitoring data. · Islenord's role as processor of assessment data on behalf of the customer organization is unchanged by the payment service and continues to be governed by this DPA.
Location and transfers Personal data is processed and stored within the EU. If a transfer outside the EU ever becomes necessary, it is made under Standard Contractual Clauses or another valid transfer mechanism.
Personal data breaches We notify the customer of a personal data breach without undue delay after becoming aware of it, and assist with notifications to authorities and data subjects.
Data subject rights We assist the customer in responding to data subject requests. Because assessment responses are anonymous, they cannot be retrieved, rectified or erased at individual level.
Audit On request we provide information demonstrating compliance and allow audits, carried out by the customer or an auditor it mandates, on reasonable terms and no more than once a year unless required by a supervisory authority.
Return and deletion After the agreement ends, organizational data is retained for the agreed retention period (24 months by default) and is then automatically and permanently deleted. Billing and accounting records are subject to their own statutory retention periods. The customer may request an export in a machine-readable format before deletion. Anonymous comparison data contains no personal data and is not identifiable, and therefore remains.
Term and contact This DPA applies for as long as we process personal data on the customer's behalf. Signed copy: contact@culturestate.fi.
This page is maintained by Islenord and may be updated as the service develops.
