Data Processing Agreement

Last updated: September 27, 2026

MaturityHR is a product of evaluoi.ai Oy Ltd (Business ID: 3582911-8). This Data Processing Agreement (DPA) applies to the processing of personal data in the MaturityHR service available at maturityhr.com and forms an integral part of the Terms of Service and Subscription Agreement.

1. Definitions

  • Data Controller: The Customer
  • Data Processor: evaluoi.ai Oy Ltd
  • Personal Data: Any data relating to an identifiable person
  • Data Subject: Individuals whose data is processed
  • Sub-processors: Approved third parties supporting the Service

2. Scope and Purpose

evaluoi.ai Oy Ltd processes personal data solely to provide the MaturityHR Service, including:

  • Collection of competence management maturity assessment data
  • Tracking of development initiatives and their impact
  • AI-assisted features (values reflection, value mapping, pulse question suggestions and translations, and the in-app help assistant)
  • Data management, storage, and deletion

Duration: the length of your subscription.

3. Types of Personal Data

  • Email addresses
  • Display names
  • Assessment responses
  • Usage metadata, including IP addresses; entries containing IP addresses and device metadata are anonymized when the related account is deleted

4. Categories of Data Subjects

  • Account owners
  • Assessment participants
  • Collaborators

5. Processor Obligations

evaluoi.ai Oy Ltd will:

  • Act only on Controller's lawful instructions
  • Maintain confidentiality
  • Implement robust security measures (AES-256, TLS 1.3, RLS)
  • Assist with Data Subject requests
  • Delete or return personal data upon termination
  • Maintain audit logs of security events; entries containing IP addresses and device metadata are anonymized upon account deletion
  • Notify the Controller of breaches within 72 hours

6. Sub-processors

We use the following approved sub-processors:

Supabase

  • Database, authentication, data storage, and authentication emails
  • EU region (AWS eu-west-1, Ireland)
  • GDPR compliant

Vercel

  • Application hosting and cookieless web analytics
  • GDPR compliant

Stripe

  • Payment processing
  • PCI DSS Level 1 certified

Sentry (Functional Software, Inc.)

  • Error monitoring; error events may include IP address, browser metadata and request URLs
  • Diagnostics are linked to a pseudonymous user ID only: access tokens are removed from URLs, session replays mask all text and inputs, and the optional feedback form does not ask for a name or an email address and takes no screenshots. The free text a user writes in that form is sent as written. Retained for up to 90 days
  • Data stored in Sentry's EU (Germany) data region
  • Transfers safeguarded by EU Standard Contractual Clauses (Sentry Data Processing Addendum)
  • GDPR compliant

Resend

  • Transactional email delivery (member invitations); recipient email addresses and message content
  • Transfers safeguarded by EU Standard Contractual Clauses (Resend Data Processing Agreement)
  • GDPR compliant

Google Cloud (Vertex AI)

  • AI-assisted features: generating the organizational values reflection and the mapping of named values to framework sub-areas (processed data: organization name, the organization's named values and their descriptions, aggregated maturity scores, and the framework's area and sub-area labels); suggesting pulse survey questions (processed data: sub-area names and the selected initiative's name and description); translating pulse survey questions (processed data: the question texts); and the in-app help assistant (processed data: the user's question, recent conversation turns, and the user's plan and role). No stored individual respondent answers are sent; text that users type into these features is sent as written
  • Processed in the EU (Vertex AI, europe-west1, Belgium)
  • Vertex AI data caching is disabled for the service's project
  • Customer data is not used to train models (Google Cloud Vertex AI terms); processing safeguarded by the Google Cloud Data Processing Addendum
  • GDPR compliant

Customers will be notified 30 days before new sub-processors are added.

7. Security Measures

  • Encryption at rest and in transit
  • Role-based access controls
  • RLS tenant isolation
  • Audit logging of security events (entries anonymized upon account deletion)
  • Encrypted daily backups (rolling retention window)
  • Incident response workflows
  • 72-hour breach reporting

8. Data Subject Rights

We assist the Controller with:

  • Access
  • Rectification
  • Deletion
  • Portability (structured export on request, delivered within 30 days)
  • Consent withdrawal

9. Breach Notification

If a breach occurs, evaluoi.ai Oy Ltd will:

  • Notify within 72 hours
  • Provide full incident details
  • Assist in regulatory notifications

10. Audits and Documentation

The Controller may:

  • Request documentation
  • Conduct audits with reasonable notice
  • Review incident and audit logs

11. Termination

Upon termination:

  • Personal data deleted within 30 days
  • Backups purged within 90 days
  • Data export available on request before deletion (structured format, delivered within 30 days)

12. Governing Law

This DPA follows the laws of Finland and the European Union (GDPR).

13. Contact

hello@evaluoi.ai