Petisionline.com

Perjanjian Pemrosesan Data (DPA)

Diperbarui terakhir: 2026-07-14

Terakhir Diperbarui halaman Subprosesor: 2026-07-04

DPA ini menguraikan syarat-syarat di mana kami memproses data pribadi atas nama Anda.

Perjanjian Pemrosesan Data ini (Perjanjian) menguraikan kewajiban dan kondisi di mana Petitions.com Group Oy (Penyedia Layanan) memproses data pribadi atas nama penulis petisi (Penulis Petisi atau Pengendali Data) dalam penyediaan layanan hosting petisi online (Layanan).

Modifikasi Ketentuan

Kami berhak untuk mengubah atau memodifikasi Persyaratan ini kapan saja tanpa pemberitahuan sebelumnya.

Definisi dan Peran

  • Penyedia Layanan: Petisionline.com (Petitions.com Group Oy), yang bertindak sebagai Pemroses Data, memproses data pribadi atas nama Pengendali Data sesuai kebutuhan untuk menyediakan Layanan.
  • Pengendali Data: Penulis Petisi, yang menentukan tujuan dan cara pemrosesan data pribadi yang dikumpulkan dari penandatangan petisi mereka. Sebagai penulis petisi yang di-hosting di Petisionline.com, Anda dianggap sebagai Pengendali Data. Anda yang memutuskan isi petisi, apa yang diminta dari para penandatangan, tujuan pemrosesan data pribadi mereka, dan durasi penyimpanan data pribadi tersebut. Petisionline.com menyediakan platform online untuk membuat dan menghosting petisi, memfasilitasi peran Anda sebagai Pengendali Data dengan otonomi untuk membentuk pengumpulan dan penggunaan data petisi sesuai dengan tujuan dan kewajiban hukum Anda.

Lingkup Pemrosesan

The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Ruang lingkup aktivitas pemrosesan terbatas pada hosting, pengelolaan, dan memfasilitasi petisi online.

As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.

The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.

Perlindungan Data

Penyedia Layanan berkomitmen untuk menerapkan langkah-langkah teknis dan organisasi guna memastikan keamanan data pribadi terhadap akses yang tidak sah, kehilangan, atau kerusakan.

Pengumpulan Data yang Dilarang

Dilarang untuk meminta nomor identifikasi pribadi (seperti nomor ID nasional) dari penandatangan.

Subprosesor

Penyedia Layanan dapat melibatkan subprosesor untuk membantu dalam menyediakan Layanan. Penyedia Layanan akan memastikan subprosesor mematuhi kewajiban perlindungan data yang konsisten dengan DPA ini. Anda mengakui dan setuju bahwa Penyedia Layanan memiliki kebijaksanaan untuk memilih dan mengganti subprosesor sesuai kebutuhan untuk menyediakan Layanan dengan efisien.

Daftar subprosesor. (Terakhir Diperbarui: 2026-07-04)

Tanggung Jawab Pengendali Data

Pengendali Data bertanggung jawab untuk memastikan bahwa pengumpulan, pemrosesan, dan penanganan data pribadi mematuhi semua hukum dan peraturan yang berlaku.

Identifikasi Pengendali Data

Di bawah Peraturan Perlindungan Data Umum (GDPR), diharuskan bahwa identitas pengontrol data dinyatakan dengan jelas. Ketentuan berikut dibuat untuk penulis petisi yang menggunakan situs web kami:

Penulis Petisi Individu

Jika Anda, sebagai individu, membuat petisi, Anda diwajibkan untuk memberikan nama lengkap Anda yang sah. Ini berfungsi sebagai identifikasi Anda sebagai pengendali data untuk tujuan GDPR.

Penulis Petisi Organisasi

Jika sebuah petisi dibuat atas nama sebuah organisasi, nama hukum lengkap organisasi tersebut harus disediakan. Selain itu, organisasi harus menunjuk dan menyediakan rincian kontak perwakilan yang bertanggung jawab atas aktivitas pemrosesan data, seperti Petugas Perlindungan Data (DPO) atau yang serupa.

Hak Subjek Data

Pengendali data harus memastikan bahwa subjek data (penandatangan petisi) dapat menegakkan hak mereka berdasarkan GDPR, seperti hak untuk mengakses, memperbaiki, atau menghapus data mereka, atau mengajukan keluhan kepada otoritas pengawas.

Menangani Permintaan Penghapusan Data Subjek dari Penandatangan

The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.

Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.

When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.

The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.

Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.

Log teknis dapat berisi data pribadi, seperti alamat IP atau metadata pengiriman email. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.

The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.

Handling Rectification Requests from Signatories

The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.

Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.

The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.

Notifying Recipients

Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.

Akuntabilitas dan Kepatuhan

Pengendali data harus dapat menunjukkan kepatuhan dengan GDPR, termasuk menanggapi permintaan subjek data terkait data pribadi mereka.

Kebijakan Privasi atau Pemberitahuan

Kebijakan atau pemberitahuan privasi yang jelas dan mudah diakses harus disediakan, yang menjelaskan bagaimana data pribadi diproses, tujuan pemrosesan, dan bagaimana subjek data dapat menjalankan hak mereka.

Pemberitahuan Perubahan

Penulis petisi diwajibkan untuk memberi tahu Petisionline.com (Petitions.com Group Oy) tentang setiap perubahan dalam status mereka sebagai pengendali data atau dalam detail kontak perwakilan mereka.

Tinjauan Tahunan Pemrosesan Data

Penulis Petisi diharuskan melakukan tinjauan tahunan untuk memastikan apakah masih ada alasan yang sah untuk melanjutkan pemrosesan data pribadi dari para penandatangan. Tinjauan ini harus menilai kebutuhan dan relevansi data terkait dengan tujuan petisi. Jika Penulis Petisi menentukan bahwa tidak ada alasan yang sah untuk melanjutkan pemrosesan data, mereka harus mengambil langkah yang tepat untuk menghentikan pemrosesan dan memulai penghapusan data sesuai dengan undang-undang perlindungan data yang berlaku.

Use of Up-to-Date Signature Data

Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.

Penyimpanan dan Penghapusan Data

Apabila Pengendali Data (penulis petisi) melanggar ketentuan apa pun dalam Perjanjian Pemrosesan Data (DPA), termasuk namun tidak terbatas pada kegagalan melakukan tinjauan tahunan atas kegiatan pemrosesan data atau memberikan justifikasi yang valid untuk pemrosesan data pribadi penandatangan yang sedang berlangsung, Penyedia Layanan berhak untuk menghapus atau menghapus data pribadi terkait dengan petisi mereka.

Batasan Tanggung Jawab

Dalam hal apa pun, total tanggung jawab prosesor data kepada pengendali data atas semua kerusakan, kerugian, dan penyebab tindakan, baik dalam kontrak, kesalahan (termasuk kelalaian), atau lainnya, tidak akan melebihi jumlah total yang dibayarkan oleh pengendali data kepada prosesor data berdasarkan perjanjian ini.

Hukum yang berlaku

Perjanjian ini akan diatur oleh hukum Finlandia.