Legal
Data Processing Agreement V5 Oct 2025
Effective from: October 8, 2025
MeetingPackage (Cocouz Oy)
Sokerilinnantie 7 C
02600 Espoo, Finland
https://meetingpackage.com
1. VALIDITY
This document is valid from October 8, 2025.
2. BACKGROUND AND PURPOSE
2.1. This DPA governs the processing of Personal Data by MeetingPackage on behalf of You as required for the delivery of the services, including but not limited to CRS for M&E and Group Sales, Booking Engine, License Platform, E-Proposal, MeetingPackage Pay, Global Lead Sharing, Venue Sales Management, Channel Manager, APIs and any other current B2B or future B2B MeetingPackage products.
2.2. Notwithstanding what is stated in the Agreement, in the event of conflict between this DPA and the Agreement, the terms and conditions of this DPA shall prevail.
2.3. “Data Protection Regulation” shall in this DPA mean any applicable data protection legislation as amended from time to time (including but not limited to the General Data Protection Regulation, “GDPR” (2016/679/EU)).
2.4. Any terms not defined in this DPA or the Agreement shall be given the meaning allocated to them in the Data Protection Regulation from time to time.
2.5. This DPA is part of the agreement between you and Cocouz Oy for your use of any part of the MeetingPackage Service Suite (“Services”). Reference to the capitalised term “You” refers to you as the company which is using the Services or any part thereof. Reference to the capitalised term MeetingPackage refers to Cocouz Oy, a limited liability company incorporated under the laws of Finland, with its registered place of business at Sokerilinnantie 7c, 02600 Espoo Finland, and operating under with the company ID-number FI2577592-9.
2.6. MeetingPackage shall process Personal Data on behalf of You and in accordance with the terms and conditions of the DPA for the purpose of providing the Services under the Agreement.
3. ROLES
3.1. MeetingPackage acts as a processor, and You act as a controller, the concepts of which are further defined in GDPR. An individual whose Personal Data is being processed by MeetingPackage under this DPA and the Agreement will act as a Data Subject, the concept of which is further defined in the Data Protection Regulation.
3.2. If You have a separate supply agreement for Application Programming Interfaces with MeetingPackage, then for that portion of the service MeetingPackage acts as a processor and You act as either a processor or a controller depending on your relationship in the data processing chain. The concepts of a processor and controller are further defined in the EU GDPR regulation.
4. YOUR RESPONSIBILITIES
You shall:
4.1. Process Personal Data in accordance with good data processing practices and in compliance with Data Protection Regulation and all applicable laws;
4.2. Give documented instructions to MeetingPackage on the processing of Personal Data, which instructions shall be binding on both You and MeetingPackage after the written approval of MeetingPackage;
5. RESPONSIBILITIES OF MEETINGPACKAGE
5.1. MeetingPackage shall process the Personal Data only in accordance with the Data Protection Regulation, the Agreement and this DPA as well as the approved documented instructions from You unless otherwise required in applicable laws and regulations to which MeetingPackage is subject. In such a case, MeetingPackage shall inform You of such requirement under applicable laws and regulations before processing of Personal Data, unless the applicable laws and regulations prohibit such notification.
5.2. Assistance of You
MeetingPackage shall, taking into account the nature of the processing of Personal Data under this DPA:
5.2.1. Assist You by appropriate technical and organizational measures in Your obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR; and
5.2.2. Assist You in ensuring compliance with its legal obligations pursuant to Articles 32 to 36 of the GDPR.
The assistance performed by MeetingPackage under this section shall be charged in accordance with the pricing and payment terms in the Agreement.
5.3. Data security
MeetingPackage shall implement technical, physical and organizational measures, as further explained under Appendix 1 (Description of the Processing of Personal Data) to comply with the obligations regarding security of processing under the GDPR.
5.4. Confidentiality
MeetingPackage shall ensure that the Personal Data processed is kept confidential. MeetingPackage shall ensure that any person MeetingPackage has authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.5. Reporting and notification obligation
MeetingPackage shall make available to You all information necessary to demonstrate compliance with the obligations laid down in this DPA and the GDPR. MeetingPackage shall maintain a record of processing activities under this DPA in accordance with the GDPR (“Record”). MeetingPackage shall provide You with the Record if requested by You.
5.6. Personal Data Breach notification
In the event of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, MeetingPackage shall notify You via email or telephone without undue delay after becoming aware of the personal data breach.
5.7. Returning or destruction of Personal Data
Upon termination of the applicable purpose of the processing of Personal Data, or upon Your written request, MeetingPackage shall either destroy or return to You all Personal Data unless otherwise required by law.
MeetingPackage shall be entitled to destroy all Personal Data processed under this DPA if You have not requested MeetingPackage to return the Personal Data within ten (10) days from the date when the applicable purpose of the processing of Personal Data has terminated.
6. TRANSFERS OF PERSONAL DATA
Allowed with GDPR-compliant safeguards.
7. SUBCONTRACTORS
General authorisation granted; changes notified; objections allowed only with legitimate reason.
8. AUDITING
8.1. At any time during the term of the DPA, You or a recognized, independent third-party auditor appointed by You with proven experience and procedures shall have the right to audit MeetingPackage’s technical and organizational security measures as well as compliance with other data protection obligations agreed under this DPA. You shall give a prior written notice to MeetingPackage, such notice to be given at least sixty (60) calendar days prior to any audit.
8.2. MeetingPackage shall assist You in the execution of an audit and charge such assistance in accordance with the pricing and payment terms defined in the Agreement.
9. LIMITATION OF LIABILITY
The limitation of liability agreed in the Agreement shall apply to this Agreement.
10. TERM
This DPA shall become effective when duly signed by both Parties and shall automatically terminate upon termination of the applicable purpose of processing of Personal Data under the Agreement.
11. APPLICABLE LAW AND DISPUTE RESOLUTION
This DPA shall be governed by the laws of Finland without regard to its principles and rules on conflict of laws and shall be subject to dispute resolution in accordance with the Agreement.
12. APPENDICES
● Appendix 1: Description of the Processing of Personal Data
● Appendix 2: Organisational and Technical Security Measures
Appendix 1 – Description Of The Processing Of Personal Data
This appendix provides a more detailed description of the Personal Data processed by MeetingPackage on behalf of You. The Parties may also agree in this appendix to provide more detail, for example, on the data security measures taken by the Supplier to secure the Personal Data.
1. Services, Nature and purpose of the processing of Personal Data
Purpose: enable the provision of Services, Customer Support, improve the quality of the service and fix issues within the Services.
2. Types of Personal Data and categories of Data Subjects
MeetingPackage processes the following categories of data subjects: End-customers (the bookers), client employees (hotel admins, staff), accounts of hotel customers (agencies or corporates), account contacts of hotel customers (employees/users of such accounts)
MeetingPackage processes the following types of Personal Data: Name, email, phone number, address, membership number, Reference ID to external systems such as CRM
3. Duration of the processing of Personal Data
3.1. For the term of the Agreement or as otherwise agreed with the You.
Appendix 2 – Organisational and Technical Security Measures
Description of the technical and organisational security measures implemented by the processor(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, as well as the risks for the rights and freedoms of natural persons.
Cocouz Oy (“MeetingPackage“) are ISO-27001 certified by Kiwa (cert nr. 13606-02) with the scope covering “Operations (development, marketing, sales and support) for maintaining and developing the MeetingPackage product / service suite”.
1. Organisational Security Measures
1.1. Governance & Policies
1.1.1. Information Security Management System (ISMS) established and maintained in line with ISO 27001.
1.1.2. Documented information security policies approved by management and communicated to employees.
1.1.3. Formal risk assessment and treatment process.
1.1.4. Regular review of ISMS performance and continual improvement.
1.2. Roles & Responsibilities
1.2.1. Appointment of an Information Security Officer or equivalent.
1.2.2. Clearly defined roles, responsibilities, and segregation of duties.
1.3. Training & Awareness
1.3.1. Mandatory information security and privacy training for all employees.
1.3.2. Regular phishing awareness and social engineering prevention exercises.
1.4. Supplier & Sub-Processor Management
1.4.1. Due diligence and contractual security requirements for all suppliers/sub-processors.
1.4.2. Periodic reviews and monitoring of sub-processors’ compliance.
2. Technical Security Measures
2.1. Physical & Environmental Security
2.1.1. Secure office premises with controlled access
2.1.2. Data centers (via cloud providers like AWS) with multi-layered security and 24/7 monitoring.
2.2. 2.2 Access Control
2.2.1. Role-based access control (RBAC) aligned with the principle of least privilege.
2.2.2. Unique user IDs for all accounts; no shared accounts for administrative access.
2.2.3. Strong password policy or multi-factor authentication (MFA) for system access.
2.2.4. Automatic session timeouts and account lockouts after repeated failed attempts.
2.3. Encryption
2.3.1. In transit: TLS 1.2+ (or higher) for all data exchanges.
2.3.2. At rest: AES-256 (or equivalent) for databases, file storage, and backups.
2.3.3. Encryption keys managed securely, with rotation policies.
2.4. Logging & Monitoring
2.4.1. Centralized logging of security-relevant events
2.4.2. Continuous monitoring for anomalies and security incidents.
2.4.3. Retention of logs in a tamper-evident format for a defined period.
2.5. Network Security
2.5.1. Firewalls, intrusion detection/prevention systems (IDS/IPS).
2.5.2. Network segmentation between environments (production, staging, development).
2.5.3. Regular vulnerability scanning.
3. Operational Security Measures
3.1. Backup & Recovery
3.1.1. Encrypted backups with defined retention and secure off-site storage.
3.1.2. Regular restoration testing to verify data integrity and recovery time objectives.
3.2. Change Management
3.2.1. Formal process for approving and documenting changes to systems.
3.2.2. Testing and review before deployment.
3.3. Incident Response
3.3.1. Documented incident response plan covering detection, reporting, containment, eradication, recovery, and lessons learned.
3.3.2. Defined breach notification procedures to customers in accordance with GDPR.
3.4. Business Continuity & Disaster Recovery
3.4.1. Documented business continuity plan (BCP) and disaster recovery plan (DRP), with periodic testing
4. Data Protection Specific Measures
4.1. Data minimisation and purpose limitation in processing.
4.2. Secure deletion or destruction of data after retention periods expire.
4.3. Clear process for handling data subject requests (access, rectification, erasure, etc.).
5. Audit & Certification
5.1. ISO 27001 certification is maintained via annual surveillance audits.
5.2. Willingness to provide evidence of compliance (audit reports, certificates).
5.3. Customer’s right to audit or receive third-party audit summaries.
Effective from: October 8, 2025
MeetingPackage (Cocouz Oy)
Sokerilinnantie 7 C
02600 Espoo, Finland
https://meetingpackage.com
1. VALIDITY
This document is valid from October 8, 2025.
2. BACKGROUND AND PURPOSE
2.1. This DPA governs the processing of Personal Data by MeetingPackage on behalf of You as required for the delivery of the services, including but not limited to CRS for M&E and Group Sales, Booking Engine, License Platform, E-Proposal, MeetingPackage Pay, Global Lead Sharing, Venue Sales Management, Channel Manager, APIs and any other current B2B or future B2B MeetingPackage products.
2.2. Notwithstanding what is stated in the Agreement, in the event of conflict between this DPA and the Agreement, the terms and conditions of this DPA shall prevail.
2.3. “Data Protection Regulation” shall in this DPA mean any applicable data protection legislation as amended from time to time (including but not limited to the General Data Protection Regulation, “GDPR” (2016/679/EU)).
2.4. Any terms not defined in this DPA or the Agreement shall be given the meaning allocated to them in the Data Protection Regulation from time to time.
2.5. This DPA is part of the agreement between you and Cocouz Oy for your use of any part of the MeetingPackage Service Suite (“Services”). Reference to the capitalised term “You” refers to you as the company which is using the Services or any part thereof. Reference to the capitalised term MeetingPackage refers to Cocouz Oy, a limited liability company incorporated under the laws of Finland, with its registered place of business at Sokerilinnantie 7c, 02600 Espoo Finland, and operating under with the company ID-number FI2577592-9.
2.6. MeetingPackage shall process Personal Data on behalf of You and in accordance with the terms and conditions of the DPA for the purpose of providing the Services under the Agreement.
3. ROLES
3.1. MeetingPackage acts as a processor, and You act as a controller, the concepts of which are further defined in GDPR. An individual whose Personal Data is being processed by MeetingPackage under this DPA and the Agreement will act as a Data Subject, the concept of which is further defined in the Data Protection Regulation.
3.2. If You have a separate supply agreement for Application Programming Interfaces with MeetingPackage, then for that portion of the service MeetingPackage acts as a processor and You act as either a processor or a controller depending on your relationship in the data processing chain. The concepts of a processor and controller are further defined in the EU GDPR regulation.
4. YOUR RESPONSIBILITIES
You shall:
4.1. Process Personal Data in accordance with good data processing practices and in compliance with Data Protection Regulation and all applicable laws;
4.2. Give documented instructions to MeetingPackage on the processing of Personal Data, which instructions shall be binding on both You and MeetingPackage after the written approval of MeetingPackage;
5. RESPONSIBILITIES OF MEETINGPACKAGE
5.1. MeetingPackage shall process the Personal Data only in accordance with the Data Protection Regulation, the Agreement and this DPA as well as the approved documented instructions from You unless otherwise required in applicable laws and regulations to which MeetingPackage is subject. In such a case, MeetingPackage shall inform You of such requirement under applicable laws and regulations before processing of Personal Data, unless the applicable laws and regulations prohibit such notification.
5.2. Assistance of You
MeetingPackage shall, taking into account the nature of the processing of Personal Data under this DPA:
5.2.1. Assist You by appropriate technical and organizational measures in Your obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR; and
5.2.2. Assist You in ensuring compliance with its legal obligations pursuant to Articles 32 to 36 of the GDPR.
The assistance performed by MeetingPackage under this section shall be charged in accordance with the pricing and payment terms in the Agreement.
5.3. Data security
MeetingPackage shall implement technical, physical and organizational measures, as further explained under Appendix 1 (Description of the Processing of Personal Data) to comply with the obligations regarding security of processing under the GDPR.
5.4. Confidentiality
MeetingPackage shall ensure that the Personal Data processed is kept confidential. MeetingPackage shall ensure that any person MeetingPackage has authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.5. Reporting and notification obligation
MeetingPackage shall make available to You all information necessary to demonstrate compliance with the obligations laid down in this DPA and the GDPR. MeetingPackage shall maintain a record of processing activities under this DPA in accordance with the GDPR (“Record”). MeetingPackage shall provide You with the Record if requested by You.
5.6. Personal Data Breach notification
In the event of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, MeetingPackage shall notify You via email or telephone without undue delay after becoming aware of the personal data breach.
5.7. Returning or destruction of Personal Data
Upon termination of the applicable purpose of the processing of Personal Data, or upon Your written request, MeetingPackage shall either destroy or return to You all Personal Data unless otherwise required by law.
MeetingPackage shall be entitled to destroy all Personal Data processed under this DPA if You have not requested MeetingPackage to return the Personal Data within ten (10) days from the date when the applicable purpose of the processing of Personal Data has terminated.
6. TRANSFERS OF PERSONAL DATA
Allowed with GDPR-compliant safeguards.
7. SUBCONTRACTORS
General authorisation granted; changes notified; objections allowed only with legitimate reason.
8. AUDITING
8.1. At any time during the term of the DPA, You or a recognized, independent third-party auditor appointed by You with proven experience and procedures shall have the right to audit MeetingPackage’s technical and organizational security measures as well as compliance with other data protection obligations agreed under this DPA. You shall give a prior written notice to MeetingPackage, such notice to be given at least sixty (60) calendar days prior to any audit.
8.2. MeetingPackage shall assist You in the execution of an audit and charge such assistance in accordance with the pricing and payment terms defined in the Agreement.
9. LIMITATION OF LIABILITY
The limitation of liability agreed in the Agreement shall apply to this Agreement.
10. TERM
This DPA shall become effective when duly signed by both Parties and shall automatically terminate upon termination of the applicable purpose of processing of Personal Data under the Agreement.
11. APPLICABLE LAW AND DISPUTE RESOLUTION
This DPA shall be governed by the laws of Finland without regard to its principles and rules on conflict of laws and shall be subject to dispute resolution in accordance with the Agreement.
12. APPENDICES
● Appendix 1: Description of the Processing of Personal Data
● Appendix 2: Organisational and Technical Security Measures
Appendix 1 – Description Of The Processing Of Personal Data
This appendix provides a more detailed description of the Personal Data processed by MeetingPackage on behalf of You. The Parties may also agree in this appendix to provide more detail, for example, on the data security measures taken by the Supplier to secure the Personal Data.
1. Services, Nature and purpose of the processing of Personal Data
Purpose: enable the provision of Services, Customer Support, improve the quality of the service and fix issues within the Services.
2. Types of Personal Data and categories of Data Subjects
MeetingPackage processes the following categories of data subjects: End-customers (the bookers), client employees (hotel admins, staff), accounts of hotel customers (agencies or corporates), account contacts of hotel customers (employees/users of such accounts)
MeetingPackage processes the following types of Personal Data: Name, email, phone number, address, membership number, Reference ID to external systems such as CRM
3. Duration of the processing of Personal Data
3.1. For the term of the Agreement or as otherwise agreed with the You.
Appendix 2 – Organisational and Technical Security Measures
Description of the technical and organisational security measures implemented by the processor(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, as well as the risks for the rights and freedoms of natural persons.
Cocouz Oy (“MeetingPackage“) are ISO-27001 certified by Kiwa (cert nr. 13606-02) with the scope covering “Operations (development, marketing, sales and support) for maintaining and developing the MeetingPackage product / service suite”.
1. Organisational Security Measures
1.1. Governance & Policies
1.1.1. Information Security Management System (ISMS) established and maintained in line with ISO 27001.
1.1.2. Documented information security policies approved by management and communicated to employees.
1.1.3. Formal risk assessment and treatment process.
1.1.4. Regular review of ISMS performance and continual improvement.
1.2. Roles & Responsibilities
1.2.1. Appointment of an Information Security Officer or equivalent.
1.2.2. Clearly defined roles, responsibilities, and segregation of duties.
1.3. Training & Awareness
1.3.1. Mandatory information security and privacy training for all employees.
1.3.2. Regular phishing awareness and social engineering prevention exercises.
1.4. Supplier & Sub-Processor Management
1.4.1. Due diligence and contractual security requirements for all suppliers/sub-processors.
1.4.2. Periodic reviews and monitoring of sub-processors’ compliance.
2. Technical Security Measures
2.1. Physical & Environmental Security
2.1.1. Secure office premises with controlled access
2.1.2. Data centers (via cloud providers like AWS) with multi-layered security and 24/7 monitoring.
2.2. 2.2 Access Control
2.2.1. Role-based access control (RBAC) aligned with the principle of least privilege.
2.2.2. Unique user IDs for all accounts; no shared accounts for administrative access.
2.2.3. Strong password policy or multi-factor authentication (MFA) for system access.
2.2.4. Automatic session timeouts and account lockouts after repeated failed attempts.
2.3. Encryption
2.3.1. In transit: TLS 1.2+ (or higher) for all data exchanges.
2.3.2. At rest: AES-256 (or equivalent) for databases, file storage, and backups.
2.3.3. Encryption keys managed securely, with rotation policies.
2.4. Logging & Monitoring
2.4.1. Centralized logging of security-relevant events
2.4.2. Continuous monitoring for anomalies and security incidents.
2.4.3. Retention of logs in a tamper-evident format for a defined period.
2.5. Network Security
2.5.1. Firewalls, intrusion detection/prevention systems (IDS/IPS).
2.5.2. Network segmentation between environments (production, staging, development).
2.5.3. Regular vulnerability scanning.
3. Operational Security Measures
3.1. Backup & Recovery
3.1.1. Encrypted backups with defined retention and secure off-site storage.
3.1.2. Regular restoration testing to verify data integrity and recovery time objectives.
3.2. Change Management
3.2.1. Formal process for approving and documenting changes to systems.
3.2.2. Testing and review before deployment.
3.3. Incident Response
3.3.1. Documented incident response plan covering detection, reporting, containment, eradication, recovery, and lessons learned.
3.3.2. Defined breach notification procedures to customers in accordance with GDPR.
3.4. Business Continuity & Disaster Recovery
3.4.1. Documented business continuity plan (BCP) and disaster recovery plan (DRP), with periodic testing
4. Data Protection Specific Measures
4.1. Data minimisation and purpose limitation in processing.
4.2. Secure deletion or destruction of data after retention periods expire.
4.3. Clear process for handling data subject requests (access, rectification, erasure, etc.).
5. Audit & Certification
5.1. ISO 27001 certification is maintained via annual surveillance audits.
5.2. Willingness to provide evidence of compliance (audit reports, certificates).
5.3. Customer’s right to audit or receive third-party audit summaries.