Please note that this Data Processing Agreement (DPA) is no longer valid. As of 8 October 2025, the new DPA will take precedence and govern. You can review the updated agreement here: Updated data protection agreement.
1 BACKGROUND AND PURPOSE
1.1 This Data Protection Agreement (“DPA”) sets out the terms and conditions for the processing of Personal Data by Cocouz Oy (“MeetingPackage“) on behalf of Partner. This DPA shall be applied to the agreement regarding the provision of electronic platform and/or related reservation and booking services by MeetingPackage (“Services”) entered into by and between the Parties (“Agreement”).
1.2 Agreement referred to in this DPA may be either:
(i) Booking Engine Service Agreement based on which MeetingPackage processes personal data on behalf of Partner by storing details of the customers’ reservations including personal data (name, email address, phone number, company name and possible additional information provided by the customers themselves) for the purposes of providing software services for Partner; or
(ii) Service Provider Agreement based on which MeetingPackage processes personal data on behalf of Partner by transferring details of the customers’ reservations including personal data (name, email address, phone number, company name and possible additional information provided by the customers themselves) to the Service Provider for the purposes of providing services for Customers; or
(iii) Partner License Agreement based on which MeetingPackage processes personal data on behalf of Partner by providing a customized platform through which customers can book meetings services, hotel rooms, venues and other products. The personal data about customers processed on behalf of the Partner may include name, email address, phone number, company name and possible additional information provided by the customers themselves or additional information asked from time to time by Partner.
1.3 Notwithstanding what is stated in the Agreement, in the event of conflict between this DPA and the Agreement the terms and conditions of this DPA shall prevail.
1.4 “Data Protection Regulation” shall in this DPA mean any applicable data protection legislation as amended from time to time (including but not limited to the EU Data Protection Directive (95/46/EC) and the General Data Protection Regulation, “GDPR” (2016/679/EU)) and the instructions and binding orders of the data protection authorities.
1.5 MeetingPackage acts as a data processor and Partner acts as a data controller, the concepts of which are further defined in the Data Protection Regulation. An individual whose Personal Data is being processed by MeetingPackage under this DPA and the Agreement will act as a Data Subject, the concept of which is further defined in the Data Protection Regulation.
1.6 The GDPR will not be applied until 25 May 2018. When the GDPR has been implemented into national legislation or if binding instructions are given by any supervisory authority, this DPA might need to be updated, if so mutually agreed between the Parties.
2 DEFINITIONS
Any terms not defined in this DPA or the Agreement shall be given the meaning allocated to them in Data Protection Regulation from time to time.
3 THE PURPOSE OF THE PROCESSING OF PERSONAL DATA
MeetingPackage shall process Personal Data on behalf of Partner and in accordance with the terms and conditions of the DPA for the purpose of providing the Services under the Agreement.
4 RIGHTS AND RESPONSIBILITIES OF PARTNER
Partner shall:
(i) process Personal Data in accordance with good data processing practices and in compliance with Data Protection Regulation and all applicable laws;
(ii) give documented instructions to MeetingPackage on the processing of Personal Data, which instructions shall be binding on both Partner and MeetingPackage after the written approval of MeetingPackage;
(iii) at all times retain the control and authority to Personal Data, including readiness to respond to requests for exercising the Data Subject’s rights under the Data Protection Regulation; and
(iv) assist MeetingPackage by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of MeetingPackage’s obligations under this DPA and Data Protection Regulation.
5 RESPONSIBILITIES OF MEETINGPACKAGE
5.1 General principles applying to the processing of Personal Data
MeetingPackage shall process the Personal Data only in accordance with the Data Protection Regulation, the Agreement and this DPA as well as the approved documented instructions from Partner, unless otherwise required in applicable laws and regulations to which MeetingPackage is subject. In such case, MeetingPackage shall inform Partner of such requirement under applicable laws and regulations before processing of Personal Data, unless the applicable laws and regulations prohibit such notification.
5.2 Assistance of Partner
5.3 MeetingPackage shall, taking into account the nature of the processing of Personal Data under this DPA:
(i) assist Partner by appropriate technical and organizational measures in Partner’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR; and
(ii) assist Partner in ensuring compliance with its legal obligations pursuant to Articles 32 to 36 of the GDPR.
5.4 The assistance performed by MeetingPackage under this section 5.2 shall be charged in accordance with the pricing and payment terms in the Agreement.
5.5 Data security
As from the date when the GDPR is applied, MeetingPackage shall implement technical, physical and organizational measures to comply with the obligations regarding security of processing under the GDPR.
5.6 Confidentiality
MeetingPackage shall ensure that the Personal Data processed are kept confidential. MeetingPackage shall ensure that any person the MeetingPackage has authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.7 Reporting and notification obligation
MeetingPackage shall make available to Partner all information necessary to demonstrate compliance with the obligations laid down in this DPA and the GDPR.
As from the date when the GDPR is applied, MeetingPackage shall maintain a record of processing activities under this DPA in accordance with the GDPR (“Record”). MeetingPackage shall provide Partner with the Record if requested by Partner.
5.8 Personal Data Breach notification
In the event of a breach of security leading to accidental or unlawful destruction, loss, alternation, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, MeetingPackage shall notify Partner via email or telephone without undue delay after becoming aware of the personal data breach.
5.9 Returning or destruction of Personal Data
5.10 Upon termination of the applicable purpose of the processing of Personal Data, or upon Partner’s written request, MeetingPackage shall either destroy or return to Partner all Personal Data unless otherwise required by law.
5.11 MeetingPackage shall be entitled to return to Partner and destroy all Personal Data processed under this DPA if Partner has not requested MeetingPackage to destroy or return the Personal Data within ten (10) days from the date when the applicable purpose of the processing of Personal Data has terminated.
5.12 Use of Anonymised and Aggregated Data
MeetingPackage.com may, for its own legitimate business purposes, create and use anonymised and/or aggregated data derived from the Personal Data processed under this DPA, provided that such data:
(i) cannot be used to identify any individual Data Subject, directly or indirectly;
(ii) does not contain any Personal Data as defined under the Data Protection Regulation; and
(iii) is used solely for statistical analysis, benchmarking, service improvement, or other analytical purposes.
MeetingPackage.com shall ensure that the anonymisation or aggregation process is performed in accordance with industry best practices to ensure irreversible anonymisation.
This right shall survive the termination of this DPA, provided that such data remains anonymised and does not constitute Personal Data.
6 TRANSFERS OF PERSONAL DATA
MeetingPackage shall have the right to transfer Personal Data outside the EU or the EEA if MeetingPackage establishes an adequate level of data protection through EU Standard Contractual Clauses based on the EU Commission’s standard contractual clauses.
MeetingPackage shall also be entitle to transfer Personal Data outside the EU or the EEA if the country or territory in which the recipient operates has been found to ensure an adequate level of protection for the rights and freedoms of Data Subjects in relation to the processing of Personal Data, including without limitation the EU-U.S. Privacy Shield or any subsequent or
separately adopted equivalent provision, as determined by the European Commission and subject to the scope restrictions of any such determination.
7 SUBCONTRACTORS
7.1 MeetingPackage may engage third-party subcontractors when providing the Services and processing Personal Data.
7.2 MeetingPackage shall ensure that the subcontractors comply with the same level of confidentiality, data security and other obligations as specified in this DPA. MeetingPackage is fully liable for the performance of the subcontractor’s obligations.
7.3 MeetingPackage shall inform Partner of possible forthcoming changes regarding the subcontractors in which case Partner may object to such change by notifying MeetingPackage within five (5) days of such notice. The Partner may not object to the changes without a grounded reason.
8 AUDITING
8.1 At any time during the term of the DPA, Partner or a recognized, independent third-party auditor appointed by Partner with proven experience and procedures shall have the right to audit MeetingPackage’s technical and organizational security measures as well as compliance with other data protection obligations agreed under this DPA. Partner shall give a prior written notice to MeetingPackage, such notice to be given at least sixty (60) calendar days prior to any audit.
8.2 MeetingPackage shall assist Partner in the execution of an audit and charge such assistance in accordance with the pricing and payment terms defined in the Agreement.
9 LIMITATION OF LIABILITY
The limitation of liability agreed in the Agreement shall be applied to this Agreement.
10 TERM
This DPA shall become effective when duly signed by both Parties and shall automatically terminate upon termination of the applicable purpose of processing of Personal Data under the Agreement.
11 APPLICABLE LAW AND DISPUTE RESOLUTION
This DPA shall be governed by the laws of Finland without regard to its principles and rules on conflict of laws and shall be subject to dispute resolution in accordance with the Agreement.