Umowa o Przetwarzanie Danych (DPA)
Ostatnia aktualizacja: 2026-07-14
Ostatnia aktualizacja strony Podprocesorów: 2026-07-04
Niniejsza Umowa o Przetwarzaniu Danych określa warunki, na jakich przetwarzamy dane osobowe w Twoim imieniu.
Niniejsza Umowa o Przetwarzaniu Danych (Umowa) określa zobowiązania i warunki, na jakich Petitions.com Group Oy (Dostawca Usług) przetwarza dane osobowe w imieniu autora petycji (Autor Petycji lub Administrator Danych) w zakresie świadczenia usług hostingowych petycji online (Usługi).
Modyfikacja Warunków
Zastrzegamy sobie prawo do zmiany lub modyfikacji niniejszych Warunków w dowolnym czasie bez wcześniejszego powiadomienia.
Definicje i Role
- Dostawca Usług: Petycjeonline.com (Petitions.com Group Oy), działający jako Przetwarzający Dane, przetwarza dane osobowe w imieniu Administratora Danych w zakresie niezbędnym do świadczenia Usług.
- Administrator danych: Autor petycji, który określa cele i sposoby przetwarzania danych osobowych zebranych od sygnatariuszy jego petycji. Jako autor petycji zamieszczonej na Petycjeonline.com, jesteś uznawany za administratora danych. Ty decydujesz o treści petycji, o tym, co jest wymagane od sygnatariuszy, o celach przetwarzania ich danych osobowych oraz o okresie, przez jaki dane osobowe są przechowywane. Petycjeonline.com udostępnia platformę internetową do tworzenia i hostowania petycji, umożliwiając Ci pełnienie roli administratora danych z autonomią w zakresie kształtowania zbierania i wykorzystania danych w petycji zgodnie z Twoimi celami i zobowiązaniami prawnymi.
Zakres przetwarzania
The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Zakres działań przetwarzania jest ograniczony do hostingu, zarządzania i ułatwiania korzystania z petycji online.
As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.
The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.
Ochrona danych
Dostawca Usług zobowiązuje się do wdrożenia środków technicznych i organizacyjnych w celu zapewnienia bezpieczeństwa danych osobowych przed nieautoryzowanym dostępem, utratą lub uszkodzeniem.
Zabronione zbieranie danych
Zabrania się żądania numerów identyfikacyjnych (takich jak numery dowodu osobistego) od sygnatariuszy.
Podwykonawcy przetwarzania
Usługodawca może angażować podprzetwarzających w celu pomocy w świadczeniu Usług. Dostawca usług zapewni, że podprzetwarzający spełniają obowiązki dotyczące ochrony danych zgodne z niniejszą Umową Powierzenia Przetwarzania Danych. Potwierdzasz i zgadzasz się, że Usługodawca zachowuje swobodę wyboru i zastępowania podprzetwórców w razie potrzeby, aby usługodawca mógł efektywnie świadczyć Usługi.
Lista podmiotów przetwarzających. (Ostatnia aktualizacja: 2026-07-04)
Obowiązki Administratora Danych
Administrator danych jest odpowiedzialny za zapewnienie, że zbieranie, przetwarzanie i przechowywanie danych osobowych jest zgodne ze wszystkimi obowiązującymi przepisami prawa i regulacjami.
Identyfikacja Administratora Danych
Zgodnie z ogólnym rozporządzeniem o ochronie danych (RODO) wymagane jest, aby tożsamość administratora danych była jasno określona. Poniższe postanowienia dotyczą autorów petycji korzystających z naszej strony internetowej:
Poszczególni autorzy petycji
Jeżeli jako osoba fizyczna tworzysz petycję, jesteś zobowiązany podać swoje pełne imię i nazwisko. To służy jako Twoja identyfikacja jako administrator danych na potrzeby RODO.
Organizatorzy petycji
Jeśli petycja jest tworzona w imieniu organizacji, należy podać jej pełną nazwę prawną. Ponadto organizacja powinna wyznaczyć i udostępnić dane kontaktowe przedstawiciela odpowiedzialnego za czynności przetwarzania danych, takiego jak Inspektor Ochrony Danych (IOD) lub osoba o podobnych kompetencjach.
Prawa osoby, której dane dotyczą
Administrator danych musi zapewnić, że osoby, których dane dotyczą (sygnatariusze petycji), mogą wykonywać swoje prawa wynikające z RODO, takie jak prawo dostępu do danych, ich sprostowania lub usunięcia, a także prawo do wniesienia skargi do organu nadzorczego.
Obsługa wniosków o usunięcie danych osobowych składanych przez sygnatariuszy
The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.
Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.
When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.
The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.
Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.
Dzienniki techniczne mogą zawierać dane osobowe, takie jak adresy IP lub metadane doręczenia wiadomości e-mail. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.
The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.
Handling Rectification Requests from Signatories
The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.
Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.
The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.
Notifying Recipients
Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.
Rozliczalność i Zgodność z Przepisami
Administrator danych musi być w stanie wykazać zgodność z RODO, w tym odpowiadać na żądania osób, których dane dotyczą, dotyczące ich danych osobowych.
Polityka prywatności lub nota informacyjna
Należy zapewnić jasną i dostępną politykę prywatności lub zawiadomienie, które określa, w jaki sposób przetwarzane są dane osobowe, cele przetwarzania oraz w jaki sposób podmioty danych mogą wykonywać swoje prawa.
Powiadomienie o Zmianach
Autorzy petycji są zobowiązani powiadomić Petycjeonline.com (Petitions.com Group Oy) o wszelkich zmianach w ich statusie jako administratora danych lub o zmianach w danych kontaktowych ich przedstawiciela.
Coroczny przegląd przetwarzania danych
Autor petycji jest zobowiązany do przeprowadzania corocznej weryfikacji w celu ustalenia, czy nadal istnieje uzasadniony powód do dalszego przetwarzania danych osobowych sygnatariuszy. Ta ocena powinna ocenić konieczność i istotność danych w odniesieniu do celu petycji. Jeśli Autor Petycji ustali, że nie ma już ważnego powodu do kontynuowania przetwarzania danych, musi podjąć odpowiednie kroki w celu zakończenia przetwarzania i rozpoczęcia usuwania danych zgodnie z obowiązującymi przepisami o ochronie danych.
Use of Up-to-Date Signature Data
Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.
Przechowywanie i usuwanie danych
W przypadku naruszenia przez Administratora Danych (autora petycji) jakichkolwiek warunków Umowy Powierzenia Przetwarzania Danych (DPA), w tym między innymi niewykonania rocznej weryfikacji działań związanych z przetwarzaniem danych lub niepodania ważnego uzasadnienia dla dalszego przetwarzania danych osobowych sygnatariuszy, Usługodawca zastrzega sobie prawo do usunięcia danych osobowych związanych z ich petycją.
Ograniczenie odpowiedzialności
W żadnym wypadku całkowita odpowiedzialność podmiotu przetwarzającego wobec administratora danych za wszystkie szkody, straty i przyczyny działań, niezależnie od tego, czy wynikają one z umowy, czynu niedozwolonego (w tym zaniedbania), czy innego, nie może przekroczyć całkowitej kwoty zapłaconej przez administratora danych podmiotowi przetwarzającemu na mocy niniejszej umowy.
Prawo właściwe
Niniejsza Umowa będzie regulowana przez prawo Finlandii.