Effective Date: June 2026 | Version: 1.0 | Contact: info@ruso.app

Effective Date: June 2026 | Version: 1.0 | Contact: info@ruso.fi

Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement, referred to as the DPA, forms part of and is incorporated into the Terms of Service between RUSO Oy, referred to as the Processor, and the Customer, referred to as the Controller. This DPA applies to all processing of personal data carried out by RUSO on behalf of the Customer in connection with the Platform, as defined in the Terms of Service.

  1. Subject Matter and Duration

RUSO processes personal data on behalf of the Customer for the duration of the Terms of Service, for the purpose of providing the Platform, including order management, fleet management, staff scheduling, warehouse scanning operations, and related reporting functions.

  1. Nature and Purpose of Processing

RUSO processes personal data to operate the management interface, the Employee application, and the Scanner application, including account creation and authentication, task assignment and completion tracking, geofenced location tracking during active work sign-in, warehouse scanning events, invoicing, and customer support.

  1. Categories of Data Subjects

Personal data processed under this DPA may relate to the Customer's employees, the Customer's administrators and supervisory staff, and the Customer's own customers where their contact or order details are entered into the Platform.

  1. Categories of Personal Data

Personal data processed may include names, contact details, employee identifiers, login credentials, work schedule and task data, geofenced location data collected during active sign-in, scanning event data, vehicle assignment data, and order and delivery details relating to the Customer's own customers.

  1. Processor Obligations

RUSO will process personal data only on the documented instructions of the Customer, including with regard to transfers of personal data to a third country, unless required to do otherwise by European Union or Finnish law, in which case RUSO will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.

RUSO will ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

RUSO will implement technical and organizational measures appropriate to the risk, as described in Section 9.

RUSO will not use identifiable Customer Data for any purpose beyond providing the Platform, except as permitted under Section 8 for Aggregated Data.

  1. Sub-processors

The Customer provides general authorization for RUSO to engage sub-processors to support the provision of the Platform. As of 8 September 2026, RUSO's sole sub-processor is Google Cloud Platform via Firebase, with core data stored in Finland, Google Cloud region europe-north1, Hamina, and Firebase Authentication and Firebase Analytics processing data in the United States under Google's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

RUSO will notify the Customer of any intended addition or replacement of a sub-processor, giving the Customer a reasonable opportunity to object on reasonable data protection grounds before the change takes effect. RUSO will impose data protection obligations on each sub-processor that are equivalent to those set out in this DPA.

  1. Assistance to the Customer

RUSO will assist the Customer, taking into account the nature of the processing, in responding to requests from data subjects seeking to exercise their rights under GDPR, including access, correction, deletion, restriction, and objection requests. RUSO will provide this assistance regardless of whether the request is received directly from an individual or forwarded by the Customer.

RUSO will assist the Customer in ensuring compliance with the Customer's own obligations under GDPR, including data protection impact assessments and prior consultation with a supervisory authority where required, taking into account the nature of processing and the information available to RUSO.

The Customer remains solely responsible for establishing a valid legal basis for its own processing of personal data, including data relating to its employees, and for meeting any additional obligations arising under the Act on the Protection of Privacy in Working Life, including necessity assessments, advance notice to employees, and any required consultation with employee representatives. RUSO's obligations under this DPA do not extend to establishing that legal basis or delivering those notices on the Customer's behalf.

  1. Aggregated Data

RUSO may generate and use Aggregated Data, meaning Customer Data processed so that it can no longer reasonably be used to identify an individual, a vehicle, or a specific Customer, for product improvement, benchmarking, and analytics offerings, including across multiple customers. Aggregation will meet a minimum group size threshold, and will exclude combinations of filters narrow enough to make any individual, vehicle, or specific Customer identifiable, before being used or published in any form. RUSO will not use identifiable Customer Data for these purposes without a separate, explicit agreement with the affected Customer.

  1. Security Measures

RUSO will implement technical and organizational measures appropriate to the risk, including encryption of personal data in transit and at rest, access controls limiting personal data access to personnel who require it to perform their role, and regular review of these measures. Further detail on RUSO's specific security measures and any certifications held is available on request.

  1. Personal Data Breach Notification

RUSO will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. This notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it, to the extent this information is available at the time of notification, with further information provided as it becomes available.

  1. Data Return and Deletion

Following termination of the Terms of Service, RUSO will delete all Customer Data within 14 working days, except where retention is required by applicable law. The Customer may request export of its Customer Data before termination takes effect, in a format made available by RUSO.

  1. Audit Rights

RUSO will make available to the Customer, on reasonable written request and no more than once per contract year absent a specific compliance concern, information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, subject to reasonable advance notice, confidentiality, and scheduling that avoids undue disruption to RUSO's operations and other customers.

  1. International Transfers

Any transfer of personal data outside the European Economic Area under this DPA will be made subject to an approved transfer mechanism, such as Standard Contractual Clauses, as required under GDPR. The transfers described in Section 6 relating to Firebase Authentication and Firebase Analytics are made on this basis.

  1. Liability

Liability under this DPA is subject to the liability provisions set out in Section 12 of the Terms of Service, except that this cap does not apply to fines or penalties imposed on the Customer as a direct result of RUSO's failure to meet its obligations as processor under this DPA.

  1. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA governs.

Contact for data protection matters: info@ruso.app

1. Parties and Scope These Terms of Service ("Terms") govern the relationship between RUSO Oy, a company registered in Vantaa, Finland ("RUSO"), and any business entering into a subscription agreement with RUSO ("Customer") for use of the RUSO platform. These Terms apply together with the RUSO Data Processing Agreement ("DPA") and, where licensed, the general terms and conditions of IT2022 YSE. In case of conflict, these Terms take priority for matters they specifically address; IT2022 YSE governs matters not otherwise addressed here.

2. Definitions

  • "Platform" means the RUSO software service, comprising the web application, the Employee application, and the Scanner application.

  • "Authorized Users" means individuals the Customer grants access to the Platform, including Customer's own employees.

  • "Customer Data" means all data submitted to, or generated within, the Platform by or on behalf of the Customer, including operational data and personal data relating to Customer's employees and Customer's own customers.

  • "Aggregated Data" means Customer Data that has been processed such that it can no longer reasonably be used to identify an individual, a vehicle, or a specific Customer entity, in line with the anonymization standard described in Section 9.

3. The Platform The Platform is a cloud-based logistics management system comprising:

  • Management interface — used by Customer's supervisory and management staff (operations, finance, executive) to manage orders, fleet, staff, customer relationships, billing, and reporting.

  • Employee application — used by Customer's staff for shift-based task execution.

  • Scanner application (Android only) — used with Customer's compatible handheld scanning hardware for warehouse operations.

Each Customer receives an administrator account with full control over its own organization's configuration: onboarding and managing its employees, vehicles, and its own customers' access within the Customer's account. RUSO does not access, modify, or manage Customer Data except as instructed under the DPA or as required to provide support.

4. Fees and Invoicing Fees are billed according to the Customer's agreed subscription tier and billing cycle. Customers on a monthly contract are invoiced monthly in advance. Customers on an annual contract are invoiced annually in advance. Invoicing continues for the full duration of the agreed contract term. Late payment may result in a formal notice and, if unresolved, suspension of access until outstanding amounts are settled in full.

5. Data Protection and GDPR Compliance

5.1. Roles. With respect to Customer Data that constitutes personal data, RUSO acts as a data processor and the Customer acts as the data controller, as those terms are defined under the General Data Protection Regulation ("GDPR"). RUSO processes personal data only on the Customer's documented instructions, as set out in the DPA.

5.2. Customer responsibilities. The Customer is solely responsible for establishing a valid legal basis for all personal data processed through the Platform, including data relating to its employees, and for providing all legally required notices to its employees and other data subjects. Where local employment or privacy legislation (including the Act on the Protection of Privacy in Working Life) imposes additional obligations on employers using monitoring or tracking functionality, meeting those obligations — including necessity assessments, advance notice, and any required consultation with employee representatives — is the Customer's sole responsibility, not RUSO's.

5.3. Data subject rights. RUSO will provide reasonable assistance to the Customer in responding to data subject access, correction, or deletion requests, as set out in the DPA. RUSO will not withhold assistance on the basis that a request came from an individual rather than the Customer.

5.4. Aggregated Data. RUSO may use Aggregated Data for product improvement, benchmarking, and analytics offerings, including across multiple customers, provided the aggregation meets a minimum group-size threshold sufficient to prevent identification of any individual, vehicle, or specific Customer, as further described in the DPA. RUSO will not use identifiable Customer Data for these purposes without a separate, explicit agreement with the affected Customer.

5.5. International transfers. Any transfer of personal data outside the European Economic Area will be made subject to an approved transfer mechanism (such as Standard Contractual Clauses) as required under GDPR.

6. Data Security RUSO maintains technical and organizational security measures appropriate to the nature of the data processed, as detailed in the DPA's security exhibit. [Insert only measures/certifications RUSO actually holds — encryption standards, hosting location, access controls, sub-processor list, and any completed audits or certifications. Do not reference a certification RUSO has not obtained.]

7. Service Availability and Support RUSO provides customer support on a 24/7 basis. Customers experiencing an urgent issue may contact RUSO's on-call support team directly by phone rather than relying solely on email. [Insert defined response and resolution time targets by severity level — an unqualified "swift" commitment isn't enforceable and should be replaced with actual numbers before this is signed.]

8. Intellectual Property RUSO retains all right, title, and interest in the Platform, including its software, design, and underlying technology. Nothing in these Terms transfers ownership of the Platform to the Customer. The Customer retains ownership of Customer Data, subject to RUSO's rights regarding Aggregated Data under Section 5.4.

9. Confidentiality Each party will protect the other's confidential information with reasonable care and use it only for purposes of performing under these Terms, for the duration of the agreement and a reasonable period following termination.

10. Liability [This section needs specific figures agreed with legal counsel — a cap tied to fees paid over a defined period, carve-outs for gross negligence/willful misconduct and for GDPR-related fines caused by each party's own non-compliance, and exclusion of indirect/consequential damages, consistent with standard IT2022 liability structure.]

11. Term and Termination This agreement remains in effect for the contract term agreed at signing. Either party may terminate in accordance with the termination provisions set out in the signed contract. Termination takes effect on the first day of the calendar month following the applicable notice period. Following termination, Customer Data will be deleted within 14 working days, except where retention is required by applicable law.

12. Amendments RUSO may amend these Terms. Customers will be notified by direct phone contact and provided with the updated Terms in writing prior to the changes taking effect. Material changes affecting data processing will require the Customer's affirmative acknowledgment before taking effect.

13. Governing Law and Dispute Resolution These Terms are governed by the laws of Finland. Any dispute arising from these Terms will be finally resolved by arbitration administered by the Finland Chamber of Commerce, seated in Helsinki, Finland, to the exclusion of ordinary courts.

14. Force Majeure Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control, including outages of third-party infrastructure providers.

This is now structurally complete but has several bracketed placeholders that need real numbers/facts before it's usable — liability caps, SLA response times, and the actual security measures/certifications RUSO holds. Those aren't things I should fill in with placeholder-sounding figures; they need to reflect what RUSO can actually commit to. Once you have those, this should go to a Finnish lawyer for a final pass, particularly Sections 5, 10, and 13, before it's used in any real customer contract.