Data Processing Agreement
Last updated: 10 July 2026 · Template — for review by both parties' counsel before signing
This Data Processing Agreement (the "DPA") forms part of the agreement for the use of the CanopyProof service (the "Service") between:
- Controller: the customer accepting this DPA (the "Customer"); and
- Processor: Talivio Technology OÜ, registry code 16991406, Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia ("Talivio").
The authoritative language of this DPA is English. It reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR").
1. Subject matter and duration
Talivio processes personal data on behalf of the Customer to provide the Service: collecting supplier and plot geolocation data, screening it against deforestation datasets, and preparing and submitting due diligence statements under Regulation (EU) 2023/1115 ("EUDR"). This DPA applies for as long as Talivio processes personal data on the Customer's behalf under the Service agreement.
2. Nature, purpose and scope of processing
Processing consists of the collection, storage, organisation, transmission and deletion of the personal data described in Annex I, strictly for the purpose of operating the Service for the Customer, including the retention of due diligence records for the five-year period expected under the EUDR.
3. Customer instructions
Talivio processes personal data only on documented instructions from the Customer, including with regard to transfers to a third country, unless required to do so by Union or Member State law; in such a case, Talivio informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Customer's use of the Service's features constitutes its documented instructions. Talivio will inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
Talivio ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security
Talivio implements the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk for the rights and freedoms of natural persons (Article 32 GDPR).
6. Sub-processors
The Customer grants a general authorisation for the sub-processors listed in Annex III. Talivio will inform the Customer of any intended changes concerning the addition or replacement of sub-processors at least 14 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. Talivio imposes on each sub-processor, by contract, the same data-protection obligations as set out in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
7. Data subject rights
Taking into account the nature of the processing, Talivio assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising the data subject's rights under Chapter III of the GDPR. Requests received directly by Talivio that concern data processed on the Customer's behalf will be forwarded to the Customer without undue delay.
8. Assistance with compliance
Talivio assists the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Talivio.
9. Personal data breach
Talivio notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf, and provides the information reasonably required for the Customer to meet its own notification obligations under Articles 33 and 34 GDPR.
10. Deletion and return
At the end of the provision of the Service, Talivio deletes or returns (at the Customer's choice) all personal data processed on the Customer's behalf, and deletes existing copies, unless Union or Member State law requires further storage. The Customer acknowledges that due diligence statements already submitted to the EU TRACES system are held by the European Commission as an independent controller and are outside Talivio's control.
11. Audit
Talivio makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, at most once per year, during business hours, and without disrupting Talivio's operations. Talivio may first satisfy an audit request by providing recent third-party attestations or detailed written responses.
12. International transfers
Personal data is hosted within the European Union. Where a sub-processor or recipient processes personal data outside the EU/EEA or is an international organisation, Talivio ensures appropriate safeguards under Chapter V GDPR, such as the European Commission's standard contractual clauses or frameworks applicable to EU institutions and international organisations.
13. Liability and governing law
Liability under this DPA is subject to the limitations of liability in the Service terms. This DPA is governed by the laws of Estonia; Article 82 GDPR remains unaffected.
Annex I — Details of processing
- Data subjects: the Customer's staff and account users; contact persons at the Customer's suppliers (e.g. farmers, cooperatives, exporters); persons identifiable from plot geolocation data.
- Categories of personal data: names, business email addresses, plot names and geolocation (coordinates or boundaries), supplier country data, and the contents of due diligence statements.
- Special categories: none intended; the Customer must not submit special-category data through the Service.
- Frequency: continuous, for the duration of the Service agreement.
- Retention: due diligence records for five years (EUDR record-keeping); account data deleted or anonymised within 90 days of account closure.
Annex II — Technical and organisational measures
- Encryption in transit (TLS) for all traffic; sensitive credentials (e.g. TRACES authentication keys) encrypted at rest.
- Password hashing (bcrypt); role-based access within the Customer's organisation; tenant isolation enforced at the application layer.
- EU-located hosting; access to production systems restricted to authorised personnel over key-based SSH.
- Security headers and a strict Content Security Policy on the application; CSRF protection on all state-changing requests.
- Logging and monitoring of application errors; documented deployment process with version control.
- Regular dependency updates; automated test suite run before deployments.
Annex III — Authorised sub-processors
- Hosting provider (EU) — infrastructure on which the Service and its database run.
- Talivio mail infrastructure (EU) — delivery of transactional emails (e.g. supplier collection links).
The following recipients are not sub-processors; they act as independent controllers or recipients as described in the Privacy Policy: the European Commission / EU TRACES information system (submission of due diligence statements), Whisp / FAO Open Foris (screening of plot geolocation), and Stripe (payments).
Signatures
Signed in two originals, one for each party.
For the Customer (Controller)
Name, title, date, signature
For Talivio Technology OÜ (Processor)
Name, title, date, signature
Questions about this document? Email [email protected]. CanopyProof is a product of Talivio Technology OÜ (registry code 16991406), Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia.