September 2, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Use or other agreement governing the use of Causalytics between the customer using the Services ("Customer") and Tidy Technologies Oy, a Finnish company with Business ID FI27343943 ("Tidy").
This DPA applies where Tidy processes Personal Data on behalf of Customer in connection with the Causalytics services ("Services").
For the purposes of this DPA, Customer is the Controller and Tidy is the Processor, unless applicable Data Protection Law provides otherwise.
1. Definitions
In this DPA:
"Customer Data" means Personal Data processed by Tidy on behalf of Customer through the Services.
"Data Protection Law" means all applicable laws and regulations relating to the protection and processing of Personal Data, including Regulation (EU) 2016/679 ("GDPR").
"Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Controller", "Processor" and "Supervisory Authority" have the meanings given to them in applicable Data Protection Law.
"Subprocessor" means a third party appointed by Tidy to process Customer Data on behalf of Customer in connection with providing the Services.
2. Scope and roles
Customer determines the purposes and means of the Processing of Customer Data and acts as Controller.
Tidy processes Customer Data on behalf of Customer for the purpose of providing, operating, securing, supporting and maintaining the Services and acts as Processor in relation to that Processing.
This DPA applies only to Personal Data that Tidy processes on behalf of Customer.
Tidy may separately process certain Personal Data as an independent Controller, including Personal Data relating to Customer's account, billing, contractual relationship, service administration, support, security, fraud prevention, website use and communications with Tidy. Such Processing is governed by Tidy's Privacy Policy and is not governed by this DPA.
Where Tidy processes information for purposes independently determined by Tidy rather than on behalf of Customer, this DPA does not apply to such Processing.
3. Processing instructions
Tidy shall process Customer Data only:
on Customer's documented instructions;
as necessary to provide the Services;
as configured or requested by Customer through the Services; or
as required by applicable law.
Customer's documented instructions include this DPA, the Terms of Use, Customer's use and configuration of the Services and other written instructions agreed between Customer and Tidy.
If applicable law requires Tidy to process Customer Data other than according to Customer's instructions, Tidy shall inform Customer of that legal requirement before Processing unless the law prohibits such notification.
If Tidy believes that an instruction from Customer infringes applicable Data Protection Law, Tidy shall inform Customer without undue delay and may suspend the relevant Processing until the issue has been resolved.
4. Details of Processing
The subject matter, nature, purpose and duration of the Processing, as well as the categories of Personal Data and Data Subjects, are described in Annex 1.
5. Customer responsibilities
Customer is responsible for ensuring that:
its Processing of Personal Data and its use of the Services comply with applicable Data Protection Law;
it has an appropriate legal basis for Processing Customer Data;
Data Subjects receive any notices required by applicable law;
Customer is entitled to provide or make Customer Data available to Tidy for Processing;
Customer's instructions to Tidy comply with applicable law; and
Customer does not instruct Tidy to process Personal Data in a manner that violates applicable Data Protection Law.
Customer is responsible for responding to requests from Data Subjects unless otherwise required by applicable law.
6. Confidentiality
Tidy shall ensure that persons authorised to process Customer Data:
process Customer Data only as necessary to perform their duties;
are subject to appropriate confidentiality obligations; and
receive appropriate instructions concerning the protection of Personal Data.
Tidy shall limit access to Customer Data to persons who require such access for the operation, maintenance, security or support of the Services.
7. Security
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing and the risks to Data Subjects, Tidy shall implement appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The measures maintained by Tidy are described in Annex 2.
Tidy may update its technical and organisational measures from time to time, provided that such updates do not materially reduce the overall level of protection provided to Customer Data.
8. Personal Data Breaches
Tidy shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
To the extent reasonably available to Tidy, the notification shall describe:
the nature of the Personal Data Breach;
the categories and approximate number of affected Data Subjects;
the categories and approximate amount of affected Personal Data;
the likely consequences of the Personal Data Breach;
measures taken or proposed to address the Personal Data Breach; and
measures taken or proposed to mitigate its possible adverse effects.
Where all information is not available at the same time, Tidy may provide information in phases as it becomes available.
Tidy shall take reasonable steps to contain, investigate and remediate a Personal Data Breach.
Notification of a Personal Data Breach does not constitute an acknowledgement by Tidy of fault or liability.
9. Data Subject requests
Taking into account the nature of the Processing, Tidy shall provide reasonable assistance to Customer, through appropriate technical and organisational measures where possible, in responding to requests by Data Subjects exercising their rights under applicable Data Protection Law.
If Tidy receives a request directly from a Data Subject relating to Customer Data, Tidy shall, where reasonably possible:
notify Customer; and
direct the Data Subject to Customer,
unless Tidy is legally required to respond directly.
10. Assistance with Customer's compliance
Taking into account the nature of the Processing and the information available to Tidy, Tidy shall provide reasonable assistance to Customer with its obligations under Articles 32 to 36 of the GDPR, including where applicable:
security of Processing;
Personal Data Breach notifications;
data protection impact assessments; and
prior consultation with Supervisory Authorities.
Tidy may charge reasonable fees for assistance that requires material work outside the ordinary operation of the Services, except where the assistance is required due to Tidy's breach of this DPA.
11. Subprocessors
Customer gives Tidy general written authorisation to engage Subprocessors to process Customer Data for the purpose of providing the Services.
Tidy shall:
enter into written agreements with its Subprocessors imposing data protection obligations that provide substantially the same level of protection required by this DPA;
remain responsible for the performance of its Subprocessors' data protection obligations to the extent required by applicable Data Protection Law; and
maintain and make available to Customer an up-to-date list of Subprocessors used to process Customer Data.
Where Tidy intends to appoint a new Subprocessor that will process Customer Data, Tidy shall provide Customer with reasonable advance notice, for example by email or through the Services.
Customer may object to a new Subprocessor on reasonable grounds relating to the protection of Personal Data.
If Customer makes such an objection, the parties shall attempt in good faith to resolve the issue. If no reasonable alternative is available, Tidy may terminate the affected part of the Services or Customer may cease using the affected part of the Services.
This section does not apply to third parties that do not process Customer Data on behalf of Tidy.
12. International transfers
Tidy shall not transfer Customer Data outside the European Economic Area unless the transfer complies with applicable Data Protection Law.
Where Customer Data is transferred to a country outside the European Economic Area, Tidy shall ensure that an appropriate transfer mechanism is in place, such as:
an adequacy decision adopted by the European Commission;
Standard Contractual Clauses adopted by the European Commission;
another transfer mechanism permitted under Chapter V of the GDPR; or
another lawful basis for the transfer under applicable Data Protection Law.
Where legally required, Tidy shall implement supplementary safeguards appropriate to the circumstances of the transfer.
13. Return and deletion of Customer Data
During Customer's use of the Services, Tidy may retain Customer Data as necessary to provide the Services.
Following termination or expiry of Customer's use of the Services, Tidy shall delete or return Customer Data, at Customer's choice, unless applicable law requires continued retention.
Customer acknowledges that Customer Data may remain temporarily in backups after deletion from active systems. Such backup copies shall remain protected under this DPA and shall be deleted or overwritten in accordance with Tidy's normal backup retention procedures.
Tidy may retain data that has been irreversibly anonymised so that it no longer constitutes Personal Data.
14. Anonymised and aggregated data
Tidy may create statistical, aggregated or anonymised information from Customer Data where the resulting information does not identify and cannot reasonably be used to identify Customer, a Data Subject or another identifiable person.
Once information has been irreversibly anonymised so that it is no longer Personal Data, it is outside the scope of this DPA.
Tidy may use such anonymised information for analytics, benchmarking, research, improving the Services and developing new products or features.
Tidy shall not disclose Customer Data itself to third parties for these purposes.
15. Information and audits
Tidy shall make available to Customer information reasonably necessary to demonstrate compliance with the processor obligations set out in Article 28 of the GDPR.
Where reasonably sufficient, Tidy may satisfy this obligation by providing security documentation, compliance documentation, audit reports, certifications or responses to reasonable security and privacy questionnaires.
If such information is not reasonably sufficient to demonstrate compliance, Customer may request an audit of Tidy's Processing of Customer Data.
Any audit shall:
be limited to matters relevant to Tidy's obligations under this DPA;
be conducted on reasonable advance notice;
take place during normal business hours;
avoid unreasonable disruption to Tidy's operations;
comply with Tidy's confidentiality and security requirements; and
normally be conducted no more than once in any 12-month period unless required by a Supervisory Authority or there is reasonable evidence of material non-compliance.
Customer shall bear its own audit costs and Tidy's reasonable costs associated with an audit unless the audit identifies a material breach of this DPA by Tidy.
Nothing in this section limits the powers of a competent Supervisory Authority.
16. Records and regulatory cooperation
Tidy shall maintain records of Processing activities as required by applicable Data Protection Law.
Tidy shall cooperate with competent Supervisory Authorities to the extent required by applicable law in relation to Processing governed by this DPA.
17. Conflict with other agreements
If there is a conflict between this DPA and the Terms of Use or another agreement between Customer and Tidy concerning the Processing of Customer Data, this DPA shall prevail with respect to the protection and Processing of Customer Data.
Except as modified by this DPA, the Terms of Use or other applicable agreement remain in effect.
18. Liability
The limitations and exclusions of liability contained in the Terms of Use or other agreement between Customer and Tidy apply to this DPA to the maximum extent permitted by applicable law.
Nothing in this DPA limits liability to the extent that such limitation is prohibited by applicable law.
19. Term
This DPA becomes effective when Customer accepts the Terms of Use, enters into another agreement incorporating this DPA or otherwise begins using Services to which this DPA applies.
This DPA remains in effect for as long as Tidy processes Customer Data on behalf of Customer.
Obligations that by their nature continue after termination, including confidentiality and protection of retained Customer Data, remain in effect for as long as Tidy retains Customer Data.
20. Governing law
Unless otherwise agreed in writing, this DPA is governed by the laws of Finland.
Any disputes relating to this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Use.
Annex 1: Details of Processing
A. Subject matter
Processing of Personal Data made available to Causalytics through Customer's use of the Services, including information obtained through Customer-authorised connections to LinkedIn and other services supported by Causalytics.
B. Purpose of Processing
Tidy processes Customer Data for the purpose of providing the Causalytics Services, including:
importing and organising Customer's professional-network activity;
analysing LinkedIn activity and performance;
creating analytics, metrics and reports;
mapping interactions into lead-generation and sales funnels;
identifying contacts, interactions and opportunities;
generating recommendations, insights and suggested actions;
analysing posting, commenting, connections and messaging activity;
providing search, filtering and contact-management functionality;
maintaining and securing the Services;
troubleshooting and customer support; and
other Processing initiated by Customer through its use of the Services.
C. Nature of Processing
Processing may include:
collection;
retrieval;
import;
recording;
organisation;
structuring;
storage;
comparison;
analysis;
classification;
scoring;
aggregation;
display;
transmission at Customer's instruction;
restriction;
anonymisation; and
deletion.
D. Duration
For the duration of Customer's use of the Services and for the limited period thereafter required for deletion, backup rotation, legal compliance and other purposes permitted under this DPA.
E. Categories of Data Subjects
Depending on Customer's use of the Services, Customer Data may relate to:
Customer's LinkedIn connections;
people who interact with Customer or Customer's content;
people whose content Customer interacts with;
people who send messages to or receive messages from Customer;
commenters;
people who react to LinkedIn content;
prospects and potential customers;
existing customers;
professional contacts;
members of Customer's professional network; and
other individuals whose information is included in data Customer connects or imports into the Services.
F. Categories of Personal Data
Depending on Customer's use of the Services, Customer Data may include:
Professional and profile information
name;
LinkedIn or other professional-network identifiers;
profile URL;
job title;
employer or organisation;
professional profile information; and
professional relationship information.
Interaction information
connection status and connection activity;
connection requests and acceptance information;
posts and post activity;
comments and replies;
reactions;
message metadata;
messages and conversation content where made available through the connected service;
interactions between Customer and other individuals;
timestamps; and
engagement information.
Analytics information
impressions;
profile views;
engagement metrics;
follower information;
interaction counts;
funnel stages;
relationship and interaction history;
classifications and scores generated by the Services; and
analytics and insights derived from the above information.
Other information
Other Personal Data contained in information Customer chooses or authorises to make available through the Services.
G. Special categories of Personal Data
The Services are not designed for the intentional Processing of special categories of Personal Data under Article 9 GDPR.
However, unstructured content such as posts, comments or messages may incidentally contain information that could constitute special-category Personal Data.
Customer shall not intentionally use the Services to process special-category Personal Data unless Customer has established an appropriate legal basis and has otherwise complied with applicable Data Protection Law.
H. Frequency
Processing is continuous or recurring depending on Customer's use of the Services, connected data sources and applicable data-refresh schedules.
Annex 2: Technical and Organisational Measures
Tidy maintains technical and organisational measures appropriate to the risks associated with Processing Customer Data. Measures include, as applicable:
1. Access control
access to production systems and Customer Data is restricted to authorised personnel;
access is granted according to role and operational need;
access rights are reviewed and removed when no longer required; and
authentication controls are used to protect administrative and user access.
2. Encryption
encryption is used to protect data in transit using industry-standard transport encryption; and
Customer Data is encrypted at rest where appropriate to the relevant system and storage technology.
3. System and network security
production infrastructure is protected against unauthorised access;
security updates and patches are applied according to risk;
vulnerabilities are reviewed and remediated as appropriate;
systems are monitored for operational and security issues; and
appropriate separation is maintained between environments and customer data.
4. Availability and resilience
Tidy maintains measures designed to preserve the availability and integrity of the Services, which may include:
backups;
infrastructure redundancy;
monitoring;
recovery procedures; and
restoration processes appropriate to the Services.
5. Secure development
Tidy applies reasonable security practices to the development and maintenance of the Services, including:
access control for source code and deployment systems;
review and testing of material changes;
dependency and vulnerability management; and
separation of development and production environments where appropriate.
6. Logging and monitoring
Tidy maintains logs and monitoring appropriate to the operation and security of the Services and uses them to identify operational failures, suspicious activity and security incidents.
7. Incident management
Tidy maintains procedures for identifying, investigating, containing and responding to security incidents and Personal Data Breaches.
8. Personnel
Personnel with access to Customer Data are subject to confidentiality obligations and are provided access only where required for their responsibilities.
9. Subprocessor management
Tidy assesses service providers that process Customer Data and imposes appropriate contractual data-protection and confidentiality obligations on them.
10. Data minimisation and retention
Tidy seeks to limit Processing to Personal Data necessary to provide the Services and deletes or anonymises Customer Data when it is no longer required, subject to applicable retention requirements.
11. Security review
Tidy periodically reviews its technical and organisational measures and updates them where reasonably necessary to address changes in technology, the Services and relevant security risks.