Petitions.com

Thoả thuận Xử lý Dữ liệu (DPA)

Cập nhật lần cuối: 2026-07-24

Trang Các Bộ Xử Lý Phụ Cập Nhật Gần Nhất: 2026-07-24

Hợp đồng xử lý dữ liệu này nêu rõ các điều khoản mà theo đó chúng tôi xử lý dữ liệu cá nhân thay mặt cho quý khách.

Thỏa thuận Xử lý Dữ liệu này (Thỏa thuận) nêu rõ các nghĩa vụ và điều kiện mà Petitions.com Group Oy (Nhà Cung Cấp Dịch Vụ) xử lý dữ liệu cá nhân thay mặt cho tác giả bản kiến nghị (Tác Giả Kiến Nghị hoặc Người Kiểm Soát Dữ Liệu) trong việc cung cấp dịch vụ lưu trữ kiến nghị trực tuyến (Dịch Vụ).

Thay đổi Điều khoản

Chúng tôi có quyền thay đổi hoặc điều chỉnh các Điều khoản này bất cứ lúc nào mà không cần thông báo trước.

Định nghĩa và Vai trò

  • Nhà cung cấp dịch vụ: Petitions.com (Petitions.com Group Oy), hoạt động như một Nhà xử lý dữ liệu, xử lý dữ liệu cá nhân thay mặt cho Nhà kiểm soát dữ liệu khi cần thiết để cung cấp Dịch vụ.
  • Người kiểm soát dữ liệu: Tác giả kiến nghị, người xác định mục đích và phương tiện xử lý dữ liệu cá nhân được thu thập từ những người ký tên vào kiến nghị của họ. Với tư cách là tác giả của một kiến nghị được lưu trữ trên Petitions.com, bạn được coi là Người Kiểm Soát Dữ Liệu. Bạn quyết định nội dung của bản kiến nghị, những yêu cầu đối với những người ký tên, mục đích xử lý dữ liệu cá nhân của họ, và thời gian lưu trữ dữ liệu cá nhân. Petitions.com cung cấp một nền tảng trực tuyến để tạo và lưu trữ các bản kiến nghị, hỗ trợ vai trò của bạn như là Người kiểm soát dữ liệu với quyền tự chủ để định hình việc thu thập và sử dụng dữ liệu của kiến nghị theo mục tiêu và nghĩa vụ pháp lý của bạn.

Phạm vi Xử lý

The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Phạm vi của các hoạt động xử lý chỉ giới hạn ở việc lưu trữ, quản lý và hỗ trợ các kiến nghị trực tuyến.

As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.

The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.

Bảo Vệ Dữ Liệu

Nhà cung cấp dịch vụ cam kết thực hiện các biện pháp kỹ thuật và tổ chức để đảm bảo an toàn dữ liệu cá nhân chống lại truy cập trái phép, mất mát hoặc hư hỏng.

Thu thập Dữ liệu Bị Cấm

Nghiêm cấm yêu cầu số nhận dạng cá nhân (chẳng hạn như số ID quốc gia) từ những người ký tên.

Các bên xử lý phụ

Nhà cung cấp dịch vụ có thể thuê các bên xử lý phụ để hỗ trợ cung cấp các dịch vụ. Nhà Cung Cấp Dịch Vụ sẽ đảm bảo các nhà thầu phụ tuân thủ các nghĩa vụ bảo vệ dữ liệu phù hợp với Thỏa Thuận Xử Lý Dữ Liệu này. Bạn thừa nhận và đồng ý rằng Nhà Cung Cấp Dịch Vụ giữ quyền tự lựa chọn và thay thế các bên xử lý thứ cấp theo nhu cầu để cung cấp Dịch Vụ một cách hiệu quả.

Danh sách các nhà thầu phụ. (Cập nhật lần cuối: 2026-07-24)

Trách Nhiệm của Bộ Điều Khiển Dữ Liệu

Người kiểm soát dữ liệu chịu trách nhiệm đảm bảo rằng việc thu thập, xử lý và quản lý dữ liệu cá nhân tuân thủ tất cả các luật và quy định hiện hành.

Nhận diện Người kiểm soát dữ liệu

Theo Quy định chung về bảo vệ dữ liệu (GDPR), yêu cầu rằng danh tính của bên kiểm soát dữ liệu phải được nêu rõ ràng. Các điều khoản sau đây được áp dụng cho các tác giả kiến nghị sử dụng trang web của chúng tôi:

Các Tác Giả Kiến Nghị Cá Nhân

Nếu bạn, với tư cách là một cá nhân, đang tạo một bản kiến nghị, bạn phải cung cấp tên hợp pháp đầy đủ của mình. Điều này đóng vai trò như sự nhận dạng của bạn với tư cách là nhà kiểm soát dữ liệu cho các mục đích của GDPR.

Các Tác Giả Lời Kêu Gọi Tổ Chức

Nếu một bản kiến nghị được tạo thay mặt cho một tổ chức, tên pháp lý đầy đủ của tổ chức đó phải được cung cấp. Ngoài ra, tổ chức nên chỉ định và cung cấp thông tin liên hệ của đại diện chịu trách nhiệm cho các hoạt động xử lý dữ liệu, chẳng hạn như Nhân viên bảo vệ dữ liệu (DPO) hoặc tương tự.

Quyền của Chủ thể Dữ liệu

Người kiểm soát dữ liệu phải đảm bảo rằng các chủ thể dữ liệu (người ký tên vào kiến nghị) có thể thực hiện các quyền của họ theo GDPR, chẳng hạn như quyền truy cập, chỉnh sửa hoặc xóa dữ liệu của họ, hoặc khiếu nại với cơ quan giám sát.

Xử lý yêu cầu xóa dữ liệu cá nhân từ những người ký

The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.

Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.

When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.

The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.

Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.

Nhật ký kỹ thuật có thể chứa dữ liệu cá nhân, chẳng hạn như địa chỉ IP hoặc siêu dữ liệu giao thư điện tử. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.

The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.

Handling Rectification Requests from Signatories

The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.

Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.

The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.

Notifying Recipients

Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.

Trách nhiệm và Tuân thủ

Người kiểm soát dữ liệu phải có khả năng chứng minh sự tuân thủ GDPR, bao gồm việc trả lời các yêu cầu của chủ thể dữ liệu liên quan đến dữ liệu cá nhân của họ.

Chính sách hoặc Thông báo về Quyền riêng tư

Một chính sách quyền riêng tư hoặc thông báo rõ ràng và dễ tiếp cận phải được cung cấp, nêu rõ cách xử lý dữ liệu cá nhân, các mục đích xử lý, và cách mà các chủ thể dữ liệu có thể thực hiện các quyền của họ.

Thông Báo Thay Đổi

Các tác giả kiến nghị được yêu cầu thông báo cho Petitions.com (Petitions.com Group Oy) về bất kỳ thay đổi nào trong tình trạng của họ như là một người kiểm soát dữ liệu hoặc thay đổi thông tin liên lạc của đại diện của họ.

Đánh giá hàng năm về việc xử lý dữ liệu

Tác giả Kiến nghị được yêu cầu tiến hành rà soát hàng năm để xác định liệu còn lý do hợp lệ nào cho việc tiếp tục xử lý dữ liệu cá nhân của những người ký tên hay không. Đánh giá này cần kiểm tra sự cần thiết và tính liên quan của dữ liệu đối với mục đích của bản kiến nghị. Nếu Tác giả Kiến nghị xác định rằng không còn lý do hợp lý nào để tiếp tục xử lý dữ liệu, họ phải thực hiện các bước thích hợp để ngừng xử lý và bắt đầu xóa dữ liệu theo các luật bảo vệ dữ liệu hiện hành.

Use of Up-to-Date Signature Data

Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.

Lưu trữ và Xóa dữ liệu

Nếu Bên kiểm soát dữ liệu (tác giả của kiến nghị) vi phạm bất kỳ điều khoản nào của Thỏa thuận Xử lý Dữ liệu (DPA), bao gồm nhưng không giới hạn việc không thực hiện đánh giá hàng năm về các hoạt động xử lý dữ liệu hoặc không cung cấp lý do hợp lệ cho việc tiếp tục xử lý dữ liệu cá nhân của những người ký tên, Nhà cung cấp dịch vụ có quyền xóa hoặc loại bỏ dữ liệu cá nhân liên quan đến kiến nghị của họ.

Giới Hạn Trách Nhiệm

Trong bất kỳ trường hợp nào, tổng trách nhiệm của bên xử lý dữ liệu đối với bên kiểm soát dữ liệu cho tất cả các thiệt hại, tổn thất và nguyên nhân của hành động, dù là trong hợp đồng, vi phạm ngoài hợp đồng (bao gồm sơ suất), hoặc cách khác, sẽ không vượt quá tổng số tiền mà bên kiểm soát dữ liệu đã thanh toán cho bên xử lý dữ liệu theo thỏa thuận này.

Luật áp dụng

Thoả thuận này được điều chỉnh bởi luật pháp của Phần Lan.