Data processing agreement.

Applies automatically to all customers and forms part of the service agreement.

First Mate Solutions Oy ยท Business ID: 3392354-9

TL;DR

  • Customer is the controller, First Mate is the processor.
  • Processing follows documented customer instructions and applicable law.
  • Authorized personnel are under strict confidentiality obligations and role-based access controls.
  • Sub-processors are contractually bound to equivalent data protection obligations.
  • Breach notifications are provided without undue delay, no later than 72 hours from awareness.

1. Scope

This Data Processing Agreement (DPA) forms part of the service agreement and applies whenever First Mate processes personal data on behalf of the customer.

2. Roles

  • Controller: the customer.
  • Processor: First Mate Solutions Oy.
  • Sub-processor: a third party engaged by First Mate to process personal data on the customer's behalf.

3. Subject matter and nature of processing

Processing is carried out to deliver the AI employee service. Details of the processing:

Subject matter Delivery of the AI employee service to the customer.
Duration The term of the agreement and the deletion period set out in Section 12.
Nature and purpose Receiving and sending messages, task execution, producing text and documents, information retrieval, tool and system integrations, memory maintenance, logging, and secure operation of the service.
Categories of personal data Contact details (name, email address, phone number), the content of messages and attachments, documents relating to tasks, usage and log data, and other personal data that the customer or a person acting on its behalf enters into the service or that the AI employee processes on the customer's instructions.
Categories of data subjects The customer's employees and other representatives, the customer's own customers and their representatives, suppliers and partners, and other individuals concerned by the tasks the customer assigns to its AI employee.
Special categories The service is not intended for processing special categories of personal data under Article 9 GDPR or criminal conviction data under Article 10. The customer must not enter such data into the service without First Mate's prior written consent.

4. Processor obligations

First Mate commits to:

  • process personal data only on documented instructions, unless law requires otherwise
  • ensure authorized personnel are bound by written confidentiality commitments
  • implement appropriate technical and organizational security measures
  • assist the controller with data subject rights requests
  • assist with breach response, DPIAs, and supervisory authority cooperation
  • delete or return personal data after the agreement ends, as set out in this DPA

5. Confidentiality and NDA commitment

First Mate, its employees, contractors, and sub-processors must not use, disclose, sell, profile, or otherwise exploit customer personal data for independent purposes.

Personal data may be accessed only to deliver and secure the service, prevent abuse, investigate incidents, comply with law, or execute documented customer instructions.

All authorized personnel are bound by written confidentiality obligations that survive termination of employment or engagement. Access is role-based, logged, and auditable.

6. Security measures

  • encryption in transit and at rest
  • customer-level infrastructure isolation
  • access control with least privilege and MFA for admin access
  • logging, monitoring, incident response, and backup controls

7. Sub-processors

The customer grants general authorization for sub-processors necessary to deliver the service. First Mate imposes equivalent data protection and confidentiality obligations by written contract.

Sub-processor Service Location
Amazon Web Services EMEA SARL Infrastructure, storage and AI inference EU
TensorX Ltd AI inference EU (Ireland / Finland)
Supabase, Inc. Database and authentication EU (Ireland)
Telegram FZ-LLC Messaging channel United Arab Emirates
Brave Software, Inc. Web search United States
AgentMail, Inc. Email inboxes for AI employees EU (Frankfurt)
Stripe, Inc. Payments EU/US
Holvi Payment Services Oy E-invoicing EU (Finland)
Resend, Inc. Transactional email United States
Vercel, Cloudflare Website delivery and CDN Global

We provide advance notice of material sub-processor changes. The customer may raise a reasoned objection.

8. International transfers

Where personal data is transferred outside the EU/EEA, appropriate safeguards are used, including SCCs and, where applicable, DPF mechanisms and supplementary technical measures.

9. Personal data breach notifications

First Mate notifies the customer without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach affecting customer data.

10. Data subject rights and DPIA assistance

First Mate provides reasonable assistance with data subject rights requests, DPIAs, and related supervisory authority interactions.

11. Audits

The customer may verify compliance with this DPA on reasonable prior notice and in a manner that does not unreasonably disrupt operations.

12. Termination and deletion

After termination, First Mate deletes or returns personal data at the customer's choice, unless retention is legally required. Service data is deleted within 30 days.

13. Liability and governing law

Liability is governed by the service agreement and applicable law. This DPA is governed by the laws of Finland.

14. Contact

  • Email: juuso@firstmate.work
  • Company: First Mate Solutions Oy
  • Address: Lapinlahdenkatu 16, 00180 Helsinki, Finland