Last updated: 11 September 2026
This Data Processing Addendum (“DPA”) forms part of an order or service agreement under which Kakumetsa Kalakasvatuse OÜ provides RevenueLuma services to the customer.
Roles and instructions
Where RevenueLuma processes personal data on the customer’s documented instructions, the customer is controller and Kakumetsa Kalakasvatuse OÜ is processor. Processing is limited to providing, securing, supporting and terminating the contracted service.
Article 28 commitments
The processor will process personal data only on documented instructions; ensure confidentiality; apply appropriate technical and organisational safeguards; impose equivalent obligations on approved subprocessors; assist with data-subject requests, security, breach response and impact assessments; delete or return personal data at the end of services subject to legal retention duties; and make information reasonably necessary for compliance and audits available.
Processing details
Subjects may include customer personnel, prospects and customers whose approved business data is connected. Data may include identity, contact, enquiry, consent, sales, marketing, service and attribution data. Duration follows the applicable order and documented retention/offboarding process.
International transfers and subprocessors
Approved hosting, payments, communications, analytics and AI providers may act as subprocessors. Where applicable, a lawful transfer mechanism and provider safeguards must be used.
Security and incidents
RevenueLuma applies tenant isolation, access controls, secret references, audit receipts, idempotency and backup/rollback controls. The processor will notify the controller without undue delay after becoming aware of a personal-data breach affecting the service.
Order of precedence
If this DPA conflicts with the service terms on personal-data processing, this DPA controls. Estonian law governs together with the applicable service agreement.