Data processing agreement
Last updated 26 August 2026
Parties and roles
This data processing agreement is part of Vide's terms of service. It covers the personal data an accounting firm stores in the service about its own clients and their staff.
The accounting firm is the controller of that data. Five Vision Oy (business ID 3633752-9), Teollisuustie 17 A, 96320 Rovaniemi, Finland, is the processor and processes the data on the firm's behalf.
For our own user accounts and the service's technical logs we are the controller ourselves. Those are covered by the privacy policy, not by this agreement.
The agreement takes effect when the accounting firm starts using the service and stays in force for as long as we process personal data on the firm's behalf.
Subject matter, duration and purpose
The processing covers personal data contained in the receipts, other documents and messages the accounting firm requests from its clients, and in client records and portal user accounts.
The purpose of the processing is to provide the service: to receive and pass material between the accounting firm and its client, to remind about outstanding requests, and to keep track of what is still open.
The processing lasts as long as the agreement is in force. After that we act as described under Return and deletion of material.
We do not use the material for our own purposes, and we do not use it to train AI models.
Categories of personal data and data subjects
The personal data processed is typically:
The data subjects are the contact persons and staff of the accounting firm's client companies, and any other people whose data the material contains. The accounting firm decides what material it requests: special categories of personal data should not be stored in the service without agreeing on it separately.
- name, email address and phone number
- the position and role of a company contact person
- information contained in receipts and documents, such as purchases, travel and expenses
- information contained in payroll material, where the accounting firm stores such material in the service
- the content of messages and comments
- sign-in and activity events in the client portal
- client record data, including data retrieved from the public trade register
- files attached to the material, as they are
Processing on documented instructions
We process personal data only on the accounting firm's documented instructions. The terms of service, this agreement and normal use of the service form those instructions.
If we consider an instruction to be unlawful, we tell the accounting firm and do not carry it out.
If the law requires us to process data otherwise than on those instructions, we tell the accounting firm beforehand, unless the law expressly forbids it.
We do not transfer personal data outside the EU or the EEA.
Confidentiality
Only those of our people who need it for their work have access to personal data.
Every such person is bound by confidentiality, and the obligation continues after their employment ends.
Access is removed when the role changes or ends.
Security
We implement a level of security appropriate to the risk (Article 32). At a minimum this includes:
We keep improving security. We will not lower its level during the contract term.
- encryption of traffic over public networks
- role-based access limits and per-firm isolation
- two-factor authentication for service users
- one-time, short-lived sign-in links for the client portal
- passwords stored only as hashes, and credential data encrypted at rest
- an event log of changes and administrative actions
- vulnerability monitoring of software dependencies
Subprocessors
The accounting firm gives general written authorisation for us to use subprocessors to provide the service.
An up-to-date list of subprocessors is published on the Subprocessors page. The list states what each one does, what personal data it sees and where the data is located.
We give at least 30 days' notice of a new or changed subprocessor. The accounting firm may object on reasonable grounds before the change takes effect, and if we cannot find a solution the firm may terminate the agreement with immediate effect.
Each subprocessor is under a contract that places the same data protection obligations on it as this agreement places on us.
We are responsible for a subprocessor's acts as for our own.
Assistance
We assist the accounting firm in responding to data subject requests concerning access, rectification, erasure, restriction of processing and portability.
If a data subject contacts us directly, we direct them to the accounting firm and do not answer the request ourselves.
We notify the accounting firm of a personal data breach without undue delay and within 24 hours of becoming aware of it, and we provide the information the firm needs to make its own notification.
We also assist the accounting firm with a data protection impact assessment and prior consultation where one is needed.
Assistance is included in the price of the service to the extent that it is reasonable and concerns data held in the service.
Return and deletion of material
Vide is a staging point, not an archive. The statutory retention duty under the Finnish Accounting Act rests with the party keeping the books, and the permanent home of the material is the accounting firm's own accounting system.
Documents stored in the service are kept for one year by default, and we notify the accounting firm well before they go. The firm is responsible for having moved the material into its own system before deletion.
When the agreement ends, the accounting firm receives its material in a machine-readable format. We delete the personal data within 30 days of the material being handed over, or of the firm telling us it is not needed.
If the law requires us to keep something longer, we say what and for how long, and we process it for nothing but meeting that obligation.
Audit rights
We give the accounting firm the information it needs to demonstrate that the obligations in this agreement are met.
The accounting firm may audit the processing once a year, and additionally after a personal data breach. An audit is agreed in advance and carried out so that it does not put other customers' data at risk.
We answer questions about audits at software@koud.fi.
Contract terms
If this agreement and the terms of service conflict on a matter concerning the processing of personal data, this agreement prevails.
We may update this agreement. We give at least 30 days' notice of material changes before they take effect.
The agreement is governed by Finnish law. Dispute resolution is agreed in the terms of service.
Questions about this agreement can be sent to software@koud.fi.