Legal · GDPR Art. 28

Data Processing Information

Last updated: 27 June 2026

This document outlines how SOTKO MARKETING OY acts as a data processor on behalf of its clients (controllers) under GDPR Article 28.

1. Subject matter

Processing of personal data for the purpose of delivering agreed marketing services.

2. Duration

Processing takes place during the term of the underlying service agreement.

3. Categories of data subjects

  • Client end-users, prospects, leads and newsletter subscribers.

4. Sub-processors

We use vetted EU/EEA sub-processors. A current list is available on request and updated with 30-day notice.

5. Security measures

  • TLS 1.2+ encryption in transit, AES-256 at rest.
  • Role-based access control and SSO with MFA.
  • Annual penetration testing and security reviews.

6. Data subject requests

We assist controllers in responding to data subject access, rectification and erasure requests within statutory timelines.

7. Breach notification

We notify the controller without undue delay (within 48 hours) of becoming aware of a personal data breach.