Last updated: 27 June 2026
This document outlines how SOTKO MARKETING OY acts as a data processor on behalf of its clients (controllers) under GDPR Article 28.
1. Subject matter
Processing of personal data for the purpose of delivering agreed marketing services.
2. Duration
Processing takes place during the term of the underlying service agreement.
3. Categories of data subjects
- Client end-users, prospects, leads and newsletter subscribers.
4. Sub-processors
We use vetted EU/EEA sub-processors. A current list is available on request and updated with 30-day notice.
5. Security measures
- TLS 1.2+ encryption in transit, AES-256 at rest.
- Role-based access control and SSO with MFA.
- Annual penetration testing and security reviews.
6. Data subject requests
We assist controllers in responding to data subject access, rectification and erasure requests within statutory timelines.
7. Breach notification
We notify the controller without undue delay (within 48 hours) of becoming aware of a personal data breach.