Petitions.com

توافقنامه پردازش داده‌ها (DPA)

آخرین به‌روزرسانی: 2026-07-14

آخرین به‌روزرسانی صفحه زیرپردازشگران: 2026-07-04

این توافقنامه پردازش داده‌ها شرایطی را که تحت آن ما داده‌های شخصی را از طرف شما پردازش می‌کنیم، شرح می‌دهد.

این موافقت‌نامه پردازش داده‌ها (موافقت‌نامه) تعهدات و شرایط تحت‌الذی را که Petitions.com Group Oy (ارائه‌دهنده خدمات) داده‌های شخصی را به نمایندگی از نویسنده طومار (نویسنده طومار یا کنترل‌کننده داده‌ها) در ارائه خدمات میزبانی آنلاین طومار پردازش می‌کند، تعیین می‌کند.

تغییر شرایط

ما حق تغییر یا اصلاح این شرایط را در هر زمان و بدون اطلاع قبلی برای خود محفوظ می‌داریم.

تعاریف و نقش‌ها

  • ارائه‌دهنده خدمات: Petitions.com (Petitions.com Group Oy)، به عنوان پردازشگر داده، داده‌های شخصی را به نمایندگی از کنترل‌کننده داده به منظور ارائه خدمات پردازش می‌کند.
  • کنترل‌کننده داده: نویسنده دادخواست که اهداف و روش‌های پردازش داده‌های شخصی جمع‌آوری‌شده از امضاکنندگان دادخواست خود را تعیین می‌کند. به عنوان نویسنده یک دادخواست که در Petitions.com میزبانی شده است، شما به عنوان کنترل‌کننده داده‌ها در نظر گرفته می‌شوید. شما محتوای دادخواست، مواردی که از امضاکنندگان درخواست می‌شود، اهداف پردازش داده‌های شخصی آن‌ها و مدت زمان نگهداری داده‌های شخصی را تعیین می‌کنید. Petitions.com یک پلتفرم آنلاین برای ایجاد و میزبانی طومارها فراهم می‌کند، که نقش شما به عنوان کنترل‌کننده داده‌ها را با امکان شکل دادن به جمع‌آوری و استفاده از داده‌های طومار بر اساس اهداف و تعهدات قانونی خود تسهیل می‌کند.

دامنه پردازش

The Service Provider will process personal data solely based on the Data Controller's instructions and only as necessary to provide the Services, unless required to do so by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider will inform the Data Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. دامنه فعالیت‌های پردازش محدود به میزبانی، مدیریت، و تسهیل دادخواست‌های آنلاین است.

As a Data Processor, the Service Provider does not erase signature data on its own initiative. Every erasure of signature data is carried out on the documented instructions of the Data Controller — whether given specifically or in advance through this Agreement.

The Data Controller's acceptance of this Agreement constitutes the Data Controller's documented instructions to the Service Provider, including the procedures for handling signatory erasure requests described below and any self-service tools the Service Provider makes available to signatories on the Data Controller's behalf.

حفاظت از داده‌ها

ارائه‌دهنده خدمات متعهد به اجرای تدابیر فنی و سازمانی برای تضمین امنیت داده‌های شخصی در برابر دسترسی غیرمجاز، از دست دادن یا آسیب است.

جمع‌آوری داده‌های ممنوعه

درخواست شماره‌های شناسایی شخصی (مانند شماره‌های ملی) از امضاکنندگان ممنوع است.

«پردازشگران فرعی»

ارائه‌دهنده خدمات می‌تواند پردازشگران فرعی را به منظور کمک در ارائه خدمات به کار گیرد. ارائه‌دهنده خدمات تضمین خواهد کرد که زیرپردازنده‌ها با تعهدات حفاظت از داده‌ها که با این توافقنامه پردازش داده‌ها (DPA) سازگار است، مطابقت دارند. شما تأیید و موافقت می کنید که ارائه دهنده خدمات اختیار دارد به منظور ارائه کارآمد خدمات، زیرپردازنده‌ها را انتخاب و جایگزین کند.

فهرست زیرپردازشگران. (آخرین به‌روزرسانی: 2026-07-04)

مسئولیت‌های کنترل‌کننده داده‌ها

کنترل‌کننده داده مسئول اطمینان از این است که جمع‌آوری، پردازش و رسیدگی به داده‌های شخصی با تمامی قوانین و مقررات قابل اعمال سازگار باشد.

شناسایی کنترل‌کننده داده‌ها

طبق مقررات عمومی حفاظت از داده‌ها (GDPR)، لازم است که هویت کنترل‌کننده داده به وضوح بیان شود. مقررات زیر برای نویسندگان دادخواست که از وب‌سایت ما استفاده می‌کنند، در نظر گرفته شده است:

نویسندگان جداگانه دادخواست

اگر شما به عنوان یک فرد، دادخواستی ایجاد می‌کنید، موظف به ارائه نام کامل قانونی خود هستید. این به عنوان شناسایی شما به عنوان کنترل‌کننده داده برای اهداف GDPR عمل می‌کند.

نویسندگان دادخواست سازمانی

اگر یک دادخواست به نمایندگی از یک سازمان ایجاد شود، باید نام کامل قانونی سازمان ارائه شود. علاوه بر این، سازمان باید نماینده‌ای را منصوب کند و جزئیات تماس نماینده مسئول فعالیت‌های پردازش داده‌ها را ارائه دهد، مانند افسر حفاظت از داده‌ها (DPO) یا مشابه آن.

حقوق افراد موضوع داده

کنترل‌کننده داده باید اطمینان حاصل کند که موضوعات داده (امضاکنندگان دادخواست) می‌توانند حقوق خود را تحت GDPR مانند حق دسترسی، اصلاح، یا حذف داده‌های خود، یا ارائه شکایت به یک مرجع نظارتی اعمال کنند.

رسیدگی به درخواست‌های حذف موضوع داده از امضاکنندگان

The roles differ depending on the data in question. For personal data collected through petition signatures, the Service Provider acts as the Data Processor and the Petition Author acts as the Data Controller. For the Service Provider's own operational data — such as account information, technical logs, and contact-form messages — the Service Provider acts as an independent Data Controller.

Because the Service Provider acts only on the Data Controller's documented instructions, the procedure below constitutes the Data Controller's standing instruction for handling such requests, authorising the Service Provider to act without seeking separate approval for each request.

When a signatory asks the Service Provider to erase personal data connected to a signature, the Service Provider will, without undue delay, hide the signature from public view and make information about the erasure available to the Petition Author within the Services (for example, on a data-protection overview page and through an in-account indicator). The Service Provider is not required to send a separate email for each erasure. The Petition Author is given 14 days to review the request and to erase any copies of the signatory's personal data that they have downloaded, exported, printed, or otherwise stored outside the Services. The Petition Author may object to the erasure only where there is a lawful ground to continue processing the data (for example, the establishment, exercise, or defence of legal claims); a mere preference to retain the signature is not a valid ground. Any such objection must be made by contacting the Service Provider within that period, stating the lawful ground; the Service Provider does not provide an automatic means for the Petition Author to reverse an erasure. If the Petition Author does not object on such grounds within that period, the Service Provider will permanently delete the signature data from the active database. The Service Provider aims to complete the process within the one-month period required by the GDPR.

The Service Provider may also make available a self-service tool — such as a removal link in signature confirmation messages or on the petition page — allowing signatories to remove their own signature directly. Where such a tool is used, the Service Provider acts on the Data Controller's behalf under the documented instructions set out in this Agreement.

Personal data may persist in routine backups for a limited period after deletion from the active database. Such backups are not used for day-to-day processing and are overwritten on a rolling cycle, after which the data is permanently removed.

گزارش‌های فنی ممکن است شامل داده‌های شخصی مانند آدرس‌های IP یا فراداده‌های ارسال ایمیل باشند. These logs are deleted within 30 days. Contact-form messages may be retained for up to 5 years for audit, security, and dispute-resolution purposes.

The Service Provider keeps a minimal record that an erasure was carried out (without retaining the erased personal data) in order to demonstrate compliance.

Handling Rectification Requests from Signatories

The right to rectification is handled on the same basis as erasure: as a Data Processor, the Service Provider does not alter signature data on its own initiative, but only on the Data Controller's documented instructions, including any self-service tool the Service Provider makes available to signatories on the Data Controller's behalf for correcting their own data.

Once a correction is made, the live signature list maintained within the Services reflects the corrected value. In accordance with the obligation to use up-to-date signature data, the Data Controller must rely only on a freshly retrieved copy and update or discard any outdated copies accordingly; the Service Provider is not required to disclose the previous (incorrect) value to the Data Controller.

The Service Provider may keep an internal record of the change (for example, the previous and new values, and the time of the change) for fraud prevention, security, and dispute-resolution purposes. This record is not made available to the Data Controller by default and is retained only for as long as necessary for those purposes.

Notifying Recipients

Where the Data Controller has disclosed signature data to any recipient (such as a decision-maker or other third party), the Data Controller is responsible, under Article 19 of the GDPR, for communicating any subsequent erasure or rectification of that data to each such recipient, unless this proves impossible or involves a disproportionate effort. The Service Provider's removal or correction of data within the Services does not discharge this obligation in respect of copies the Data Controller has shared outside the Services.

پاسخگویی و رعایت قوانین

کنترل‌کننده داده باید بتواند رعایت مقررات عمومی حفاظت از داده‌ها (GDPR) را اثبات کند، از جمله پاسخگویی به درخواست‌های موضوعات داده درباره داده‌های شخصی آنها.

سیاست یا اطلاعیه حفظ حریم خصوصی

باید یک سیاست حفظ حریم خصوصی شفاف و در دسترس ارائه شود که نحوه پردازش داده‌های شخصی، اهداف پردازش و نحوه اعمال حقوق افراد موضوع داده را تشریح کند.

اطلاع‌رسانی تغییرات

نویسندگان دادخواست موظفند هرگونه تغییر در وضعیت خود به عنوان یک کنترل‌کننده داده یا تغییر در جزئیات تماس نماینده‌شان را به Petitions.com (Petitions.com Group Oy) اطلاع دهند.

بررسی سالانه پردازش داده‌ها

نویسنده دادخواست موظف است که یک بررسی سالانه انجام دهد تا مشخص شود که آیا هنوز دلیل معتبری برای ادامه پردازش داده‌های شخصی امضاکنندگان وجود دارد یا خیر. این بررسی باید ضرورت و مربوط بودن داده‌ها را در رابطه با هدف دادخواست ارزیابی کند. اگر نویسنده‌ی دادخواست تشخیص دهد که دیگر دلیل معتبری برای ادامه‌ی پردازش داده‌ها وجود ندارد، باید مراحل مناسب برای توقف پردازش و آغاز حذف داده‌ها را مطابق با قوانین قابل اجرا در حفاظت از داده‌ها انجام دهد.

Use of Up-to-Date Signature Data

Before the Data Controller discloses signature data to any third party (such as a decision-maker or other recipient of the petition), or otherwise processes the data outside the Services — including contacting signatories by email — the Data Controller must retrieve a fresh copy of the signature list from the Services and use only that current version. Signatories may exercise their right to erasure at any time, and only the live list maintained within the Services reflects such erasures. The Data Controller must not rely on previously downloaded, exported, or printed copies for these purposes, and must securely discard outdated copies.

نگهداری و حذف داده‌ها

در صورتی که کنترل‌کننده داده‌ها (نویسنده دادخواست) هر یک از شروط قرارداد پردازش داده‌ها (DPA) را نقض کند، از جمله اما نه محدود به عدم انجام مرور سالانه فعالیت‌های پردازش داده‌ها یا عدم ارائه توجیه معتبر برای ادامه پردازش داده‌های شخصی امضاکنندگان، ارائه‌دهنده خدمات این حق را برای خود محفوظ می‌داند که داده‌های شخصی مرتبط با دادخواست را حذف یا از بین ببرد.

محدودیت مسئولیت

تحت هیچ شرایطی مسئولیت کل پردازشگر داده نسبت به کنترل‌کننده داده برای تمامی خسارات، ضررها و علل اقدام، چه در قرارداد، چه در مسئولیت مدنی (از جمله سهل‌انگاری) یا به هر نحو دیگر، از مقدار کل پرداخت شده توسط کنترل‌کننده داده به پردازشگر داده تحت این توافق‌نامه تجاوز نخواهد کرد.

قانون قابل اجرا

این توافقنامه تابع قوانین فنلاند خواهد بود.