Last updated: 14 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Panda Capital Oy Ab (Finnish business ID 3297809-7) ("Provider", "we", "us") and the customer using the Saturn SQL service ("Customer", "you"). It applies whenever we process personal data on your behalf in the course of providing the Service, and reflects the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR"). By using the Service, you accept this DPA; no signature is required. A countersigned copy is available on request.
"Customer Data" means personal data contained in the databases you connect to the Service, in the results of queries you run, and in content you submit to the Service (such as query text, dashboards, and export destinations), to the extent it constitutes personal data under the GDPR. Terms such as "controller", "processor", "data subject", "processing", and "personal data breach" have the meanings given in the GDPR. Capitalised terms not defined here have the meanings given in the Terms & Conditions.
For Customer Data, you are the controller (or a processor acting on behalf of another controller) and we are your processor. For personal data we collect for our own purposes, such as account, authentication, billing, support, and usage data, we act as an independent controller as described in our Privacy Policy; that processing is outside the scope of this DPA.
| Subject matter | Provision of a collaborative SQL editor and query workspace, including query execution against Customer-connected databases and delivery of results to Customer-configured destinations |
| Duration | The term of the Terms & Conditions, plus the deletion period in Section 10 |
| Nature and purpose | Executing queries you initiate or schedule, transmitting and temporarily processing query results, storing content you save in the Service, and delivering results to destinations you configure (such as Google Sheets or Slack) |
| Categories of data subjects | Determined by you: any data subjects whose personal data is contained in the databases you connect (for example your customers, users, or employees) |
| Categories of personal data | Determined by you: any categories of personal data contained in the databases you connect or in your query results. You are responsible for not processing special categories of data (Article 9 GDPR) through the Service unless you have a lawful basis to do so |
We do not use Customer Data for any purpose other than providing the Service. We do not use Customer Data to develop or train artificial intelligence or machine learning models, and we do not sell it.
We will:
Taking into account the state of the art and the nature of the processing, we implement appropriate measures to protect Customer Data, including:
We may update these measures from time to time, provided the overall level of protection is not materially reduced.
You grant us general authorisation to engage subprocessors to provide the Service. Our current subprocessors are listed in Section 15 of the Privacy Policy. We will update that list before adding or replacing a subprocessor. If you object to a new subprocessor on reasonable data protection grounds, you may terminate the affected subscription before the change takes effect; continued use of the Service after the change constitutes acceptance.
We impose data protection obligations on each subprocessor that are materially equivalent to those in this DPA, and we remain liable to you for their performance.
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to data subject requests under Chapter III of the GDPR. In practice, because the Service queries your own databases rather than storing a copy of them, you can usually fulfil such requests directly in your source systems. If a data subject contacts us directly about Customer Data, we will refer them to you.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to us to help you meet your obligations under Articles 33 and 34 of the GDPR, including the nature of the breach, the categories and approximate number of data subjects and records concerned where known, the likely consequences, and the measures taken or proposed.
We will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 of the GDPR, insofar as they relate to our processing of Customer Data and the necessary information is available to us.
Customer Data held by the Service is limited to content you have saved (such as query text, connection configurations, dashboards, and cached results needed to display them). You can delete connections, queries, and other content at any time through the Service. Upon termination of your account, we will delete Customer Data within ninety (90) days, unless retention is required by applicable law. You are responsible for exporting any content you wish to keep before termination. Your source databases are never stored by us and are unaffected by deletion of your account.
We will make available to you information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you. Audits may be conducted no more than once per twelve (12) months (except following a personal data breach or at the instruction of a supervisory authority), on at least thirty (30) days' written notice, during normal business hours, without disrupting our operations, and at your cost. We may first satisfy an audit request by providing recent third-party certifications or audit reports from ourselves or our infrastructure subprocessors.
Customer Data may be processed by subprocessors located outside the European Economic Area, including in the United States, as listed in the Privacy Policy. Where such transfers occur, we rely on adequacy decisions of the European Commission (including the EU-U.S. Data Privacy Framework where the recipient is certified) or the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into our agreements with the relevant subprocessors. Where we transfer Customer Data to you outside the EEA at your instruction (for example, delivering query results to a destination you configure), you are responsible for the lawfulness of that transfer.
The liability of each party under this DPA is subject to the limitations of liability in the Terms & Conditions. This DPA takes effect when you first use the Service, remains in force for as long as we process Customer Data on your behalf, and automatically terminates upon deletion of Customer Data under Section 10. In case of conflict between this DPA and the Terms & Conditions regarding the processing of Customer Data, this DPA prevails. This DPA is governed by the laws of Finland, and disputes are subject to the exclusive jurisdiction of the courts of Helsinki, Finland.
Questions about this DPA, requests for a countersigned copy, and data protection enquiries may be submitted through the contact form in the Service.
© 2026 Panda Capital Oy Ab. All rights reserved.