Data Processing Agreement (Auftragsverarbeitungsvertrag)
Last updated: August 2026
Data processing agreement (Auftragsverarbeitungsvertrag) pursuant to Art. 28 GDPR
Humane Plus UG (haftungsbeschränkt)
Lagerplatzstraße 4
36391 Sinntal
(hereinafter also the “Processor” (Auftragnehmer))
This data processing agreement applies to the processing operations involving personal data carried out by the Processor which are rendered to customers (hereinafter the “Controller” (Auftraggeber)) in performance of the main agreement.
Preamble
The Processor renders services to the Controller pursuant to the SaaS agreement concluded between them (hereinafter: the “main agreement"). Part of the performance of the main agreement is the processing of personal data within the meaning of the General Data Protection Regulation (“GDPR"). In order to satisfy the requirements of the GDPR for constellations of this kind, the parties conclude the following data processing agreement (also the “Agreement”), which comes into existence upon signature or upon the main agreement taking effect.
Subject matter/scope of the engagement
Within the framework of the parties’ cooperation under the main agreement, the Processor has access to personal data of the Controller (hereinafter the “Controller Data"). The Processor processes this Controller Data on behalf of and on the instructions of the Controller within the meaning of Art. 4(8) and Art. 28 GDPR.
Clarification: “Controller Data” within the meaning of this Agreement means all personal data that the Processor processes in the course of rendering services for the Controller (including the content that the Controller or its end users enter into the Processor’s systems, as well as personal outputs/reports generated therefrom). The following do not constitute “Controller Data”: (i) purely technical operating and security logs (e.g. system and access data) which the Processor processes in order to ensure information security, for error analysis and for the stability of the service, to the extent that such data processing is necessary for the secure provision of the service, and (ii) aggregated, anonymised statistics without any personal reference. To the extent that operating/security logs exceptionally contain personal data, the Processor processes such data exclusively for the aforementioned purposes and applying appropriate protective measures.
The processing of the Controller Data by the Processor takes place in the manner described in the annexes and within the scope and for the purpose specified there. The categories of persons affected by the data processing are set out. The duration of the processing corresponds to the term of the main agreement.
Whether the Processor’s services are suitable for the processing of special categories of personal data pursuant to Art. 9(1) GDPR requires a risk assessment by the Controller. To the extent that the Controller provides the Processor with special categories of personal data pursuant to Art. 9(1) GDPR for processing, or such data is processed in the course of the commissioned services, the following applies: the processing takes place exclusively on documented instructions of the Controller and only within the scope described in this Agreement and its annexes. For this purpose the Processor applies an elevated level of protection appropriate to the risk (in particular restrictive authorisation concepts/need-to-know, encryption during transmission, tenant separation, logging of privileged access and measures to ensure confidentiality). The Processor supports the Controller in accordance with this Agreement in carrying out any data protection impact assessment that may be required (Art. 35 GDPR) and in documenting the information necessary for this purpose.
The Processor is prohibited from processing Controller Data in any manner deviating from the processing operations specified in the annexes.
The processing of the Controller Data takes place in principle within the territory of the Federal Republic of Germany, in a member state of the European Union or in another state party to the Agreement on the European Economic Area.
Processing or any other transfer of Controller Data in a third country (outside the EU/EEA), or the possibility of access from a third country (e.g. support/administration), takes place only with the prior consent of the Controller and only in compliance with the requirements of Art. 44 to 49 GDPR.
To the extent that no adequacy decision is applicable, the parties agree appropriate safeguards, in particular the standard contractual clauses pursuant to Implementing Decision (EU) 2021/914. To the extent that an adequacy decision is relied upon (e.g. the EU-US Data Privacy Framework), the Processor may rely on it only if the respective data importer is validly certified/listed for the applicable mechanism.
The Processor supports the Controller in carrying out and documenting the assessment required for third-country transfers (transfer assessment) by providing the information necessary for this purpose (in particular regarding data categories, recipients, the sub-processor chain, storage/access locations, technical and organisational measures (technische und organisatorische Maßnahmen)). Any necessary supplementary measures to safeguard the transfer are implemented in accordance with the EDPB recommendations on supplementary measures.
Onward transfers to further third countries are permissible only if the requirements of Art. 44 to 49 GDPR are also met for such transfers and the respective recipient assumes at least equivalent obligations (in particular under the SCC or an adequacy decision). The Processor documents onward transfers in an appropriate manner.
The provisions of this Agreement apply to all activities connected with the main agreement. The same applies to all activities in which the Processor and its employees, or persons engaged by the Processor, come into contact with Controller Data.
The Controller’s authority to issue instructions
The Processor processes the Controller Data within the framework of the engagement and on behalf of and on the instructions of the Controller within the meaning of Art. 28 GDPR (processing on behalf of a controller). The Controller has the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also the "right to issue instructions"). If the Processor is required to carry out further processing by the law of the European Union or of the member states to which it is subject, it shall inform the Controller of those legal requirements before processing.
Instructions are as a rule issued by the Controller in writing or in electronic form (e-mail is sufficient); instructions issued orally must be confirmed by the Processor in electronic form.
If the Processor is of the opinion that an instruction of the Controller infringes data protection provisions, it must inform the Controller thereof. The Processor is entitled to suspend the implementation of the instruction concerned until it is confirmed or amended by the Controller.
Protective measures of the Processor
The Processor is obliged to observe the statutory provisions on data protection and not to pass on to third parties, or expose to their access, the information obtained from the Controller’s sphere. Documents and data must be secured against being accessed by unauthorised persons, taking into account the state of the art.
Furthermore, the Processor will bind all persons entrusted by it with the handling and performance of this Agreement (hereinafter referred to as "employees") to confidentiality (obligation of confidentiality, Art. 28(3)(b) GDPR). At the Controller’s request, the Processor will provide the Controller with evidence of the employees’ obligation in writing or in electronic form.
The Processor will structure its internal organisation in such a way that it meets the special requirements of data protection. It undertakes to take all appropriate technical and organisational measures for the adequate protection of the Controller Data pursuant to Art. 32 GDPR, in particular the measures listed in Annex 2 to this Agreement, and to maintain them for the duration of the processing of the Controller Data.
The Processor reserves the right to amend the technical and organisational measures taken, whereby it ensures that the contractually agreed level of protection is not undercut.
At the Controller’s request, the Processor will provide the Controller with evidence of compliance with the technical and organisational measures.
The Processor and the persons employed by or for it are entitled to have the services to be rendered under the main agreement, and thus also the processing of personal data, rendered from its head office, its business premises, its branch offices or from a home or mobile office, provided it is ensured that the protective measures defined in this Agreement are complied with in doing so.
Information and support obligations of the Processor
In the event of malfunctions, suspected data protection breaches or breaches of the Processor’s contractual obligations, suspected security-relevant incidents or other irregularities in the processing of the Controller Data, the Processor shall inform the Controller without undue delay upon becoming aware thereof.
The information is provided as an initial notification without undue delay, as a rule within 24 hours, at least with the core information available at that time (nature of the incident, affected systems/data categories, initial assessment of the possible impact, immediate measures initiated, point of contact). To the extent that not all details are available in full, the Processor supplements the information without culpable delay at appropriate intervals (updates) until the notification is complete.
The same applies to inspections of the Processor by data protection supervisory authorities, to the extent legally permissible.
Other obligations of the Processor
The Processor is obliged, provided that the requirements of Art. 30 GDPR apply to it, to maintain a record of all categories of processing activities carried out on behalf of the Controller pursuant to Art. 30(2) GDPR. The record must be made available to the Controller on request.
The Processor is obliged to support the Controller in preparing a data protection impact assessment pursuant to Art. 35 GDPR and any prior consultation of the supervisory authority pursuant to Art. 36 GDPR.
The Processor confirms that it has appointed a data protection officer – to the extent that there is a statutory obligation to do so.
Should the Controller Data held by the Processor be endangered by seizure or attachment, by insolvency or composition proceedings or by other events or measures of third parties, the Processor must inform the Controller thereof without undue delay, unless it is prohibited from doing so by a judicial or official order. In this connection, the Processor will inform all competent bodies without undue delay that the authority to decide on the data lies exclusively with the Controller as the “controller” (Verantwortlicher) within the meaning of the GDPR.
Sub-processor relationships
The Processor may have the processing of personal data carried out in whole or in part by further processors (hereinafter also “sub-processors” or “subcontractors”).
A sub-processor relationship within the meaning of these provisions does not exist where the Processor engages third parties with services that are to be regarded as purely ancillary services. These include, for example, postal, transport and shipping services, cleaning services, security services, telecommunications services without any specific reference to services that the Processor renders for the Controller, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems. The Processor’s obligation to ensure compliance with data protection and data security in these cases as well remains unaffected.
The Processor will agree the provisions laid down in this Agreement with the sub-processor with identical content. In particular, the technical and organisational measures to be agreed with the sub-processor must display an equivalent level of protection.
The Processor has established sub-processor relationships with the companies named in Annex 1, to which the Controller consents upon conclusion of this data processing agreement. The companies named in Annex 1 may be added to or reduced by the Processor. Should the Processor add a further sub-processor, it shall insert it into Annex 1 and inform the Controller thereof no later than 4 weeks before the intended deployment of the sub-processor. Should the Controller not agree to the addition of the further sub-processor, it has the opportunity to object to the Processor within 4 weeks of the addition. If the Controller objects to the addition of the further sub-processor, the Processor has the right to terminate the main agreement including all annexes within 2 weeks, should no alternative solution for continued cooperation be found and should the addition of the further sub-processor be of particular importance for the Processor’s business.
Before deploying any sub-processor, the Processor concludes an agreement with it that reflects the requirements of Art. 28(3) and (4) GDPR in substance and ensures an equivalent level of protection (in particular with regard to technical and organisational measures). Upon this Agreement taking effect, the Controller approves the sub-processors named in this Agreement and its annexes. The Processor remains fully responsible to the Controller for the fulfilment of all obligations under this data processing agreement even where sub-processors are deployed.
The data processing agreements with the sub-processors also include in particular that the sub-processors ensure that they have, for their part, taken adequate and appropriate technical and organisational measures pursuant to Art. 32 GDPR in respect of the processing of personal data carried out by them on behalf of a controller.
Audit rights
The Controller is entitled to verify compliance with the provisions of this Agreement to an appropriate extent. The Processor supports such verifications by providing the Controller on request with suitable evidence (e.g. current documentation of the technical and organisational measures, summaries of audit reports, certifications/attestations, where available) and by providing appropriate information.
Verifications are conducted primarily as remote audits (document review, questionnaire, video meeting). On-site inspections are considered only where (i) a remote audit is not sufficient, (ii) there is a specific cause (e.g. a serious security incident) or (iii) a supervisory authority requires this, and provided that no overriding confidentiality or security interests conflict with this.
The Controller shall announce on-site inspections with reasonable notice (as a rule at least 30 calendar days) and shall take the Processor’s business operations into account. Inspections are carried out during normal business hours. The auditor engaged by the Controller must not be in a competitive relationship with the Processor and must be bound to confidentiality in writing in advance.
To the extent that the Controller carries out recurring routine audits without any specific cause, these are limited to a maximum of one audit per calendar year. Further audits remain permissible where there is a specific cause or upon official request.
Any cost arrangements for audits (in particular on-site inspections) are agreed transparently; in doing so the parties take into account that audit and evidence obligations form part of the cooperation provided for by law under Art. 28(3)(h) GDPR.
Rights of data subjects
The Processor supports the Controller as far as possible with suitable technical and organisational measures in fulfilling the latter’s obligations under Art. 12 to 22 and Art. 32 to 36 GDPR. The Processor makes the information required for this purpose available to the Controller without undue delay, at the latest within 5 working days, to the extent that the Controller does not itself have the relevant information. In urgent cases (in particular where a deadline is imminent or in the case of official enquiries), the Processor deals with the request as a priority and makes the available information accessible as quickly as possible.
To the extent that the Controller instructs the Processor to rectify or erase Controller Data or to restrict the processing, the Processor implements the instruction without undue delay; implementation takes place at the latest within 5 working days, unless a longer, objectively necessary period is required due to the technical set-up (e.g. backup/restore processes). In this case the Processor informs the Controller of the reasons and of the expected implementation period without undue delay.
If a data subject asserts rights, for example to information, rectification or erasure with regard to his or her data, directly against the Processor, the Processor will forward this request to the Controller and await the Controller’s instructions. Without a corresponding individual instruction, the Processor will not contact the data subject.
Term and termination
The term of this Agreement corresponds to the term of the main agreement. It therefore ends automatically upon termination of the main agreement. If the main agreement can be terminated by ordinary notice, the provisions on ordinary termination apply accordingly to this Agreement. Should the Processor no longer process any Controller Data before expiry of the main agreement, this Agreement also ends automatically.
Erasure and return upon expiry of the Agreement
Upon termination of the main agreement, or at any time at the Controller’s request, the Processor will return to the Controller all documents, data and data carriers provided to it or, at the Controller’s wish and unless a statutory retention period exists, erase them completely and irreversibly. This also applies to reproductions of the Controller Data held by the Processor, such as data backups, but not to documentation that serves as evidence of the processing of the Controller Data in accordance with the engagement and in due form. Such documentation must be retained by the Processor for a period of 6 months and handed over to the Controller on request.
The Processor confirms the erasure/return to the Controller in text form (“erasure confirmation”). The erasure confirmation contains at least: (i) the date of erasure/return, (ii) a description of the affected data categories and systems/storage locations, (iii) a statement as to whether and to what extent data is contained in backups/archives, and (iv) the period and the procedure according to which backups/archives are routinely overwritten or deleted.
To the extent that immediate erasure in backups/archives is not possible for technical reasons, the Processor ensures that the data is not restored to production or otherwise used until it is finally erased, unless this is strictly necessary for rectifying a malfunction; in this case restoration takes place only under controlled conditions and is documented.
The Processor is obliged to treat the data that has come to its knowledge in connection with the main agreement as confidential even beyond the end of the main agreement.
Liability
The liability of the parties is governed by Art. 82 GDPR. Liability of the Processor towards the Controller for breach of obligations under this Agreement or the main agreement remains unaffected thereby.
The parties shall each indemnify the other from liability if a party proves that it is in no way responsible for the circumstance that gave rise to the damage suffered by a data subject. This applies accordingly in the case of a fine imposed on a party, whereby the indemnification is given to the extent that the respective other party bears a share of the responsibility for the infringement sanctioned by the fine.
Confidentiality & data secrecy
The Processor undertakes to observe the same rules on the protection of secrets as apply to the Controller.
An obligation of secrecy applies to the Processor’s employees and to third parties engaged by it. The Processor must bind the persons employed in the processing of Controller Data to confidentiality in writing pursuant to Art. 28(3)(b) GDPR. This is not necessary if the employed persons are already subject to an appropriate statutory obligation of secrecy. The Processor will document the obligation laid down in this clause in writing and submit it to the Controller at the latter’s request.
The Processor confirms that it is aware of the relevant data protection provisions. The Processor warrants that it will familiarise the employees engaged in carrying out the work with the data protection provisions applicable to them and that it will bind them to compliance with the applicable data protection provisions. It monitors compliance with the data protection provisions.
The obligations of secrecy laid down in this clause continue to exist after termination of the contractual relationship.
In addition, the Processor is obliged, alongside the respectively applicable statutory provisions (in particular § 3 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, German Telecommunications Digital Services Data Protection Act), § 203 StGB (Strafgesetzbuch, German Criminal Code), §§ 4, 23 GeschGehG (Geschäftsgeheimnisgesetz, German Trade Secrets Act) as well as any special professional obligations of secrecy), to keep secret and not to pass on to third parties all information and data that comes to its knowledge in the course of the contractually agreed services (confidential information). Confidential information includes in particular business and trade secrets, contract conclusions, technical or commercial information of any kind and other details that are designated as confidential or are to be regarded as confidential by their nature. This applies in particular also to:
Names, addresses and the personal, legal and economic circumstances of all customers of the Controller and the personal, legal and economic circumstances of the Controller and of all other persons working for the Controller.
Information is not to be regarded as confidential if, at the time the Processor obtained knowledge of the information, it was already publicly known. Likewise, information that has subsequently become publicly known or been made public with the Controller’s consent is not to be regarded as confidential.
The Processor undertakes to bind all employees who, in the course of their activity for the Controller, obtain knowledge of the aforementioned confidential information of the Controller, as well as itself.
If the Processor engages third parties, it must ensure that the requirements of paragraphs 1 to 6 are implemented accordingly.
Final provisions
The parties agree that the defence of a right of retention by the Processor within the meaning of § 273 BGB (Bürgerliches Gesetzbuch, German Civil Code) with regard to the data to be processed and the associated data carriers is excluded.
Amendments and supplements to this agreement must be made in electronic form.
In case of doubt, the provisions of this Agreement take precedence over the provisions of the main agreement. Should individual provisions of this agreement prove to be invalid or unenforceable in whole or in part, or become invalid or unenforceable as a result of changes in legislation after conclusion of the agreement, the validity of the remaining provisions shall not be affected thereby. The invalid or unenforceable provision shall be replaced by the valid and enforceable provision that comes as close as possible to the meaning and purpose of the void provision.
This agreement is governed by German law. The exclusive place of jurisdiction is the registered office of the Processor.
Annexes
Annex 1Specifications relating to the Agreement
Annex 2Technical and organisational measures of the Processor (Art. 32 GDPR)
Annex 1 - Specifications relating to the Agreement
| Subject matter and duration of the engagement Overview of the requirements and specifications | |
|---|---|
| Main agreement | SaaS agreement |
| Subject matter of the engagement | AI-supported customer support automation platform for e-commerce merchants in the DACH region who operate their Shopify shop and wish to automate their customer support |
| Purpose of the data collection, data processing or data use | In order to fulfil the Processor’s obligations under the main agreement, personal data from the Controller’s sphere of control is processed by the Processor in full within the meaning of Art. 4(2) GDPR, in particular collected, stored, altered, read out, queried, used, disclosed, compared, linked and erased, in each case to the extent required. The purpose of the processing therefore depends on the engagement described in the main agreement in each case. |
| Type of data | The categories of personal data affected by the processing depend on the Controller’s use of the Processor’s services. Categories of data that may be the subject of the processing are possibly master data (e.g. names, addresses, dates of birth), contact data (e.g. e-mail addresses, telephone numbers), content data (e.g. photographs, videos, contents of documents), contract data (e.g. subject matter of the contract, terms, customers), payment data (e.g. bank details, payment service providers), usage data (e.g. history of web services, access times), connection data (e.g. device ID, IP addresses, URL referrer), location data (e.g. GPS data, IP geolocation), |
| Categories of data subjects | The categories of data subjects affected by the processing depend on the Controller’s use of the Processor’s services. The following categories of data subjects may be considered: customers/prospective customers suppliers and service providers |
Sub-processors
| No. | Sub-processor address / country | Subject matter of the service | Storage/processing location (EU/EEA/third country) | Transfer mechanism (adequacy decision / DPF or SCC 2021/914) | Personal data processed |
|---|---|---|---|---|---|
| 1 | OpenAI Ireland Ltd., 1 Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Irland | AI-supported analysis and response generation | EU | DPF | See “Type of data” above |
| 2 | Clerk Inc., 101 S Reid St, Palatine, IL 60067 | Authentication and user account management | USA | DPF | See “Type of data” above |
| 3 | Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Irland | Payment processing and invoicing | EU | DPF | See “Type of data” above |
| 4 | Contabo GmbH, Aschauer Straße 32a, 81549 München | Server hosting and infrastructure | EU | / | See “Type of data” above |
| 5 | Shopify International Ltd., Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Irland | Retrieval of order data and customer data for contextualisation | EU | Adequacy decision | See “Type of data” above |
| 6 | Klaviyo Inc., 125 Summer Street, Boston, MA 02110, USA | Newsletter and e-mail marketing | USA | DPF | See “Type of data” above |
| 7 | Postmark (ActiveCampaign, LLC), 1 N Dearborn St, Chicago, IL 60602, USA | Inbound e-mail forwarding and transactional e-mail dispatch | USA | DPF | See “Type of data” above |
| 8 | netcup GmbH Emmy-Noether-Str. 10 76131 Karlsruhe | Server & hosting | DE | / | See “Type of data” above |
| 9 | Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Storage of attachments and backups (Cloudflare R2) | USA | DPF | See “Type of data” above |
| 10 | VASTAR SINGAPORE TECHNOLOGY PTE. LTD. (17TRACK), Singapur | Retrieval and processing of shipment status data and tracking numbers | China / USA | SCC 2021/914 | See “Type of data” above |
Annex 2 - Technical and organisational measures
Controllers responsible for the data processing are obliged pursuant to Art. 32 GDPR to take technical and organisational measures by which the security of the processing of personal data is ensured. Measures must be chosen in such a way that, taken together, they ensure an appropriate level of protection. Against this background, this overview explains which specific measures have been taken by the Processor with regard to the processing of personal data in the specific case.
| Instructions on technical and organisational measures |
|---|
| 1. Organisation of information security Guidelines, processes and responsibilities must be defined by means of which information security can be implemented and monitored. |
| Measures: ☒ Obligation of employees to maintain secrecy and to observe data secrecy. |
| Further measures implemented / explanations: Since currently only the 3 shareholders of the operating Humane Plus UG have access to the system, all 3 are subject to a confidentiality declaration which is set out in the company’s articles of association. Future employees would receive appropriate instructions, guidelines & training on these topics. |
| 2. Privacy by design Privacy by design embodies the idea that systems should be designed and constructed in such a way that the volume of personal data processed is minimised. Essential elements of data minimisation are the separation of personal identifying characteristics and content data, the use of pseudonyms and anonymisation. In addition, the erasure of personal data in accordance with a configurable retention period must be implemented. |
|---|
| Measures: ☒ No more personal data is collected than is necessary for the respective purpose. ☒ The processing operations and systems are designed in such a way that they enable and ensure GDPR-compliant erasure of the personal data processed. |
| 3. Privacy by default Privacy by default refers to privacy-friendly default settings / standard settings. To what extent have these been implemented by you? Example: when visiting a website, the visitor can expect that all programs which collect personal data are initially deactivated. |
|---|
| Measures: ☒ Simple exercise of the data subject’s right of withdrawal by means of technical measures. ☒ All pre-selections of options satisfy the requirements of the GDPR with regard to privacy-friendly default settings (e.g. no pre-selected opt-ins). |
| 4. Access control and admission control Measures that ensure that persons authorised to use the data processing procedures can access exclusively the personal data or the information and data requiring protection that is subject to their access authorisation (description of the security mechanisms inherent in the system, encryption procedures in accordance with the state of the art. In the case of online access it must be clarified which side is responsible for the issue and administration of access security codes.). The Processor ensures that users authorised to use the IT infrastructure can access exclusively content for which they are authorised, and that personal data cannot be copied, altered or erased without authorisation during processing and after storage. |
| Measures: ☒ Access to data is restricted and possible only for authorised persons. ☒ Blocking of the user account in the event of failed attempts / inactivity. ☒ Locking of the end device when leaving the workplace or in the event of inactivity. ☒ Number of administrators reduced to the “absolute minimum”. ☒ Regular review of authorisations. ☒ Password policy, implementation of complex passwords. ☒ Use of strong authentication with at least 2 factors from knowledge, possession, characteristics (PIN, token, smartcard, biometric procedures). |
| Further measures implemented / explanations: Blocking of the user account in the event of failed attempts / inactivity: Clerk natively blocks all user accounts after 100 failed attempts |
| 5. Cryptography and / or pseudonymisation Use of encryption procedures to ensure the proper and effective protection of the confidentiality, authenticity or integrity of personal data or of information requiring protection. Measures suitable for making identification of the data subject more difficult. |
|---|
| Measures: ☒ Encryption of data carriers (e.g. mobile hard drives, USB sticks, etc.). ☒ Encryption of end devices (PC, laptop, smartphones). ☒ Encrypted storage of personal data. ☒ Encryption of data backup media (e.g. tapes, hard drives, etc.). ☒ Encryption of access to network access points and connections. ☒ Use of pseudonyms, procedures for the pseudonymisation of data. ☒ Use of procedures for the anonymisation of data. |
| 6. Protection of buildings Prevention of unauthorised physical access to the organisation’s information and information-processing facilities as well as their damage and impairment. The Processor takes measures to prevent unauthorised persons from gaining admission (to be understood in a physical sense) to data processing systems with which personal data is processed. |
|---|
| Further measures implemented / explanations: Measures implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please feel free to contact us. |
| 7. Protection of operating resources / information assets Prevention of loss, damage, theft or impairment of assets and of interruptions to the organisation’s business operations. |
|---|
| Further measures implemented / explanations: Measures implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please feel free to contact us. |
| 8. Operating procedures and responsibilities Ensuring the proper and secure operation of systems as well as procedures for the processing of information. |
|---|
| Measures: ☒ Clear allocation of responsibilities for system and application support. ☒ Separation of development, test and production systems. |
| 9. Data backups Measures that ensure that personal data or information and data requiring protection is protected against accidental destruction or loss. |
|---|
| Further measures implemented / explanations: Measures implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please feel free to contact us. |
| 10. Protection against malware and patch management Prevention of the exploitation of technical vulnerabilities through the use of up-to-date antivirus software and the implementation of patch management. |
|---|
| Measures: ☒ Regular monitoring of the status of security updates and system vulnerabilities. ☒ Use of anti-malware software. ☒ Regular installation of security patches and updates. |
| 11. Logging and monitoring Measures that ensure that it can subsequently be verified and established whether and by whom personal data has been entered into, altered in or removed from IT systems. (All system activities are logged; the logs are retained by the Processor for at least 3 years.) |
|---|
| Measures: ☒ Logging of access. ☒ Evaluation of log files. |
| 12. Network security management Appropriate protection must be implemented for the network so that the information and the infrastructure components are protected. |
|---|
| Measures: ☒ Use of firewall systems. ☒ User authentication and encryption of external access. |
| Further measures implemented / explanations: Further measures implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please feel free to contact us. |
| 13. Transfer of information Measures that ensure that personal data or information and data requiring protection cannot be read, copied, altered or removed without authorisation during electronic transmission or during their transport or their storage on data carriers, and that it can be verified and established to which bodies a transfer of personal data or of information and data requiring protection by means of data transmission facilities is envisaged. (Description of the facilities and transmission protocols used, e.g. identification and authentication, encryption in accordance with the state of the art, automatic call-back, and others) |
|---|
| Measures: ☒ Rules for the exchange of sensitive information and restriction of the group of persons authorised to transmit it. ☒ Disclosure of data to third parties only after examination of the legal basis. ☒ Lawfulness and written specification of the disclosure of data to third countries. ☒ Secure data transmission between client and server. ☒ Appropriate protection of e-mails that contain sensitive information / data. ☒ Use of encrypted external access. |
| 14. Network segregation Groups of information services, tenants, users and information systems should be kept segregated from one another in networks. |
|---|
| Measures: ☒ Logical tenant separation. |
| 15. Acquisition, development and maintenance of systems Measures that ensure that information security is an integral part throughout the life cycle of information systems. |
|---|
| Measures: ☒ Guidelines for secure system development. ☒ Monitoring of outsourced system development activities. ☒ Protection of test data. |
| 16. Supplier relationships Measures concerning information security to reduce risks in connection with suppliers’ access to the company’s assets should be agreed and documented with sub-suppliers / sub-processors. |
|---|
| Measures: ☒Selection of the processor on the basis of due care (in particular with regard to data security). ☒ the processor has appointed a data protection officer. ☒ Ongoing review of the processor and its activities. ☒ Ensuring the destruction of data after termination of the engagement. |
| 17. Management of information security incidents Consistent and effective measures for the management of information security incidents (theft, system failure, etc.) must be implemented. |
|---|
| Measures: ☒Immediate information of the Controller in the event of data protection incidents. |
| 18. Information security aspects of business continuity management / emergency management The maintenance of system availability in difficult situations, such as crises or damage events. Emergency management must ensure this. The requirements regarding information security should be defined in the planning for business continuity and disaster recovery. |
|---|
| Further measures implemented / explanations: Measures implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please feel free to contact us. |
| 19. Compliance with statutory and contractual requirements Implementation of measures to avoid breaches of statutory, official or contractual obligations as well as of any security requirements. |
|---|
| Measures: ☒Ensuring compliance with the statutory obligations in the course of the cooperation. ☒Establishment of licence management. ☒Confidentiality obligations with employees as well as sub-suppliers and service providers. |
| 20. Data protection requirements and data protection management Privacy and the protection of personal data should be ensured in accordance with the requirements of the relevant statutory provisions, other regulations and contractual provisions. |
|---|
| Measures: ☒Establishment of a data protection organisation. ☒Provision of data protection training. ☒Establishment of a data protection management system. |