Data Processing Agreement for Processors (DPA)
between
Customer Name
Str. PLZ & Ort
(hereinafter called "Controller")
and/und
Alexander Thamm GmbH
Sapporobogen 6-8, 80637 München
(hereinafter called "Processor")
(hereinafter, the Controller and the Processor shall also be referred to collectively as the "Parties")
Preamble
This Agreement specifies the Parties' data protection obligations in relation to data processing to be performed by Processor for Controller. The provisions contained herein apply to all activities in which employees of Processor or third parties engaged by Processor ("Sub-processors") may come into contact with personal data of Controller.
The German language version of this Agreement has priority over the English language version.
§1 Subject-matter and duration of the order; scope, nature and purpose of the data processing; type of data and data subjects concerned
(1) The subject-matter of the order on data handling and data processing, as referred to in Art. 4(2) and Art. 28 GDPR, is the performance of the tasks specified in Annex 1 Section 1 by Processor (Processing Descriptions).
(2) The duration of the order shall be determined based on the provisions of Annex 1 Section 2.
(3) The scope, nature and purpose of the data processing shall be determined based on the Processing Descriptions specified in Annex 1 Section 1 in connection with Controller's instructions.
(4) The processing concerns the categories of data subjects (as defined in Art. 4(1) GDPR) and the types of data (as defined in Art. 4(1), (13), (14) and (15) GDPR) specified in Annex 1 Section 1.
(5) Instructions shall initially be established by the Processing Descriptions provided in Annex 1 Section 1. Controller may subsequently change, add to or replace its instructions in writing or in an electronic format (text form) by means of individual instructions ("individual instruction") addressed to one of the Processor's instruction recipients listed in Annex 1 Section 4.
(6) The performance of the contractually agreed data processing shall take place exclusively in a Member State of the European Union (EU) or in another State party to the Agreement on the European Economic Area (EEA). This also applies to data processing by Sub-processors. Any transfer, even of partial work, to a third country, including the engagement of a Sub-processor based in a third country, requires the prior written consent of the Controller, and may only take place if the special requirements of Art. 44 et seq. GDPR (e.g., adequacy decision of the European Commission, standard contractual clauses and authorized code of conduct) have been fulfilled.
(7) If the Processor performs the contractually agreed data processing in premises not exclusively used by the Processor (e.g. co-working space, private residence), the Processor is obliged to notify the Controller thereof in Annex 1, Section 1.
§2 Technical and organizational measures
(1) The specific data processing under contract shall guarantee a level of protection appropriate to the risk posed to the rights and freedoms of the natural persons affected by the processing. Processor must take technical and organizational measures pursuant to Art. 28(3)(c) and Art. 32 GDPR that will ensure the ongoing confidentiality, integrity, availability and resilience of the processing systems and services.
(2) In its area of responsibility, Processor warrants the implementation and observation of the general, technical and organizational measures that are required in order to guarantee the level of data protection or data security appropriate to the data protection regulations in force in each case. Processor guarantees that it will fulfil its duties under Art. 32(1)(d) GDPR to implement a process to regularly review the effectiveness of the technical and organizational measures to ensure the security of the Processing. In particular, Processor shall arrange its internal organization such that it meets the special requirements of the data protection regulations in force in each case.
(3) Before the order was issued, Processor provided Controller with a comprehensive and up-to-date data protection and data security concept or a description of the technical and organizational measures taken for this data processing, as applicable. A description of the data protection and data security concept or of the technical and organizational measures taken, as applicable, is attached as Annex 2 and forms a component of this Agreement. The Processor shall take at least these technical and organisational measures listed in Annex 2 to ensure the security of the personal data and shall maintain them throughout the duration of the contract.
(4) The technical and organizational measures are subject to technical progress and further development. In this respect, processor is permitted to implement alternative adequate measures. However, in doing so, the security level of the specified measures must not be undermined. Major changes must be documented and reported to the Controller's authorized contact person listed in Annex 1, Section 4. Such documentation must be stored for the duration of this Agreement and must be provided to one of the Controller's authorized contact persons listed in Annex 1, Section 4, on request.
§3 Correction, blocking and deletion / rights of the data subjects
(1) Processor shall not correct, block or delete the data processed under contract except at the documented instruction of Controller (i.e., not on Processor's own authority).
(2) Processor shall assist Controller pursuant to the data protection regulations then in force in fulfilling its duty to respond to requests to safeguard the rights of the data subject ("rights of data subjects"). The rights of data subjects may include but are not limited to the following: duty to inform and right of access to personal data; the right to rectification, erasure (being forgotten) and data portability; the right to object and the right to other than exclusively automated decision-making in a specific case.
(3) Insofar as a data subject directly contacts the Processor for the purpose of exercising his/her data subject rights with regard to data processed by the Processor on behalf of the Controller, the Processor shall immediately forward this request to the contact person authorised by the Controller as listed in Annex 1, Section 4. The Processor shall not respond to the request itself unless it has been authorised to do so by the Controller.
§4 Processor's duties and controls
(1) The Processor shall not use the personal data provided for processing for any purposes other than those specified in the Processing Description in Annex 1, Section 1 or by documented Individual Instruction and, in particular, for its own purposes, unless it is obliged to do so by the law of the European Union or of the Member States of the European Union to which the Processor is subject; in such a case, the Processor shall notify the Controller of these legal requirements prior to the processing, unless the law in question prohibits such notification due to an important public interest.
(2) Processor confirms that it is familiar with the data protection regulations of the GDPR that are relevant for purposes of the processing under contract.
(3) Processor agrees to observe confidentiality when processing Controller's personal data under contract. This confidentiality duty shall survive the termination of this Agreement.
(4) If the applicable data protection regulations in force so require, Processor shall appoint in writing a Data Protection Officer. Contact data of the appointed Processor's Data Protection Officer is provided in Annex 1 Section 3. Processor shall promptly inform Controller in writing regarding any change of Data Protection Officer and/or of his contact data. The information shall be addressed to the contact person authorized by the Controller as listed in Annex 1, Section 4.
(5) Processor warrants that, before starting the activity, it has familiarized its employees involved in performing the work with the data protection provisions applicable to them and has ensured that they have appropriately committed themselves to confidentiality for the duration of their activity, as well as after the termination of their employment relationship (Art. 28(3)(b), Arts. 29, 32 GDPR).
(6) Processor shall promptly inform Controller regarding control activities, investigations and other measures of the data protection supervisory authorities, insofar as these measures relate to this Agreement. This also applies if, in the course of a regulatory offense proceeding or criminal proceeding, any competent body investigates the processing of personal data in connection with the processing under contract by Processor.
(7) Processor shall promptly notify Controller if it believes that any instruction issued by Controller infringes statutory regulations (Art. 28(3) sentence 3 GDPR). Processor has the right to suspend performance of the relevant instruction until such time as it has been confirmed or changed by the contact person authorized by the Controller as listed in Annex 1, Section 4.
(8) Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Art. 32, 35 and 36 of the GDPR taking into account the nature of processing and the information available to the Processor, namely assistance with ensuring the security of data processing, carrying out data protection impact assessments (if relevant) and consulting the competent Supervisory Authority if necessary (if relevant).
§5 Subcontracting relationships (Sub-processors)
(1) Subcontracting relationships in the sense of this Agreement shall be understood as such processing operations, which directly relate to the performance of the processing operations described in Annex 1 Section 1 or documented individual instructions, insofar as personal data are processed by the sub-processor performing processing operations on behalf of the processor, which the processor processes on behalf of the Controller.
(2) For purposes of data processing, Processor may engage Sub-processors for each of the services as specified in Annex 1 Section 5.
(3) Processor is liable to Controller for all acts and omissions of the Sub-processors engaged by Processor. If the Sub-processor fails to comply with its data protection obligations, the Processor shall be liable to the Controller for compliance with the obligations of that Sub-processor (Art. 28(4) sentence 2 GDPR).
(4) Processor has the right to engage Sub-processors or to replace those it has already engaged. Data may not be disclosed to the Sub-processor unless and until the Sub-processor has fulfilled the obligations specified in Art. 29 and Art. 32(4) GDPR concerning its employees. Processor shall inform the contact person authorized by the Controller as listed in Annex 1, Section 4 in writing at least four (4) weeks in advance of any change it plans to make regarding the engagement or replacement of a Sub-processor as specified in Art. 28(2) GDPR. Controller may object to a planned change but only for good cause (for example, in cases where there are indications that a Sub-processor to be engaged may be unreliable in terms of compliance with legal/contractual data protection obligations or is a competitor of the Controller). If Controller makes an objection, Processor shall not engage or replace the respective Sub-processor but shall seek an amicable solution with Controller. If good cause exists and the Parties fail to reach an amicable solution, Controller shall have a special right of termination.
(5) Furthermore, Processor must ensure that it exercises due diligence in selecting the Sub-processor by paying special attention to the appropriateness of the technical and organizational measures taken by it as specified in Art. 32 GDPR.
(6) If Processor engages Sub-processors, the contractual arrangements with the Sub-processors must be structured in such a way that they comply with the requirements concerning confidentiality, data protection and data security between the Parties to the present Agreement. Controller must be granted control and verification rights in accordance with §6 of this Agreement with respect to the Sub-processors such that they also grant these rights directly to Controller vis-à-vis the Sub-processors, notwithstanding Processor's liability for the Sub-processors. Upon request, Processor must provide Controller with information about the essential content of the agreement and the Sub-processors' implementation of the data protection obligations or (if expressly requested) to provide a copy of the contract with the Sub-processor. To the extent necessary to protect business secrets or other confidential information, including personal data, the Processor may obscure the relevant wording of the contract with the Sub-processor before providing a copy. The information or the copy shall be addressed to the Controller's authorized contact person listed in Annex 1, Section 4.
(7) If the Sub-processor performs the agreed service outside the EU/EEA, the Processor shall ensure compliance with Chapter V of the GDPR. If personal data are transferred to a country outside the EU/EEA on the basis of suitable guarantees (Art. 46 of the GDPR), the admissibility under data protection law must be ensured by the Processor agreeing and implementing additional technical and organisational measures to ensure an adequate level of data protection outside the EU/EEA, insofar as the selected suitable guarantee is not sufficient for this purpose.
(8) The Processor confirms that it has carried out a data transfer impact assessment (TIA) with regard to data transfers to Sub-processors on the basis of appropriate guarantees (§5(7) of this Agreement) and that it has come to the conclusion that an appropriate level of data protection is guaranteed for the personal data transferred in the destination country. A TIA is required for such data transfers against the background of the Schrems II decision of the European Court of Justice (16 July 2020, Case C-311/18) as well as pursuant to clause 14 of the standard contractual clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021) or a corresponding clause in standard contractual clauses replacing or modifying the previous standard contractual clauses. The Processor confirms that the TIAs comply with the requirements formulated in the Schrems II Decision and set out in Article 14 of the said standard contractual clauses. The Processor shall provide the documentation of the TIA to the Controller upon the Controller's request.
§6 Controller's control rights
(1) Processor shall use appropriate means to document vis-à-vis Controller that it complies with the duties laid down in this Agreement. As evidence of its compliance with the agreed duties, Processor may submit the following information to Controller:
- the results of a self-audit conducted by Processor
- the results of an external audit
- an internal code of conduct, including external evidence of compliance with it
- certificate of data protection and information security
- an authorized code of conduct in accordance with Art. 40 GDPR
- certificates in accordance with Art. 42 GDPR
(2) The Controller is entitled to demand suitable evidence of compliance with the obligations set out in this Agreement. This applies in particular to evidence of the implementation and effectiveness of the technical and organisational measures implemented by the Processor in accordance with §2 of this Agreement.
(3) If, in individual cases, it becomes necessary for Controller or an auditor engaged by it to conduct any audits regarding compliance with this Agreement and the duties specified in Art. 28 GDPR in a specific case (e.g. on-site inspections), these audits shall be conducted at normal business hours without disrupting the course of business and with adequate advance notice. Processor shall provide Controller with the necessary information within a reasonable time upon request. Insofar as the consent of third parties is required for controls in individual cases, the Processor shall be obliged to obtain such consent prior to the start of processing.
(4) Processor may make the control measure contingent on adequate advance notice and on the signing of a declaration of confidentiality regarding other customers' data. If the auditor engaged by Controller is a competitor of Processor, Processor has the right to object to Controller's engagement of this auditor.
§7 Notifications of infringements by the Processor
(1) Processor shall report any and all cases in which it or any of the parties engaged by it infringe regulations protecting the personal data of Controller, alleged infringement of data protection regulations, or irregularities have occurred when processing personal data or are in conflict with the determinations made here.
(2) Processor is aware of the duties in force under data protection law (e.g., under Art. 33 and Art. 34 GDPR) as to reporting to supervisory authorities and data subjects, and particularly their requirements in terms of timing and content. Therefore, such events must be promptly reported to Controller regardless of the cause. Furthermore, Processor shall assist the Controller in ensuring its compliance with the obligations pursuant Art. 33 and Art. 34 GDPR taking into account the nature of processing and the information available to the Processor, namely assistance with notifying the Supervisory Authority of the Personal Data Breach and communicating to Data Subjects that there has been a data breach. In particular, the Processor shall provide the Controller with the following information:
- the nature of the personal data, where possible, indicating the categories and approximate number of data subjects as well as the categories and approximate number of personal data sets concerned;
- the likely consequences of the personal data breach; and
- the measures taken or proposed to address the personal data breach and, where appropriate, measures to mitigate its possible adverse effects.
(3) Processor must take appropriate measures in consultation with Controller to safeguard the data and to minimize any potential adverse effects for data subjects.
§8 Controller's right, duties and authority
(1) The data shall be handled exclusively as agreed and according to Controller's documented instructions. In the context of the description made in this Agreement, Controller reserves a comprehensive right to give instructions concerning the type and scope of the data processing and the procedures for the same, which Controller may specify in more detail through individual instructions. Changes to the subject-matter of the processing and to the procedures used must be coordinated and documented jointly by the Parties. The contact persons of the Controller authorized to issue instructions and the recipients of instructions on the part of the Processor are listed in Annex 1 Section 4. In the event of a change or long-term prevention of the contact persons, the contracting party shall be informed immediately and in principle in writing or electronically of the successors or the representatives. The instructions shall be kept for their period of validity and subsequently for three full calendar years.
(2) If Controller's instructions include discretionary powers, Processor must obtain Controller's respective decision. Processor has no right to exercise its own independent discretion or to make any decision as a gesture of goodwill.
(3) Controller shall promptly confirm its oral instructions in writing or via e-mail (in text form). Processor shall not use the data for any other purpose and, in particular, does not have the right to disclose the data to third parties or without a corresponding, express and written instruction from Controller to bodies outside the Member States of the EEA unless an exception set out in §4(1) of this Agreement is relevant. Copies and duplicates shall not be made without Controller's knowledge. This does not include backup copies if they are required for purposes of guaranteeing proper data processing.
§9 Deletion of data and return of data carriers
(1) After completing the contractual services or prior thereto upon request from Controller, but no later than upon the termination of the Performance Specifications provided in Annex 1 Section 1, Processor must hand over to Controller all documents, results of processing and use, and databases in its possession or obtained by Sub-processors in relation to the contractual relationship or destroy them in accordance with data protection law upon prior consent with Controller, as specified in Art. 28(3)(g) GDPR unless the Processor is obliged to store the personal data under Union or EU Member State law. The same applies to test and scrap material. The deletion record must be submitted to Controller upon request.
(2) Documentation that serves as evidence that the data have been processed properly and in accordance with the contract must be retained by Processor beyond the end of the Agreement in accordance with the respective retention periods. Processor may, to his discharge, hand this documentation over to Controller at the end of the Agreement.
§10 Costs
(1) Processor shall bear all costs it incurs by fulfilling the obligations specified herein.
(2) The Parties agree that Processor shall be compensated for fulfilling the obligations specified in this Agreement by means of the fee set forth in the Main Agreement / the contract and that Processor shall not receive any additional compensation in relation to this Agreement.
§11 Miscellaneous and general provisions
(1) If Controller's personal data held by Processor are put at risk through seizure or attachment, bankruptcy or insolvency proceedings or other events or measures on the part of third parties, Processor must promptly inform Controller of this. Processor shall promptly inform all Controllers that the sovereignty over Controller's personal data rests with Controller.
(2) Changes and additions to this Agreement and all of its components, including any representations made by Processor, must be made in a written agreement, which may also be made in an electronic format (text form), and the express statement that it constitutes a change or addition to the present terms and conditions. This also applies to any waiver of this written-form requirement.
(3) The provisions of this Agreement shall survive the termination of the Main Agreement / the contract and remain in force until such time as all personal data of Controller have been destroyed in full or returned to Controller.
(4) In other respects, the provisions of the Main Agreement / the contract shall apply in like manner.
(5) The defense of the right of retention as specified in §273 of the German Civil Code (BGB) is excluded regarding the data processed for Controller and the associated data carriers.
(6) The Parties are liable to data subjects in accordance with the provision laid down in Art. 82 GDPR. If a data subject takes action against Controller regarding any claims under Art. 82 GDPR, Processor agrees to assist Controller in defending against the claim to the best of its ability.
(7) If any individual part of this Agreement is invalid, this shall not affect the validity of the remainder of the Agreement.
(8) This Agreement shall be governed and interpreted in accordance with the laws of Germany.
(9) Controller may terminate the Main Agreement / the contract at any time without notice if Processor commits a serious infringement of data protection regulations or the provisions of this Agreement, Processor is unwilling or unable to carry out an instruction issued by Controller, or Processor rejects control rights of Controller in a manner that violates the Agreement. In particular, any non-compliance with the duties agreed upon in this Agreement and/or derived from Art. 28 GDPR constitutes a serious infringement.
(10) In the event of any conflict between the provisions of this Agreement and any other agreement entered into between the Parties, the provisions of this Agreement have priority.
Signatures
Controller's signature
1:
(Place, date) (Controller's signature)
2:
(Place, date) (Controller's signature)
Processor's signature
(Place, date) (Processor's signature)
Annex 1
Section 1 – Processing descriptions
| Processing descriptions | Categories of data subjects | Types of data |
|---|---|---|
| Casebase is a Software as a Service solution for data & AI use case management that supports documenting, managing and controlling along the entire lifecycle of AI use cases. Customers create a profile in Casebase with name, email address and password. There is active user management and admin rights for software settings. | Users: employees of the Controller | User accounts (e.g. name, email, password, settings) Organisational data (e.g. company, department, team, role) Profile information (e.g. job title) |
The processing of personal data takes place
☐ not ☒ partly ☐ completely
in premises not exclusively used by the Processor (e.g. co-working space, private apartment).
Section 2 – Duration of contract
The duration of the order is determined by the provisions of the Main Agreement.
Section 3 – Processor's Data Protection Officer
Name: Thomas Regier │ DataCo GmbH
Contact: 089740045840 / datenschutz@dataguard.de
Section 4 – Persons of Controller authorized to issue instructions to the Processor
| Name | Organizational unit and position | Contact |
|---|---|---|
| (to be completed by Controller) | ||
Instruction recipient at the Processor:
| Name | Organizational unit and position | Contact |
|---|---|---|
| Marc Böggemann | Head of Business Operations | marc.boeggemann@alexanderthamm.com |
Section 5 – Processor's Sub-processors
| Full company name, address, country | Processings | Contractual relation |
|---|---|---|
| Amazon Web Services (AWS) Frankfurt, Germany |
Cloud Hosting | AWS_GDPR_DPA.pdf |
| Functional Software, Inc. d/b/a Sentry 45 Fremont Street, San Francisco, CA 94105, USA (Data processing on EU servers) |
Error monitoring and application stability | https://sentry.io/legal/dpa/ No third-country transfer (data processing on EU servers) |
| Pendo.io, Inc. 150 Fayetteville St, Raleigh, NC 27601, USA |
Product analytics and usage statistics | https://www.pendo.io/legal/privacy-policy/ Third-country transfer to USA — basis: EU-US Data Privacy Framework and Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR |
Annex 2: Technical and Organizational Measures (TOMs) pursuant to Art. 32 GDPR
General
| Measure | Implementation |
|---|---|
| Procedures for regular review, assessment and evaluation of the effectiveness of technical and organizational measures | Annual internal audits of the entire management system, annual external surveillance audits within the ISO 27001 certification framework, triennial recertification to ISO 27001 and TISAX, annual penetration testing, continuous monitoring. |
| Measures to ensure system configuration, including standard configuration | Policies for standard configurations of IT systems and applications; use of images and templates; automated system provisioning; implementation of hardening measures. |
| Measures for internal IT governance and IT security management | Development, implementation and at least annual review of policies and processes; risk management; disciplinary separation between operational IT and the supervisory function of the information security officer. |
| Measures for certification/quality assurance of processes and products | Certification to international standards (ISO 27001, ISO 9001, TISAX); regular internal audits; continuous improvement process; feedback and complaint management. |
| Measures to ensure data minimisation | Collection of required, purpose-bound data; restriction of access; encryption; employee training; regular automated data cleansing per deletion concept. |
| Measures to prevent storage limitation violations | Data minimisation; regular and automated deletion processes; encryption; annual mandatory employee training. |
| Measures to ensure accountability | Annual review of data protection and information security policies; documentation of data protection measures (DPA, risk management, DPIA); records of processing activities. |
| Measures to enable data portability and ensure erasure | Export functions; standardised data formats (JSON, XML, CSV); API access; common transfer protocols (FTP, SFTP); certified and logged data deletion (e.g. Certus). |
Confidentiality
| Measure | Implementation |
|---|---|
| Measures for pseudonymisation and encryption of personal data | Replacement of direct identifiers with pseudonymous codes; rotation of pseudonymisation keys; separate key storage; AES-256 encryption for stored data. |
| Measures for user identification and authorisation | Unique user identification; MFA; Single Sign-On (SSO); centralised Identity and Access Management (IAM); role-based access control (RBAC). |
| Measures to protect data during transmission | Encrypted communication via HTTPS, SSL/TLS; VPN; secure email; end-to-end encryption for sensitive transmissions. |
| Measures to protect data during storage | Encryption at rest (AES-256); data segmentation and isolation; employee training; multiple daily backups; secure configuration and regular updates. |
| Measures to ensure physical security | Multi-level zone concept; escorting of visitors; lockable doors; privacy screens; chip card/key access control; video surveillance in security areas. |
Integrity
| Measure | Implementation |
|---|---|
| Measures to ensure logging of events | Logging policies; automated and secured logging; long-term log storage; timestamps; log encryption; regular anomaly analysis. |
| Measures to ensure data quality | Data validation via scripts, database constraints or regex; standardised quality metrics; automated cleansing; deduplication. |
| Measures to ensure data separation | Network separation; physical server separation; multi-tenancy with strict data isolation; RBAC; database partitioning; encryption. |
Availability
| Measure | Implementation |
|---|---|
| Measures to ensure continuous availability | Multiple daily backups (3-2-1 and multi-generation principle); annual DR/BCP review and testing; redundant infrastructure; automatic failover. |
| Measures to ensure rapid restoration of availability after incidents | Disaster Recovery and Business Continuity Plans including regular restoration exercises; emergency team; fail-over mechanisms; regular backup testing; automated multiple daily backups. |
