Data Processing Agreement pursuant to Art. 28 GDPR
Non-binding English translation. This is a convenience translation of the German original „Auftragsverarbeitungsvertrag gemäß Art. 28 DSGVO“. The legally binding version is the German original; in the event of any discrepancy, the German version shall prevail.
Joshua Maurer
c/o CS Business Center GmbH
Mittelweg 144
20148 Hamburg
(hereinafter also the “Processor”)
for
„LaizyNote“
This Data Processing Agreement applies to the processing of personal data carried out by the Processor for customers (hereinafter the “Controller”) in performance of the Main Agreement.
Preamble
The Processor provides services to the Controller under the SaaS agreement concluded between them (hereinafter the “Main Agreement”). Part of performing the Main Agreement is the processing of personal data within the meaning of the General Data Protection Regulation (“GDPR”). To meet the GDPR requirements applicable to such arrangements, the parties enter into the following Data Processing Agreement (also the “Agreement”), which comes into effect upon signature or upon the Main Agreement becoming effective.
1. Subject matter / scope of the engagement
(1) Within the scope of the parties’ cooperation under the Main Agreement, the Processor has access to personal data of the Controller (hereinafter “Controller Data”). The Processor processes such Controller Data on behalf of and under the instructions of the Controller within the meaning of Art. 4 No. 8 and Art. 28 GDPR.
(2) Clarification: “Controller Data” within the meaning of this Agreement means all personal data that the Processor processes in the course of providing services to the Controller (including the content that the Controller or its end users enter into the Processor’s systems, as well as personal outputs/reports generated therefrom). The following do not constitute “Controller Data”: (i) purely technical operating and security logs (e.g. system and access data) that the Processor processes to ensure information security, for error analysis and for the stability of the service, insofar as such processing is necessary for the secure provision of the service, and (ii) aggregated, anonymised statistics without any personal reference. Where operating/security logs exceptionally contain personal data, the Processor processes them solely for the aforementioned purposes and applying appropriate safeguards.
(3) The processing of Controller Data by the Processor takes place in the manner described in the Annexes and to the extent and for the purposes specified therein. The categories of data subjects affected by the processing are set out therein. The duration of the processing corresponds to the term of the Main Agreement.
(4) Whether the Processor’s services are suitable for processing special categories of personal data pursuant to Art. 9(1) GDPR requires a risk assessment by the Controller. Insofar as the Controller provides the Processor with special categories of personal data pursuant to Art. 9(1) GDPR for processing, or such data are processed within the scope of the engaged services, the following applies: processing is carried out solely on documented instructions of the Controller and only to the extent described in this Agreement and its Annexes. The Processor applies an enhanced level of protection appropriate to the risk (in particular restrictive authorisation concepts / need-to-know, encryption in transit, tenant separation, logging of privileged access and measures to ensure confidentiality). The Processor supports the Controller in accordance with this Agreement in carrying out any required data protection impact assessment (Art. 35 GDPR) and in documenting the information required for this purpose.
(5) The Processor is prohibited from processing Controller Data in any manner that deviates from the processing operations specified in the Annexes.
(6) The processing of Controller Data shall, in principle, take place within the territory of the Federal Republic of Germany, in a member state of the European Union or in another contracting state of the Agreement on the European Economic Area.
(7) Any processing or other transfer of Controller Data to a third country (outside the EU/EEA), or any possibility of access from a third country (e.g. support/administration), shall take place only with the prior consent of the Controller and only in compliance with the requirements of Art. 44 to 49 GDPR.
(8) Where no adequacy decision applies, the parties agree on appropriate safeguards, in particular the Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914. Where an adequacy decision is relied upon (e.g. the EU–US Data Privacy Framework), the Processor may rely on it only if the relevant data importer is validly certified/listed for the applicable mechanism.
(9) The Processor supports the Controller in carrying out and documenting the assessment required for third-country transfers (transfer assessment) by providing the necessary information (in particular regarding data categories, recipients, the sub-processor chain, storage/access locations, and technical and organisational measures). Any required supplementary measures to safeguard the transfer shall be implemented in accordance with the EDPB recommendations on supplementary measures.
(10) Onward transfers to further third countries are permitted only where the requirements of Art. 44 to 49 GDPR are also met and the respective recipient assumes at least equivalent obligations (in particular under SCCs or an adequacy decision). The Processor documents onward transfers in an appropriate manner.
(11) The provisions of this Agreement apply to all activities connected with the Main Agreement. The same applies to all activities in which the Processor and its staff, or persons engaged by the Processor, come into contact with Controller Data.
2. Controller’s right to issue instructions
(1) The Processor processes the Controller Data within the scope of the engagement and on behalf of and under the instructions of the Controller within the meaning of Art. 28 GDPR (processing on behalf of a controller). The Controller has the sole right to issue instructions regarding the nature, scope and method of the processing activities (hereinafter also the “right to issue instructions”). If the Processor is required to carry out further processing under EU or member-state law to which it is subject, it shall notify the Controller of these legal requirements prior to processing.
(2) Instructions are, as a rule, issued by the Controller in writing or in electronic form (e-mail being sufficient); instructions issued orally must be confirmed by the Processor in electronic form.
(3) If the Processor is of the opinion that an instruction of the Controller infringes data protection provisions, it shall notify the Controller accordingly. The Processor is entitled to suspend the execution of the instruction concerned until it is confirmed or amended by the Controller.
3. Protective measures of the Processor
(1) The Processor is obliged to comply with the statutory provisions on data protection and not to disclose information obtained from the Controller’s sphere to third parties or to expose it to their access. Documents and data must be secured against access by unauthorised persons taking into account the state of the art.
(2) Furthermore, the Processor shall oblige all persons entrusted by it with the handling and performance of this Agreement (hereinafter “staff”) to maintain confidentiality (confidentiality obligation, Art. 28(3)(b) GDPR). At the Controller’s request, the Processor shall provide written or electronic evidence of the staff’s obligation.
(3) The Processor shall organise its internal organisation in such a way that it meets the particular requirements of data protection. It undertakes to take all appropriate technical and organisational measures for the adequate protection of the Controller Data pursuant to Art. 32 GDPR, in particular the measures listed in Annex 2 to this Agreement, and to maintain them for the duration of the processing of the Controller Data.
(4) The Processor reserves the right to amend the technical and organisational measures taken, provided that it ensures that the contractually agreed level of protection is not undercut.
(5) At the Controller’s request, the Processor shall demonstrate to the Controller its compliance with the technical and organisational measures.
(6) The Processor and the persons employed by or for it are entitled to provide the services to be rendered under the Main Agreement, and thus also the processing of personal data, from its head office, its business premises, branches or from home and mobile offices, provided that it is ensured that the protective measures defined in this Agreement are observed.
4. Information and support obligations of the Processor
(1) In the event of disruptions, suspected data protection breaches or breaches of the Processor’s contractual obligations, suspected security-relevant incidents or other irregularities in the processing of Controller Data, the Processor shall inform the Controller without undue delay after becoming aware.
(2) The notification shall be given as an initial report without undue delay, as a rule within 24 hours, at least with the core information available at that time (type of incident, affected systems/data categories, initial assessment of possible impact, immediate measures taken, point of contact). Insofar as not all information is fully available, the Processor shall supplement the information without culpable delay at appropriate intervals (updates) until the report is complete.
(3) The same applies to audits of the Processor by data protection supervisory authorities, insofar as legally permissible.
5. Other obligations of the Processor
(1) Insofar as the conditions of Art. 30 GDPR apply to it, the Processor is obliged to maintain a record of all categories of processing activities carried out on behalf of the Controller pursuant to Art. 30(2) GDPR. The record shall be made available to the Controller on request.
(2) The Processor is obliged to support the Controller in preparing a data protection impact assessment pursuant to Art. 35 GDPR and any prior consultation of the supervisory authority pursuant to Art. 36 GDPR.
(3) The Processor confirms that – insofar as there is a statutory obligation to do so – it has appointed a data protection officer.
(4) Should the Controller Data held by the Processor be endangered by seizure or attachment, by insolvency or composition proceedings, or by other events or measures of third parties, the Processor shall inform the Controller thereof without undue delay, unless prohibited from doing so by a court or official order. In this context, the Processor shall inform all competent bodies without undue delay that the sole authority to decide on the data lies with the Controller as the “controller” within the meaning of the GDPR.
6. Sub-processing relationships
(1) The Processor may have the processing of personal data carried out in whole or in part by further processors (hereinafter also “sub-processors”).
(2) A sub-processing relationship within the meaning of these provisions does not exist where the Processor engages third parties with services that are to be regarded as mere ancillary services. These include, for example, postal, transport and shipping services, cleaning services, security services, telecommunications services without a specific
connection to the services that the Processor provides to the Controller, and other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing systems. The Processor’s obligation to ensure compliance with data protection and data security in these cases as well remains unaffected.
(3) The Processor shall agree with the sub-processor the same provisions as set out in this Agreement. In particular, the technical and organisational measures to be agreed with the sub-processor must provide an equivalent level of protection.
(4) The Processor has established sub-processing relationships with the companies listed in Annex 1, to which the Controller consents upon conclusion of this Data Processing Agreement. The companies listed in Annex 1 may be added to or reduced by the Processor. Should the Processor add a further sub-processor, it shall add them to Annex 1 and inform the Controller thereof at least 4 weeks before the intended use of the sub-processor. Should the Controller not agree with the addition of the further sub-processor, it has the option to object to the Processor within 4 weeks of the addition. If the Controller objects to the addition of the further sub-processor, the Processor has the right to terminate the Main Agreement including all annexes within 2 weeks, should no alternative solution for continued cooperation be found and should the addition of the further sub-processor be of particular importance to the Processor’s business.
(5) Before engaging any sub-processor, the Processor concludes a contract with it that reflects the requirements of Art. 28(3) and (4) GDPR in substance and ensures an equivalent level of protection (in particular with regard to technical and organisational measures). Upon this Agreement becoming effective, the Controller approves the sub-processors named in this Agreement and its Annexes. The Processor remains fully responsible to the Controller for the performance of all obligations under this DPA, including where sub-processors are used.
(6) An integral part of the data processing agreements with the sub-processors is, in particular, that the sub-processors ensure that they have, for their part, taken adequate and appropriate technical and organisational measures pursuant to Art. 32 GDPR in respect of the processing of personal data carried out by them on behalf of the Controller.
7. Audit rights
(1) The Controller is entitled to verify compliance with the provisions of this Agreement to a reasonable extent. The Processor supports such verifications by providing the Controller, on request, with appropriate evidence (e.g. current documentation of technical and organisational measures, summaries of audit reports, certifications/attestations, where available) and by providing reasonable information.
(2) Verifications shall primarily take place as remote audits (document review, questionnaire, video meeting). On-site inspections shall be considered only where (i) a remote audit is not sufficient, (ii) there is a specific cause (e.g. a serious security incident) or (iii) a supervisory authority so requires, and provided that no overriding confidentiality or security interests conflict.
(3) The Controller shall announce on-site inspections with reasonable notice (as a rule at least 30 calendar days) and shall take into account the Processor’s business operations. Inspections shall be carried out during normal business hours. The auditor engaged by the Controller must not be in a competitive relationship with the Processor and must be bound in writing to confidentiality in advance.
(4) Insofar as the Controller carries out recurring routine audits without specific cause, these shall be limited to no more than one audit per calendar year. Further audits remain permissible where there is cause or upon request by an authority.
(5) Any cost arrangements for audits (in particular on-site inspections) shall be agreed transparently; the parties take into account that audit and evidence obligations are part of the statutorily provided cooperation under Art. 28(3)(h) GDPR.
8. Rights of data subjects
(1) The Processor supports the Controller as far as possible with appropriate technical and organisational measures in fulfilling its obligations under Art. 12 to 22 and Art. 32 to 36 GDPR. The Processor makes the information required for this purpose available to the Controller without undue delay, at the latest within 5 working days, insofar as the Controller does not itself have the relevant information. In urgent cases (in particular where a deadline is imminent or in the case of requests from authorities), the Processor handles the request as a priority and provides the available information as quickly as possible.
(2) Insofar as the Controller instructs the Processor to rectify, erase or restrict the processing of Controller Data, the Processor implements the instruction without undue delay; implementation takes place at the latest within 5 working days, unless a longer, objectively necessary period is required due to the technical setup (e.g. backup/restore processes). In that case, the Processor informs the Controller of the reasons and the expected implementation period without undue delay.
(3) If a data subject asserts rights – such as to information, rectification or erasure of their data – directly against the Processor, the Processor will forward this request to the Controller and await its instructions. Without a corresponding individual instruction, the Processor will not contact the data subject.
9. Term and termination
The term of this Agreement corresponds to the term of the Main Agreement. It therefore ends automatically upon termination of the Main Agreement. If the Main Agreement may be terminated by ordinary notice, the provisions on ordinary termination apply accordingly to this Agreement. Should the Processor no longer process any Controller Data before the expiry of the Main Agreement, this Agreement likewise ends automatically.
10. Erasure and return after the end of the Agreement
(1) After termination of the Main Agreement, or at any time at the Controller’s request, the Processor will return to the Controller all documents, data and data carriers provided to it or, at the Controller’s wish and unless a statutory retention period exists, erase them completely and irrevocably. This also applies to copies of the Controller Data held by the Processor, such as data backups, but not to documentation that serves as evidence of the orderly and contractual processing of the Controller Data. Such documentation must be retained by the Processor for a period of 6 months and surrendered to the Controller on request.
(2) The Processor confirms the erasure/return to the Controller in text form (“erasure confirmation”). The erasure confirmation contains at least: (i) the date of erasure/return, (ii) a description of the affected data categories and systems/storage locations, (iii) a statement of whether and to what extent data are contained in backups/archives, and (iv) the period and procedure according to which backups/archives are routinely overwritten or erased.
(3) Insofar as immediate erasure in backups/archives is not possible for technical reasons, the Processor ensures that the data are not restored to production or otherwise used until final erasure, unless this is strictly necessary to remedy a disruption; in that case, restoration takes place only under controlled and documented conditions.
(4) The Processor is obliged to treat the data that became known to it in connection with the Main Agreement confidentially even beyond the end of the Main Agreement.
11. Liability
(1) The liability of the parties is governed by Art. 82 GDPR. Any liability of the Processor towards the Controller for breach of obligations under this Agreement or the Main Agreement remains unaffected thereby.
(2) Each party shall be released from liability if it proves that it is in no way responsible for the circumstance giving rise to the damage suffered by a data subject. This applies accordingly in the case of an administrative fine imposed on
a party, whereby the release takes place to the extent that the respective other party bears a share of the responsibility for the infringement sanctioned by the fine.
12. Confidentiality & data secrecy
(1) The Processor undertakes to observe the same rules on the protection of secrets as apply to the Controller.
(2) A duty of confidentiality applies to the Processor’s staff and to third parties engaged by it. The Processor must bind the persons employed in the processing of Controller Data in writing to confidentiality pursuant to Art. 28(3)(b) GDPR. This is not required where the persons employed are already subject to an appropriate statutory duty of confidentiality. The Processor will document the obligation set out in this section in writing and present it to the Controller on request.
(3) The Processor confirms that it is familiar with the relevant data protection provisions. The Processor warrants that it familiarises the staff employed in carrying out the work with the data protection provisions relevant to them and obliges them to comply with the applicable data protection provisions. It monitors compliance with the data protection provisions.
(4) The confidentiality obligations set out in this section continue to apply even after the end of the contractual relationship.
(5) In addition, the Processor is obliged – alongside the applicable statutory provisions (in particular § 3 TDDDG, § 203 StGB, §§ 4, 23 GeschGehG, and where applicable special professional confidentiality obligations) – to keep confidential all information and data that come to its knowledge within the scope of the contractually agreed services and not to pass them on to third parties (confidential information). Confidential information includes, in particular, trade and business secrets, conclusions of contracts, technical or commercial information of any kind, and other details that are designated as confidential or are by their nature to be regarded as confidential. This applies in particular also to:
names, addresses and the personal, legal and economic circumstances of all customers of the Controller, and the personal, legal and economic circumstances of the Controller and of all other persons acting for the Controller.
Information is not to be regarded as confidential if, at the time the Processor became aware of it, it was already publicly known. Likewise, information that subsequently became publicly known or was made public with the Controller’s consent is to be regarded as not confidential.
(6) The Processor undertakes to oblige all staff who gain knowledge of the aforementioned confidential information of the Controller in the course of their work for the Controller, as well as itself.
(7) If the Processor engages third parties, it must ensure that the requirements of paragraphs 1 to 6 are implemented accordingly.
13. Final provisions
(1) The parties agree that the defence of a right of retention by the Processor within the meaning of § 273 BGB with regard to the data to be processed and the associated data carriers is excluded.
(2) Amendments and supplements to this Agreement must be made in electronic form.
(3) In case of doubt, the provisions of this Agreement take precedence over the provisions of the Main Agreement. Should individual provisions of this Agreement prove to be wholly or partly invalid or unenforceable, or become invalid or unenforceable as a result of changes in legislation after the conclusion of the Agreement, the validity of the remaining provisions shall not be affected. The invalid or unenforceable provision shall be replaced by the valid and enforceable provision that comes as close as possible to the meaning and purpose of the void provision.
(4) This Agreement is governed by German law. The exclusive place of jurisdiction is the Processor’s registered seat.
Annexes
Annex 1 – Specifications for the Agreement
Annex 2 – Technical and organisational measures of the Processor (Art. 32 GDPR)
Annex 1 – Specifications for the Agreement
| Subject matter and duration of the engagement – Overview of requirements and specifications | |
|---|---|
| • Main Agreement | SaaS agreement on the SaaS software „LaizyNote“ |
| • Subject matter of the engagement | „LaizyNote“ is a web-based productivity and collaboration software for individual users, self-employed persons and small and medium-sized teams |
| • Purpose of data collection, data processing or data use | In order to fulfil the Processor’s obligations under the Main Agreement, personal data from the Controller’s sphere of control are processed by the Processor in full within the meaning of Art. 4 No. 2 GDPR, in particular – to the extent required in each case – collected, stored, altered, read out, queried, used, disclosed, compared, linked and erased. The purpose of the processing therefore depends on the engagement described in the Main Agreement. |
| • Type of data | The categories of personal data affected by the processing depend on the Controller’s use of the Processor’s services. Categories of data that may be the subject of processing are: • master data (e.g. names, addresses, dates of birth), • contact data (e.g. e-mail addresses, telephone numbers), • content data (e.g. photographs, videos, contents of documents), • contract data (e.g. subject matter of contract, terms, customers), • payment data (e.g. bank details, payment service providers), • usage data (e.g. history of web services, access times), • connection data (e.g. device ID, IP addresses, URL referrer), • location data (e.g. GPS data, IP geolocation), • Art. 9 GDPR data (e.g. health data, biometric data). |
| • Categories of data subjects | The categories of data subjects affected by the processing depend on the Controller’s use of the Processor’s services. The following categories of data subjects may be considered: • employees • trainees and interns • applicants • former employees • freelancers • shareholders, corporate bodies of the company • relatives of employees • customers / prospective customers • suppliers and service providers • tenants • business partners • external advisers • visitors |
Sub-processors
| No. | Sub-processor address / country | Subject matter of the service | Storage/processing location (EU/EEA/third country) | Transfer mechanism (adequacy decision / DPF or SCC 2021/914) | Personal data processed |
|---|---|---|---|---|---|
| 1 | Google Ireland Ltd. (Firebase), Gordon House, Barrow Street, Dublin 4, D04 V4X7, Ireland | Backend infrastructure (database, authentication, storage, cloud functions, App Check). | EU | DPF | See “Type of data” above |
| 2 | Mistral AI SAS, Paris, 15 Rue des Halles, 75001 Paris, France | AI language model for the assistant Daisy | EU | DPA / EU | See “Type of data” above |
| 3 | Cloudflare Germany GmbH, c/o Design Offices München Atlas, Rosenheimer Straße 143C (8th floor), 81671 Munich | Bot protection at login (Turnstile) | EU | DPF | See “Type of data” above |
| 4 | Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland | Payment processing and Stripe Tax | EU | DPF | See “Type of data” above |
| 5 | webgo GmbH Wendenstraße 8–12, 20097 Hamburg |
Web hosting of laizy.eu and business e-mail mailboxes | Germany | DPA / Germany | See “Type of data” above |
| 6 | UAB “MailerLite”, J. Basanavičiaus 15, LT-03108 Vilnius, Lithuania | Newsletter dispatch (MailerLite) and dispatch of transactional e-mails (MailerSend) | EU | DPA / EU | See “Type of data” above |
Annex 2 – Technical and organisational measures
Controllers are obliged under Art. 32 GDPR to take technical and organisational measures ensuring the security of the processing of personal data. The measures must be chosen such that, taken together, they ensure an appropriate level of protection. Against this background, this overview explains which specific measures have been taken by the Processor with regard to the processing of personal data in the specific case.
| Instructions on technical and organisational measures |
|---|
| 1. Organisation of information security Policies, processes and responsibilities must be established by which information security can be implemented and controlled. |
| Measures: ☒ Definition of roles and responsibilities for the operation of applications and systems, data protection and information security. ☒ Obligation of staff to maintain secrecy and to safeguard data secrecy. ☒ Regular conduct of training and awareness measures. |
| 2. Privacy by Design Privacy by Design embodies the idea that systems should be designed and built so that the volume of personal data processed is minimised. Key elements of data minimisation are the separation of personal identifying characteristics from content data, the use of pseudonyms and anonymisation. In addition, the erasure of personal data must be implemented in accordance with a configurable retention period. |
|---|
| Measures: ☒ No more personal data are collected than are necessary for the respective purpose. ☒ Process to ensure Privacy by Design when introducing or modifying systems and applications. ☒ The processing operations and systems are designed to enable and ensure GDPR-compliant erasure of the processed personal data. |
| 3. Privacy by Default Privacy by Default refers to privacy-friendly default settings. To what extent have these been implemented by you? Example: when visiting a website, the visitor can expect that all programs which collect personal data are initially deactivated. |
|---|
| Measures: ☒ Simple exercise of the data subject’s right of withdrawal through technical measures. ☒ Tracking functions that monitor the data subject are deactivated by default. ☒ All pre-selections of options meet the GDPR requirements regarding privacy-friendly default settings (e.g. no pre-selected opt-ins). |
| 4. Access control and entry control Measures ensuring that persons authorised to use the data processing procedures can access only the personal data, or sensitive information and data, covered by their access authorisation (description of system-inherent security mechanisms and encryption methods in line with the state of the art; for online access, it must be clarified which party is responsible for issuing and managing access security codes). The Processor ensures that users authorised to use IT infrastructure can access only content for which they are authorised, and that personal data cannot be copied, altered or erased without authorisation during processing and after storage. |
| Measures: ☒ Avoidance of group users. ☒ Access to data is restricted and only possible for authorised persons. ☒ Locking of the user account upon failed attempts / inactivity. ☒ Locking of the end device upon leaving the workstation or upon inactivity. ☒ Number of administrators reduced to the “absolute minimum”. ☒ Regular review of authorisations. ☒ Password policy, implementation of complex passwords. |
| 5. Cryptography and/or pseudonymisation Use of encryption methods to ensure the proper and effective protection of the confidentiality, authenticity or integrity of personal data or sensitive information. Measures suitable for making identification of the data subject more difficult. |
|---|
| Measures: ☒ Encryption of end devices (PC, laptop, smartphones). ☒ Encrypted storage of personal data. ☒ Encryption of backup media (e.g. tapes, hard drives, etc.). ☒ Use of methods for anonymising data. |
| 6. Protection of buildings Prevention of unauthorised physical access to the organisation’s information and information-processing facilities, as well as their damage and impairment. The Processor takes measures to prevent unauthorised persons from gaining (physical) entry to data processing systems with which personal data are processed. |
|---|
| Measures such as building security and employee ID cards are implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please contact us. |
| 7. Protection of operating resources / information assets Prevention of loss, damage, theft or impairment of assets and interruptions to the organisation’s business operations. |
|---|
| Measures such as protection of operating resources or secure storage of files are implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please contact us. |
| 8. Operating procedures and responsibilities Ensuring the proper and secure operation of systems and procedures for processing information. |
|---|
| Measures: ☒ Clear allocation of responsibilities for system and application support. ☒ Separation of the processing of data of the individual tenants. ☒ Separation of development, test and production systems. ☒ Monitoring of system operation and facilities. |
| 9. Data backups Measures ensuring that personal data or sensitive information and data are protected against accidental destruction or loss. |
|---|
| Measures such as relocating backups to other fire zones and buildings are implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please contact us. |
| 10. Protection against malware and patch management Prevention of the exploitation of technical vulnerabilities through the use of up-to-date antivirus software and the implementation of patch management. |
|---|
| Measures: ☒ Regular monitoring of the status of security updates and system vulnerabilities. ☒ Use of anti-malware software. ☒ Regular installation of security patches and updates. |
| 11. Network security management An appropriate level of protection must be implemented for the network so that the information and the infrastructure components are protected. |
|---|
| Measures: ☒ Use of firewall systems. ☒ User authentication and encryption of external access. |
| Further implemented measures / explanations: Intrusion detection/prevention takes place at the platform/edge level through Firebase App Check, Google Cloud protection mechanisms and Cloudflare. |
| 12. Information transfer Measures ensuring that personal data or sensitive information and data cannot be read, copied, altered or removed without authorisation during electronic transmission or during their transport or storage on data carriers, and that it can be checked and established to which bodies a transmission of personal data or sensitive information and data is provided for by means of data transmission facilities. (Description of the facilities and transmission protocols used, e.g. identification and authentication, encryption in line with the state of the art, automatic callback, etc.) |
|---|
| Measures: ☒ Rules for the exchange of sensitive information and restriction of the group of persons authorised to transmit it. ☒ Disclosure of data to third parties only after review of the legal basis. ☒ Lawfulness and written specification of the disclosure of data to third countries. ☒ Secure data transmission between client and server. ☒ Appropriate protection of e-mails containing sensitive information / data. ☒ Use of encrypted external access. |
| 13. Network segregation Groups of information services, tenants, users and information systems should be kept separate from one another in networks. |
|---|
| Measures: ☒ Logical tenant separation. |
| 14. Acquisition, development and maintenance of systems Measures ensuring that information security is an integral part of the entire lifecycle of information systems. |
|---|
| Measures: ☒ Establishment of security-specific rules and requirements for the use of new information systems and for the extension of existing information systems. ☒ Establishment of rules for the development and adaptation of software and systems. ☒ Monitoring of outsourced system development activities. ☒ Protection of test data. |
| Further implemented measures / explanations: External development/system components (Firebase, Mistral, etc.) are governed through data processing agreements and service-provider selection. |
| 15. Supplier relationships Measures concerning information security to reduce risks associated with suppliers’ access to the company’s assets should be agreed and documented with sub-suppliers / sub-contractors. |
|---|
| Measures: ☒ Selection of the processor on the basis of due diligence (in particular with regard to data security). ☒ Written instructions to the processor (e.g. by data processing agreement) within the meaning of the GDPR. ☒ The processor has appointed a data protection officer. ☒ Effective audit rights agreed vis-à-vis the processor. ☒ Prior review and documentation of the security measures taken at the processor. ☒ Obligation of the processor’s staff to data secrecy. ☒ Ongoing review of the processor and its activities. ☒ Ensuring the destruction of data after the end of the engagement. |
| 16. Management of information security incidents Consistent and effective measures for the management of information security incidents (theft, system failure, etc.) must be implemented. |
|---|
| Measures: ☒ Documented procedure for handling security incidents. ☒ Immediate information of the Controller in the event of data protection incidents. ☒ Formal process and responsibilities for the follow-up of security incidents and data breaches. |
| 17. Information security aspects of business continuity management / emergency management Maintaining system availability in difficult situations, such as crises or damage events. Emergency management must ensure this. The information security requirements should be defined in the planning for business continuity and disaster recovery. |
|---|
| Measures such as redundancy of systems or documented emergency plans are implemented by our service providers. If you are interested in the specific technical and organisational measures of the service providers, please contact us. |
| 18. Compliance with legal and contractual requirements Implementation of measures to avoid breaches of legal, official or contractual obligations and of any security requirements. |
|---|
| Measures: ☒ Ensuring compliance with statutory obligations within the scope of the cooperation. ☒ Return of all data, operating resources and information assets to the Controller at the end of the Agreement. ☒ Establishment of licence management. ☒ Confidentiality obligations with staff as well as sub-suppliers and service providers. |
| 19. Data protection requirements and data protection management Privacy and the protection of personal data should be ensured in accordance with the requirements of the relevant statutory provisions, other regulations and contractual terms. |
|---|
| Measures: ☒ Establishment of a data protection organisation. ☒ Record of processing activities. ☒ Conduct of data protection training. |
As of: May 2026
With the kind support of
