Data Processing Agreement

Understand, how we process your data.

THIS DATA PROCESSING AGREEMENT (“DPA”) (in the version dated July, 2026) GOVERNS THE DATA PROCESSING OPERATIONS BETWEEN THE CUSTOMER (“DATA CONTROLLER”) AND Helu.io GMBH (“DATA PROCESSOR”)

 

       

1. BACKGROUND

       

1. The Data Controller and the Data Processor have entered into a Commercial Agreement (“Agreement”) under which the Data Processor shall provide certain services (application services) to the Data Controller. Within the scope and for the purpose of the performance of the services defined in the Agreement, the Data Processor will process beside other data potentially Personal Data on behalf of the Data Controller. In no event will the Data Controller use sensitive Personal Data, such as information on health, sexual orientation, political orientation, race etc. Data Controller has sole responsibility for the adequacy, accuracy, quality and legality of the data processed.

‍

       

2. The Data Controller and the Data Processor have entered into this DPA in order to fulfill the requirement of a written agreement between a data controller and a data processor of Personal Data as set out in Applicable Data Protection Legislation. In addition to what may be set out in the Agreement, the following shall apply in relation to the Data Processor’s processing of Personal Data on behalf of the Data Controller. Data Subjects, data categories as well as the extent, nature and purpose of data processing are determined by the Agreement, Appendix 1 to this DPA and the Data Controller’s instructions.

‍

       

2. DEFINITIONS

       

All terms used in this DPA are to be understood in accordance with the EU General Data Protection Regulation ((EU) 2016/679 “GDPR”), unless otherwise expressly agreed. The following terms and expressions in this DPA shall have the meaning set out below:

‍

“Applicable Data Protection Legislation” means any national or internationally binding data protection laws or regulations (including but not limited to the GDPR and the Austrian Data Protection Act (“DSG”)) including any requirements, guidelines and recommendations of the competent data protection authorities applicable at any time during the term of this DPA on, as the case may be, the Data Controller or the Data Processor;

‍

“Data Controller” means the legal person which, alone or jointly with others, determines the purposes and means of the processing of Personal Data under this DPA;

‍

“Data Processor” means a Helu.io GmbH;

‍

“Sub-processor” means any legal or natural person, including any agents and intermediaries, processing Personal Data on behalf of the Data Processor as set forth in Art 28 (2) and (4) GDPR and section 4.1 below;

‍

“Personal Data” means any information relating to an identified or identifiable living, natural person (“data subject”) as set forth in Art 4 (1) GDPR;

‍

“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means as set forth in Art 4 (2) GDPR.

‍

“Text Form” means a legible declaration in which the person making the declaration is identified and which is made on a durable medium. Text Form shall include, in particular, communication by email, notification through the customer portal, electronically transmitted documents or electronic signature. A handwritten signature or qualified electronic signature shall not be required.

‍

       

3. PROCESSING OF PERSONAL DATA

       

1. The Data Processor and any person acting under its authority (e.g. personnel, Sub-processors and persons acting under the Sub-processor’s authority) undertake to only process Personal Data in accordance with documented instructions communicated by the Data Controller (Appendix 1). The Data Processor shall only process Personal Data to the extent necessary to fulfil its obligations under this DPA or Applicable Data Protection Legislation.

‍

2. The Data Processor assures that all processing of Personal Data is exclusively executed and hosted within the EU or the EEA

‍

3. If the services are altered during the term of the Agreement and such altered services involve new or amended processing of Personal Data, or if the Data Controller’s instructions are otherwise changed or updated, the parties shall ensure that Appendix 1 is updated as appropriate before or at the latest in connection with the commencement of such processing or change.

‍

4. When processing Personal Data under this DPA, the Data Processor shall comply with any and all Applicable Data Protection Legislation and applicable recommendations by competent Data Protection Authorities or other competent authorities and shall keep itself updated on and comply with any changes in such legislation and/or recommendations. The Data Processor shall accept to make any changes and amendments to this DPA that are required under Applicable Data Protection Legislation.

‍

5. The Data Processor shall assist the Data Controller in fulfilling its legal obligations under Applicable Data Protection Legislation, including but not limited to the Data Controller’s obligation to comply with the rights of data subjects and in ensuring compliance with the Data Controller’s obligations relating to the security of processing (Art. 32 GDPR), the notification of a Personal Data Breach (Art 33, 34 GDPR) and the Data Protection Impact Assessment and the prior consultation (Art 35, 36 GDPR), obligation to respond to requests for exercising the data subject’s rights to information regarding the processing of its Personal Data. The Data Processor shall not carry out any act, or omit any act, that would cause the Data Controller to be in breach of Applicable Data Protection Legislation.

‍

6. The Data Processor shall immediately inform the Data Controller of a request, complaint, message, or any other communication received from a competent authority or any other third party regarding the processing of Personal Data covered by this DPA. The Data Processor may not in any way act on behalf of or as a representative of the Data Controller and may not, without prior instructions from the Data Controller, transfer or in any other way disclose Personal Data or any other information relating to the processing of Personal Data to any third party, unless the Data Processor is required to do so by law. The Data Processor shall assist the Data Controller in an appropriate manner to enable him to respond to such a request, complaint, message or other communication in accordance with Applicable Data Protection Legislation. In particular, the Data Processor shall not publish any submissions, notifications, communications, announcements or press releases in the event of a breach of data protection as defined in section 6.3. In the event the Data Processor, according to applicable laws and regulations, is required to disclose Personal Data that the Data Processor processes on behalf of the Data Controller, the Data Processor shall be obliged to inform the Data Controller thereof immediately, unless prohibited by law.

‍

7. The Data Processor is obliged to delete all Personal Data processed under this DPA and destroy all processing results and documents that contain Personal Data within 5 days upon request of the Data Controller. In addition, the Data Controller has the possibilty to delete the Personal Data directly in the software application provided by the Data Processor as follows:

‍

       

4. SUB-PROCESSORS

       

1. The Data Controller grants the Data Processor general authorisation to engage the Sub-processors listed in Appendix 1 and to engage additional Sub-processors or replace existing Sub-processors in accordance with this Section 4.

The Data Processor shall inform the Data Controller in advance of any intended engagement or replacement of a Sub-processor, in principle no later than eight weeks before the relevant Sub-processor commences the processing of Personal Data.

Such information shall be provided in Text Form and shall include at least:

  • the identity and address of the Sub-processor;
  • the purpose and nature of its engagement;
  • the categories of Personal Data affected by the processing;
  • the intended location of processing; and
  • where applicable, information concerning a transfer of Personal Data to a third country and the appropriate safeguards relied upon for such transfer.

The Sub-processors shall be engaged by the Data Processor and shall process Personal Data exclusively on the basis of documented instructions issued to them by the Data Processor.

‍

2. The Data Controller may object to the intended engagement or replacement of a Sub-processor within eight weeks of receipt of the notification in Text Form, provided that the objection is based on objectively justified data protection grounds.

If no objection is raised within this period, the relevant Sub-processor shall be deemed authorised under the general authorisation granted pursuant to Section 4.1.

In the event of a timely and justified objection, the Parties shall cooperate in good faith to find an appropriate solution. In particular, the Data Processor may assess whether the affected processing can be performed without the relevant Sub-processor or by using an alternative Sub-processor.

If no economically and technically reasonable alternative is available to the Data Processor, the Data Processor shall be entitled to discontinue the services affected by the objection or terminate the affected part of the Agreement by giving reasonable notice. If partial termination is not possible or reasonable, either Party may terminate the Agreement in its entirety by giving reasonable notice.

‍

3. The Data Processor shall require each Sub-processor, by means of a contract or another legally binding instrument under Applicable Data Protection Legislation, to comply with data protection obligations that are substantially equivalent to those set out in this DPA.

In particular, the Data Processor shall ensure that each Sub-processor implements appropriate technical and organisational measures, processes Personal Data exclusively on documented instructions, is bound by confidentiality obligations and complies with the requirements of Applicable Data Protection Legislation relating to the security and lawfulness of processing.

‍

‍

       

5. TRANSFER TO THIRD COUNTRIES

       

The Data Processor shall transfer Personal Data to, or make Personal Data accessible from, a country outside the European Economic Area only where the requirements of Chapter V GDPR are fulfilled.

A transfer to a third country shall, in particular, be permitted where:

  • the European Commission has adopted an adequacy decision in respect of the relevant third country;
  • appropriate safeguards pursuant to Article 46 GDPR, in particular the applicable Standard Contractual Clauses adopted by the European Commission, have been implemented;
  • another transfer mechanism permitted under Applicable Data Protection Legislation applies; or
  • the Data Controller has expressly authorised the relevant transfer in Text Form, to the extent such authorisation is legally permissible and sufficient.

Where required, the Data Processor shall implement additional technical, contractual or organisational measures to ensure a level of protection consistent with the GDPR.

Information concerning existing transfers to third countries, the relevant recipient countries and the applicable transfer mechanisms shall be set out in Appendix 1 or in an up-to-date Sub-processor list referred to therein.

‍

       

6. SECURITY OF PROCESSING

       

1. As set forth in Appendix 2, the Data Processor guarantees to implement and uphold appropriate technical and organizational measures according to the current state of the art to ensure an appropriate level of security for the Personal Data and shall continuously review and improve the effectiveness of its security measures. The Data Processor shall protect the Personal Data against destruction, modification, unlawful dissemination, or unlawful loss, alteration or access. The Personal Data shall also be protected against all other forms of unlawful processing. Having regard to the state of the art and the costs of implementation and taking into account the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects, the technical and organizational measures to be implemented by the Data Processor shall include, as appropriate:

  1. the pseudonymization and encryption of Personal Data;
  1. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services processing Personal Data;
  1. the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and
  1. a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

2. The Data Processor shall without undue delay notify the Data Controller of any accidental or unauthorized access or supposed access to Personal Data or any other actual or supposed, threatened or potential security incidents (personal data breach) after becoming aware of such incidents. The notification shall be in Text Form and shall at least:

  1. describe the nature of the Personal Data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned;
  1. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
  1. describe the likely consequences of the personal data breach;
  1. describe the measures taken or proposed to be taken by the Data Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects;
  1. include any other information available to the Data Processor which the Data Controller is required to notify the Data Protection Authorities and/or the data subjects.

3. The Data Processor will furthermore provide reasonable assistance requested by the Data Controller for the Data Controller to investigate the personal data breach and notify it to the Data Protection Authorities and/or the data subjects as required by Applicable Data Protection Legislation.

4. In addition, the Data Processor shall at its own expense immediately take necessary measures to restore and/or reconstruct Personal Data that has been lost, damaged, destroyed or corrupted as a result of the personal data breach.

5. The Data Processor undertakes to not disclose or otherwise make the Personal Data processed under this DPA available to any third party, without the Data Controller’s prior approval in Text Form. This Section 6.5. shall not apply if the Data Processor is required by applicable laws and regulations to disclose Personal Data that the Data Processor processes on behalf of the Data Controller, in which case what is set out in section 3.5 shall apply.

6. The Data Processor undertakes to ensure that access to Personal Data under this DPA is restricted to those of its personnel who directly require access to the Personal Data in order to fulfil the Data Processor’s obligations in accordance with this DPA and the Agreement. The Data Processor shall ensure that such personnel (whether employees or others engaged by the Data Processor) (i) has the necessary knowledge of and training in the Applicable Data Protection Legislation to perform the contracted services; and (ii) is bound by a confidentiality obligation concerning the Personal Data to the same extent as the Data Processor in accordance with this DPA.

7. The Data Processor requires all of its personnel (employees and Sub-processors) authorized to process Personal Data not to process Personal Data for any other purpose, except on instructions from the Data Controller or unless required by applicable law. The Data Processor shall ensure that this confidentiality obligation extends beyond the termination of employment contracts, Sub-processor contracts, service contracts or the termination of this DPA. This confidentiality obligation shall remain in force after the expiry or termination of the DPA. 

‍

 

 

7. INDEMNIFICATION

       

The Data Processor shall indemnify and hold harmless the Data Controller upon the Data Controller’s first demand insofar as third parties (Data Subjects in particular) make claims against the Data Controller on the grounds of an infringement of their personal rights or of data protection law where such infringement is caused by actions of the Data Processor in intentional or gross negligent violation of this DPA. The obligation to indemnify is – except in cases of willful intent or in relation to personal injuries or death – capped with the amount of fees paid by the Data Controller under the Agreement in the 12 months immediately before the infringing incidence.

       

‍

8. TERM

       

1. The term of this DPA in principle follows the above-mentioned Agreement.

2. In case of a termination of the Agreement, this DPA shall remain in force as long as the Data Processor processes Personal Data for the Data Controller.

3. The Data Controller may terminate the Agreement without notice as a result of a breach of the obligations under this DPA by the Data Processor or one of its Sub-processors.

‍

‍

9. NOTICES

       

1. Notices and declarations under this DPA shall be made in Text Form and sent to the contact details most recently notified by the Parties.

Notices may, in particular, be delivered by email, through the customer portal or through a comparable electronic notification system.

Notices to the Data Controller may be validly delivered to:

  • the email address designated by the Data Controller for contractual or data protection matters;
  • a contractual or data protection contact stored by the Data Controller in its customer account; or
  • a user designated by the Data Controller as a contract administrator or otherwise authorised person.

A notice shall be deemed received once it has entered the recipient’s electronic sphere of control and can ordinarily be retrieved. This shall not apply where the sender receives an error message or other indication that delivery has failed.

The Parties shall notify each other in Text Form without undue delay of any changes to their contact or delivery details.

2. In case the Data Processor determines that any instruction to process data of the Data Controller violates Applicable Data Protection Legislation or substantial provisions of this DPA (including technical and organizational measures), it will immediately inform the Data Controller thereof.

3. The Data Controller shall designate to the Data Processor at least one contact person responsible for contractual and data protection matters together with an email address designated for such communications.

The Data Controller shall be responsible for ensuring that the designated person is authorised to receive notices under this DPA. The designation of a contact person shall not, however, automatically authorise that person to accept material contractual amendments or changes to the processing instructions on behalf of the Data Controller.

Any change to the designated contact person or their contact details shall be notified to the Data Processor without undue delay in Text Form.

‍

‍

10. MEASURES  UPON COMPLETION OF PROCESSING OF PERSONAL DATA

       

Upon request by the Data Controller, the Data Processor shall provide a notice in Text Form of the measures taken by itself or its Sub-processors with regard to the deletion or return of the Personal Data upon the completion of the processing.

     

 

11. AMENDMENTS TO THIS DPA

       

Amendments and additions to this DPA shall, as a general rule, require agreement between the Parties in Text Form.

The Data Processor shall be entitled to amend this DPA unilaterally in Text Form where the amendment:

  1. is required due to a change in Applicable Data Protection Legislation or a binding regulatory or court order;
  2. solely serves to correct manifest errors, update contact, company or reference information or provide linguistic clarification; or
  3. does not materially reduce the agreed level of data protection and does not unreasonably prejudice the legitimate interests of the Data Controller.

The Data Processor shall, in principle, inform the Data Controller in Text Form at least eight weeks before the intended effective date of the amendment and shall specify the amendment, its intended effective date and any applicable right to object.

The Data Controller may object to an amendment under paragraph 2 within eight weeks of receipt of the notice in Text Form. If no objection is made within that period, the amendment shall be deemed accepted, provided that the Data Processor expressly informed the Data Controller of this consequence in the amendment notice.

In the event of a timely objection, the previous version of the DPA shall initially remain in force. If it is not legally, technically or economically reasonable for the Data Processor to continue providing the Services under the previous version, either Party shall be entitled to terminate the Agreement or the services affected by the amendment by giving reasonable notice.

Material amendments, including amendments to:

  • the purposes or essential nature of the processing;
  • the categories of Data Subjects or Personal Data;
  • the fundamental responsibilities of the Parties;
  • the Data Controller’s authority to issue instructions;
  • the security requirements, where the level of protection would thereby be materially reduced; or
  • the conditions applicable to transfers to third countries,

shall require the express agreement of both Parties in Text Form.

The engagement or replacement of Sub-processors shall be governed exclusively by Section 4

‍

12. FINAL PROVISIONS

‍

1. This DPA is executed in the German and English languages. Both language versions are intended to reflect the same contractual terms. In the event of any discrepancy or conflict between the language versions, the German version shall prevail.

If the Data Controller and the Data Processor have entered into additional agreements in conflict with this DPA, the provisions of this DPA regarding the processing of Personal Data shall take priority. All other conflicting provisions shall be governed by the provisions of the Agreement.

This DPA, including its Appendices, forms an integral part of the Agreement entered into between the Data Controller and the Data Processor for the provision of the Services.

In the event of any conflict between this DPA and any other contractual documents applicable between the Parties, this DPA shall prevail with respect to the processing of Personal Data.

In all other respects, the provisions of the principal Agreement, including any agreed limitations of liability and other contractual terms, shall remain unaffected unless this DPA expressly provides otherwise or mandatory data protection law requires otherwise.

Each person entering into or accepting this DPA or any amendment to this DPA on behalf of a Party represents that they are legally authorised to represent the relevant Party or have been duly authorised to make the relevant declaration.

Where the DPA or an amendment is entered into or accepted electronically, the Data Processor may generally rely on a person designated by the Data Controller as an authorised representative, contract administrator or expressly authorised person being authorised to make the relevant declaration, unless the Data Processor knows or ought reasonably to know otherwise.

An ordinary user account for the platform shall not, by itself, authorise the relevant user to enter into or accept this DPA or any material amendment to this DPA on behalf of the Data Controller.

‍

2. This DPA is governed by the law of the Republic of Austria to the exclusion of the conflict law rules under private international law and the UN Convention on the International Sale of Goods. In the event of all disputes arising from this DPA – including disputes about its existence or non-existence – the courts with subject-matter jurisdiction at the registered seat of the Data Processor shall be the exclusive forum.

‍

3. If a provision or parts of a provision in this DPA is or becomes ineffective under applicable legislation, this will not affect the effectiveness and validity of the remaining provisions. The contracting parties will replace it by a provision which, in terms of content, is as close as possible to the ineffective provision.

‍

‍

‍

       

Vienna/Wien_________________

___________________________

 

Data  Controller/Verantwortlicher

 

‍

Electronic execution is permitted.

This DPA may also be executed electronically or accepted by means of an electronic declaration made by a duly authorised person. Electronic counterparts and electronically submitted declarations of acceptance shall have the same effect as an originally signed counterpart.

 

‍

APPENDIX 1 – DATA PROCESSING INSTRUCTIONS

           

Purposes

Specify all purposes for which the personal data will be processed by the Data Processor: 

Financial data reporting and analytics.

‍

Categories of data

Specify the different types of Personal Data that will be processed by the Data Processor:

The following Personal Data is processed by default. If the Data Controller intends to process other categories of Personal Data with the Application Services of the Data Processor, the latter must be notified hereof, and an additional agreement must be concluded.

  • Email address
  • Name (on a voluntary basis)
  • Creditors, to the extent that they are natural persons
  • Debtors, to the extent that they are natural persons
  • Other third parties, to the extent that they are natural persons and are referenced in the payment description

Data subjects

Specify the categories of data subjects whose personal data will be processed by the Data Processor:

The following categories of data subjects are affected by the data processing operations by default. If the Data Controller intends to process Personal Data of other categories of data subjects with the Application Services of the Data Processor, the latter must be notified hereof, and an additional agreement must be concluded.

  • Users of the Application Services

Processing operations

Specify all processing activities to be conducted by the Data Processor:

Collect, harmonize, store and analyze data.

‍

Sub-processor(s)

Specify the Sub-processors engaged by the Data Processor (if any) and the purposes for which the personal data is processed by such Sub-processor

Applicable in case of Application Services hosting by Data Processor:

  • Amazon Web Services EMEA SARL (AWS) (Purpose: Cloud infrastructure and hosting of the Helu application, including the storage, processing, and backup of customer and application data; Data hosting: AWS Region Frankfurt, Germany (eu-central-1); Company headquarters: Luxembourg)
  • Google Ireland Limited (Google Workspace) (Purpose: Corporate email services, document management, file storage, collaboration, and internal business communication; Data processed: business contact data, emails, documents, contracts, and operational files; Company headquarters: Dublin, Ireland)
  • Microsoft Ireland Operations Limited / Microsoft Corporation (Purpose: Email, document management, file storage, collaboration, video conferencing, and internal communication through Microsoft 365; European headquarters: Dublin, Ireland)
  • GitHub B.V (Prins Bernhardplein 200, Amsterdam 1097JB, Niederlande), Datenverarbeitung: EU 
  • ClickHouse, Inc. (Purpose: Storage, processing, and analysis of application, usage, and reporting data; Data hosting: AWS Region Frankfurt, Germany (eu-central-1); Company headquarters: United States)
  • Mixpanel, Inc., One Front Street, Floor 28, San Francisco, CA 94111, USA (Purpose: Product analysis / Usage analysis / Event Tracking), Datenhosting: EU Region (EU Data Residency)
  • Product Fruits s.r.o. (Purpose: In-app onboarding, product tours, tooltips, and user guidance within the Helu application; Data hosting: Prague, Czech Republic (EU data hosting, default hosting region: Ireland)
  • Hotjar Ltd. (Purpose: User behavior analytics, website and application usage analysis, heatmaps, session recordings, feedback collection, and user experience optimization within the Helu application; Data hosting: European Union (default hosting region: Ireland; Company headquarters: Malta)
  • HubSpot Ireland Limited / HubSpot, Inc. (Purpose: CRM system, management of customer and prospect data, sales and marketing activities, communication with customers and prospects, and support/ticket management; European headquarters: Dublin, Ireland)
  • Calendly LLC (Purpose: Scheduling and appointment management, booking and coordination of meetings with customers and prospects, sending appointment confirmations and reminders, and integration with calendar and video conferencing systems; registered office: Atlanta, Georgia, USA)
  • Asana, Inc. (Purpose: Project and task management, internal collaboration, coordination and documentation of workflows, and management of project-related customer and company information; registered office: San Francisco, California, USA)
  • Fathom Video Inc. (Purpose: AI-powered recording, transcription, summarization and analysis of online meetings, as well as documentation and follow-up of customer, sales and project meetings; registered office: San Francisco, California, USA)

Purpose: Hosting infrastructure for server and databases.

Applicable in case of Application Services hosting by Data Controller:

‍

Location of Processing Operations

Specify all locations where the Personal Data will be processed by the Data Processor and any Sub-processor (if applicable)

Applicable in case of Application Services hosting by Data Processor:

  • The data will be hosted exclusively on servers located in a data center in the EU or EEA.

At the request of the Data Controller, the specific location will be communicated to the Data Controller.

Applicable in case of Application Services hosting by Data Controller:

  • Austria and Data Processing Service Center of Data Controller.

‍

 

       

APPENDIX 2 – TECHNICAL AND ORGANIZATIONAL MEASURES (“TOMS”)

       

The Data Processor confirms that the implemented technical and organizational measures provide an appropriate level of protection for the Data Controller’s Personal Data considering the risks associated with the processing.

‍

General Description of Measures

Description of Measures Implemented

Access Control (premises)

‍

Preventing unauthorized persons from gaining access to data processing systems

Used hosting provider complies:

  • Access control systems (smart cards, security keys)
  • Right to access generally limited
  • List of authorized people (manager approval required)

‍

Access Control (systems)

Preventing data processing systems from being used without authorization

  • Database security controls restrict access
  • Access rights based on roles and need to know
  • Password policy
  • Automatic blocking of access (e.g. password, timeout)

‍

Access Control (data)

Ensuring that persons entitled to use a data processing system have access only to the data to which they have a right of access, and that Personal Data cannot be read, copied, modified or removed without authorization

  • Access rights based on roles and need to know
  • Approval process for access rights; periodical reviews and audits
  • Signed confidentiality undertakings

‍

Transmission Control

Ensuring that Personal Data cannot be read, copied, modified or removed without authorization during electronic transmission or transport, and that it is possible to review and establish which bodies are to receive the Personal Data

  • Encrypted transfer (HTTPS, SSL, SSH; RSA, 4096-bit keys)
  • Log files

‍

Input Control

Ensuring that it is possible to review and establish whether and by whom Personal Data have been input into data processing systems, modified, or removed

  • Access rights based on roles and need to know
  • Approval process for access rights
  • Log files

‍

Job Control

Ensuring that the Personal Data is processed exclusively in accordance with the instructions

  • Diligently selecting (Sub-)processors and other service providers
  • Documenting selection procedures (privacy and security policies, audit reports, certifications)
  • Backgrounds of service providers are checked, subsequent monitoring
  • Standardized policies and procedures (including clear segregation of responsibilities); documentation of instructions received from data controller
  • Signed confidentiality undertakings

‍

Availability Control

Ensuring that Personal Data is protected from accidental destruction and loss

  • Daily backup procedures
  • Routinely test-running data recovery

‍

Separation Control

Ensuring that data collected for different purposes can be processed separately

  • Separation between productive and test data
  • Detailed management of access rights

‍

 

‍