Data Processing Agreement
The binding Data Processing Agreement has not been published. A signed DPA must be in place before production personal data is processed. This page shows the structure of the agreement; every clause marked [[ to be supplied: … ]] is being drafted and reviewed by counsel. For the current early-access document, contact hello@itsmx.eu.
1. Parties
Processor:
[[ to be supplied: legal entity name ]]
[[ to be supplied: postal address ]]
Commercial register: [[ to be supplied: commercial register entry, or confirmation that none applies ]]
VAT ID: [[ to be supplied: VAT ID, or confirmation that none applies ]]
E-mail: hello@itsmx.eu
Controller: the customer. [[ to be supplied: how the controller is identified in the contract ]]
2. Subject matter and duration
[[ to be supplied: counsel-reviewed clause — subject matter; duration tied to the service agreement ]]
3. Nature and purpose of processing
[[ to be supplied: counsel-reviewed clause — nature and purpose of processing in TENSOR ]]
4. Types of personal data and categories of data subjects
[[ to be supplied: counsel-reviewed clause — data types and data subject categories ]]
5. Obligations and rights of the controller
[[ to be supplied: counsel-reviewed clause — controller obligations and rights ]]
6. Processing only on documented instructions (Art. 28(3)(a) GDPR)
[[ to be supplied: counsel-reviewed clause — processing only on documented instructions ]]
7. Confidentiality of authorised personnel (Art. 28(3)(b) GDPR)
[[ to be supplied: counsel-reviewed clause — confidentiality of authorised personnel ]]
8. Security of processing (Art. 32) — technical and organisational measures (Art. 28(3)(c) GDPR)
[[ to be supplied: counsel-reviewed clause — security of processing (art. 32) — technical and organisational measures ]]
9. Engaging sub-processors (Art. 28(3)(d) GDPR)
The current list of sub-processors is published on the sub-processor page.
[[ to be supplied: counsel-reviewed clause — engaging sub-processors ]]
10. Assistance with data subject requests (Art. 28(3)(e) GDPR)
[[ to be supplied: counsel-reviewed clause — assistance with data subject requests ]]
11. Assistance with Arts. 32–36 (security, breach notification, DPIA) (Art. 28(3)(f) GDPR)
[[ to be supplied: counsel-reviewed clause — assistance with arts. 32–36 (security, breach notification, dpia) ]]
12. Deletion or return of data at the end of the service (Art. 28(3)(g) GDPR)
[[ to be supplied: counsel-reviewed clause — deletion or return of data at the end of the service ]]
13. Information and audits (Art. 28(3)(h) GDPR)
[[ to be supplied: counsel-reviewed clause — information and audits ]]